Communication method and device

By carrying multiple network function types customer authentication certificates in the service consumer network element service request message, the problem of service request failure in indirect communication scenarios is solved, ensuring that the service provider network element can correctly verify the service consumer network element, and effective authentication and service provision are achieved.

CN115396892BActive Publication Date: 2025-08-12HUAWEI TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202110502638.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-05-09
Publication Date
2025-08-12
Estimated Expiration
2041-05-09

AI Technical Summary

Technical Problem

The existing standards do not define how to generate the correct customer authentication certificate (CCA) in different indirect communication scenarios, resulting in the problem that service consumption network element request service may fail.

Method used

The service consumer network element sends a service request message to the service communication agent that includes the customer authentication certificate of the first network function type and the second network function type to ensure that the service provider network element can correctly verify the service consumer network element and thus provide the required services.

Benefits of technology

By carrying customer authentication certificates of multiple network function types, the service communication agent can successfully authenticate the service consumer network element, solve the problem of service request failure in indirect communication scenarios, and realize the effective authentication of the service consumer network element.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115396892B_ABST
    Figure CN115396892B_ABST
Patent Text Reader

Abstract

A communication method and device, which can be used in an indirect communication scenario, includes: a service-consuming network element sends a first service request message to a service communication agent, and the service-consuming network element receives a response message to the first service request message from the service communication agent. The first service request message is used to request a first service from a service-providing network element, and the first service request message includes a first customer authentication credential, and the first customer authentication credential includes a first network function type and a second network function type. The first network function type is the network function type of the service-providing network element, and the second network function type is the network function type of the network element that provides the second service, and the second service is associated with the first service. The above method can ensure that when the service-consuming network element requests a service from the service-providing network element through the service communication agent, the problem of service request failure caused by the CCA only containing the network function type of the service-providing network element is avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of wireless communications, and in particular to a communication method and apparatus. Background Art

[0002] like Figure 1 The figure shows an enhanced service-oriented architecture. In the enhanced service-oriented architecture, network elements can communicate with each other not only directly (referred to as direct communication) but also indirectly (referred to as indirect communication, also referred to as indirect communication). During indirect communication, the two communicating network elements can exchange messages through a service communication proxy (SCP). In direct communication and indirect communication, the two communicating parties are respectively referred to as service consumers and service providers. Consumers refer to the requesters of services or the callers of services, and providers refer to the providers of services. Service consumers are also called service-consuming network elements, and service providers are also called service-providing network elements.

[0003] In indirect communication scenarios, an authentication scheme based on client credentials assertion (CCA) is introduced. The consumer includes CCA in the service request so that the receiving endpoint can authenticate the consumer. In different indirect communication scenarios, the consumer (i.e., the authenticated party) needs to generate the correct CCA so that the receiving endpoint (i.e., the authenticator) can accurately authenticate the consumer and provide the consumer with the requested service if the authentication is successful. However, the existing standards do not define how to generate the correct CCA in different indirect communication scenarios to prevent the service consumption network element from failing to request the service. Summary of the Invention

[0004] The embodiments of the present application provide a communication method and apparatus for improving the situation where a service consuming network element fails to request a service.

[0005] In a first aspect, an embodiment of the present application provides a communication method, the method comprising:

[0006] A service-consuming network element sends a first service request message to a service communication agent, where the first service request message is used to request a first service from a service-providing network element, and the first service request message includes a first customer authentication credential, where the first customer authentication credential is used to authenticate the service-consuming network element, and the first customer authentication credential includes a first network function type and a second network function type, where the first network function type is the network function type of the service-providing network element, and the second network function type is the network function type of the network element providing a second service; wherein the second service is associated with the first service; and the service-consuming network element receives a response message to the first service request message from the service communication agent.

[0007] By adopting the above method, in a scenario where a service-consuming network element requests a first service from a service-consuming network element through a service communication agent, the service-consuming network element carries a customer authentication credential containing both the first network function type and the second network function type in the first service request message sent to the service communication agent. This ensures that when the service communication agent requests a second service, the network element providing the second service successfully authenticates the service-consuming network element, thereby providing a guarantee for the service-consuming network element to request the first service, and solves the problem of failure of the service-consuming network element to request a service due to failure of authentication of the customer authentication credential in an indirect communication scenario.

[0008] In one possible design, the second service is used to provide an access token corresponding to the first service, and the access token corresponding to the first service is used to represent that the service consumption network element has the authority to obtain the first service.

[0009] In one possible design, the service consumption network element determines that there is no available access token corresponding to the first service.

[0010] The above design enables the service consumption network element to generate the first customer authentication credential on demand, thereby preventing the first customer authentication credential from being abused.

[0011] In addition, after the service consuming network element determines that there is no available access token corresponding to the first service, the service consuming network element may carry parameters for obtaining the access token corresponding to the first service in the first service request message.

[0012] In one possible design, the service consumption network element determines that there is no available access token corresponding to the first service, which may include the following situations: the service consumption network element determines that the access token corresponding to the first service is not stored; or the service consumption network element determines that the stored access token corresponding to the first service has expired.

[0013] In one possible design, when the stored access token corresponding to the first service has expired, the service consumption network element deletes the expired access token.

[0014] The above design can release storage space in a timely manner and reduce the storage burden of the system.

[0015] In one possible design, the second service is used to provide information of the service providing network element.

[0016] In one possible design, the service consuming network element determines that the first service request message will trigger the service communication agent to request the second service.

[0017] In one possible design, when the service consumption network element determines that the first service request message will trigger the service communication agent to request the second service, the service consumption network element determines that the first service request message will trigger the service communication agent to request the second service based on one or more of the following: the context of the first terminal device is not stored, and the first terminal device is associated with the first service; or, the context of the first service is not stored; or, the service providing network element belongs to the first slice and the context corresponding to the first slice is not stored; or, the service consumption network element communicates with the service communication agent for the first time.

[0018] In addition, after the service consuming network element determines that the first service request message will trigger the service communication agent to request the second service, the service consuming network element may carry parameters for discovering the service providing network element in the first service request message.

[0019] In one possible design, the service consuming network element determines to use the indirect communication mode of mode D to request the first service.

[0020] For example, when a service-consuming network element communicates with a service communication agent using mode D, as agreed upon in a standard protocol or configured through pre-configuration information, the first service request message always carries client authentication credentials including the first network function type and the second network function type. Alternatively, when the service-consuming network element communicates with the service communication agent using mode D, if it is determined that the first service request message will trigger the service communication agent to request the second service, the first service request message carries client authentication credentials including the first network function type and the second network function type.

[0021] In one possible design, the service consuming network element sends a second service request message to the service communication agent, where the second service request message is used to request the first service, the second service request message includes a second customer authentication credential, the second customer authentication credential includes the first network function type, and the second customer authentication credential is used to authenticate the service consuming network element; the service consuming network element receives a response message to the second service request message from the service communication agent, where the response message to the second service request message includes indication information. When the service consuming network element sends the first service request message to the service communication agent, the service consuming network element sends the first service request message to the service communication agent based on the indication information.

[0022] With the above design, the service consuming network element can send a first service request message to the service communication agent according to the indication information.

[0023] In one possible design, the indication information includes a third customer authentication credential, and the third customer authentication credential includes the second network function type; wherein, the third customer authentication credential is used to authenticate the network element providing the second service; when the service consumption network element sends the first service request message to the service communication agent according to the indication information, if the network element providing the second service is successfully authenticated according to the third customer authentication credential, the service consumption network element sends the first service request message to the service communication agent.

[0024] With the above design, the service-consuming network element can authenticate the network element providing the second service based on the third customer authentication credential, and when the authentication is successful, send a first service request message based on the second network function type included in the third customer authentication credential.

[0025] In one possible design, the network element providing the second service is a network storage function network element.

[0026] In one possible design, the first customer authentication credential also includes one or more of the following: an identifier of the service consumption network element or validity period information, wherein the validity period information is used to represent the validity period of the first customer authentication credential.

[0027] In a second aspect, the present application provides a communication method, which includes: a first network element receives a first service request message from a service communication agent, the first service request message is used to request a first service from the first network element, the first service request message includes a first customer authentication credential, the first customer authentication credential is used to authenticate the service consumption network element, wherein the first customer authentication credential includes multiple network function types; the first network element authenticates the service consumption network element based on the first customer authentication credential, wherein the first network element authenticates the service consumption network element based on the first customer authentication credential, including: the first network element determines whether its own network function type matches one or more of the multiple network function types; the first network element sends a response message to the service communication agent based on the authentication result.

[0028] Using the above method, when the first client authentication credential includes multiple network function types, the first network element determines whether its own network function type matches one or more of the multiple network function types to obtain an authentication result. Therefore, the above method can determine whether authentication of a service-consuming network element is successful when the client authentication credential includes multiple network function types, and further enables network elements with different network function types to authenticate the service-consuming network element using the same client authentication credential.

[0029] In one possible design, when the authentication result is successful authentication, the first network element sends a response message to the service communication agent for the first service request message, and the response message to the first service request message is used to provide the first service; or, when the authentication result is failed authentication, the first network element sends a response message to the service communication agent for the first service request message, and the response message to the first service request message indicates that the request for the first service failed.

[0030] In one possible design, the multiple network function types include a first network function type and a second network function type, the first network function type is the network function type of the first network element, the second network function type is the network function type of the network element providing a second service, and the second service is associated with the first service.

[0031] By adopting the above design, a network element with two different network function types can use the same customer authentication credential to authenticate the service-consuming network element.

[0032] In one possible design, the second service is used to provide an access token corresponding to the first service, wherein the access token corresponding to the first service is used to represent that the service-consuming network element has the authority to obtain the first service; or, the second service is used to provide information about the first network element.

[0033] In one possible design, the network element providing the second service is a network storage function network element.

[0034] In one possible design, the first service is used to provide an access token corresponding to the second service, wherein the access token corresponding to the second service is used to represent that the service consumption network element has the authority to obtain the second service; or, the first service is used to provide information of the second service network element.

[0035] By adopting the above design, a network element with two different network function types can use the same customer authentication credential to authenticate the service-consuming network element.

[0036] In one possible design, the first network element is a network storage function network element.

[0037] In one possible design, the first network element receives a second service request message from the service communication agent, where the second service request message is used to request the first service from the first network element, and the second service request message includes a second customer authentication credential, and the second customer authentication credential includes a third network function type; when the third network function type does not match the network function type of the first network element, the first network element sends a response message to the service communication agent for the second service request message, and the response message to the second service request message includes indication information, wherein the indication information is used to trigger the first service request message.

[0038] With the above design, when the network function type in the customer authentication credential does not match the network function type of the first network element, the first network element can carry indication information in the response message to the second service request message. The indication information can trigger the first service request message, and then obtain the customer authentication credential including the network function type that matches the network function type of the first network element, thereby achieving successful authentication of the service-consuming network element by the first network element.

[0039] In one possible design, the indication information includes a third customer authentication credential for authenticating the first network element, and the third customer authentication credential includes a network function type of the first network element.

[0040] By adopting the above design, the network function type of the first network element can be carried in the indication information, thereby triggering the first customer authentication credential in the first service request message to carry the network function type that matches the network function type of the first network element, so as to achieve successful authentication of the service consumption network element.

[0041] In one possible design, the first customer authentication credential also includes an identifier of the service consumption network element and the validity time information of the first customer authentication credential; the validity time information of the first customer authentication credential is used to characterize the validity time of the first customer authentication credential; the first network element authenticates the service consumption network element based on the first customer authentication credential, and also includes one or more of the following: the first network element verifies whether the signature of the first customer authentication credential is passed, verifies whether the first customer authentication credential is expired based on the validity time information included in the first customer authentication credential, or verifies whether the identifier of the service consumption network element in the first customer authentication credential is the same as the identifier of the network element in the certificate used to sign the first customer authentication credential.

[0042] In a third aspect, the present application provides a communication method, which includes: a service-consuming network element sends a first service request message to a service communication agent, the first service request message is used to request a first service from a service-providing network element, the first service request message includes a fourth customer authentication credential and a fifth customer authentication credential, the fourth customer authentication credential is used by the service-providing network element to authenticate the service-consuming network element, the fifth customer authentication credential is used by the network element providing a second service to authenticate the service-consuming network element, the fourth customer authentication credential includes a first network function type, the fifth customer authentication credential includes a second network function type, the first network function type is the network function type of the service-providing network element, the second network function type is the network function type of the network element providing the second service, wherein the second service is associated with the first service; the service-consuming network element receives a response message to the first service request message from the service communication agent.

[0043] Using the above embodiment, the service-consuming network element sends a first service request message to the service communication agent, wherein the first service request message includes a fourth customer authentication credential and a fifth customer authentication credential, the fourth customer authentication credential includes a first network function type, and the fifth customer authentication credential includes a second network function type, which enables the network element providing the second service to successfully authenticate the service-consuming network element, thereby also providing a guarantee for the service-consuming network element to request the first service, and solves the problem of failure of the service-consuming network element to request a service due to failure of authentication of the customer authentication credential in an indirect communication scenario.

[0044] In one possible design, the fourth customer authentication credential also includes the identifier of the service consumption network element, the validity time information of the fourth customer authentication credential, and the validity time information of the fourth customer authentication credential is used to represent the validity time of the fourth customer authentication credential; the fifth customer authentication credential also includes the identifier of the service consumption network element, the validity time information of the fifth customer authentication credential, and the validity time information of the fifth customer authentication credential is used to represent the validity time of the fifth customer authentication credential.

[0045] In one possible design, the validity period of the fifth customer authentication credential is shorter than the validity period of the fourth customer authentication credential.

[0046] The above design can reduce the risk of the fifth client authentication credential being maliciously used by the service communication agent, thereby ensuring the security of the communication process.

[0047] In one possible design, the validity period of the fourth customer authentication credential is associated with a first duration, which is determined by the transmission delay between the service consumption network element and the service communication agent and the transmission delay between the service communication agent and the network element providing the second service.

[0048] The above configuration rules for the validity period of the fourth and fifth client authentication credentials can ensure that the fourth and fifth client authentication credentials are not maliciously used by the service communication agent, thereby ensuring the security of the communication process.

[0049] In one possible design, the second service is used to provide an access token corresponding to the first service, and the access token corresponding to the first service is used to represent that the service consumption network element has the authority to obtain the first service.

[0050] In one possible design, the service consumption network element determines that there is no available access token corresponding to the first service.

[0051] In addition, after the service consuming network element determines that there is no available access token corresponding to the first service, the service consuming network element may carry parameters for obtaining the access token corresponding to the first service in the first service request message.

[0052] The above design enables the service consumption network element to generate the first customer authentication credential on demand, thereby preventing the first customer authentication credential from being abused.

[0053] In one possible design, the service consumption network element determines that there is no available access token corresponding to the first service, which may include the following situations: the service consumption network element determines that the access token corresponding to the first service is not stored; or the service consumption network element determines that the stored access token corresponding to the first service has expired.

[0054] In one possible design, when the stored access token corresponding to the first service has expired, the service consumption network element deletes the expired access token.

[0055] The above design can release storage space in a timely manner and reduce the storage burden of the system.

[0056] In one possible design, the second service is used to provide information of the service providing network element.

[0057] In one possible design, the service consuming network element determines that the first service request message will trigger the service communication agent to request the second service.

[0058] In one possible design, when the service consumption network element determines that the first service request message will trigger the service communication agent to request the second service, the service consumption network element determines that the first service request message will trigger the service communication agent to request the second service based on one or more of the following: the context of the first terminal device is not stored, and the first terminal device is associated with the first service; or, the context of the first service is not stored; or, the service providing network element belongs to the first slice and the context corresponding to the first slice is not stored; or, the service consumption network element communicates with the service communication agent for the first time.

[0059] In addition, after the service consuming network element determines that the first service request message will trigger the service communication agent to request the second service, the service consuming network element may carry parameters for discovering the service providing network element in the first service request message.

[0060] In one possible design, the service consuming network element determines to use the indirect communication mode of mode D to request the first service.

[0061] For example, when a service-consuming network element communicates with a service communication agent using mode D, as agreed upon in a standard protocol or configured through pre-configuration information, the first service request message always carries client authentication credentials including the first network function type and the second network function type. Alternatively, when the service-consuming network element communicates with the service communication agent using mode D, if it is determined that the first service request message will trigger the service communication agent to request the second service, the first service request message carries client authentication credentials including the first network function type and the second network function type.

[0062] In one possible design, the service consuming network element sends a second service request message to the service communication agent, where the second service request message is used to request the first service, the second service request message includes a second customer authentication credential, the second customer authentication credential includes the first network function type, and the second customer authentication credential is used to authenticate the service consuming network element; the service consuming network element receives a response message to the second service request message from the service communication agent, where the response message to the second service request message includes indication information. When the service consuming network element sends the first service request message to the service communication agent, the service consuming network element sends the first service request message to the service communication agent based on the indication information.

[0063] With the above design, the service consuming network element can send a first service request message to the service communication agent according to the indication information.

[0064] In one possible design, the indication information includes a third customer authentication credential, and the third customer authentication credential includes the second network function type; wherein, the third customer authentication credential is used to authenticate the network element providing the second service; when the service consumption network element sends the first service request message to the service communication agent according to the indication information, if the network element providing the second service is successfully authenticated according to the third customer authentication credential, the service consumption network element sends the first service request message to the service communication agent.

[0065] With the above design, the service-consuming network element can authenticate the network element providing the second service based on the third customer authentication credential, and when the authentication is successful, send a first service request message based on the second network function type included in the third customer authentication credential.

[0066] In one possible design, the network element providing the second service is a network storage function network element.

[0067] In a fourth aspect, the present application provides a communication method, the method comprising: a service communication agent receiving a first service request message from a service consuming network element, the first service request message being used to request a first service from a service providing network element, the first service request message comprising a fourth customer authentication credential and a fifth customer authentication credential, the fourth customer authentication credential being used by the service providing network element to authenticate the service consuming network element, the fifth customer authentication credential being used by the first network element to authenticate the service consuming network element, wherein the fourth customer authentication credential comprises a first network function type, the fifth customer authentication credential comprises a second network function type, the first network function type being the network function type of the service providing network element, and the second network function type being the network function type of the service providing network element. the service communication agent sends a second service request message to the first network element in response to the first service request message, where the second service request message is used to request a second service, and the second service request message includes the fifth client authentication credential; the service communication agent receives a response message to the second service request message from the first network element; and the service communication agent sends a third service request message to the service providing network element based on the response message to the second service request message, where the third service request message is used to request the first service from the service providing network element, and the third service request message includes the fourth client authentication credential.

[0068] Using the above embodiment, the service consuming network element sends a first service request message to the service communication agent, wherein the first service request message includes a fourth customer authentication credential and a fifth customer authentication credential, the fourth customer authentication credential includes a first network function type, and the fifth customer authentication credential includes a second network function type. The service communication agent requests the second service to carry the fifth customer authentication credential, which enables the network element providing the second service to successfully authenticate the service consuming network element. The service communication agent requests the first service to carry the fourth customer authentication credential, which enables the service providing network element to successfully authenticate the service consuming network element, thereby providing a guarantee for the service consuming network element to request the first service, and solving the problem of failure of the service consuming network element to request a service due to failure of authentication of the customer authentication credential in an indirect communication scenario.

[0069] In one possible design, the service communication agent determines that it is necessary to request the second service from the first network element based on the first service request message; the service communication agent determines that the fifth customer authentication credential should be carried in the second service request message based on the network function type of the first network element.

[0070] With the above design, the service communication agent can parse the first service request message and select the fifth customer authentication credential from the fourth customer authentication credential and the fifth customer authentication credential according to the network function type of the first network element to add to the second service request message.

[0071] In one possible design, the service communication agent determines to carry the fourth client authentication credential in the third service request message based on the network function type of the service providing network element.

[0072] With the above design, the service communication agent can parse the first service request message and select the fourth customer authentication credential from the fourth customer authentication credential and the fifth customer authentication credential according to the network function type of the service providing network element to add to the second service request message.

[0073] In one possible design, before the service communication agent receives the first service request message from the service consumption network element, the service communication agent receives a fourth service request message from the service consumption network element, the fourth service request message is used to request the first service, the third service request message includes a sixth customer authentication credential, and the sixth customer authentication credential includes a third network function type; the service communication agent sends a fifth service request message to the first network element, the fifth service request message is used to request the second service, and the fifth service request message includes the sixth customer authentication credential; the service communication agent receives a response message to the fifth service request message from the first network element, and the response message to the fifth service request message includes indication information; the service communication agent sends a response message to the fourth service request message to the service consumption network element according to the indication information.

[0074] With the above design, the service communication agent can send a response message to the service consumption network element for the fourth service request message according to the indication information to obtain a customer authentication credential that matches the network function type of the first network, so that the first network element can successfully authenticate the service consumption network element.

[0075] In one possible design, the indication information includes a seventh customer authentication credential, and the seventh customer authentication credential includes the network function type of the first network element; the response message to the fourth service request message also includes the seventh customer authentication credential.

[0076] With the above design, the indication information can trigger the service consuming network element to send a first service request message, and include a customer authentication credential matching the network function type of the first network in the first service request message.

[0077] In one possible design, the second service is used to provide an access token corresponding to the first service, and the access token corresponding to the first service is used to represent that the service consumption network element has the authority to obtain the first service.

[0078] In one possible design, the service communication agent determines that no available access token corresponding to the first service is stored and the first service request message does not include the access token corresponding to the first service.

[0079] In one possible design, the second service is used to provide information of the service providing network element.

[0080] In one possible design, the service communication agent determines that the information of the service-providing network element is not stored and the first service request message does not include the information of the service-providing network element.

[0081] In one possible design, the fourth customer authentication credential also includes the identifier of the service consumption network element, the validity time information of the fourth customer authentication credential, and the validity time information of the fourth customer authentication credential is used to represent the validity time of the fourth customer authentication credential; the fifth customer authentication credential also includes the identifier of the service consumption network element, the validity time information of the fifth customer authentication credential, and the validity time information of the fifth customer authentication credential is used to represent the validity time of the fifth customer authentication credential.

[0082] In one possible design, the validity period of the fifth customer authentication credential is shorter than the validity period of the fourth customer authentication credential.

[0083] The above design can reduce the risk of the fifth client authentication credential being maliciously used by the service communication agent, thereby ensuring the security of the communication process.

[0084] In one possible design, the validity period of the fourth customer authentication credential is associated with a first duration, which is determined by the transmission delay between the service consumption network element and the service communication agent and the transmission delay between the service communication agent and the network element providing the second service.

[0085] The above configuration rules for the validity period of the fourth and fifth client authentication credentials can ensure that the fourth and fifth client authentication credentials are not maliciously used by the service communication agent, thereby ensuring the security of the communication process.

[0086] In one possible design, the network element providing the second service is a network storage function network element.

[0087] In a fifth aspect, the present application provides a communication method, which includes: a first network element receives a first service request message from a service communication agent, the first service request message is used to request a first service from the first network element, the first service request message includes multiple customer authentication credentials; each customer authentication credential includes a network function type; the first network element authenticates the service consumption network element based on the multiple customer authentication credentials; wherein, when the first network element authenticates the service consumption network element based on the multiple customer authentication credentials, the first network element determines whether there is one or more customer authentication credentials among the multiple customer authentication credentials that successfully authenticate the service consumption network element; the first network element sends a response message to the service communication agent based on the authentication result for the first service request message.

[0088] Using the above method, when the first service request message includes multiple client authentication credentials, the first network element determines whether one or more client authentication credentials successfully authenticate the service consuming network element and obtains an authentication result. Therefore, the above method can determine whether authentication of the service consuming network element is successful when multiple client authentication credentials are present.

[0089] In one possible design, when the authentication result indicates that one or more customer authentication credentials have successfully authenticated the service consumption network element, the first network element sends a response message to the service communication agent for the first service request message, and the response message to the first service request message is used to provide the first service; or, when the authentication result indicates that any one of the multiple customer authentication credentials has failed to authenticate the service consumption network element, the first network element sends a response message to the service communication agent for the first service request message, and the response message to the first service request message indicates that the request for the first service has failed.

[0090] With the above design, when one or more customer authentication credentials successfully authenticate the service consumption network element, it is determined that the authentication of the service consumption network element is successful. When any one of the multiple customer authentication credentials fails to authenticate the service consumption network element, that is, all customer authentication credentials fail to authenticate the service consumption network element, it is determined that the authentication of the service consumption network element has failed.

[0091] In one possible design, the multiple customer authentication credentials include a fourth customer authentication credential and a fifth customer authentication credential, the fourth customer authentication credential includes a first network function type, the fifth customer authentication credential includes a second network function type, the first network function type is the network function type of the first network element, the second network function type is the network function type of the network element providing a second service, and the second service is associated with the first service.

[0092] In one possible design, the second service is used to provide an access token corresponding to the first service, wherein the access token corresponding to the first service is used to represent that the service-consuming network element has the authority to obtain the first service; or, the second service is used to provide information about the first network element.

[0093] In one possible design, the network element providing the second service is a network storage function network element.

[0094] In one possible design, the first service is used to provide an access token corresponding to the second service, wherein the access token corresponding to the second service is used to represent that the service consumption network element has the authority to obtain the second service; or, the first service is used to provide information of the second service network element.

[0095] In one possible design, the first network element is a network storage function network element.

[0096] In one possible design, the first network element receives a second service request message from the service communication agent, where the second service request message is used to request the first service from the first network element, and the second service request message includes a sixth customer authentication credential, and the sixth customer authentication credential includes a third network function type; when the third network function type does not match the network function type of the first network element, the first network element sends a response message to the service communication agent for the third service request message, and the response message to the third service request message includes indication information, wherein the indication information is used to trigger the first service request message.

[0097] With the above design, when the network function type in the customer authentication credential does not match the network function type of the first network element, the first network element can carry indication information in the response message to the third service request message. The indication information can trigger the first service request message, and then obtain the customer authentication credential including the network function type that matches the network function type of the first network element, thereby achieving successful authentication of the service consumption network element by the first network element.

[0098] In one possible design, the indication information includes a seventh customer authentication credential for authenticating the first network element, and the seventh customer authentication credential includes a network function type of the first network element.

[0099] By adopting the above design, the network function type of the first network element can be carried in the indication information, thereby triggering the first customer authentication credential in the first service request message to carry the customer authentication credential of the network function type that matches the network function type of the first network element, so as to achieve successful authentication of the service consumption network element.

[0100] In a sixth aspect, the present application provides a communication method, which is applied to a scenario in which a service-consuming network element requests a first service from a service-providing network element through a service communication agent, the method comprising: the service communication agent sends a customer authentication credential request message to the service-consuming network element; the customer authentication credential request message is used to request a first customer authentication credential, and the first customer authentication credential is used to provide a second service network element to authenticate the service-consuming network element, and the second service is associated with the first service; the service communication agent receives a response message to the customer authentication credential request message from the service-consuming network element, and the response message to the customer authentication credential request message includes the first customer authentication credential, and the first customer authentication credential includes a first network function type and a second network function type, or the first customer authentication credential includes a second network function type, and the first network function type is the network function type of the service-providing network element, and the second network function type is the network function type of the network element providing the second service.

[0101] With the above design, the service communication agent can request the client authentication credential, thereby ensuring that the service communication agent requests the second service and the service consuming network element requests the first service.

[0102] In one possible design, before the service communication agent sends a customer authentication credential request message to the service consumption network element, the service communication agent receives a first service request message from the service consumption network element, the first service request message is used to request the first service, the first service request message includes a second customer authentication credential, and the second customer authentication credential includes the first network function type; the service communication agent sends a second service request message to the first network element, the second service request message is used to request the second service, and the second service request message includes the second customer authentication credential; the service communication agent receives a response message to the second service request message from the first network element, and the response message to the second service request message includes indication information; when the service communication agent sends a customer authentication credential request message to the service consumption network element, the service communication agent sends the customer authentication credential request message to the service consumption network element according to the indication information.

[0103] With the above design, when the network function type in the customer authentication credential does not match the network function type of the first network element, the first network element can carry indication information in the response message to the second service request message. The indication information can trigger the customer authentication credential request message, and then obtain the customer authentication credential including the network function type that matches the network function type of the first network element, thereby achieving successful authentication of the service consumption network element by the first network element.

[0104] In one possible design, the indication information includes a third customer authentication credential, and the third customer authentication credential includes the network function type of the first network element; the customer authentication credential request message includes the third customer authentication credential.

[0105] By adopting the above design, the network function type of the first network element can be carried in the indication information, thereby triggering the first customer authentication credential in the first service request message to carry the customer authentication credential of the network function type that matches the network function type of the first network element, so as to achieve successful authentication of the service consumption network element.

[0106] In one possible design, the first customer authentication credential includes the second network function type; the service communication agent sends a third service request message to the first network element, the third service request message is used to request the second service, and the third service request message includes the first customer authentication credential; the service communication agent receives a response message to the third service request message from the first network element; the service communication agent sends a fourth service request message to the service providing network element based on the response message to the third service request message, the fourth service request message is used to request the first service, and the fourth service request message includes the second customer authentication credential.

[0107] Using the above design, the service communication agent parses the response message for the customer authentication credential, carries the first customer authentication credential in the third service request message according to the network function type of the first network element, and carries the second customer authentication credential in the fourth service request message according to the network function type of the service providing network element.

[0108] In one possible design, the first customer authentication credential includes the first network function type and the second network function type; the service communication agent sends a third service request message to the first network element, the third service request message is used to request the second service, and the third service request message includes the first customer authentication credential; the service communication agent receives a response message to the third service request message from the first network element; the service communication agent sends a fourth service request message to the service providing network element based on the response message to the third service request message, the fourth service request message is used to request the first service, and the fourth service request message includes the first customer authentication credential, or the fourth service request message includes the second customer authentication credential.

[0109] Using the above design, the service communication agent parses the response message for the customer authentication credential, carries the first customer authentication credential in the third service request message according to the network function type of the first network element, and carries the first customer authentication credential or the second customer authentication credential in the fourth service request message according to the network function type of the service providing network element.

[0110] In one possible design, the second service is used to provide an access token corresponding to the first service, and the access token corresponding to the first service is used to represent that the service consumption network element has the authority to obtain the first service.

[0111] In one possible design, the service communication agent determines that the first access token is not stored and the first service request message does not include the first access token.

[0112] In one possible design, the second service is used to provide information of the service providing network element.

[0113] In one possible design, the service communication agent determines that the information of the service-providing network element is not stored and the first service request message does not include the information of the service-providing network element.

[0114] In one possible design, the network element providing the second service is a network storage function network element.

[0115] In the seventh aspect, the present application provides a communication device, which includes a transceiver unit and a processing unit, and the processing unit calls the transceiver unit to execute: sending a first service request message to a service communication agent, the first service request message is used to request a first service from a service providing network element, the first service request message includes a first customer authentication credential, the first customer authentication credential is used to authenticate the device, the first customer authentication credential includes a first network function type and a second network function type, the first network function type is the network function type of the service providing network element, and the second network function type is the network function type of the network element providing the second service; wherein the second service is associated with the first service; receiving a response message to the first service request message from the service communication agent.

[0116] In one possible design, the second service is used to provide an access token corresponding to the first service, and the access token corresponding to the first service is used to indicate that the device has the authority to obtain the first service.

[0117] In one possible design, the processing unit is used to determine that there is no available access token corresponding to the first service.

[0118] In one possible design, the processing unit is used to, when determining that there is no available access token corresponding to the first service, not store the access token corresponding to the first service; or, to determine that the stored access token corresponding to the first service has expired.

[0119] In one possible design, when the stored access token corresponding to the first service has expired, the processing unit is used to delete the expired access token.

[0120] In one possible design, the second service is used to provide information of the service providing network element.

[0121] In one possible design, the processing unit is used to determine that the first service request message will trigger the service communication agent to request the second service.

[0122] In one possible design, when it is determined that the first service request message will trigger the service communication agent to request the second service, the processing unit is used to determine that the first service request message will trigger the service communication agent to request the second service based on one or more of the following: the context of the first terminal device is not stored, and the first terminal device is associated with the first service; or, the context of the first service is not stored; or, the service providing network element belongs to the first slice and the context corresponding to the first slice is not stored; or, the device communicates with the service communication agent for the first time.

[0123] In one possible design, the processing unit is used to determine the indirect communication mode using mode D to request the first service.

[0124] In one possible design, the transceiver unit is configured to: send a second service request message to the service communication agent, the second service request message being used to request the first service, the second service request message including a second client authentication credential, the second client authentication credential including the first network function type, and the second client authentication credential being used to authenticate the device; and receive a response message to the second service request message from the service communication agent, the response message to the second service request message including indication information. When sending the first service request message to the service communication agent, the processing unit is configured to send the first service request message to the service communication agent based on the indication information.

[0125] In one possible design, the indication information includes a third customer authentication credential, and the third customer authentication credential includes the second network function type; wherein the third customer authentication credential is used to authenticate the network element providing the second service; the transceiver unit is used to: when sending the first service request message to the service communication agent according to the indication information, if the network element providing the second service is successfully authenticated according to the third customer authentication credential, send the first service request message to the service communication agent.

[0126] In one possible design, the network element providing the second service is a network storage function network element.

[0127] In one possible design, the first customer authentication credential further includes one or more of the following: an identification of the device or validity time information, wherein the validity time information is used to represent the validity time of the first customer authentication credential.

[0128] In an eighth aspect, the present application provides a communication device, which includes a transceiver unit and a processing unit, wherein the transceiver unit is used to receive a first service request message from a service communication agent, the first service request message is used to request a first service from the device, the first service request message includes a first customer authentication credential, and the first customer authentication credential is used to authenticate a service consumption network element, wherein the first customer authentication credential includes multiple network function types; the processing unit is used to authenticate the service consumption network element based on the first customer authentication credential, wherein when authenticating the service consumption network element based on the first customer authentication credential, the processing unit determines whether its own network function type matches one or more of the multiple network function types; the processing unit calls the transceiver unit to send a response message to the service communication agent based on the authentication result.

[0129] In one possible design, when the authentication result is successful authentication, the transceiver unit is used to send a response message to the service communication agent for the first service request message, and the response message to the first service request message is used to provide the first service; or, when the authentication result is failed authentication, the transceiver unit is used to send a response message to the service communication agent for the first service request message, and the response message to the first service request message indicates that the request for the first service failed.

[0130] In one possible design, the multiple network function types include a first network function type and a second network function type, the first network function type is the network function type of the device, the second network function type is the network function type of a network element providing a second service, and the second service is associated with the first service.

[0131] In one possible design, the second service is used to provide an access token corresponding to the first service, wherein the access token corresponding to the first service is used to represent that the service consumption network element has the authority to obtain the first service; or, the second service is used to provide information about the device.

[0132] In one possible design, the network element providing the second service is a network storage function network element.

[0133] In one possible design, the first service is used to provide an access token corresponding to the second service, wherein the access token corresponding to the second service is used to represent that the service consumption network element has the authority to obtain the second service; or, the first service is used to provide information of the second service network element.

[0134] In one possible design, the device is a network storage function network element.

[0135] In one possible design, the transceiver unit is configured to receive a second service request message from the service communication agent, the second service request message being used to request the first service from the device, the second service request message including a second client authentication credential, the second client authentication credential including a third network function type;

[0136] In the case that the third network function type does not match the network function type of the device, the transceiver unit is used to send a response message to the second service request message to the service communication agent, and the response message to the second service request message includes indication information, wherein the indication information is used to trigger the first service request message.

[0137] In one possible design, the indication information includes a third client authentication credential for authenticating the device, and the third client authentication credential includes a network function type of the device.

[0138] In one possible design, the first customer authentication credential also includes an identifier of the service consumption network element and the validity time information of the first customer authentication credential; the validity time information of the first customer authentication credential is used to characterize the validity time of the first customer authentication credential; the processing unit is used to authenticate the service consumption network element based on the first customer authentication credential, and also includes one or more of the following: verifying whether the signature of the first customer authentication credential is passed, verifying whether the first customer authentication credential is expired based on the validity time information included in the first customer authentication credential, or verifying whether the identifier of the service consumption network element in the first customer authentication credential is the same as the identifier of the network element in the certificate used to sign the first customer authentication credential.

[0139] In the ninth aspect, the present application provides a communication device, which includes a transceiver unit and a processing unit: the processing unit calls the transceiver unit to execute: sending a first service request message to a service communication agent, the first service request message is used to request a first service from a service providing network element, the first service request message includes a fourth customer authentication credential and a fifth customer authentication credential, the fourth customer authentication credential is used by the service providing network element to authenticate the service consuming network element, the fifth customer authentication credential is used by the network element providing a second service to authenticate the service consuming network element, the fourth customer authentication credential includes a first network function type, the fifth customer authentication credential includes a second network function type, the first network function type is the network function type of the service providing network element, the second network function type is the network function type of the network element providing the second service, wherein the second service is associated with the first service; receiving a response message to the first service request message from the service communication agent.

[0140] In one possible design, the fourth customer authentication credential also includes the identifier of the service consumption network element, the validity time information of the fourth customer authentication credential, and the validity time information of the fourth customer authentication credential is used to represent the validity time of the fourth customer authentication credential; the fifth customer authentication credential also includes the identifier of the service consumption network element, the validity time information of the fifth customer authentication credential, and the validity time information of the fifth customer authentication credential is used to represent the validity time of the fifth customer authentication credential.

[0141] In one possible design, the validity period of the fifth customer authentication credential is shorter than the validity period of the fourth customer authentication credential.

[0142] In one possible design, the validity period of the fourth customer authentication credential is associated with a first duration, which is determined by the transmission delay between the service consumption network element and the service communication agent and the transmission delay between the service communication agent and the network element providing the second service.

[0143] In one possible design, the second service is used to provide an access token corresponding to the first service, and the access token corresponding to the first service is used to indicate that the device has the authority to obtain the first service.

[0144] In one possible design, the processing unit is used to determine that there is no available access token corresponding to the first service.

[0145] In one possible design, the processing unit is used to, when determining that there is no available access token corresponding to the first service, not store the access token corresponding to the first service; or, to determine that the stored access token corresponding to the first service has expired.

[0146] In one possible design, when the stored access token corresponding to the first service has expired, the processing unit is used to delete the expired access token.

[0147] In one possible design, the second service is used to provide information of the service providing network element.

[0148] In one possible design, the processing unit is used to determine that the first service request message will trigger the service communication agent to request the second service.

[0149] In one possible design, when it is determined that the first service request message will trigger the service communication agent to request the second service, the processing unit is used to determine that the first service request message will trigger the service communication agent to request the second service based on one or more of the following: the context of the first terminal device is not stored, and the first terminal device is associated with the first service; or, the context of the first service is not stored; or, the service providing network element belongs to the first slice and the context corresponding to the first slice is not stored; or, the device communicates with the service communication agent for the first time.

[0150] In one possible design, the processing unit is used to determine the indirect communication mode using mode D to request the first service.

[0151] In one possible design, the transceiver unit is configured to: send a second service request message to the service communication agent, the second service request message being used to request the first service, the second service request message including a second client authentication credential, the second client authentication credential including the first network function type, and the second client authentication credential being used to authenticate the device; and receive a response message to the second service request message from the service communication agent, the response message to the second service request message including indication information. When sending the first service request message to the service communication agent, the processing unit is configured to send the first service request message to the service communication agent based on the indication information.

[0152] In one possible design, the indication information includes a third customer authentication credential, and the third customer authentication credential includes the second network function type; wherein the third customer authentication credential is used to authenticate the network element providing the second service; the transceiver unit is used to: when sending the first service request message to the service communication agent according to the indication information, if the network element providing the second service is successfully authenticated according to the third customer authentication credential, send the first service request message to the service communication agent.

[0153] In one possible design, the network element providing the second service is a network storage function network element.

[0154] In one possible design, the first customer authentication credential further includes one or more of the following: an identification of the device or validity time information, wherein the validity time information is used to represent the validity time of the first customer authentication credential.

[0155] In a tenth aspect, the present application provides a communication device, the device comprising a transceiver unit and a processing unit, the processing unit calling the transceiver unit to execute: receiving a first service request message from a service consuming network element, the first service request message being used to request a first service from a service providing network element, the first service request message comprising a fourth customer authentication credential and a fifth customer authentication credential, the fourth customer authentication credential being used by the service providing network element to authenticate the service consuming network element, the fifth customer authentication credential being used by the first network element to authenticate the service consuming network element, wherein the fourth customer authentication credential comprises a first network function type, the fifth customer authentication credential comprises a second network function type, the first network function type type is the network function type of the service providing network element, and the second network function type is the network function type of the first network element; in response to the first service request message, a second service request message is sent to the first network element, the second service request message is used to request a second service, and the second service request message includes the fifth customer authentication credential; a response message to the second service request message from the first network element is received; according to the response message to the second service request message, a third service request message is sent to the service providing network element, the third service request message is used to request the first service from the service providing network element, and the third service request message includes the fourth customer authentication credential.

[0156] In one possible design, the processing unit is used to determine, based on the first service request message, that it is necessary to request the second service from the first network element; and to determine, based on the network function type of the first network element, to carry the fifth customer authentication credential in the second service request message.

[0157] In one possible design, the processing unit is used to determine whether to carry the fourth customer authentication credential in the third service request message based on the network function type of the service providing network element.

[0158] In one possible design, before receiving the first service request message from the service consumption network element, the transceiver unit is used to receive a fourth service request message from the service consumption network element, the fourth service request message is used to request the first service, the third service request message includes a sixth customer authentication credential, and the sixth customer authentication credential includes a third network function type; send a fifth service request message to the first network element, the fifth service request message is used to request the second service, and the fifth service request message includes the sixth customer authentication credential; receive a response message to the fifth service request message from the first network element, the response message to the fifth service request message includes indication information; and send a response message to the fourth service request message to the service consumption network element according to the indication information.

[0159] In one possible design, the indication information includes a seventh customer authentication credential, and the seventh customer authentication credential includes the network function type of the first network element; the response message to the fourth service request message also includes the seventh customer authentication credential.

[0160] In one possible design, the second service is used to provide an access token corresponding to the first service, and the access token corresponding to the first service is used to represent that the service consumption network element has the authority to obtain the first service.

[0161] In one possible design, the processing unit is used to determine that an available access token corresponding to the first service is not stored and the first service request message does not include the access token corresponding to the first service.

[0162] In one possible design, the second service is used to provide information of the service providing network element.

[0163] In one possible design, the processing unit is used to determine that the information of the service providing network element is not stored and the first service request message does not include the information of the service providing network element.

[0164] In one possible design, the fourth customer authentication credential also includes the identifier of the service consumption network element, the validity time information of the fourth customer authentication credential, and the validity time information of the fourth customer authentication credential is used to represent the validity time of the fourth customer authentication credential; the fifth customer authentication credential also includes the identifier of the service consumption network element, the validity time information of the fifth customer authentication credential, and the validity time information of the fifth customer authentication credential is used to represent the validity time of the fifth customer authentication credential.

[0165] In one possible design, the validity period of the fifth customer authentication credential is shorter than the validity period of the fourth customer authentication credential.

[0166] In one possible design, the validity period of the fourth customer authentication credential is associated with a first duration, which is determined by the transmission delay between the service consumption network element and the service communication agent and the transmission delay between the service communication agent and the network element providing the second service.

[0167] In one possible design, the network element providing the second service is a network storage function network element.

[0168] On the eleventh aspect, the present application provides a communication device, which includes a transceiver unit and a processing unit, and the processing unit calls the transceiver unit to execute: receiving a first service request message from a service communication agent, the first service request message is used to request a first service from the first network element, the first service request message includes multiple customer authentication credentials; each customer authentication credential includes a network function type; the first network element authenticates the service consumption network element based on the multiple customer authentication credentials; wherein, the first network element authenticates the service consumption network element based on the multiple customer authentication credentials, including: the first network element determines whether there is one or more customer authentication credentials among the multiple customer authentication credentials that successfully authenticate the service consumption network element; the first network element sends a response message to the service communication agent based on the authentication result to the first service request message.

[0169] In one possible design, when the authentication result indicates that one or more customer authentication credentials have successfully authenticated the service consumption network element, the first network element sends a response message to the service communication agent for the first service request message, and the response message to the first service request message is used to provide the first service; or, when the authentication result indicates that any one of the multiple customer authentication credentials has failed to authenticate the service consumption network element, the first network element sends a response message to the service communication agent for the first service request message, and the response message to the first service request message indicates that the request for the first service has failed.

[0170] In one possible design, the multiple customer authentication credentials include a fourth customer authentication credential and a fifth customer authentication credential, the fourth customer authentication credential includes a first network function type, the fifth customer authentication credential includes a second network function type, the first network function type is the network function type of the first network element, the second network function type is the network function type of the network element providing a second service, and the second service is associated with the first service.

[0171] In one possible design, the second service is used to provide an access token corresponding to the first service, wherein the access token corresponding to the first service is used to represent that the service-consuming network element has the authority to obtain the first service; or, the second service is used to provide information about the first network element.

[0172] In one possible design, the network element providing the second service is a network storage function network element.

[0173] In one possible design, the first service is used to provide an access token corresponding to the second service, wherein the access token corresponding to the second service is used to represent that the service consumption network element has the authority to obtain the second service; or, the first service is used to provide information of the second service network element.

[0174] In one possible design, the first network element is a network storage function network element.

[0175] In one possible design, the transceiver unit is configured to receive a second service request message from the service communication agent, the second service request message being used to request the first service from the first network element, the second service request message including a sixth client authentication credential, the sixth client authentication credential including a third network function type;

[0176] In the case that the third network function type does not match the network function type of the first network element, the transceiver unit is used to send a response message to the second service request message to the service communication agent, and the response message to the second service request message includes indication information, wherein the indication information is used to trigger the first service request message.

[0177] In one possible design, the indication information includes a seventh customer authentication credential for authenticating the first network element, and the seventh customer authentication credential includes a network function type of the first network element.

[0178] In the twelfth aspect, the present application provides a communication device, which includes a transceiver unit and a processing unit. A service consuming network element requests a first service from a service providing network element through the device, and the processing unit calls the transceiver unit to execute: sending a customer authentication credential request message to the service consuming network element; the customer authentication credential request message is used to request a first customer authentication credential, and the first customer authentication credential is used to provide a second service network element to authenticate the service consuming network element, and the second service is associated with the first service; receiving a response message to the customer authentication credential request message from the service consuming network element, and the response message to the customer authentication credential request message includes the first customer authentication credential, and the first customer authentication credential includes a first network function type and a second network function type, or the first customer authentication credential includes a second network function type, and the first network function type is the network function type of the service providing network element, and the second network function type is the network function type of the network element providing the second service.

[0179] In one possible design, before sending a customer authentication credential request message to the service consumption network element, the transceiver unit is used to receive a first service request message from the service consumption network element, where the first service request message is used to request the first service, the first service request message includes a second customer authentication credential, and the second customer authentication credential includes the first network function type; send a second service request message to the network element providing the second service, where the second service request message is used to request the second service, and the second service request message includes the second customer authentication credential; receive a response message to the second service request message from the network element providing the second service, where the response message to the second service request message includes indication information; and when sending a customer authentication credential request message to the service consumption network element, send the customer authentication credential request message to the service consumption network element according to the indication information.

[0180] In one possible design, the indication information includes a third customer authentication credential, and the third customer authentication credential includes the network function type of the first network element; the customer authentication credential request message includes the third customer authentication credential.

[0181] In one possible design, the first customer authentication credential includes the second network function type; the service communication agent sends a third service request message to the first network element, the third service request message is used to request the second service, and the third service request message includes the first customer authentication credential; the service communication agent receives a response message to the third service request message from the first network element; the service communication agent sends a fourth service request message to the service providing network element based on the response message to the third service request message, the fourth service request message is used to request the first service, and the fourth service request message includes the second customer authentication credential.

[0182] In one possible design, the first customer authentication credential includes the first network function type and the second network function type; the transceiver unit is used to send a third service request message to the first network element, the third service request message is used to request the second service, and the third service request message includes the first customer authentication credential; receive a response message to the third service request message from the first network element; and send a fourth service request message to the service providing network element based on the response message to the third service request message, the fourth service request message is used to request the first service, and the fourth service request message includes the first customer authentication credential, or the fourth service request message includes the second customer authentication credential.

[0183] In one possible design, the second service is used to provide an access token corresponding to the first service, and the access token corresponding to the first service is used to represent that the service consumption network element has the authority to obtain the first service.

[0184] In one possible design, before sending a customer authentication credential request message to the service consuming network element, the processing unit is configured to determine that the first access token is not stored and the first service request message does not include the first access token.

[0185] In one possible design, the second service is used to provide information of the service providing network element.

[0186] In one possible design, before sending a customer authentication credential request message to the service consuming network element, the processing unit is used to determine that the information of the service providing network element is not stored and the first service request message does not include the information of the service providing network element.

[0187] In one possible design, the network element providing the second service is a network storage function network element.

[0188] In a thirteenth aspect, the present application further provides a communication device. The device can execute the above-mentioned method design. The device can be a chip or circuit capable of executing the functions corresponding to the above-mentioned method, or a device including the chip or circuit.

[0189] In one possible implementation, the apparatus includes: a memory for storing computer-executable program code; and a processor coupled to the memory. The program code stored in the memory includes instructions, and when the processor executes the instructions, the apparatus or a device equipped with the apparatus performs the method of any possible design of the first to sixth aspects described above.

[0190] The device may further include a communication interface, which may be a transceiver, or, if the device is a chip or a circuit, the communication interface may be an input / output interface of the chip, such as an input / output pin.

[0191] In one possible design, the device includes corresponding functional units for implementing the steps in the above method. The functions can be implemented by hardware or by hardware executing corresponding software implementations. The hardware or software includes one or more units corresponding to the above functions.

[0192] In the fourteenth aspect, an embodiment of the present application provides a computer-readable storage medium, which stores a computer program. When the computer program runs on a device, it executes a method in any possible design of the first to sixth aspects.

[0193] In a fifteenth aspect, an embodiment of the present application provides a computer program product, which includes a computer program. When the computer program runs on a device, it executes a method in any possible design of aspects 1 to 6.

[0194] In the sixteenth aspect, the present application provides a communication chip having stored therein instructions, which, when executed on a communication device, enables the communication chip to execute a method in any possible design of the first to sixth aspects above. BRIEF DESCRIPTION OF THE DRAWINGS

[0195] Figure 1 A schematic diagram of the architecture of a mobile communication system used in the embodiments of the present application;

[0196] Figure 2 Schematic diagram of the indirect communication mode of mode C in an embodiment of the present application;

[0197] Figure 3 Schematic diagram of the indirect communication mode of mode D in an embodiment of the present application;

[0198] Figure 4 This is a schematic diagram of the NF service consumer directly interacting with the NRF in the indirect communication mode of Mode C in an embodiment of the present application;

[0199] Figure 5 This is a schematic diagram of the interaction between the NF service consumer and the NRF through the SCP in the indirect communication mode of mode C in an embodiment of the present application;

[0200] Figure 6 This is a schematic diagram of an NF service consumer interacting with an NRF through an SCP in the indirect communication mode of mode D in an embodiment of the present application;

[0201] Figure 7 This is the second schematic diagram of the interaction between the NF service consumer and the NRF through the SCP in the indirect communication mode of mode D in an embodiment of the present application;

[0202] Figure 8 This is one of the flow charts summarizing a communication method in an embodiment of the present application;

[0203] Figure 9 This is a specific process in which a service consumption network element sends a first service request message to a service communication agent according to instruction information in an embodiment of the present application;

[0204] Figure 10 This is a second flow chart outlining a communication method in an embodiment of the present application;

[0205] Figure 11 This is a third flow chart outlining a communication method in an embodiment of the present application;

[0206] Figure 12 This is a fourth flow chart outlining a communication method in an embodiment of the present application;

[0207] Figure 13 This is one of the flowcharts of an NF service consumer obtaining a first service when it is determined that a first service needs to be requested and there is no available access token corresponding to the first service in an embodiment of the present application;

[0208] Figure 14 This is the second flowchart of an NF service consumer obtaining the first service when it is determined that the first service needs to be requested and there is no available access token corresponding to the first service in an embodiment of the present application;

[0209] Figure 15 This is the third flowchart of an NF service consumer obtaining the first service when it is determined that the first service needs to be requested and there is no available access token corresponding to the first service in an embodiment of the present application;

[0210] Figure 16 This is a flowchart of an NF service consumer acquiring a first service when it is determined that a first service needs to be requested and there is an available access token corresponding to the first service in an embodiment of the present application;

[0211] Figure 17 One of the flow charts of an NF service consumer obtaining the first service when the first service needs to be requested and the request for the first service triggers the SCP to request parameters of the NF service producer in an embodiment of the present application;

[0212] Figure 18 This is the second flowchart of the NF service consumer obtaining the first service when the first service needs to be requested and the request for the first service triggers the SCP to request parameters of the NF service producer in an embodiment of the present application;

[0213] Figure 19 This is a flowchart of an NF service consumer sending a service request message to an SCP according to instruction information to obtain a first service in an embodiment of the present application;

[0214] Figure 20 This is a flow chart of an NF service consumer acquiring a first service when an SCP proactively requests a client authentication credential in an embodiment of the present application;

[0215] Figure 21 This is one of the structural diagrams of a communication device in an embodiment of the present application;

[0216] Figure 22 This is the second structural diagram of a communication device in an embodiment of the present application. DETAILED DESCRIPTION

[0217] The technical solutions in the embodiments of the present application will be described clearly and completely below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, not all of the embodiments. The terms "first", "second" and corresponding terminology labels in the specification and claims of this application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the terms used in this way are interchangeable where appropriate, and this is merely a way of distinguishing objects of the same properties when describing the embodiments of the present application. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, so that a process, method, system, product or device that includes a series of units is not necessarily limited to those units, but may include other units that are not clearly listed or inherent to these processes, methods, products or devices.

[0218] In the description of this application, unless otherwise specified, " / " means or, for example, A / B can mean A or B; "and / or" in this application is merely a description of the association relationship of associated objects, indicating that there can be three relationships, for example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, in the description of this application, "at least one" refers to one or more items, and "multiple items" refers to two or more items. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, c can be single or multiple.

[0219] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as: Wideband Code Division Multiple Access (WCDMA) system, general packet radio service (GPRS), long term evolution (LTE) system, LTE frequency division duplex (FDD) system, LTE time division duplex (TDD), universal mobile telecommunication system (UMTS), world-wide interoperability for microwave access (WiMAX) communication system, fifth generation (5G) system or future sixth generation communication system, etc.

[0220] In order to facilitate understanding of the embodiments of the present application, Figure 1 The enhanced service-oriented architecture shown in the figure is used as an example to illustrate the application scenario used in this application. Specifically, the enhanced service-oriented architecture may include but is not limited to the following devices:

[0221] 1. Session Management Network Element: Mainly used for session management, allocation and management of Internet Protocol (IP) addresses for terminal devices, selection of endpoints for manageable user equipment plane functions, policy control, or charging function interfaces, and downlink data notification. In 5G communications, the session management network element can be a session management function (SMF) network element. In future communications such as 6G communications, the session management function network element can still be an SMF network element or have other names, which are not limited in this application. Nsmf is a service-based interface provided by SMF. SMF can communicate with other network functions through Nsmf.

[0222] 2. Access management network element: mainly used for mobility management and access management, etc., and can be used to implement other functions of the mobility management entity (MME) except session management, such as lawful interception, or access authorization (or authentication) and other functions. In 5G communications, the access management network element can be an access management function (AMF) network element. In future communications such as 6G communications, the access management network element can still be an AMF network element, or have other names, which is not limited in this application. Namf is a service-based interface provided by AMF. AMF can communicate with other network functions through Namf.

[0223] 3. Authentication service network element: Mainly used for user authentication, etc. In 5G communications, the authentication service network element can be an authentication server function (AUSF) network element. In future communications such as 6G communications, the authentication service network element can still be an AUSF network element, or have other names, which are not limited by this application. Nausf is a service-based interface provided by AUSF, and AUSF can communicate with other network functions through Nausf.

[0224] 4. Network Exposure Element: This element is used to securely expose services and capabilities provided by 3rd Generation Partnership Project (3GPP) network functions to the outside world. In 5G communications, the Network Exposure Element may be a Network Exposure Function (NEF) element. In future communications, such as 6G communications, the Network Exposure Function element may still be an NEF element, or may have other names, which are not limited in this application. Nnef is a service-based interface provided by the NEF, through which the NEF can communicate with other network functions.

[0225] 5. Network Storage Element: This element provides service registration, discovery, and authorization, and maintains information about available network function (NF) instances. This enables on-demand configuration of network functions and services, as well as interconnection between NFs. Service registration means that NFs must register with the network storage element before they can provide services. Service discovery means that when an NF requires services from other NFs, it must first perform service discovery through the network storage element to discover the desired NF. For example, when NF 1 requires services from NF 2, it must first perform service discovery through the network storage element to discover NF 2. Service authorization means that when an NF requires services from other NFs, it must first obtain authorization information from the network storage element, and then use this information to obtain services provided by the other NF. For example, before NF 1 requests services from NF 2, it first requests authorization information for accessing NF 2 from the network storage element. NF 1 then uses the obtained authorization information to request services from NF 2. In 5G communications, the network storage network element may be a network repository function (NRF) network element. In future communications such as 6G communications, the network storage function network element may still be an NRF network element, or have other names, which are not limited in this application. Nnrf is a service-based interface provided by NRF, and NRF can communicate with other network functions through Nnrf.

[0226] 6. Policy control network element: A unified policy framework used to guide network behavior, providing policy rule information for control plane function network elements (such as AMF, SMF, etc.). In 5G communications, the policy control network element can be a policy control function (PCF) network element. In future communications such as 6G communications, the policy control function network element can still be an NEF network element, or have other names, which are not limited in this application. Among them, Npcf is a service-based interface provided by PCF, and PCF can communicate with other network functions through Npcf.

[0227] 7. Data Management NE: This element is used to process user identification, access authentication, registration, or mobility management. In 5G communications, the data management NE may be a unified data management (UDM) NE. In future communications, such as 6G communications, the data management NE may still be a UDM NE, or may have other names, which are not limited in this application. Nudm is a service-based interface provided by UDM, through which UDM can communicate with other network functions.

[0228] 8. Application Network Element: This element is used for routing application-affected data, accessing network open functions, or interacting with the policy framework for policy control. In 5G communications, an application network element may be an application function (AF) network element. In future communications such as 6G communications, the application network element may still be an AF network element or have other names, which are not limited in this application. Naf is a service-based interface provided by the AF. The AF can communicate with other network functions through Naf.

[0229] 9. User equipment (UE): This includes various handheld devices with wireless communication capabilities, vehicle-mounted devices, wearable devices, computing devices, or other processing devices connected to a wireless modem, as well as various forms of terminals, including mobile stations (MS), terminals, user equipment (UE), and soft terminals, such as water meters, electricity meters, and sensors.

[0230] 10. Radio access network (R)AN element: This element provides network access for authorized user devices in a specific area and can use transmission tunnels of different qualities based on the level of the user device and service requirements.

[0231] RAN can manage wireless resources, provide access services for terminal devices, and then complete the forwarding of control signals and user equipment data between the terminal and the core network. RAN can also be understood as the base station in the traditional network.

[0232] 11. User plane function (UPF) network element: used for packet routing and forwarding, or quality of service (QoS) processing of user plane data. In 5G communications, the user plane network element may be a user plane function (UPF) network element. In future communications such as 6G communications, the user plane network element may still be a UPF network element or have other names, which is not limited in this application.

[0233] 12. Data network (DN) element: A network used to transmit data, such as the Internet. A DN element can be a data network authentication, authorization, and accounting function, or an application server.

[0234] 13. SCP: used to complete the routing and forwarding of service-oriented interface messages. It can also be understood that SCP can provide routing and forwarding services for the sender of service-oriented interface signaling. For example, when AMF requests SMF to establish a session, AMF sends a session establishment request message to SCP, which then sends the session establishment request message to SMF. SMF determines whether to respond to the session establishment request message. If SMF sends a session establishment response message to SCP, SCP sends the session establishment response message to AMF. If SMF sends a session establishment rejection message to SCP, SCP sends the session establishment rejection message to AMF. Messages exchanged between AMF and SMF can pass through one hop SCP or multiple hop SCPs.

[0235] It is understood that the above functions or network elements can be network elements in hardware devices, software functions running on dedicated hardware, or virtualized functions instantiated on a platform (e.g., a cloud platform). The application scenarios of the embodiments of the present application are not limited to these, and any network architecture that can implement the above-mentioned network functions is applicable to the embodiments of the present application.

[0236] It should be noted that the consumer, service-consuming network element, and NF service consumer in the following content refer to the same type of network element, while the provider, service-providing network element, and NF service producer refer to the same type of network element. The following embodiments of this application assume that the local operator's policy instructs the NF service consumer to send a service request message to the SCP with a CCA. For example, the local operator's policy may configure the NF service consumer to generate a CCA when using indirect communication, which is used to authenticate the NF service consumer via the CCA.

[0237] Based on the enhanced service-oriented architecture described above, several modes of indirect communication processes are briefly described below.

[0238] First, indirect communication without delegated discovery (Mode C for short):

[0239] The consumer communicates directly with the NRF to perform a service discovery process to select a corresponding service providing network element. The service discovery process does not require the participation of the SCP network element.

[0240] The following combination Figure 2 The above-mentioned mode C will be described.

[0241] Step 201: The consumer sends a producer discovery message to the NRF.

[0242] Step 202: NRF sends information about available producers to the consumer.

[0243] In some embodiments, a consumer can select a target producer based on the available producer information obtained. The available producer information may include the NF set ID or the identifier of a specific NF instance. Specifically, the target producer can be any NF instance corresponding to the NF set ID (i.e., any producer in the producer set), a specific NF instance (i.e., a specific producer) among the NF instances corresponding to a specific NF set ID, or a specific NF instance (i.e., a specific producer).

[0244] In some embodiments, the SCP may be responsible for selecting a target producer, as detailed in step 204 below.

[0245] Step 203: The consumer sends a service request message to the SCP, which is used to request a specific service from the target producer through the SCP.

[0246] Step 204: The SCP obtains parameters for selecting a target producer by interacting with the NRF.

[0247] For example, the parameters acquired by the SCP may include but are not limited to the location or capacity of the NF instance.

[0248] It should be noted that step 204 is optional. Exemplarily, the service request message includes available producer information. For example, the available producer information includes NF set IDs, meaning that the available producer information points to a group of NF instances. The SCP needs to select an NF instance from the group as the target producer. Specifically, the SCP may select the target producer based on parameters obtained from the NRF. For example, the SCP may determine the target producer from the group of NF instances based on the obtained location of the NF instance.

[0249] Step 205: The SCP sends a service request message to the target producer, requesting the specific service from the target producer.

[0250] Step 206: The target producer sends a service request response message for providing the specific service to the SCP.

[0251] Step 207: The SCP sends a service request response message for providing the specific service to the consumer.

[0252] Second, indirect communication with delegated discovery (Mode D for short):

[0253] Consumers do not communicate directly with NRF. Instead, SCP network elements act as agents for consumers to communicate with NRF and perform service discovery procedures to select the corresponding service providing network element.

[0254] The following combination Figure 3 The above-mentioned mode D will be described.

[0255] Step 301: The consumer sends a service request message to the SCP, which is used to request a specific service from the target producer through the SCP.

[0256] The service request message includes parameters for discovering and selecting a target producer.

[0257] Step 302: The SCP obtains information about available producers by interacting with the NRF.

[0258] The SCP may obtain information about available producers based on the parameters used for target producer discovery and selection in the service request message in step 301 and determine the target producer from the information about available producers.

[0259] Step 303: The SCP sends a service request message to the target producer to request a specific service from the target producer.

[0260] Step 304: The target producer sends a service request response message for providing the specific service to the SCP.

[0261] Step 305: The SCP sends a service request response message for providing the specific service to the consumer.

[0262] It should be noted that, in various embodiments of the present application, the service request message received by the SCP from the consumer and the service request message sent by the SCP to the target producer may be the same or different. For example, the SCP may make corresponding modifications to the service request message received from the consumer (for example, add, delete or modify some information) to generate a service request message to be sent to the target producer. Similarly, the service request response message received by the SCP from the target producer and the service request response message sent by the SCP to the consumer may be the same or different. For example, the SCP may make corresponding modifications to the service request response message received from the target producer to generate a service request response message to be sent to the consumer.

[0263] Furthermore, giving the above Figure 2 and Figure 3 In the indirect communication process shown in the figure, when the consumer communicates with the producer through SCP, the producer also needs to authenticate the consumer that initiates the service request. Similarly, when the consumer communicates with NRF through SCP, NRF also needs to authenticate the consumer that initiates the service request.

[0264] In response to the authentication requirements in the above-mentioned indirect communication scenario, the verification information involved in the embodiments of this application is explained below.

[0265] 1. Client Credentials Assertion (CCA)

[0266] The CCA may be, for example, a token signed by the authenticated party, which is used by the authenticator to authenticate / verify the authenticated party, that is, to determine the identity of the authenticated party.

[0267] Exemplarily, a CCA is a token signed by an NF service consumer. Including the CCA in a message allows the message receiver (i.e., the authenticator, such as an NRF or NF service producer) to authenticate the NF service consumer. For example, the CCA can be included in the header or body of a Hypertext Transfer Protocol (HTTP) message.

[0268] Among them, CCA can include three parts: message header (header), payload (payload) and signature (signature).

[0269] The payload includes claims, illustratively including the NF instance ID of the NF service consumer, a timestamp, an expiration date, and the NF type of the intended audience. The timestamp indicates when the CCA was issued, and the expiration date indicates the time after which the CCA is considered expired. The NF type of the intended audience is the NF type of the network element that authenticates the NF service consumer.

[0270] The message header and payload are signed by the NF service consumer using the private key of the NF service consumer certificate. The message header includes certificate information, i.e., information about the NF service consumer certificate, such as the certificate or certificate chain that locates the public key, or the uniform resource locator (URL) that locates the certificate or certificate chain that locates the public key.

[0271] When the authenticator (e.g. NRF or NF service producer) receives a message containing CCA, it authenticates the NF service consumer based on the CCA. The specific authentication process is as follows:

[0272] Verify the signature of the CCA. If the signature verification passes, verify whether the CCA is expired based on the timestamp and / or the expiration time of the CCA. If the CCA is not expired, the authenticator further verifies whether the NF type of the expected audience matches its own NF type. If they match, verify whether the NF instance ID of the NF service consumer in the CCA matches the NF instance ID in the certificate used to sign the CCA. If they match, all verifications pass, and the authenticator determines that the NF service consumer authentication is successful. It should be noted that this application does not limit the order of the above verifications.

[0273] The authenticator's verification of whether the NF type of the desired audience matches its own NF type may, for example, include determining whether the authenticator verifies that the NF type of the desired audience is the same as its own NF type. For example, when the NF type of the desired audience is AMF, the authenticator verifies whether its own NF type is AMF. Verifying whether the NF instance ID of the NF service consumer in the CCA matches the NF instance ID in the certificate used to sign the CCA may, for example, include determining whether the NF instance ID of the NF service consumer in the CCA is the same as the NF instance ID in the certificate used to sign the CCA.

[0274] It is understandable that the above authentication process is only an example, and the authenticator may also use other sequences to verify the CCA, which is not limited in this application.

[0275] 2. Access token

[0276] The access token is used to represent / indicate that the consumer has the authority to obtain the service. The provider will only provide the corresponding service to the consumer if the access token is verified.

[0277] For example, the NRF receives an access token request message from the NF service consumer or SCP, performs an authorization check, and if the authorization is confirmed, the NRF generates an access token including claims.

[0278] Among them, access tokens are divided into two types: access tokens based on the NF type of the NF service producer (referred to as type A) and access tokens based on the NF service producer instance or the NF service producer service instance (referred to as type B).

[0279] When defining instances from the perspective of functionality, an instance can be an NF service consumer instance or an NF service producer instance. When defining instances from the perspective of services, an instance can also be called a service instance. For example, a service instance can be a service instance that provides service A or a service instance that provides service B.

[0280] If the NF service consumer requests an access token of type A, that is, the requested access token is used to indicate the NF service consumer's permission to access any NF service producer corresponding to the NF type to obtain services, or the requested access token is used to indicate the NF service consumer's permission to access services of any NF service producer corresponding to the NF type. The access token request message includes the NF instance ID of the NF service consumer, the desired service name, the NF type of the NF service consumer, and the NF type of the desired NF service producer. Optionally, the access token request message may also include a list of single network slice selection assistance information (S-NSSAI) or a list of network slice instance identifiers (NSI ID) of the desired NF service producer instance, the NF Set ID of the desired NF service producer instance, the S-NSSAI list of the NF service consumer, etc.

[0281] Accordingly, the claims in the access token generated by the NRF include the NF instance ID of the NRF, the NF instance ID of the NF service consumer, the NF type of the NF service producer, the desired service name, and the validity period of the access token. Optionally, the claims may also include additional scopes (e.g., requested resources and requested operations on resources), the S-NSSAI list or NSI ID list of the desired NF service producer instance, and the NF Set ID of the desired NF service producer instance.

[0282] If an NF service consumer requests an access token of type B, the requested access token is used to authorize access to a specific NF service producer instance or NF service producer service instance to obtain services. The access token request message includes the NF service consumer's NF instance ID, the desired service name, and the requested NF service producer instance ID(s).

[0283] Accordingly, the claims in the access token generated by the NRF include the NF instance ID of the NRF, the NF instance ID of the NF service consumer, the NF instance ID(s) of the NF service producer, the desired service name, and the validity period of the access token. Optionally, the claims may also include additional scopes (e.g., the requested resource and the requested operation on the resource).

[0284] In addition, generally, the validity period of CCA is shorter than that of access token.

[0285] Furthermore, after the NRF generates the access token, the NRF performs integrity protection on the access token, for example, using a key shared with the NF service producer to perform integrity protection on the claims, such as generating a message authentication code (MAC) or signing the claims using the private key of the NRF certificate.

[0286] When a provider (e.g., NF service producer) receives a service request message including an access token, it performs integrity verification, for example, verifying the MAC of the access token using a key shared with the NRF or verifying the signature of the access token using the public key of the NRF certificate. If the integrity verification succeeds, it further verifies the claims in the access token.

[0287] For the claims in the access token of type A, the provider verifies the following:

[0288] (1) The provider verifies whether the NF type of the requested NF service producer in the claims matches its own NF type;

[0289] (2) If the claims include the S-NSSAI list or NSI ID list of the desired NF service producer instance, the provider verifies whether it can serve the corresponding slice;

[0290] (3) If the claims include the NF Set Id of the desired NF service producer instance, the provider verifies whether the NF Set Id in the claims matches its own NF Set Id;

[0291] (4) If the claims include the expected service name, the provider verifies whether it matches the service operation requested by the service request message;

[0292] (5) If the claims include additional scope information, the provider verifies whether the additional scope information matches the service operation requested by the service request message;

[0293] (6) The provider verifies the validity period in the access token based on the current data / time to check whether the access token has expired, or the provider verifies the validity period in the access token based on the current data / time to check whether the access token is within the validity period.

[0294] For the claims in the access token of type B, the provider verifies the following:

[0295] (1) The provider verifies whether the NF instance ID(s) of the requested NF service producer in the claims include its own ID;

[0296] (2) If the claims include the expected service name, the provider verifies whether it matches the service operation requested by the service request message;

[0297] (3) If the claims include additional scope information, the provider verifies whether the additional scope information matches the service operation requested by the service request message;

[0298] (4) The provider verifies the expiration time in the access token based on the current data / time to check whether the access token has expired, or the provider verifies the validity time in the access token based on the current data / time to check whether the access token is within the validity period.

[0299] The following further explains the indirect communication scenario by combining the above CCA and access token verification process:

[0300] Scenario 1: Indirect flow without agent discovery (Pattern C)

[0301] NF service consumer interacts directly with NRF, such as Figure 4 shown.

[0302] Step 401: The NF service consumer determines that there is no information about an available NF service producer, and initiates a discovery process for the NF service producer.

[0303] The discovery process is used to discover available NF service producers.

[0304] For example, if steps 402 and 403 request an access token of type B, it is necessary to initiate the discovery process before step 402 and determine the identifier of a specific NF service producer instance or the identifier of the NF service producer service instance.

[0305] Exemplarily, if steps 402 and 403 request an access token of type A, the NF service producer discovery process (i.e., step 401) may be initiated before steps 402 and 403, or the NF service producer discovery process (i.e., step 404) may be initiated after steps 402 and 403.

[0306] It is understandable that the NF service consumer only needs to initiate the NF service producer discovery process once.

[0307] Step 402: The NF service consumer sends an access token request message (e.g., Nnrf_AccessToken_Get_Request) to the NRF. As can be seen from the above content, there are two types of access tokens. The specific content included in the access token request message varies for different types of access tokens. For details, see the above description of access tokens.

[0308] Step 403: The NRF sends an access token response message (e.g., Nnrf_AccessToken_Get_Response) to the NF service consumer. The access token response message includes the access token generated by the NRF.

[0309] Specifically, the NRF receives an access token request message from an NF service consumer and performs an authorization check to verify whether the NF service consumer is authorized to obtain the requested service. If authorization is successful, the NRF generates an access token and performs integrity protection on the access token.

[0310] Step 404: The NF service consumer determines that there is no available producer information (ie, step 401 is not executed), and the NF service consumer initiates a producer discovery process.

[0311] Step 404 is an optional step, and only one of steps 401 and 404 may be executed.

[0312] Step 405: The NF service consumer sends a service request message (eg, Service Request) to the SCP. The service request message includes an access token and a CCA.

[0313] CCA is used by NF service producers to authenticate NF service consumers. Specifically, the claims in a CCA include the NF service consumer's NF instance ID, timestamp and expiration time, and the NF type of the intended recipient. According to the definition of CCA, the receiving endpoint of a service request message is the NF service producer. Therefore, the NF type of the intended recipient is the NF type of the NF service producer. For more information about CCA, please refer to the above-mentioned relevant content and will not be repeated here.

[0314] For example, when AMF requests SMF to establish a session through SCP, AMF sends a session establishment request message to SCP, which includes an access token and CCA. The CCA at this time includes the NF instance ID of AMF, timestamp and expiration time, and the NF type of the expected audience is SMF.

[0315] Step 406: The SCP sends a service request message to the NF service producer.

[0316] Exemplarily, the SCP performs application programming interface (API) modification and sends the received service request message to the NF service producer.

[0317] If the service request message includes the identifier of a specific NF service producer instance or the identifier of an NF service producer service instance, the SCP sends the service request message to the specific NF service producer instance or the NF service producer service instance. If the service request message includes the NF set ID, the SCP may select an NF instance to send the service request message to.

[0318] Step 407: The NF service producer receives the service request message from the SCP and verifies the CCA and access token.

[0319] The NF service producer performs integrity verification on the access token. If integrity verification succeeds, it further verifies the claims in the access token. For details, see the above section on access token claims verification. The NF service producer also needs to verify the NF service consumer based on the CCA. The specific process for verifying the CCA can be found in the above description of CCA verification.

[0320] Step 408: The NF service producer determines that the access token and CCA are successfully verified, and then the NF service producer sends a service response message (eg, Service Response) to the SCP.

[0321] Step 409: The SCP sends a service response message to the NF service consumer.

[0322] Exemplarily, the SCP receives a service response message from the NF service producer, performs API modification, and sends a service response message to the NF service consumer.

[0323] Scenario 2: Indirect process without agent discovery (Mode C): NF service consumer interacts with NRF through SCP, such as Figure 5 shown.

[0324] Step 501: The NF service consumer determines that there is no available NF service producer information, and the NF service consumer initiates a discovery process for the NF service producer.

[0325] The discovery process is used to discover available NF service producers.

[0326] For example, if steps 502 and 503 request an access token of type B, it is necessary to initiate the discovery process before step 502 and determine the identifier of a specific NF service producer instance or the identifier of the NF service producer service instance.

[0327] Exemplarily, if steps 502 and 503 request an access token of type A, the NF service producer discovery process (i.e., step 501) can be initiated before steps 502 and 503, or the NF service producer discovery process (i.e., step 504) can be initiated after steps 502 and 503.

[0328] It is understandable that the NF service producer only needs to initiate the discovery process once.

[0329] Step 502: The NF service consumer sends an access token request message to the SCP.

[0330] The specific parameters included in the access token request message are determined by the type of access token requested. For details, please refer to the relevant description of the access token above. In addition, the access token request message may also include CCA*, which is used by the NRF to authenticate the NF service consumer. Specifically, the claims in CCA* include the NF instance ID of the NF service consumer, the timestamp and expiration time, and the NF type of the intended audience. According to the definition of CCA, the receiving endpoint of the access token request message is the NF service producer, so the NF type of the intended audience here is NFR.

[0331] Step 503: The SCP sends the access token request message received in step 501 to the NRF.

[0332] Step 504: The NRF determines that the CCA* verification is successful and generates an access token.

[0333] Specifically, the NRF authenticates the NF service consumer based on CCA*. If authentication succeeds, the NRF performs further authorization checks. If authorization succeeds, the NRF generates an access token and performs integrity protection on the access token.

[0334] Step 505: The NRF sends an access token response message to the SCP. The access token response message includes the access token generated by the NRF.

[0335] Step 506: The SCP sends an access token response message to the NRF, where the access token response message includes the access token generated by the NRF.

[0336] The details of steps 507 to 511 can be found in Figure 5 Steps 505 to 509 in the illustrated embodiment.

[0337] Scenario 3: Communication authorization under the agent discovery process (mode D): NF service consumer interacts with NRF through SCP, such as Figure 6 shown.

[0338] Step 601: The NF service consumer sends a service request message to the SCP. The service request message includes a CCA and an access token. Neither the CCA nor the access token must have expired. The claims in the CCA include the NF instance ID of the NF service consumer, the timestamp and expiration time, and the NF type of the intended recipient. According to the definition of the CCA, the receiving endpoint of the service request message is the NF service producer. Therefore, the NF type of the intended recipient is the NF type of the NF service producer.

[0339] Step 602: The SCP sends a service request message to the NF service producer. The service request message includes a CCA and an access token.

[0340] The details of steps 603 to 605 can be found in Figure 5 Steps 509 to 511 in the illustrated embodiment.

[0341] Scenario 4: Communication authorization under the agent discovery process (mode D): NF service consumer interacts with NRF through SCP, such as Figure 7 shown.

[0342] Step 701: The NF service consumer sends a service request message to the SCP. The service request message includes a CCA. The claims in the CCA include the NF service consumer's NF instance ID, timestamp, expiration time, and the NF type of the intended recipient. If the receiving endpoint of the service request is the NF service producer, the NF type of the intended recipient is the NF type of the NF service producer.

[0343] Step 702: The SCP sends an access token request message to the NRF.

[0344] For example, the SCP can determine whether to initiate an access token request process to the NRF based on the service request message. For example, if the SCP determines that the received service request message does not include an access token and there is no access token corresponding to the service request message locally, the SCP sends an access token request message to the NRF.

[0345] The access token request message includes the CCA in step 701.

[0346] Step 703: The NRF determines that verification of the CCA fails.

[0347] The NF type of the expected audience in the CCA is the NF type of the NF service producer. Since the NF type in the CCA is inconsistent with the NF type of the NRF, the NRF determines that the CCA verification fails.

[0348] Step 704: The NRF sends an access token response message to the SCP. The access token response message does not include the access token.

[0349] Therefore, since the SCP fails to obtain the access token, the NF service consumer fails to request services from the NF service producer.

[0350] Based on the indirect communication scenario of mode D, the embodiments of the present application provide the following embodiments to solve the problem that when the NF service consumer directly sends a service request message to the SCP to trigger the SCP to initiate a request for other services, the receiving endpoint of the service request (the provider of the other service) fails to authenticate the NF service consumer, resulting in the SCP's request for the other service failing, and then the NF service consumer's request for the service failing.

[0351] First, the technical concepts involved in the following embodiments are explained:

[0352] 1. The embodiments of the present application involve at least two network function types. The first network function type is different from the second network function type. A network function type refers to a general term for a network function that provides a set of functional behaviors or a set of services in a network. For example, the network function types in a 5G network may include AMF type or SMF type, where an AMF type functional network element can provide services related to access and mobility management, and an SMF type functional network element can provide services related to PDU session management.

[0353] 2. The embodiment of the present application also involves at least two services, wherein the first service is different from the second service and the first service is associated with the second service.

[0354] For example, the first service may be a request for session establishment, and the second service may be a request for an access token corresponding to the first service. Alternatively, the first service may be a request for session establishment, and the second service may be a request for information about a network element providing the first service.

[0355] For example, in the indirect communication scenario based on mode D, when AMF requests SMF to establish a session, AMF sends a session establishment request message to SCP. Before SCP sends the session establishment request to SMF, if SCP needs to first obtain the access token corresponding to the session establishment request from NRF (hereinafter referred to as access token 1), then after SCP obtains access token 1 from NRF, SCP sends the session establishment request message to SMF. At this time, the session establishment request message includes access token 1. The first service here refers to requesting session establishment, and the second service refers to requesting the access token corresponding to the first service. SCP's request for the access token corresponding to the first service from NRF occurs before SCP sends the session establishment request message to SMF, that is, SCP initiates a request for the second service before initiating a request for the first service. In addition, in some scenarios, SCP may initiate a request for the second service after initiating a request for the first service, which is not limited to this in the embodiments of the present application. Unless otherwise specified, the following is only explained by taking SCP initiating a request for the second service before initiating a request for the first service as an example.

[0356] The association between the first service and the second service may be, for example, that initiating a request for the first service may trigger a request for the second service.

[0357] In one example, the second service is used to provide an access token corresponding to the first service. The access token corresponding to the first service is used to represent / indicate that the service-consuming network element has permission to obtain the first service. Because the service-consuming network element requests the first service, and the access token corresponding to the first service provided by the second service represents / indicates that the service-consuming network element has permission to obtain the first service, the first service is associated with the second service. For example, a NF service consumer's request for the first service may trigger an SCP to request the access token corresponding to the first service. The access token corresponding to the first service represents / indicates that the NF service consumer has permission to obtain or access the first service.

[0358] In another example, the second service is used to provide information about a service-providing network element. Because the service-consuming network element requests the first service, the information about the service-providing network element provided by the second service indicates that the service-providing network element can provide the first service. Therefore, the first service is associated with the second service. For example, the NF service consumer's request for the first service may trigger the SCP to request information about the NF service producer. The NF service producer provides the first service to the NF service consumer.

[0359] In addition, initiating a request for the first service may also trigger a request for multiple second services. For example, the NF service consumer requesting the first service may trigger the SCP to request information about the NF service producer, and trigger the SCP to request the access token corresponding to the first service. The NF service producer provides the first service to the NF service consumer, and the access token corresponding to the first service is used to represent / indicate that the service consuming network element has the authority to obtain the first service. Specifically, the SCP can request the access token corresponding to the first service from NRF1, and request information about the NF service producer from NRF1. At this time, NRF1 provides two second services. Alternatively, the SCP can request the access token corresponding to the first service from NRF1, and request information about the NF service producer from NRF2. At this time, NRF1 is different from NRF2, and the second service provided by NRF1 is different from the second service provided by NRF2.

[0360] It will be understood that the above-mentioned first service and second service are merely examples and are not intended to limit the embodiments of the present application.

[0361] The following description only uses the network element providing the second service as a network storage function network element as an example. The network element providing the second service may also be other types of network elements, and the embodiments of the present application do not limit this.

[0362] The embodiment of the present application provides a communication method, in which a service consumption network element sends a service request message to a service communication agent, and the service request message includes a first customer authentication credential, and the first customer authentication credential may include at least two different network function types, thereby enabling different network elements to successfully authenticate the service consumption network element based on the first customer authentication credential. Figure 8 The embodiment shown is described as an example.

[0363] Step 801: A service consuming network element sends a first service request message to a service communication agent. The first service request message is used to request a first service from a service providing network element. The first service request message includes a first client authentication credential.

[0364] The first customer authentication credential is used to authenticate the service-consuming network element. The first customer authentication credential includes a first network function type and a second network function type. The first network function type is the network function type of the network element providing the first service, i.e., the network function type of the service-providing network element. The second network function type is the network function type of the network element providing the second service, which is associated with the first service. The network function type of the network element providing the second service can be the network function type of a network storage function network element.

[0365] Compared to existing CCAs, the first customer authentication credential includes two network function types. Therefore, existing CCAs are only used by the receiving endpoint of a service request to authenticate the service-consuming network element, that is, to authenticate the identity of the service-consuming network element. However, in the embodiments of the present application, the first customer authentication credential can be used by network elements of both network function types to authenticate the service-consuming network element, namely, by the receiving endpoint of the service request and the receiving endpoint of the request message triggered by the service request. In addition, the first customer authentication credential also includes one or more of the following: an identifier of the service-consuming network element and validity period information of the first customer authentication credential. The validity period information of the first customer authentication credential indicates the validity period of the first customer authentication credential. For example, the validity period information of the first customer authentication credential may include a timestamp and an expiration time of the first customer authentication credential. These contents have the same meaning as the corresponding concepts in existing CCAs and are not further described here. For example, if the timestamp indicates time A and the expiration time indicates time B, then the first customer authentication credential is valid for the period determined by time A and time B. Alternatively, the validity period information of the first customer authentication credential may include a timestamp and the validity period of the first customer authentication credential. The timestamp here has the same meaning as the corresponding concept in existing CCA, and the validity period can refer to a period of time after the timestamp. For example, if the timestamp indicates time A and the validity period indicates time period C (e.g., 5 minutes), then the first customer authentication credential is valid for time period C after time A.

[0366] Among them, the validity time information of the first customer authentication certificate is associated with the first duration, and the first duration is determined by the transmission delay between the service consumption network element and the service communication agent, the transmission delay between the service communication agent and the network element providing the second service, and the transmission delay between the service communication agent and the service providing network element (that is, the network element providing the first service).

[0367] Exemplarily, the transmission delay between the service consumption network element and the service communication agent is recorded as T1, the transmission delay between the service communication agent and the network element providing the second service is recorded as T2, and the transmission delay between the service communication agent and the service providing network element is recorded as T3. The above-mentioned transmission delay can be the average value of the transmission delay between the two network elements or slightly greater than the average value of the transmission delay. If the service communication agent requests the second service earlier than the first service, the first duration = T1+2T2+T3. At this time, the validity period of the first customer authentication certificate can be the sum of the first duration and the preset duration. Alternatively, the expiration time of the first customer authentication certificate can be determined by the timestamp, the first duration and the preset duration. The preset duration here can be pre-set or dynamically adjusted. It should be noted that if the preset duration is set too long, it may cause the CCA to be valid for a long time, and there is a risk that the CCA may be reused.

[0368] The above configuration rule for the validity period information of the first client authentication credential can ensure that the first client authentication credential is not maliciously used by the service communication agent to the greatest extent possible, thereby ensuring the security of the communication process.

[0369] It is understandable that before the service consumption network element sends the first service request message to the service communication agent, the service consumption network element also needs to determine whether an available first customer authentication credential is stored locally. If an available customer authentication credential is stored (for example, an unexpired customer authentication credential is saved), the unexpired customer authentication credential is used as the first customer credential. If no available customer authentication credential is stored (for example, the customer authentication credential has expired or the customer authentication credential is not stored), the service consumption network element generates the first customer authentication credential. In addition, when an expired customer authentication credential exists, the service consumption network element can delete the expired customer authentication credential. Therefore, the service consumption network element can release storage space and reduce the storage burden of the system by deleting the expired customer authentication credential.

[0370] The following describes several possible scenarios for triggering the service consuming network element to send the first service request message to the service communication agent.

[0371] Scenario 1: When a first service needs to be requested and there is no available access token corresponding to the first service, the service consuming network element sends a first service request message to the service communication agent.

[0372] Exemplarily, the service consuming network element determines that a first service needs to be requested and there is no available access token corresponding to the first service, and the service consuming network element sends a first service request message to the service communication agent.

[0373] In some embodiments, the service consuming network element determining that there is no available access token corresponding to the first service includes: the service consuming network element determining that the access token corresponding to the first service is not stored, or the service consuming network element determining that the stored access token corresponding to the first service has expired. Furthermore, if the stored access token corresponding to the first service has expired, the service consuming network element may delete the expired access token corresponding to the first service.

[0374] Exemplarily, the access token can be stored in the public storage space of the NF service consumer (for example, the access token is stored in the context of the node level). The NF service consumer can receive the service request message of the UE and determine that the first service needs to be requested based on the service request message. The NF service consumer obtains the relevant information of the UE (for example, the context information of the UE) based on the identifier of the UE. Further, the NF service consumer checks whether the public storage space includes the access token corresponding to the first service. If the access token corresponding to the first service is included and the access token has not expired, the access token is used; if the access token corresponding to the first service is not included, it is determined that there is no available access token; or if the access token corresponding to the first service is included but the access token has expired, it is determined that there is no available access token. Further, optionally, the NF service consumer deletes the access token. The relevant information of the UE can be stored in the public storage space of the NF service consumer, or the NF service consumer obtains the relevant information of the UE from other network elements based on the identifier of the UE.

[0375] It is understandable that if the service consuming network element determines that there is an available access token corresponding to the first service, then the first service request message sent by the service consuming network element to the service communication agent may not need to include the second network function type, but only the first network function type.

[0376] Scenario 2: When a first service needs to be requested and the request for the first service triggers the service communication agent to request information of the service providing network element, the service consuming network element sends a first service request message to the service communication agent.

[0377] Exemplarily, the service consuming network element determines that it needs to request the first service and the request for the first service triggers the service communication agent to request information of the service providing network element, and the service consuming network element sends a first service request message to the service communication agent.

[0378] The service-consuming network element may determine that requesting the first service triggers the service communication agent to request information from the service-providing network element when one or more of the following conditions occur. For example, the service-consuming network element receives a first message associated with a first terminal device, and the service-consuming network element determines, based on the first message, that a request for the first service is necessary. Furthermore, the service-consuming network element determines that requesting the first service triggers the service communication agent to request information from the service-providing network element based on one or more of the following conditions.

[0379] Case 1: The context of the first terminal device is not stored.

[0380] Exemplarily, an NF service consumer may receive a service request message from a UE and determine, based on the service request message, that it needs to request a first service. The NF service consumer obtains UE context information based on the UE identifier. If the UE context information cannot be obtained, i.e., the UE is new and has not triggered the NF service consumer to request a service from the NF service producer, the NF service consumer determines that requesting the first service triggers an SCP to request information from the NF service producer. The UE context information may be stored in the NF service consumer, or the NF service consumer may obtain the UE context information from another network element based on the UE identifier.

[0381] Case 2: The context of the first service is not stored.

[0382] Exemplarily, an NF service consumer may receive a service request message from a UE and determine, based on the service request message, that it needs to request a first service. The NF service consumer obtains the UE's context information based on the UE's identifier and determines, based on the UE's context information, that the context of the first service is not included. That is, the UE has not triggered the NF service consumer to request the first service from the NF service producer. The NF service consumer then determines that requesting the first service triggers the SCP to request information from the NF service producer. The UE's context information may be stored in the NF service consumer, or the NF service consumer may obtain the UE's context information from another network element based on the UE's identifier.

[0383] Case 3: The first slice belongs to the service providing network element and the context of the first slice is not stored;

[0384] Exemplarily, the NF service consumer may receive a service request message from the UE, and determine, based on the service request message, that it needs to request a first service and that it needs to request the first service from the service providing network element in the first slice. The NF service consumer obtains the UE's context information based on the UE's identifier, and determines, based on the UE's context information, that the context of the first slice is not included, that is, the UE has not triggered the NF service consumer to request the first service from the NF service producer in the first slice. The NF service consumer then determines that requesting the first service triggers the SCP to request information from the NF service producer. The UE's context information may be stored in the NF service consumer, or the NF service consumer may obtain the UE's context information from other network elements based on the UE's identifier.

[0385] Case 4: The service consuming network element communicates with the service communication agent for the first time.

[0386] It can be understood that the service-consuming network element can request services from the service-providing network element through multiple service communication agents. If the service-consuming network element determines to send a first service request message to a new service communication agent, that is, the service-consuming network element communicates with the service communication agent for the first time, then the service-consuming network element determines that the first service request message triggers the service communication agent to request a second service.

[0387] Furthermore, the NF service consumer receives a service request response message containing a binding indicator, which is used in subsequent related service messages. In this scenario, if the NF service consumer initiates a request for a first service, the first service request message carries the binding information. This binding information allows the SCP to route the first service request to a specific NF service producer. In this case, the SCP does not need to initiate the NF service producer discovery process.

[0388] Scenario 3: When a first service needs to be requested and the service consuming network element communicates with the service communication proxy using the indirect communication mode of mode D, the service consuming network element sends a first service request message to the service communication proxy.

[0389] Exemplarily, when the service consuming network element uses mode D to communicate with the service communication agent through standard protocol agreement or pre-configuration information configuration, the first service request message always carries the customer authentication credentials including the first network function type and the second network function type.

[0390] Scenario 4: Before the service consuming network element sends the first service request message to the service communication agent, the service consuming network element obtains indication information, and the service consuming network element sends the first service request message to the service communication agent according to the indication information.

[0391] like Figure 9 As shown, the following Figure 8 The specific process of the service consuming network element sending the first service request message to the service communication agent according to the instruction information in scenario 4 in step 801 is described.

[0392] Step 901: Before the service consuming network element sends a first service request message to the service communication agent, the service consuming network element sends a second service request message to the service communication agent, where the second service request message is used to request the first service, and the second service request message includes a second customer authentication credential, and the second customer authentication credential includes a first network function type, and the second customer authentication credential is used by the service providing network element to authenticate the service consuming network element.

[0393] It should be noted that, at this time, the second client authentication credential does not include the second network function type.

[0394] Step 902: The service communication agent sends a third service request message to the network storage function network element, where the third service request message is used to request a second service and includes a second client authentication credential. The network storage function network element is used to provide the second service.

[0395] The service communication agent determining that requesting the first service triggers requesting the second service may include but is not limited to the following scenarios:

[0396] Scenario A: If no available access token corresponding to the first service is stored and the second service request message does not include the access token corresponding to the first service, the service communication agent sends a third service request message to the network storage function network element. The third service request message is used to request the access token corresponding to the first service. If the service communication agent determines that no available access token corresponding to the first service is stored and the second service request message does not include the access token corresponding to the first service, the service communication agent sends the third service request message to the network storage function network element.

[0397] Exemplarily, the service communication agent can determine that the access token corresponding to the first service is needed based on the received second service request message. For example, the service communication agent can determine that the access token corresponding to the first service is needed based on the type of the service request message or the access scope of the service request. Furthermore, the service communication agent inquires whether the access token corresponding to the first service is stored. If it is not stored or the stored access token corresponding to the first service has expired, and the second service request message does not include the access token, the service communication agent can determine the parameters required to request the access token corresponding to the first service based on the type of the service request message, that is, the parameters in the claim, such as the name of the desired service, the NF instance ID of the consumer, etc. In addition, when the stored access token corresponding to the first service has expired, the service communication agent can delete the expired access token.

[0398] Scenario B: If no available service providing network element information is stored and the second service request message does not include the service providing network element information, the service communication agent sends a third service request message to the network storage function network element. The third service request message is used to request the service providing network element information. The service communication agent determines that no available service providing network element information is stored and the second service request message does not include the service providing network element information, and sends the third service request message to the network storage function network element. Exemplarily, the service communication agent may determine this based on the type of the second service request message and / or indication information in the second service request message.

[0399] After receiving the second service request message, the service communication agent parses the second service request message to determine the recipient of the message and whether the recipient of the message (i.e., the service providing network element) needs to be discovered. The service communication agent determines whether to discover the service providing network element, similar to how the service consuming network element determines whether to discover the service provider in direct communication. For example, if the request message received by the SCP is a session establishment request, the SCP determines that the message needs to be forwarded to the SMF. The SCP will determine whether there is any qualified SMF instance information locally based on the parameters in the message.

[0400] Step 903: The network storage function network element determines that the service consumption network element authentication fails based on the second customer authentication credential.

[0401] Exemplarily, the network storage function network element determines that the service consumption network element authentication fails according to the second customer authentication credential, including: the network storage function network element determines that the first network function type does not match the network function type of the network storage function network element. Or,

[0402] The network storage function network element determines that the service consumption network element authentication fails based on the second customer authentication credential, including: the network storage function network element verifies that the signature of the second customer authentication credential is passed, verifies that the second customer authentication credential is not expired based on the timestamp included in the second customer authentication credential and / or the expiration time of the second customer authentication credential, verifies that the identifier of the service consumption network element in the second customer authentication credential is the same as the identifier of the network element in the certificate used to sign the second customer authentication credential, and verifies that the first network function type does not match the network function type of the network storage function network element.

[0403] Step 904: If the first network function type does not match the network function type of the network storage function network element, the network storage function network element sends a response message to the service communication agent for the third service request message. The response message to the third service request message includes a cause value and / or first indication information.

[0404] Among them, the reason value and / or the first indication information indicates that the second customer authentication credential does not include the second network function type, or indicates that the first network function type included in the second customer authentication credential does not match the network function type of the network storage function network element, or indicates that the correct network function type is missing in the second customer authentication credential, etc.

[0405] Optionally, the first indication information may be a third customer authentication credential. The third customer authentication credential includes an identifier of the network storage function network element, a timestamp of the third customer authentication credential, an expiration date of the third customer authentication credential, and a network function type of the service consuming network element. Optionally, the third customer authentication credential may further include the network function type of the network storage function network element, to instruct the service consuming network element to generate a customer authentication credential including the network function type of the network storage function network element.

[0406] As can be seen from step 903, the network storage function network element fails to authenticate the service consumption network element, and the response message to the third service request message may also indicate that the second service request has failed.

[0407] Step 905: The service communication agent sends a response message to the second service request message to the service consuming network element according to the response message to the third service request message, wherein the response message to the second service request message includes the second indication information.

[0408] The second indication information is used to trigger the service consumption network element to send Figure 8 The first service request message of step 801 in the embodiment (ie, the service request message carrying both the network function type of the service providing network element and the network function type of the network storage function network element).

[0409] In one possible implementation, the second indication information is used to indicate that the second customer authentication credential does not include the network function type of the network storage function network element (i.e., the above-mentioned second network function type), or indicates that the first network function type included in the second customer authentication credential does not match the network function type of the network storage function network element, or indicates that the second customer authentication credential lacks the correct network function type, etc.

[0410] In a specific implementation, the second indication information may be the same as the first indication information, or may be information obtained after the service communication agent processes the first indication information. This embodiment of the present application does not limit this.

[0411] In some embodiments, the service communication agent can also generate the second indication information based on the response message to the third service request message. The second indication information can trigger the service consumption network element to re-initiate the service request message requesting the first service and carry the customer authentication credentials including the network function type of the network storage function network element and the network function type of the service providing network element when re-initiating the request for the first service (i.e., executing the above step 801).

[0412] Step 906: The service consuming network element sends a first service request message to the service communication agent according to the second indication information.

[0413] In some embodiments, when the second indication information includes a third customer authentication credential and the third customer authentication credential includes the network function type of the network storage function network element, the service consumption network element can authenticate the network storage function network element based on the third customer authentication credential. When the authentication of the network storage function network element is successful, the service consumption network element sends a first service request message to the service communication agent, wherein the service consumption network element determines that the second network function type is the network function type of the network storage function network element (wherein, the network storage function network element is used to provide a second service, and the network function type of the network storage function network element is the network function type of the network element providing the second service).

[0414] Step 802: The service communication agent receives a first service request message from a service consumption network element, and sends a fourth service request message to the network storage function network element. The fourth service request message is used to request a second service and includes a first client authentication credential.

[0415] The service communication agent may determine that requesting the first service triggers requesting the second service by referring to the above step 902 , and the repeated parts will not be repeated here.

[0416] Step 803: The network storage function network element receives the fourth service request message from the service communication agent, and the network storage function network element authenticates the service consumption network element according to the first customer authentication credential.

[0417] The network storage function network element determines that if there is a network function type that is the same as the network function type of the network storage function network element in the first network function type and the second network function type, the network storage function network element determines that the service consumption network element authentication is successful, wherein the second network function type is the same as the network function type of the network storage function network element.

[0418] Specifically, the network storage function network element verifies that the signature of the first customer authentication certificate is passed, verifies that the first customer authentication certificate is not expired based on the timestamp included in the first customer authentication certificate and / or the expiration time of the first customer authentication certificate, verifies that the identifier of the service consumption network element in the first customer authentication certificate is the same as the identifier of the network element in the certificate used to sign the first customer authentication certificate, and verifies that the second network function type in the first network function type and the second network function type matches the network function type of the network storage function network element. Then, the network storage function network element determines that the authentication of the service consumption network element is successful.

[0419] Step 804: When the service consumption network element is successfully authenticated, the network storage function network element sends a response message to the service communication agent for the fourth service request message.

[0420] Exemplarily, if the fourth service request message requests an access token corresponding to the first service, the network storage function network element performs an authorization check after the service consuming network element successfully authenticates the service. If authorization is confirmed, the network storage function network element generates an access token corresponding to the first service. The network storage function network element sends a response message to the service communication agent in response to the fourth service request message. The response message to the fourth service request message includes the access token corresponding to the first service.

[0421] Exemplarily, if the fourth service request message requests information of the service providing network element, the network storage function network element sends a response message to the service communication agent after the service consuming network element is successfully authenticated. The response message to the fourth service request message includes information of the service providing network element.

[0422] Step 805: The service communication agent receives a response message to the fourth service request message from the network storage function network element. The service communication agent sends a fifth service request message to the service providing network element based on the response message to the fourth service request message. The fifth service request message is used to request the first service. The fifth service request message includes the first customer authentication credential.

[0423] It can be understood that the fifth service request message also includes the access token corresponding to the first service.

[0424] Exemplarily, when the response message to the fourth service request message includes the access token corresponding to the first service, the service communication agent sends a fifth service request message to the service providing network element, and the fifth service request message is used to request the first service, and the fifth service request message includes the first customer authentication credential and the access token corresponding to the first service.

[0425] Exemplarily, when the response message to the fourth service request message includes information about the service providing network element, the service communication agent sends a fifth service request message to the service providing network element indicated by the information about the service providing network element. The fifth service request message is used to request the first service, and the fifth service request message includes the first client authentication credential and an access token corresponding to the first service. The access token corresponding to the first service in this case may be stored by the service communication agent or carried in the first request message.

[0426] Alternatively, in another implementation, the service communication agent uses the first client authentication credentials to request the network storage function network element for an access token corresponding to the first service and information about the service-providing network element. That is, by executing steps 802-804 twice, the service communication agent can initiate two service request messages for the second service: one request for the access token corresponding to the first service and one request for information about the service-providing network element. In this case, the access token corresponding to the first service in step 805 can be the one obtained by the service communication agent from the network storage function network through steps 802-804.

[0427] Step 806: The service providing network element receives the fifth service request message from the service communication agent, and the service providing network element authenticates the service consuming network element according to the first customer authentication credential.

[0428] It is understandable that the service providing network element also needs to verify the access token corresponding to the first service. For details, please refer to the above-mentioned access token verification process, which will not be repeated here.

[0429] The service providing network element authenticates the service consuming network element according to the first customer authentication credential, including: the service providing network element determines whether its own network function type matches one or more of the first network function type and the second network function type.

[0430] Specifically, the service providing network element authenticates the service consuming network element based on the first customer authentication certificate, and also includes: the service providing network element verifies whether the signature of the first customer authentication certificate is passed, verifies whether the first customer authentication certificate is not expired based on the timestamp included in the first customer authentication certificate and / or the expiration time of the first customer authentication certificate, and verifies whether the identifier of the service consuming network element in the first customer authentication certificate is the same as the identifier of the network element in the certificate used to sign the first customer authentication certificate.

[0431] Among them, the network storage function network element and the service providing network element have the same authentication ideas for authenticating the service consuming network element based on the first customer authentication credential. The corresponding contents can be referenced to each other and will not be repeated here.

[0432] Step 807: When the service consuming network element is successfully authenticated, the service providing network element sends a response message to the service communication agent for the fifth service request message.

[0433] For example, when the service consuming network element is successfully authenticated and the access token corresponding to the first service is successfully verified, the response message to the fifth service request message is used to indicate that the first service is provided or that the fifth service request is successful. Alternatively, when the service consuming network element fails to be authenticated and / or the access token corresponding to the first service fails to be verified, the response message to the fifth service request message indicates that the request for the first service failed.

[0434] Step 808: The service communication agent sends a response message to the service consuming network element in response to the first service request message.

[0435] When the response message to the fifth service request message indicates that the first service is provided or that the fifth service request is successful, the response message to the first service request message indicates that the first service is provided or that the first service request is successful. Alternatively, when the response message to the fifth service request message indicates that the first service request has failed, the response message to the first service request message indicates that the first service request has failed. For example, the service communication agent may modify the information in the message header of the response message to the fifth service request message, but the content of the response message to the fifth service request message remains essentially unchanged. The service communication agent primarily serves as a message router.

[0436] By adopting the above embodiment, in a scenario where a service-consuming network element requests a first service from a service-consuming network element through a service communication agent, the service-consuming network element carries a customer authentication credential containing both the first network function type and the second network function type in the first service request message sent to the service communication agent, thereby ensuring that when the service communication agent requests a second service, the network element providing the second service successfully authenticates the service-consuming network element, thereby also providing a guarantee for the service-consuming network element to request the first service, and solving the problem of failure of the service-consuming network element to request a service due to failure of authentication of the customer authentication credential in an indirect communication scenario.

[0437] The embodiment of the present application provides a communication method, in which a service consumption network element sends a service request message to a service communication agent, the service request message includes a fourth customer authentication credential and a fifth customer authentication credential, the fourth customer authentication credential and the fifth customer authentication credential respectively including different network function types, and the service communication agent sends corresponding customer authentication credentials to different network elements, thereby enabling different network elements to authenticate the service consumption network element according to different customer authentication credentials. Figure 10 The embodiment shown is described as an example.

[0438] The present application provides a communication method, such as Figure 10 As shown, the method includes:

[0439] Step 1001: A service consuming network element sends a first service request message to a service communication agent. The first service request message is used to request a first service. The first service request message includes a fourth client authentication credential and a fifth client authentication credential.

[0440] Among them, the fourth customer authentication credential is used to authenticate the service-providing network element of the service-consuming network element, and the fifth customer authentication credential is used to authenticate the service-consuming network element of the network element providing the second service. The fourth customer authentication credential includes a first network function type, and the fifth customer authentication credential includes a second network function type. The first network function type is the network function type of the service-providing network element, and the second network function type is the network function type of the network element providing the second service. The second service is associated with the first service.

[0441] The fourth customer authentication credential also includes one or more items of the identifier of the service consumption network element and the validity period information of the fourth customer authentication credential. The validity period information of the fourth customer authentication credential indicates the expiration time of the fourth customer authentication credential. For example, the validity period information of the fourth customer authentication credential includes a timestamp and the expiration time of the fourth customer authentication credential. Alternatively, the validity period information of the fourth customer authentication credential may include the timestamp of the fourth customer authentication credential and the validity period of the fourth customer authentication credential. The fifth customer authentication credential also includes one or more items of the identifier of the service consumption network element and the validity period information of the fifth customer authentication credential. The validity period information of the fifth customer authentication credential indicates the validity period of the fifth customer authentication credential. For example, the validity period information of the fifth customer authentication credential includes the timestamp of the fifth customer authentication credential and the expiration time of the fifth customer authentication credential. Alternatively, the validity period information of the fifth customer authentication credential may include the timestamp of the fifth customer authentication credential and the validity period of the fifth customer authentication credential.

[0442] In the case where the service communication agent requests the second service earlier than the first service, the validity period of the fifth customer authentication credential is shorter than the validity period of the fourth customer authentication credential. Exemplarily, in the case where the service communication agent requests the second service earlier than the first service, the validity period of the fifth customer authentication credential is associated with the first duration, and the first duration is determined by the transmission delay between the service consumption network element and the service communication agent and the transmission delay between the service communication agent and the network element providing the second service. For example, the transmission delay between the service consumption network element and the service communication agent is recorded as T1, and the transmission delay between the service communication agent and the network element providing the second service is recorded as T2. The above-mentioned transmission delay can be the average value of the transmission delay or slightly greater than the average value of the transmission delay. First duration = T1 + T2. For example, the expiration time of the first customer authentication credential can be determined by the timestamp, the first duration and the preset duration. The preset duration here can be determined based on an empirical value.

[0443] In a case where the service communication agent requests the second service later than the first service, the validity period of the fifth client authentication credential is longer than the validity period of the fourth client authentication credential.

[0444] The above configuration rules for the validity period of the fourth and fifth client authentication credentials can ensure that the fourth and fifth client authentication credentials are not maliciously used by the service communication agent, thereby ensuring the security of the communication process.

[0445] It is understandable that before the service consumption network element sends the first service request message to the service communication agent, the service consumption network element also needs to determine whether an available customer authentication credential is stored locally. If an available customer authentication credential is stored (for example, an unexpired customer authentication credential is saved), the available customer authentication credential is used as the fourth customer authentication credential. If no available customer authentication credential is stored (for example, the saved customer authentication credential has expired or the customer authentication credential is not stored), the service consumption network element generates the fourth customer authentication credential. In addition, when there is an expired customer authentication credential, the service consumption network element can delete the expired customer authentication credential. Therefore, the service consumption network element can release storage space and reduce the storage burden of the system by deleting the expired customer authentication credential. Similarly, it applies to the fifth customer authentication credential and will not be described in detail here.

[0446] Among them, the network function type of the network element providing the second service may be the network function type of a network storage function network element.

[0447] Among them, several scenarios of triggering the service consumption network element to send the first service request message to the service communication agent can be specifically referred to Figure 8 The relevant contents of the illustrated embodiment will not be repeated any more.

[0448] Step 1002: The service communication agent receives a first service request message from a service consumption network element, and sends a second service request message to the network storage function network element, where the second service request message is used to request a second service and includes a fifth client authentication credential.

[0449] The service communication agent may determine that requesting the first service triggers requesting the second service by referring to the above step 902 , and the repeated parts will not be repeated here.

[0450] Among them, after the service communication agent determines that requesting the first service triggers requesting the second service, the service communication agent sends a second service request message to the network storage function network element according to the network function type of the network storage function network element, and the second service request message includes the fifth customer authentication credential.

[0451] Exemplarily, the service communication agent determines that it needs to request an access token corresponding to the first service from the network storage function network element, and selects a fifth client authentication credential from the fourth client authentication credential and the fifth client authentication credential based on the network function type of the network storage function network element, and adds the fifth client authentication credential to the second service request message. Alternatively, the service communication agent determines that it needs to request information about a service provision network element from the network storage function network element, and selects a fifth client authentication credential from the fourth client authentication credential and the fifth client authentication credential based on the network function type of the network storage function network element, and adds the fifth client authentication credential to the second service request message.

[0452] Step 1003: The network storage function network element receives the second service request message from the service communication agent, and the network storage function network element authenticates the service consumption network element according to the fifth customer authentication credential.

[0453] The network storage function network element determines that the service consumption network element has been successfully authenticated. Specifically, the network storage function network element verifies that the signature of the fifth customer authentication credential is passed, verifies that the fifth customer authentication credential has not expired based on the timestamp and / or expiration time included in the fifth customer authentication credential, verifies that the identifier of the service consumption network element in the fifth customer authentication credential is the same as the identifier of the network element in the certificate used to sign the fifth customer authentication credential, and verifies that the second network function type matches the network function type of the network storage function network element. Then, the network storage function network element determines that the service consumption network element has been successfully authenticated.

[0454] Step 1004: The network storage function network element sends a response message to the service communication agent for the second service request message.

[0455] Exemplarily, if the second service request message requests an access token corresponding to the first service, the network storage function network element performs an authorization check after the service consuming network element successfully authenticates the service. If authorization is confirmed, the network storage function network element generates an access token corresponding to the first service. The network storage function network element sends a response message to the service communication agent in response to the second service request message. The response message to the second service request message includes the access token corresponding to the first service.

[0456] Exemplarily, if the second service request message requests information of the service providing network element, the network storage function network element sends a response message to the service communication agent after the service consuming network element is successfully authenticated. The response message to the second service request message includes information of the service providing network element.

[0457] Optionally, when the network storage function network element fails to authenticate the service consuming network element, the network storage function network element sends a response message to the service communication agent for the second service request message, indicating that the request for the second service has failed.

[0458] Step 1005: The service communication agent receives a response message to the second service request message from the network storage function network element. The service communication agent sends a third service request message to the service providing network element based on the response message to the second service request message. The third service request message is used to request the first service. The third service request message includes a fourth customer authentication credential.

[0459] It is understandable that the third service request message also includes the access token corresponding to the first service.

[0460] Exemplarily, the service communication agent determines that the service consuming network element requests the first service, selects a fourth customer authentication credential from the fourth customer authentication credential and the fifth customer authentication credential according to the type of the service providing network element, and adds the fourth customer authentication credential to the third service request message.

[0461] Exemplarily, when the response message to the second service request message includes the access token corresponding to the first service, the service communication agent sends a third service request message to the service providing network element. The third service request message is used to request the first service and includes the fourth client authentication credential and the access token corresponding to the first service. Alternatively, when the response message to the second service request message includes information about the service providing network element, the service communication agent sends a third service request message to the service providing network element indicated by the information about the service providing network element. The third service request message is used to request the first service and includes the fourth client authentication credential and the access token corresponding to the first service. In this case, the access token corresponding to the first service may be one that the service communication agent has stored or that was carried in the first service request message.

[0462] Step 1006: The service providing network element receives the third service request message from the service communication agent, and the service providing network element authenticates the service consuming network element according to the fourth customer authentication credential.

[0463] It is understandable that the service providing network element also needs to verify the access token corresponding to the first service. For details, please refer to the above-mentioned access token verification process, which will not be repeated here.

[0464] The service-providing network element determines that the service-consuming network element has been successfully authenticated. Specifically, the service-providing network element verifies that the signature of the fourth customer authentication credential is passed, verifies that the fourth customer authentication credential has not expired based on the timestamp and / or expiration time included in the fourth customer authentication credential, verifies that the identifier of the service-consuming network element in the fourth customer authentication credential is the same as the identifier of the network element in the certificate used to sign the fourth customer authentication credential, and verifies that the first network function type matches the network function type of the service-providing network element. Then, the service-providing network element determines that the service-consuming network element has been successfully authenticated.

[0465] Step 1007: The service providing network element sends a response message to the service communication agent in response to the third service request message.

[0466] When the service consuming network element is successfully authenticated and the access token corresponding to the first service is successfully verified, the response message to the third service request message is used to indicate that the first service is provided or that the third service request is successful. Alternatively, when the service consuming network element is unauthenticated and / or the access token corresponding to the first service is unverified, the response message to the third service request message indicates that the first service request has failed.

[0467] Step 1008: The service communication agent sends a response message to the service consuming network element in response to the first service request message.

[0468] When the response message to the third service request message indicates that the first service is provided or that the third service request is successful, the response message to the first service request message indicates that the first service is provided or that the first service request is successful. Alternatively, when the response message to the third service request message indicates that the first service request has failed, the response message to the first service request message indicates that the first service request has failed. For example, the service communication agent may modify the information in the message header of the response message to the third service request message, but the content of the response message to the third service request message remains essentially unchanged. The service communication agent primarily serves as a message router.

[0469] Using the above embodiment, the service consuming network element sends a first service request message to the service communication agent, wherein the first service request message includes a fourth customer authentication credential and a fifth customer authentication credential, the fourth customer authentication credential includes a first network function type, and the fifth customer authentication credential includes a second network function type, thereby ensuring that when the service communication agent requests a second service, the network element providing the second service successfully authenticates the service consuming network element, thereby also providing a guarantee for the service consuming network element to request the first service.

[0470] The embodiment of the present application provides a communication method, in which a service consumption network element sends a service request message to a service communication agent, and the service request message includes a fourth customer authentication credential and a fifth customer authentication credential, and the fourth customer authentication credential and the fifth customer authentication credential respectively include different network function types. When the network storage function network element (or service providing network element) receives the fourth customer authentication credential and the fifth customer authentication credential, it determines that the service consumption network element is successfully authenticated according to the fourth customer authentication credential or determines that the service consumption network element is successfully authenticated according to the fifth customer authentication credential, and thus determines that the service consumption network element is successfully authenticated. The following is Figure 11 The embodiment shown is described as an example.

[0471] The present application provides a communication method, such as Figure 11 As shown, the method includes:

[0472] Step 1101: A service consuming network element sends a first service request message to a service communication agent. The first service request message is used to request a first service. The first service request message includes a fourth client authentication credential and a fifth client authentication credential.

[0473] For details, please refer to Figure 10 Step 1001 in the above description will not be repeated.

[0474] Step 1102: The service communication agent receives a first service request message from a service consumption network element, and sends a second service request message to the network storage function network element. The second service request message is used to request a second service, and the second service request message includes a fourth customer authentication credential and a fifth customer authentication credential.

[0475] The service communication agent may determine that requesting the first service triggers requesting the second service by referring to the above step 902 , and the repeated parts will not be repeated here.

[0476] Step 1103: The network storage function network element receives the second service request message from the service communication agent, and the network storage function network element authenticates the service consumption network element according to the fourth customer authentication credential and the fifth customer authentication credential.

[0477] If the network storage function network element successfully authenticates the service consumption network element according to one or more of the fourth customer authentication credentials and the fifth customer authentication credentials, the network storage function network element determines that the service consumption network element authentication is successful.

[0478] The network storage function network element determines that the service consumption network element has been successfully authenticated based on the fifth customer authentication credential. Specifically, the network storage function network element verifies that the signature of the fifth customer authentication credential is successful, verifies that the fifth customer authentication credential has not expired based on the timestamp and / or expiration time included in the fifth customer authentication credential, verifies that the identifier of the service consumption network element in the fifth customer authentication credential is the same as the identifier of the network element in the certificate used to sign the fifth customer authentication credential, and verifies that the second network function type matches the network function type of the network storage function network element. The network storage function network element then determines that the service consumption network element has been successfully authenticated.

[0479] The network storage function network element determines that the service consumption network element authentication has failed based on the fourth customer authentication credential. Specifically, the network storage function network element verifies that the signature of the fourth customer authentication credential is successful, verifies that the fourth customer authentication credential has not expired based on the timestamp and / or expiration time included in the fourth customer authentication credential, verifies that the identifier of the service consumption network element in the fourth customer authentication credential is the same as the identifier of the network element in the certificate used to sign the fourth customer authentication credential, and verifies that the first network function type does not match the network function type of the network storage function network element. Then, the network storage function network element determines that the service consumption network element authentication has failed.

[0480] From the above, it can be seen that the network storage function network element successfully authenticates the service consumption network element according to the fifth customer authentication certificate, and fails to authenticate the service consumption network element according to the fourth customer authentication certificate, then the network storage function network element determines that the service consumption authentication is successful.

[0481] Step 1104: When the service consumption network element is successfully authenticated, the network storage function network element sends a response message to the service communication agent for the second service request message.

[0482] Exemplarily, if the second service request message requests an access token corresponding to the first service, the network storage function network element performs an authorization check after the service consuming network element successfully authenticates the service. If authorization is confirmed, the network storage function network element generates an access token corresponding to the first service. The network storage function network element sends a response message to the service communication agent in response to the second service request message. The response message to the second service request message includes the access token corresponding to the first service.

[0483] Exemplarily, if the second service request message requests information of the service providing network element, the network storage function network element sends a response message to the service communication agent after the service consuming network element is successfully authenticated. The response message to the second service request message includes information of the service providing network element.

[0484] Step 1105: The service communication agent receives a response message to the second service request message from the network storage function network element. The service communication agent sends a third service request message to the service providing network element based on the response message to the second service request message. The third service request message is used to request the first service. The third service request message includes a fourth customer authentication credential and a fifth customer authentication credential.

[0485] It is understandable that the third service request message also includes the access token corresponding to the first service.

[0486] Exemplarily, when the response message to the second service request message includes the access token corresponding to the first service, the service communication agent sends a third service request message to the service providing network element, and the third service request message is used to request the first service, and the third service request message includes a fourth customer authentication credential and the access token corresponding to the first service.

[0487] Exemplarily, when the response message to the second service request message includes information about the service providing network element, the service communication agent sends a third service request message to the service providing network element indicated by the information about the service providing network element. The third service request message is used to request the first service, and the third service request message includes the fourth client authentication credential and an access token corresponding to the first service. The access token corresponding to the first service in this case may be one already stored by the service communication agent or carried in the first service request message.

[0488] Step 1106: The service providing network element receives the third service request message from the service communication agent, and verifies the fourth client authentication credential and the fifth client authentication credential.

[0489] It is understandable that the service providing network element also needs to verify the access token corresponding to the first service. For details, please refer to the above-mentioned access token verification process, which will not be repeated here.

[0490] If the service providing network element successfully authenticates the service consuming network element according to one or more of the fourth customer authentication credential and the fifth customer authentication credential, the service providing network element determines that the authentication of the service consuming network element is successful.

[0491] The service-providing network element determines that authentication of the service-consuming network element is successful based on the fourth customer authentication credential. Specifically, the service-providing network element verifies that the signature of the fourth customer authentication credential is successful, verifies that the fourth customer authentication credential is not expired based on the timestamp and / or expiration time included in the fourth customer authentication credential, verifies that the identifier of the service-consuming network element in the fourth customer authentication credential is the same as the identifier of the network element in the certificate used to sign the fourth customer authentication credential, and verifies that the first network function type matches the network function type of the service-providing network element. The service-providing network element then determines that authentication of the service-consuming network element is successful.

[0492] The service-providing network element determines, based on the fifth customer authentication credential, that authentication of the service-consuming network element has failed. Specifically, the service-providing network element verifies that the signature of the fifth customer authentication credential is successful, verifies that the fifth customer authentication credential has not expired based on the timestamp and / or expiration time of the fifth customer authentication credential, verifies that the identifier of the service-consuming network element in the fifth customer authentication credential is the same as the identifier of the network element in the certificate used to sign the fifth customer authentication credential, and verifies that the second network function type does not match the network function type of the service-providing network element. The service-providing network element then determines that authentication of the service-consuming network element has failed.

[0493] From the above, it can be seen that the service providing network element successfully authenticates the service consuming network element according to the fourth customer authentication credential, but fails to authenticate the service consuming network element according to the fifth customer authentication credential. Then the service providing network element determines that the service consuming authentication is successful.

[0494] Step 1107: The service providing network element sends a response message to the service communication agent in response to the third service request message.

[0495] Step 1108: The service communication agent sends a response message to the service consuming network element in response to the first service request message.

[0496] Step 1107 and step 1108 are respectively Figure 10 In the embodiment, step 1007 and step 1008 are the same and are not described in detail.

[0497] compared to Figure 10 An embodiment of Figure 11 In this embodiment, the service communication agent does not need to carry different CCAs in the service request message depending on the service requesting object, simplifying the service communication agent's processing logic. Furthermore, because the service communication agent carries both CCAs after receiving the service request from the service-consuming network element, whether requesting the second service from the network storage function network element or the first service from the service-providing network element, it can always ensure that the network storage function network element and the service-providing network element successfully authenticate the service-consuming network element, thereby avoiding the problem of the service-consuming network element failing to request a service.

[0498] An embodiment of the present application provides a communication method. When a service communication agent fails to request a second service, the service communication agent can proactively request a customer authentication credential from a service consuming network element to ensure that the service communication agent can obtain the second service, thereby ensuring that the service consuming network element can obtain the first service.

[0499] The present application provides a communication method, such as Figure 12 As shown, the method includes:

[0500] Step 1201: A service-consuming network element sends a service request message 1 to a service communication agent. The service request message 1 is used to request a first service and includes a client authentication credential A. The client authentication credential A includes a first network function type. The client authentication credential A is used by the service-providing network element to authenticate the service-consuming network element. The first network function type is the network function type of the service-providing network element.

[0501] It should be noted that, at this time, the client authentication credential A does not include the second network function type, where the second network function type is the network function type of the network element providing the second service, and the second service is associated with the first service.

[0502] Step 1202: The service communication agent sends a service request message 2 to the network storage function network element. The service request message 2 is used to request a second service and includes a client authentication credential A. The network storage function network element is used to provide the second service.

[0503] Step 1203: The network storage function network element determines, based on the client authentication credential A, that the service consumption network element authentication has failed.

[0504] Step 1204: The network storage function network element sends a response message to the service communication agent for the service request message 2.

[0505] The above steps 1201 to 1204 refer to Figure 9 Steps 901 to 904 in the embodiment are the same and will not be described in detail.

[0506] Step 1205: The service communication agent sends a client authentication credential request message to the service consuming network element according to the response message to the service request message 2.

[0507] The client authentication credential request message may indicate that the first service request has failed. The client authentication credential request message may further include indication information.

[0508] In some embodiments, the indication information may include the client authentication credential B and / or the cause value. When the indication information includes the client authentication credential B, it can prevent the service communication agent from maliciously triggering the service consuming network element to request the client authentication credential.

[0509] In some embodiments, the service communication agent may also generate indication information based on the response message to the service request message 2. The indication information may also not include the customer authentication credential B or the reason value. The indication information may instruct the service consumption network element to request the customer authentication credential and carry the customer authentication credential of the network function type including the network storage function network element when requesting the customer authentication credential.

[0510] Step 1206: The service consuming network element sends a response message to the service communication agent in response to the client authentication credential request message according to the instruction information.

[0511] In some embodiments, when the indication information includes customer authentication credential B and customer authentication credential B includes the network function type of the network storage function network element, the service consumption network element can verify the customer authentication credential B. When the verification of customer authentication credential B is successful, the service consumption network element sends a response message to the service communication agent for the customer authentication credential request message. The response message to the customer authentication credential request message includes customer authentication credential C. Customer authentication credential C includes a first network function type and a second network function type, or customer authentication credential C includes a second network function type. The first network function type is the network function type of the service providing network element, and the second network function type is the network function type of the network element providing the second service.

[0512] Step 1207: The service communication agent receives a response message to the customer authentication credential request message from the service consumption network element, and the service communication agent sends a service request message 3 to the network storage function network element. The service request message 3 is used to request the second service, and the service request message 3 includes the customer authentication credential C.

[0513] Exemplarily, when no available access token corresponding to the first service is stored and the first service request message does not include the access token corresponding to the first service, the service communication agent sends a service request message 3 to the network storage function network element, and the service request message 3 is used to request the access token corresponding to the first service.

[0514] Alternatively, when the information of the service providing network element is not stored and the first service request message does not include the information of the service providing network element, the service communication agent sends a service request message 3 to the network storage function network element, where the service request message 3 is used to request the information of the service providing network element.

[0515] Step 1208: The network storage function network element receives the service request message 3 from the service communication agent, and the network storage function network element authenticates the service consumption network element according to the customer authentication credential C.

[0516] If the customer authentication credential C includes a first network function type and a second network function type, and the network storage function network element determines that there is a network function type that matches the network function type of the network storage function network element in the first network function type and the second network function type, then the network storage function network element determines that the customer authentication credential C has been successfully verified. The second network function type matches the network function type of the network storage function network element. Specifically, the network storage function network element verifies that the signature of the customer authentication credential C is passed, verifies that the customer authentication credential C has not expired based on the timestamp included in the customer authentication credential C and / or the expiration time of the customer authentication credential C, verifies that the identifier of the service consumption network element in the customer authentication credential C is the same as the identifier of the network element in the certificate used to sign the customer authentication credential C, and verifies that the second network function type in the first network function type and the second network function type matches the network function type of the network storage function network element. Then, the network storage function network element determines that the service consumption network element has been successfully authenticated.

[0517] If the customer authentication credential C includes a second network function type, the network storage function network element verifies that the signature of the customer authentication credential C is passed, verifies that the customer authentication credential C is not expired based on the timestamp included in the customer authentication credential C and / or the expiration time of the customer authentication credential C, verifies that the identifier of the service consumption network element in the customer authentication credential C is the same as the identifier of the network element in the certificate used to sign the customer authentication credential C, and verifies that the second network function type matches the network function type of the network storage function network element, then the network storage function network element determines that the authentication of the service consumption network element is successful.

[0518] Step 1209: When the service consumption network element is successfully authenticated, the network storage function network element sends a response message to the service communication agent for the service request message 3.

[0519] For example, if the service request message 3 requests an access token corresponding to the first service, the network storage function network element performs an authorization check after the service consumption network element successfully authenticates the service consumption network element. If the authorization is confirmed, the network storage function network element generates an access token corresponding to the first service. The network storage function network element sends a response message to the service communication agent in response to the service request message 3. The response message to the service request message 3 includes the access token corresponding to the first service.

[0520] Exemplarily, if the service request message 3 requests information of the service providing network element, the network storage function network element sends a response message to the service request message 3 to the service communication agent after the service consuming network element is successfully authenticated. The response message to the service request message 3 includes information of the service providing network element.

[0521] Step 1210: The service communication agent receives a response message to the service request message 3 from the network storage function network element. The service communication agent sends a service request message 4 to the service providing network element based on the response message to the service request message 3. The service request message 4 is used to request the first service. The service request message 4 includes the customer authentication credential A or the customer authentication credential C.

[0522] It is understandable that the service request message 4 also includes an access token corresponding to the first service.

[0523] Exemplarily, when the response message to the service request message 3 includes the access token corresponding to the first service, the service communication agent sends a service request message 4 to the service providing network element, where the service request message 4 is used to request the first service, and the service request message 4 includes the first customer authentication credential and the access token corresponding to the first service.

[0524] Exemplarily, when the response message to service request message 3 includes information about the service providing network element, the service communication agent sends a service request message 4 to the service providing network element indicated by the information about the service providing network element. Service request message 4 is used to request a first service and includes the first client authentication credential and an access token corresponding to the first service. The access token corresponding to the first service may be one already stored by the service communication agent or carried in service request message 1.

[0525] Step 1211: The service providing network element receives the service request message 4 from the service communication agent, and the service providing network element authenticates the NF service consumer based on the customer authentication credential A or the customer authentication credential C.

[0526] It is understandable that the service providing network element also needs to verify the access token corresponding to the first service. For details, please refer to the above-mentioned access token verification process, which will not be repeated here.

[0527] If the service request message 4 includes the customer authentication credential C, and the service providing network element determines that there is a network function type matching the network function type of the service providing network element between the first network function type and the second network function type, then the service providing network element determines that the service consuming network element has been successfully authenticated based on the customer authentication credential C. The first network function type matches the network function type of the service providing network element. Specifically, the service providing network element verifies that the signature of the customer authentication credential C is passed, verifies that the customer authentication credential C is not expired based on the timestamp and / or expiration time included in the customer authentication credential C, verifies that the identifier of the service consuming network element in the customer authentication credential C is the same as the identifier of the network element in the certificate used to sign the customer authentication credential C, and verifies that the first network function type between the first network function type and the second network function type matches the network function type of the service providing network element. Then, the service providing network element determines that the service consuming network element has been successfully authenticated.

[0528] If the service request message 4 includes customer authentication credential A, the service providing network element verifies that the signature of the customer authentication credential A is passed, verifies that the customer authentication credential A is not expired based on the timestamp included in the customer authentication credential A and / or the expiration time of the customer authentication credential A, verifies that the identifier of the service consuming network element in the customer authentication credential A is the same as the identifier of the network element in the certificate used to sign the customer authentication credential A, and verifies that the first network function type matches the network function type of the service providing network element, then the service providing network element determines that the authentication of the service consuming network element is successful.

[0529] Step 1212: The service providing network element sends a response message to the service request message 4 to the service communication agent.

[0530] When the service consuming network element is successfully authenticated and the access token corresponding to the first service is successfully verified, the response message to service request message 4 is used to indicate that the first service is provided or to indicate that the service request 4 is successful. Alternatively, when the service consuming network element fails to be authenticated and / or the access token corresponding to the first service fails to be verified, the response message to service request message 4 indicates that the first service request has failed.

[0531] Step 1213: The service communication agent sends a response message to the service request message 1 to the service consuming network element.

[0532] When the response message to service request message 4 indicates that the first service is provided or that service request 4 is successful, the response message to service request message 1 indicates that the first service is provided or that service request 1 is successful. Alternatively, when the response message to service request message 4 indicates that the first service request failed, the response message to service request message 1 indicates that the first service request failed.

[0533] By adopting the above embodiment, the service communication agent sends a client authentication credential request message to the service consuming network element, thereby ensuring that when the service communication agent requests the second service, the network element providing the second service successfully authenticates the service consuming network element, thereby also providing a guarantee for the service consuming network element to request the first service.

[0534] The following is a detailed description of the above-mentioned embodiments in combination with specific embodiments 1 to 8. Figures 8 to 12 The embodiments shown are for illustration purposes only.

[0535] Example 1: Combination Figure 8 In the embodiment shown, when it is determined that the first service needs to be requested and there is no available access token corresponding to the first service, the NF service consumer can adopt but is not limited to the following embodiments to obtain the first service, such as Figure 13 shown.

[0536] Step 1301: The NF service consumer determines that it requests a first service and there is no available access token corresponding to the first service. The NF service consumer obtains a CCA. The access token corresponding to the first service represents / indicates that the NF service consumer has the authority to obtain the first service or the authority to access the first service.

[0537] It is understandable that the NF service consumer may also determine that the current indirect communication mode is mode D before step 1301.

[0538] After the NF service consumer determines to request the first service, the NF service consumer checks whether an access token corresponding to the first service is locally stored. The NF service consumer's determination that no available access token corresponding to the first service exists means that the NF service consumer determines that no access token corresponding to the first service is stored or that the stored access token corresponding to the first service has expired. Furthermore, if the NF service consumer determines that the stored access token corresponding to the first service has expired, the NF service consumer deletes the expired access token corresponding to the first service.

[0539] Exemplarily, the NF service consumer may receive a service request message from the UE, and determine that it needs to request the first service based on the service request message. The NF service consumer obtains relevant information of the UE (such as the context information of the UE) based on the identifier of the UE. Furthermore, the NF service consumer checks whether the public storage space includes an access token corresponding to the first service. If the access token corresponding to the first service is included and the access token has not expired, the access token is used; if the access token corresponding to the first service is not included, it is determined that there is no available access token; or if the access token corresponding to the first service is included but the access token has expired, it is determined that there is no available access token, and further optionally, the NF service consumer deletes the access token. The relevant information of the UE may be stored in the public storage space of the NF service consumer, or the NF service consumer obtains the relevant information of the UE from other network elements based on the identifier of the UE.

[0540] The NF service consumer also needs to determine whether a valid CCA is stored locally. If a valid CCA is stored (e.g., not expired), it uses that CCA. If no valid CCA is stored (e.g., expired or not stored), the NF service consumer generates a CCA. Furthermore, if a CCA expires, the NF service consumer deletes the expired CCA.

[0541] The CCA includes a first NF type and a second NF type, wherein the first NF type is the NF type of the NF service producer that expects to provide the first service, and the second NF type is the NF type of the NRF that expects to provide an access token.

[0542] In addition, the CCA also includes the identifier, timestamp, and expiration time of the NF instance of the NF service consumer.

[0543] Step 1302: The NF service consumer sends a first service request message to the SCP. The first service request message includes the CCA in step 1301 and parameters for obtaining an access token. The first service request message is used to request a first service.

[0544] The parameters used to obtain the access token can be the same as the parameters used to discover the NF service producer, or they can be completely different or partially different. The parameters used to obtain the access token can use the same information element indication as the parameters used to discover the NF service producer, or they can use different information element indications. For example, if the two are completely the same, the same information element indication can be used. If the two are completely different, the first service request message also includes the parameters used to discover the NF service producer. If they are partially different, the first service request message also includes the remaining parameters used to discover the NF service producer.

[0545] For example, the parameters used to obtain an access token may include the desired service name, the NF type of the NF service consumer and the NF type of the desired NF service producer, the S-NSSAI list or NSI ID list of the desired NF service producer instance, the NF Set ID of the desired NF service producer instance, the S-NSSAI list of the NF service consumer, etc. The parameters used to discover the NF service producer may include the NF type of the desired NF service producer and the S-NSSAI list or NSI ID list of the desired NF service producer instance. In this case, the parameters used to obtain an access token may be partially the same as the parameters used to discover the NF service producer.

[0546] Step 1303: The SCP sends an access token request message to the NRF. The access token request message includes the CCA and parameters for obtaining the access token.

[0547] Before the SCP sends the access token request message to the NRF, the SCP determines that the first service request message does not include the access token corresponding to the first service and the access token corresponding to the first service is not stored locally, or the SCP determines that the first service request message does not include the access token corresponding to the first service and the stored access token corresponding to the first service has expired. If it is determined that the stored access token corresponding to the first service has expired, the SCP deletes the expired access token corresponding to the first service.

[0548] Furthermore, it is understood that if the access token corresponding to the first service is a Type B access token, the SCP must initiate the NF service producer discovery process before step 1303. Otherwise, the SCP may initiate the NF service producer discovery process after obtaining the access token corresponding to the first service. Alternatively, if the NF service producer information is locally stored, the SCP may not initiate the NF service producer discovery process.

[0549] Among them, the access token request message can be NNrf_AccessToken_Get_Request or other messages, which is not limited in this embodiment of the present application.

[0550] Step 1304: The NRF receives the access token request message and authenticates the NF service Consumer based on the CCA.

[0551] The NRF successfully authenticates the NF service Consumer based on the CCA, performs an authorization check, confirms that the authorization is successful, and generates an access token corresponding to the first service.

[0552] The NRF verifies the signature of the CCA, verifies whether the CCA is expired based on the timestamp and / or expiration time of the CCA, and verifies whether the NF instance ID of the NF service consumer in the CCA matches the NF instance ID in the certificate used to sign the CCA. In addition to the successful verification of the above verification contents, the NRF also needs to verify whether the first NF type and the second NF type included in the CCA are the same as the NF type of the NRF. If the NRF determines that the second NF type matches the NF type of the NRF, the NRF determines that the NF service consumer authentication is successful.

[0553] Step 1305: The NRF sends an access token response message to the SCP, where the access token response message includes the access token corresponding to the first service.

[0554] Step 1306: The SCP sends a second service request message to the NF service producer. The second service request message includes the access token and CCA corresponding to the first service.

[0555] Step 1307: The NF service producer receives the second service request message from the SCP and authenticates the NF service consumer according to the CCA.

[0556] The NF service producer performs integrity verification on the access token corresponding to the first service. If the integrity verification succeeds, it further verifies the claims in the access token corresponding to the first service. For details, see the relevant content of the claims verification in the access token above.

[0557] The NF service producer also needs to authenticate the NF service consumer based on the CCA. The NF service producer verifies the CCA's signature, verifies whether the CCA has expired based on the timestamp and / or expiration time of the CCA, and verifies whether the NF instance ID of the NF service consumer in the CCA matches the NF instance ID in the certificate used to sign the CCA. In addition to successfully verifying all of the above, the NF service producer also needs to verify whether the first NF type and second NF type included in the CCA match the NF type of the NF service producer. If the NF service producer determines that the first NF type matches the NF type of the NF service producer, the NF service producer determines that the NF service consumer authentication is successful.

[0558] The order of verifying the access token and CCA can also be to verify the CCA first, and then verify the access token after successful verification. This is not limited here.

[0559] In addition, the NF service producer also checks whether the NF instance ID of the NF service consumer in the CCA is the same as the NF instance ID of the NF service consumer contained in the access token. If they are the same, the NF service producer provides the requested service to the NF service consumer.

[0560] Step 1308: The NF service producer determines that the first access token is successfully verified and the NF service consumer is successfully authenticated, and then the NF service producer sends a response message to the SCP for the second service request message. The response message to the second service request message is used to indicate the provision of the first service or the success of the second service request.

[0561] It is understandable that if the first access token verification fails and / or the NF service consumer authentication fails, the response message to the second service request message indicates that the first service request has failed.

[0562] Step 1309: The SCP receives a response message to the second service request message from the NF service producer, and sends a response message to the first service request message to the NF service consumer.

[0563] The response message to the second service request message may include the access token corresponding to the first service. The NF service Consumer stores the access token corresponding to the first service for subsequent initiation of requests for the first service.

[0564] Furthermore, if the NF service consumer determines that an access token corresponding to the first service is available, the NF service consumer may determine whether a CCA is stored. If so, it uses the CCA; if not, it generates a CCA. It is understood that the CCA may not include the second NF type. However, if the NF service consumer determines before step 1301 that the current indirect communication mode is Mode D, the first service request message must carry the first NF type and the second NF type.

[0565] In the above embodiment, the CCA includes the first NF type and the second NF type, thereby ensuring that the NRF and the NF service producer successfully authenticate the NF service consumer according to the CCA, thereby ensuring that the NF service consumer obtains the first service.

[0566] Example 2: Combination Figure 10 In the embodiment shown, when it is determined that the first service needs to be requested and there is no available access token corresponding to the first service, the NF service consumer can adopt but is not limited to the following embodiments to obtain the first service, such as Figure 14 shown.

[0567] Step 1401: The NF service consumer determines that it requests a first service and there is no available access token corresponding to the first service. The NF service consumer obtains CCA1 and CCA2. The access token corresponding to the first service represents / indicates that the NF service consumer has the authority to obtain the first service or the authority to access the first service.

[0568] It is understandable that the NF service consumer may also determine that the current indirect communication mode is mode D before step 1401. The NF service consumer determines that the first service is requested and there is no available access token corresponding to the first service. Figure 13The relevant descriptions in step 1301 in the above description will not be repeated.

[0569] In addition, the NF service consumer needs to determine whether available CCA1 and CCA2 are stored locally. If an available CCA1 is stored (for example, CCA1 has not expired), then this CCA1 is used. If an available CCA1 is not stored (for example, CCA1 has expired), then the NF service consumer generates CCA1. If an available CCA2 is stored (for example, CCA2 has not expired or CCA2 is not stored), then this CCA2 is used. If an available CCA2 is not stored (for example, CCA2 has expired or CCA2 is not stored), then the NF service consumer generates CCA2. When CCA1 or CCA2 expires, the NF service consumer deletes the expired CCA.

[0570] Among them, CCA1 includes a first NF type, and CCA2 includes a second NF type, wherein the first NF type is the NF type of the NF service producer that expects to provide the first service, and the second NF type is the NF type of the NRF that expects to provide an access token.

[0571] In addition, CCA1 also includes the identifier of the NF instance of the NF service consumer, a timestamp, and the expiration time of CCA1. CCA2 also includes the identifier of the NF instance of the NF service consumer, a timestamp, and the expiration time of CCA2.

[0572] Step 1402: The NF service consumer sends a first service request message to the SCP. The first service request message includes CCA1 and CCA2 in step 1401 and parameters for obtaining an access token. The first service request message is used to request a first service.

[0573] Regarding the parameters used to obtain the access token and the parameters used to discover the NF service producer, please refer to step 1402 in Example 1, and the repeated parts will not be repeated.

[0574] Step 1403: The SCP sends an access token request message to the NRF. The access token request message includes CCA2 and parameters for obtaining an access token.

[0575] Before the SCP sends the access token request message to the NRF, the SCP determines that the first service request message does not include the access token corresponding to the first service and the access token corresponding to the first service is not stored locally, or the SCP determines that the first service request message does not include the access token corresponding to the first service and the stored access token corresponding to the first service has expired. If it is determined that the stored access token corresponding to the first service has expired, the SCP deletes the expired access token corresponding to the first service.

[0576] Since SCP needs to send an access token request message to NRF, SCP selects CCA2 and adds it to the access token request message.

[0577] Furthermore, it is understood that if the access token corresponding to the first service is a Type B access token, the SCP must initiate the NF service producer discovery process before step 1403. Otherwise, the SCP may initiate the NF service producer discovery process after obtaining the access token corresponding to the first service. Alternatively, if the NF service producer information is locally stored, the SCP may not initiate the NF service producer discovery process.

[0578] Exemplarily, the access token request message may be NNrf_AccessToken_Get_Request or other messages, which is not limited in the embodiments of the present application.

[0579] Step 1404: The NRF receives the access token request message and authenticates the NF service consumer according to CCA2.

[0580] The NRF successfully authenticates the NF service Consumer according to CCA2, performs an authorization check, confirms that the authorization is passed, and generates an access token corresponding to the first service.

[0581] The NRF verifies the signature of CCA2, verifies whether CCA2 has expired based on the timestamp and / or expiration time of CCA2, and verifies whether the NF instance ID of the NF service consumer in CCA2 matches the NF instance ID in the certificate used to sign CCA2. In addition to the successful verification of the above verification contents, the NRF also needs to verify whether the second NF type included in CCA2 is the same as the NRF's NF type. Because the second NF type matches the NRF's NF type, the NRF determines that CCA2 verification is successful.

[0582] Step 1405: The NRF sends an access token response message to the SCP, where the access token response message includes the access token corresponding to the first service.

[0583] Step 1406: The SCP sends a second service request message to the NF service producer. The second service request message includes the access token and CCA1 corresponding to the first service.

[0584] Since the SCP needs to send a second service request message to the NF service producer, the SCP selects CCA1 to be added to the second service request message.

[0585] Step 1407: The NF service producer receives the second service request message from the SCP, and verifies CCA1 and the access token corresponding to the first service.

[0586] The NF service producer performs integrity verification on the access token corresponding to the first service. If the integrity verification succeeds, it further verifies the claims in the access token corresponding to the first service. For details, see the relevant content of the claims verification in the access token above.

[0587] The NF service producer also needs to authenticate the NF service consumer based on CCA1. The NF service producer verifies the signature of CCA1, verifies whether CCA1 has expired based on the timestamp and / or expiration time of CCA1, and verifies whether the NF instance ID of the NF service consumer in CCA1 matches the NF instance ID in the certificate used to sign CCA1. In addition to successfully verifying all of the above, the NF service consumer also needs to verify whether the first NF type included in CCA1 matches the NF type of the NF service producer. Since the first NF type matches the NF type of the NF service producer, the NF service consumer authentication is successful.

[0588] The order of verifying the access token and CCA1 can also be to verify CCA1 first, and then verify the access token after successful verification. This is not limited here.

[0589] After both the access token and CCA1 are successfully verified, the NF service producer also checks whether the NF instance ID of the NF service consumer in CCA1 is the same as the NF instance ID of the NF service consumer contained in the access token. If they are the same, the NF service producer provides the requested service to the NF service consumer.

[0590] Step 1408: If the NF service producer determines the first access token and the NF service consumer is successfully authenticated, the NF service producer sends a response message to the SCP for the second service request message. The response message to the second service request message is used to indicate that the first service is provided or that the second service request is successful.

[0591] It is understandable that if the first access token verification fails and / or the NF service consumer authentication fails, the response message to the second service request message indicates that the first service request has failed.

[0592] Step 1409: The SCP receives a response message to the second service request message from the NF service producer, and sends a response message to the first service request message to the NF service consumer.

[0593] The response message to the first service request message may include the access token corresponding to the first service. The NF service consumer stores the access token corresponding to the first service for subsequent initiation of requests for the first service.

[0594] Furthermore, if the NF service consumer determines that an access token corresponding to the first service is available, the NF service consumer can determine whether an available CCA1 is stored. If an available CCA1 is stored, the CCA1 is used; if no available CCA1 is stored, a CCA1 is generated. It is understood that at this point, the NF service consumer does not need to determine whether an available CCA2 is stored. Even if an available CCA2 is not stored, it does not need to generate a CCA2 or obtain the access token corresponding to the first service through the SCP. The first service request message may not include a CCA2. However, if the NF service consumer determines before step 1401 that the current indirect communication mode is mode D, the first service request message must carry both CCA1 and CCA2.

[0595] In the above embodiment, CCA1 includes the first NF type, and CCA2 includes the second NF type, thereby ensuring that the NRF successfully authenticates the NF service consumer according to CCA2, and the NF service producer successfully authenticates the NF service consumer according to CCA1, thereby ensuring that the NF service consumer obtains the first service.

[0596] Example 3: Combination Figure 11 In the embodiment shown, when it is determined that the first service needs to be requested and there is no available access token corresponding to the first service, the NF service consumer can adopt but is not limited to the following embodiments to obtain the first service, such as Figure 15 shown.

[0597] Step 1501 and step 1502 can refer to Figure 14 The repetitions between step 1401 and step 1402 are not repeated here.

[0598] Step 1503: The SCP sends an access token request message to the NRF. The access token request message includes CCA2 and CCA1 and parameters for obtaining the access token.

[0599] Before the SCP sends the access token request message to the NRF, the SCP determines that the first service request message does not include the access token corresponding to the first service and the access token corresponding to the first service is not stored locally, or the SCP determines that the first service request message does not include the access token corresponding to the first service and the stored access token corresponding to the first service has expired. If it is determined that the stored access token corresponding to the first service has expired, the SCP deletes the expired access token corresponding to the first service.

[0600] Furthermore, it is understood that if the access token corresponding to the first service is a Type B access token, the SCP must initiate the NF service producer discovery process before step 1503. Otherwise, the SCP may initiate the NF service producer discovery process after obtaining the access token corresponding to the first service. Alternatively, if the NF service producer information is locally stored, the SCP may not initiate the NF service producer discovery process.

[0601] Exemplarily, the access token request message may be NNrf_AccessToken_Get_Request or other messages, which is not limited in the embodiments of the present application.

[0602] Step 1504: The NRF receives the access token request message and authenticates the NF service consumer based on CCA1 and CCA2.

[0603] If the NRF successfully authenticates the NF service consumer according to CCA1 or successfully authenticates the NF service consumer according to CCA2, the NRF performs an authorization check, determines that the authorization is passed, and generates an access token corresponding to the first service.

[0604] NRF authenticates the NF service consumer based on CCA1 and CCA2. At this time, NRF does not need to determine that the NF service consumer authentication is successful based on CCA1 and that the NF service consumer authentication is successful based on CCA2. When the NF service consumer authentication is successful based on CCA1 or the NF service consumer authentication is successful based on CCA2, NRF determines that the NF service consumer authentication is successful.

[0605] The NRF verifies the signature of CCA1, verifies whether CCA1 has expired based on the timestamp and / or expiration time of CCA1, and verifies whether the NF instance ID of the NF service consumer in CCA1 matches the NF instance ID in the certificate used to sign CCA1. In addition to the successful verification of the above verification contents, the NRF also needs to verify whether the first NF type included in CCA1 matches the NF type of the NRF. Since the first NF type does not match the NF type of the NRF, the NRF determines that the NF service consumer authentication has failed.

[0606] The NRF verifies the signature of CCA2, verifies whether CCA2 has expired based on the timestamp and / or expiration time of CCA2, and verifies whether the NF instance ID of the NF service consumer in CCA2 matches the NF instance ID in the certificate used to sign CCA2. In addition to the successful verification of the above verification contents, the NRF also needs to verify whether the second NF type included in CCA2 matches the NF type of the NRF. Since the second NF type matches the NF type of the NRF, the NRF determines that the NF service consumer authentication is successful.

[0607] Step 1505: The NRF sends an access token response message to the SCP, where the access token response message includes the access token corresponding to the first service.

[0608] Step 1506: The SCP sends a second service request message to the NF service producer. The second service request message includes the access token, CCA1, and CCA2 corresponding to the first service.

[0609] Step 1507: The NF service producer receives the second service request message from the SCP and verifies CCA1, CCA2, and the access token.

[0610] The NF service producer performs integrity verification on the access token corresponding to the first service. If the integrity verification succeeds, it further verifies the claims in the access token corresponding to the first service. For details, see the relevant content of the claims verification in the access token above.

[0611] The NF service producer authenticates the NF service consumer according to CCA1 and CCA2. In this case, the NF service producer does not need to determine that the NF service consumer authentication is successful according to CCA1 and that the NF service consumer authentication is successful according to CCA2. When the NF service producer determines that the NF service consumer authentication is successful according to CCA1 or that the NF service consumer authentication is successful according to CCA2, the NF service producer determines that the NF service consumer authentication is successful.

[0612] The NF service producer verifies the signature of CCA1, verifies whether CCA1 has expired based on the timestamp and / or expiration time of CCA1, and verifies whether the NF instance ID of the NF service consumer in CCA1 matches the NF instance ID in the certificate used to sign the CCA1. In addition to successfully verifying all of the above verification items, the NF service producer also needs to verify whether the first NF type included in CCA1 matches the NF type of the NF service producer. If the first NF type matches the NF type of the NF service producer, the NF service producer determines that the NF service consumer authentication is successful.

[0613] The NF service producer verifies the signature of CCA2, verifies whether CCA2 has expired based on the timestamp and / or expiration time of CCA2, and verifies whether the NF instance ID of the NF service consumer in CCA2 matches the NF instance ID in the certificate used to sign CCA2. In addition to the successful verification of the above verification contents, the NF service producer also needs to verify whether the second NF type included in CCA2 matches the NF type of the NF service producer. Because the second NF type is the NF type of the NF service producer that is expected to provide the access token corresponding to the first service, the second NF type does not match the NF type of the NF service producer. Therefore, the NF service producer determines that the NF service consumer authentication has failed.

[0614] Step 1508: The NF service producer determines that the first access token is successfully verified and the NF service consumer is successfully authenticated, and then the NF service producer sends a response message to the SCP for the second service request message. The response message to the second service request message is used to indicate the provision of the first service or the success of the second service request.

[0615] It is understandable that if the first access token verification fails and / or the NF service consumer authentication fails, the response message to the second service request message indicates that the first service request has failed.

[0616] Step 1509: The SCP receives a response message to the second service request message from the NF service producer, and sends a response message to the first service request message to the NF service consumer.

[0617] The response message to the second service request message may include the access token corresponding to the first service. The NF service consumer stores the access token corresponding to the first service for subsequent initiation of requests for the first service.

[0618] In the above embodiment, CCA1 includes the first NF type and CCA2 includes the second NF type, thereby ensuring that the NRF successfully authenticates the NF service consumer according to CCA1 and the NF service producer successfully authenticates the NF service consumer according to CCA2, thereby ensuring that the NF service consumer obtains the first service.

[0619] Example 4: When it is determined that the first service needs to be requested and there is an available access token corresponding to the first service, the NF service consumer can obtain the first service by adopting but not limited to the following embodiments, such as Figure 16 shown.

[0620] Step 1601: The NF service consumer determines that it requests a first service and there is an available access token corresponding to the first service. The NF service consumer obtains a CCA. The access token corresponding to the first service represents / indicates that the NF service consumer has the authority to obtain the first service or the authority to access the first service.

[0621] If the NF service consumer determines that an access token corresponding to the first service is available, the NF service consumer may further determine whether a valid CCA is stored. If so, the CCA is used. If not, the CCA is generated. It is understood that the CCA generated by the NF service consumer at this time does not need to include the second NF type.

[0622] The CCA includes the identifier, timestamp, expiration time and first NF type of the NF instance of the NF service consumer, wherein the first NF type is the NF type of the NF service producer that expects to provide the first service.

[0623] Step 1602: The NF service Consumer sends a first service request message to the SCP. The first service request message includes the CCA in step 1601 and the access token corresponding to the first service.

[0624] Step 1603: The SCP sends a second service request message to the NF service producer. The second service request message includes the access token and CCA corresponding to the first service.

[0625] Before the SCP sends the second service request message to the NF service producer, the SCP determines that the first service request message includes the access token corresponding to the first service or locally stores the access token corresponding to the first service.

[0626] Step 1604: The NF service producer receives the second service request message from the SCP. The NF service producer authenticates the NF service consumer according to the CCA.

[0627] The NF service consumer performs integrity verification on the access token corresponding to the first service. If the integrity verification succeeds, the NF service consumer further verifies the claims in the access token corresponding to the first service. For details, see the above section on claims verification in access tokens. The NF service producer also needs to authenticate the NF service consumer based on the CCA. For details, please refer to the existing CCA verification process.

[0628] The NF service producer verifies the signature of the CCA, verifies whether the CCA has expired based on the timestamp and / or expiration time of the CCA, and verifies whether the NF instance ID of the NF service consumer in the CCA matches the NF instance ID in the certificate used to sign the CCA. In addition to successfully verifying all of the above, the NF service producer also needs to verify whether the first NF type included in CCA1 matches the NF type of the NF service producer. If the first NF type matches the NF type of the NF service producer, the NF service producer determines that the NF service consumer authentication is successful.

[0629] Step 1605: The NF service producer determines that the first access token verification is successful and the NF service consumer authentication is successful, then the NF service producer sends a response message to the SCP for the second service request message.

[0630] The response message to the second service request message is used to indicate that the first service is provided or to indicate that the second service request is successful.

[0631] It is understandable that if the first access token verification fails and / or the NF service consumer authentication fails, the response message to the second service request message indicates that the first service request has failed.

[0632] Step 1606: The SCP receives a response message to the second service request message from the NF service producer, and sends a response message to the first service request message to the NF service consumer.

[0633] By using the above embodiment and determining the available stored CCA, the NF service consumer can obtain the first service by only carrying the first NFtype.

[0634] Example 5: Combination Figure 8In the embodiment shown, when the first service needs to be requested and the request for the first service triggers the SCP to request the parameters of the NF service producer (triggering the SCP to initiate the discovery process of the NF service producer), the NF service consumer can adopt but is not limited to the following embodiments to obtain the first service, such as Figure 17 shown.

[0635] Step 1701: The NF service consumer determines to trigger the SCP to initiate the discovery process of the NF service producer, and the NF service consumer obtains the CCA.

[0636] It is understandable that the NF service consumer may also determine that the current indirect communication mode is mode D before step 1701.

[0637] For example, the NF service consumer may determine to trigger the SCP to initiate the NF service producer discovery process based on one or more of the following:

[0638] Case 1: The UE context is not stored. Exemplarily, the NF service consumer determines that it needs to request the first service according to the service request message of the UE.

[0639] Case 2: The context of the first service is not stored.

[0640] Case 3: The first slice belongs to the service providing network element and the context of the first slice is not stored. For example, the NF service consumer determines that it needs to request the first service from the service providing network element in the first slice based on the service request message of the UE.

[0641] Case 4: The service consuming network element communicates with the service communication agent for the first time.

[0642] Before an NF service consumer generates a CCA, it first determines whether a locally available CCA is stored. If a locally available CCA is stored (e.g., not expired), it uses that CCA. If no locally available CCA is stored (e.g., expired or not stored), the NF service consumer generates a CCA. When a CCA expires, the NF service consumer deletes the expired CCA.

[0643] The CCA includes a first NF type and a second NF type, wherein the first NF type is the NF type of the NF service producer that expects to provide the first service, and the second NF type is the NF type of the NRF that expects to provide information of the NF service producer.

[0644] In addition, the CCA also includes the identifier, timestamp, and expiration time of the NF instance of the NF service consumer.

[0645] Step 1702: The NF service consumer sends a first service request message to the SCP. The first service request message includes the CCA in step 1701 and parameters for discovering the NF service producer. The first service request message is used to request a first service.

[0646] Exemplarily, the parameters for discovering the NF service producer may include the NFtype of the desired NF service producer, the S-NSSAI list or NSI ID list of the desired NF service producer instance, etc.

[0647] Step 1703: The SCP sends a discovery request message to the NRF. The discovery request message includes the CCA and parameters for discovering the NF service producer.

[0648] Before the SCP sends the discovery request message to the NRF, the SCP determines that the first service request message does not include the information of the NF service producer and the information of the NF service producer is not stored locally.

[0649] It is assumed here that the first service request message further includes an access token corresponding to the first service, or the SCP locally stores the access token corresponding to the first service.

[0650] Step 1704: The NRF receives the discovery request message and authenticates the NF service consumer based on the CCA.

[0651] The NRF verifies the signature of the CCA, verifies whether the CCA is expired based on the timestamp and / or expiration time of the CCA, and verifies whether the NF instance ID of the NF service consumer in the CCA matches the NF instance ID in the certificate used to sign the CCA. In addition to the successful verification of the above verification contents, the NRF also needs to verify whether the first NF type and the second NF type included in the CCA match the NF type of the NRF. If the NRF determines that the second NF type matches the NF type of the NRF, the NRF determines that the NF service consumer authentication is successful.

[0652] Step 1705: The NRF sends a discovery response message to the SCP. The discovery response message includes parameters of the NF service producer.

[0653] When the NF service consumer is successfully authenticated, the NRF sends a discovery response message to the SCP. The discovery response message includes the parameters of the NF service producer.

[0654] Step 1706: The SCP sends a second service request message to the NF service producer. The second service request message includes the access token and CCA corresponding to the first service.

[0655] The SCP sends a second service request message to the NF service producer indicated by the parameter of the NF service producer in the discovery response message.

[0656] Step 1707: The NF service producer receives the second service request message from the SCP and authenticates the NF service consumer based on the CCA.

[0657] The NF service producer performs integrity verification on the access token corresponding to the first service. If the integrity verification succeeds, it further verifies the claims in the access token corresponding to the first service. For details, see the relevant content related to access token claims verification above. The NF service producer also needs to authenticate the NF service consumer according to the CCA.

[0658] Among them, the NF service producer verifies the signature of the CCA, verifies whether the CCA is expired based on the timestamp and / or the expiration time of the CCA, and verifies whether the NF instance ID of the NF service consumer in the CCA matches the NF instance ID in the certificate used to sign the CCA. In addition to the successful verification of the above verification contents, the NF service producer also needs to verify whether the first NFtype and the second NFtype included in the CCA have an NF type that matches the NF type of the NF service producer. When the NF service producer determines that the first NF type matches the NF type of the NF service producer, the NF service producer determines that the NF service consumer authentication is successful.

[0659] Step 1708: The NF service producer determines that the first access token is successfully verified and the NF service consumer is successfully authenticated, and then the NF service producer sends a response message to the SCP for the second service request message. The response message to the second service request message is used to indicate the provision of the first service or the success of the second service request.

[0660] It is understandable that if the first access token verification fails and / or the NF service consumer authentication fails, the response message to the second service request message indicates that the first service request has failed.

[0661] Step 1709: The SCP receives a response message to the second service request message from the NF service producer, and sends a response message to the first service request message to the NF service consumer.

[0662] In the above embodiment, the CCA includes the first NF type and the second NF type, thereby ensuring that the NRF and the NF service producer successfully authenticate the NF service consumer according to the CCA, thereby ensuring that the NF service consumer obtains the first service.

[0663] Example 6: Combination Figure 10 In the embodiment shown, when the first service needs to be requested and the request for the first service triggers the SCP to request the parameters of the NF service producer (triggering the SCP to initiate the discovery process of the NF service producer), the NF service consumer can adopt but is not limited to the following embodiments to obtain the first service, such as Figure 18 shown.

[0664] Step 1801: The NF service consumer determines to trigger the SCP to execute the discovery process of the NF service producer, and the NF service consumer obtains CCA1 and CCA2.

[0665] It is understandable that the NF service consumer may also determine that the current indirect communication mode is mode D before step 1801.

[0666] For example, the NF service consumer determines to trigger the SCP to execute the discovery process of the NF service producer, which can refer to the relevant description in step 1701 of the above embodiment 5.

[0667] In addition, before the NF service consumer generates CCA1 and CCA2, the NF service consumer needs to first determine whether available CCA1 and CCA2 are stored locally. If an available CCA1 is stored (for example, CCA1 is still within the expiration time), the CCA1 is used. If an available CCA1 is not stored (for example, CCA1 has expired or CCA1 is not stored), the NF service consumer generates CCA1. If an available CCA2 is stored (for example, CCA2 has not expired), the CCA2 is used. If an available CCA2 is not stored (for example, CCA2 has expired or CCA2 is not stored), the NF service consumer generates CCA2. Among them, if CCA1 or CCA2 expires, the NF service consumer deletes the expired CCA.

[0668] Among them, CCA1 includes a first NF type, and CCA2 includes a second NF type, wherein the first NF type is the NF type of the NF service producer that expects to provide the first service, and the second NF type is the NF type of the NRF that expects to provide information of the NF service producer.

[0669] In addition, CCA1 also includes the identifier of the NF instance of the NF service consumer, a timestamp, and the expiration time of CCA1. CCA2 also includes the identifier of the NF instance of the NF service consumer, a timestamp, and the expiration time of CCA2.

[0670] Step 1802: The NF service consumer sends a first service request message to the SCP. The first service request message includes CCA1 and CCA2 in step 1801 and parameters for discovering the NF service producer. The first service request message is used to request a first service.

[0671] Step 1803: The SCP sends a discovery request message to the NRF. The discovery request message includes CCA2 and parameters for discovering the NF service producer.

[0672] Before the SCP sends the discovery request message to the NRF, the SCP determines that the first service request message does not include the information of the NF service producer and the information of the NF service producer is not stored locally.

[0673] It is assumed here that the first service request message further includes an access token corresponding to the first service, or the SCP locally stores the access token corresponding to the first service.

[0674] Since the SCP needs to send a discovery request message to the NRF, the SCP selects CCA2 and adds it to the discovery request message.

[0675] Step 1804: NRF receives the discovery request message and authenticates the NF service consumer according to CCA2.

[0676] The NRF verifies the signature of CCA2, verifies whether CCA2 has expired based on the timestamp and / or expiration time of CCA2, and verifies whether the NF instance ID of the NF service consumer in CCA2 matches the NF instance ID in the certificate used to sign CCA2. In addition to the successful verification of the above verification contents, the NRF also needs to verify whether the second NF type included in CCA2 matches the NF type of the NRF. Because the second NF type matches the NF type of the NRF, the NRF determines that the NF service consumer authentication is successful.

[0677] Step 1805: The NRF sends a discovery response message to the SCP. The discovery response message includes information about the NF service producer.

[0678] When the NF service consumer is successfully authenticated, the NRF sends a discovery response message to the SCP. The discovery response message includes the parameters of the NF service producer.

[0679] Step 1806: The SCP sends a second service request message to the NF service producer. The second service request message includes the access token and CCA1 corresponding to the first service.

[0680] The SCP sends a second service request message to the NF service producer indicated by the parameter of the NF service producer in the discovery response message.

[0681] Since the SCP needs to send a second service request message to the NF service producer, the SCP selects CCA1 to be added to the second service request message.

[0682] Step 1807: The NF service producer receives the second service request message from the SCP and authenticates the NF service consumer according to CCA1.

[0683] The NF service producer performs integrity verification on the access token corresponding to the first service. If the integrity verification succeeds, it further verifies the claims in the access token corresponding to the first service. For details, see the relevant content related to access token claims verification above. The NF service producer also needs to authenticate the NF service consumer according to CCA1.

[0684] The NF service producer verifies the signature of CCA1, verifies whether CCA1 has expired based on its timestamp and / or expiration time, and verifies whether the NF instance ID of the NF service consumer in CCA1 matches the NF instance ID in the certificate used to sign the CCA1. In addition to successfully verifying all of the above, the NF service consumer also needs to verify whether the first NF type included in CCA1 matches the NF type of the NF service producer. Since the first NF type matches the NF type of the NF service producer, the NF service producer determines that the NF service consumer authentication is successful.

[0685] Step 1808: The NF service producer determines that the first access token is successfully verified and the NF service consumer is successfully authenticated, and then the NF service producer sends a response message to the SCP for the second service request message. The response message to the second service request message is used to indicate the provision of the first service or the success of the second service request.

[0686] It is understandable that if the first access token verification fails and / or the NF service consumer authentication fails, the response message to the second service request message indicates that the first service request has failed.

[0687] Step 1809: The SCP receives a response message to the second service request message from the NF service producer, and sends a response message to the first service request message to the NF service consumer.

[0688] Furthermore, if the NF service consumer determines that it does not need to trigger the SCP to execute the NF service producer's discovery process, the NF service consumer can determine whether an available CCA1 is stored. If so, it uses that CCA1; if not, it generates a CCA1. It is understood that at this point, the NF service consumer does not need to determine whether an available CCA2 is stored. Even if an available CCA2 is not stored, it does not need to generate a CCA2, and the first service request message may not include a CCA2. However, if the NF service consumer determines before step 1801 that the current indirect communication mode is Mode D, the first service request message must carry both CCA1 and CCA2.

[0689] In the above embodiment, CCA1 includes the first NF type and CCA2 includes the second NF type, thereby ensuring that the NRF successfully authenticates the NF service consumer according to CCA1 and the NF service producer successfully authenticates the NF service consumer according to CCA2, thereby ensuring that the NF service consumer obtains the first service.

[0690] Example 7: Combination Figure 8 and Figure 10 In the embodiment shown, the NF service consumer obtains the indication information, and the NF service consumer sends a service request message to the SCP according to the indication information. The NF service consumer can adopt but is not limited to the following embodiments to obtain the first service, such as Figure 19 shown.

[0691] Step 1901: NF service consumer obtains CCA1.

[0692] It is understandable that the NF service consumer may also determine that the current indirect communication mode is mode D before step 1901.

[0693] The NF service consumer determines to request the first service and obtains CCA1. Before generating CCA1, the NF service consumer must first determine whether a locally available CCA1 is stored. If a locally available CCA1 is stored (e.g., not expired), the CCA1 is used. If no locally available CCA1 is stored (e.g., expired, or not stored), the NF service consumer generates CCA1. Furthermore, if CCA1 is expired, the NF service consumer deletes the expired CCA1.

[0694] Among them, CCA1 includes the identifier of the NF instance of the NF service consumer, a timestamp, an expiration time of CCA1, and a first NFtype, where the first NFtype is the NFtype of the NF service producer that expects to provide the first service.

[0695] Step 1902: The NF service consumer sends a first service request message to the SCP, where the first service request message includes CCA1 in step 1901. The first service request message is used to request a first service.

[0696] Step 1903: The SCP sends a second service request message to the NRF. The second service request message includes CCA1 and is used to request a second service.

[0697] Step 1904: The NRF receives the second service request message, and the NRF fails to authenticate the NF service consumer according to CCA1.

[0698] The NRF verifies the signature of CCA1, verifies whether CCA1 has expired based on the timestamp and / or expiration time of CCA1, and verifies whether the NF instance ID of the NF service consumer in CCA1 matches the NF instance ID in the certificate used to sign CCA1. In addition to the successful verification of the above verification contents, the NRF also needs to verify whether the first NF type included in CCA1 matches the NF type of the NRF. Since the first NF type does not match the NF type of the NRF, the NRF determines that the NF service consumer authentication has failed.

[0699] Step 1905: The NRF sends a response message to the SCP in response to the second service request message. The response message includes CCA2, which includes the identifier, timestamp, and expiration time of the NRF's NF instance, the NF type of the NF service consumer, and the NF type of the NRF.

[0700] Step 1906: The SCP sends a response message to the NF service consumer in response to the first service request message. The response message to the first service request message includes CCA2.

[0701] Step 1907: The NF service consumer sends a third service request message to the SCP, where the third service request message includes CCA3 and CCA4, or the third service request message includes CCA5.

[0702] CCA3 includes the identifier of the NF instance of the NF service consumer, a timestamp, the expiration time of the CCA3, and the first NFtype.

[0703] CCA4 includes the identifier of the NF instance of the NF service consumer, a timestamp, the expiration time of CCA4, and the second NFtype.

[0704] CCA5 includes the identifier of the NF instance of the NF service consumer, timestamp, expiration time of CCA5, first NF type, and second NF type.

[0705] The first NF type is the NF type of the NF service producer that expects to provide the first service, and the second NF type is the NF type of the NF service producer that expects to provide the second service.

[0706] For example, the NF service consumer authenticates the NRF according to CCA2, and if the NRF authentication is successful, generates CCA3 and CCA4, or CCA5 according to the NF type of the NRF in CCA2.

[0707] Step 1908: The SCP sends a fourth service request message to the NRF. The fourth service request message includes CCA4 or CCA5. The fourth service request message is used to request the second service.

[0708] Step 1909: The NRF receives the fourth service request message, and the NRF authenticates the NF service consumer according to the CCA in the fourth service request message.

[0709] For example, if the fourth service request message includes CCA4, the NRF successfully authenticates the NF service consumer based on CCA4. The NRF verifies the signature of the CCA4, verifies whether the CCA4 is expired based on the timestamp and / or expiration time of the CCA4, and verifies whether the NF instance ID of the NF service consumer in the CCA4 matches the NF instance ID in the certificate used to sign the CCA4. In addition to the successful verification of the aforementioned verification contents, the NRF also needs to verify whether the second NF type included in the CCA4 matches the NRF's NF type. Since the second NF type matches the NRF's NF type, the NRF determines that the NF service consumer authentication is successful.

[0710] For example, if the fourth service request message includes CCA5, the NRF successfully authenticates the NF service consumer based on the CCA5. The NRF verifies the signature of the CCA5, verifies whether the CCA5 is expired based on the timestamp and / or expiration time of the CCA5, and verifies whether the NF instance ID of the NF service consumer in the CCA5 matches the NF instance ID in the certificate used to sign the CCA5. In addition to the successful verification of the aforementioned verification contents, the NRF also needs to verify whether the first NF type and the second NF type included in the CCA5 match the NRF's NF type. Since the second NF type matches the NRF's NF type, the NRF determines that the NF service consumer authentication is successful.

[0711] Step 1910: The NRF sends a response message to the SCP in response to the fourth service request message.

[0712] Step 1911: The SCP sends a fifth service request message to the NF service producer. The fifth service request message includes CCA3 and the access token corresponding to the first service, or the fifth service request message includes CCA5 and the access token corresponding to the first service.

[0713] Step 1912: The NF service producer receives the fifth service request message from the SCP and authenticates the NF service consumer based on the CCA in the fifth service request message.

[0714] The NF service producer performs integrity verification on the access token corresponding to the first service. If the integrity verification succeeds, it further verifies the claims in the access token corresponding to the first service. For details, see the relevant content of the claims verification in the access token above.

[0715] If the fifth service request message includes a CCA3, the NF service producer also needs to authenticate the NF service consumer based on the CCA3. The NF service producer verifies the signature of the CCA3, verifies whether the CCA3 is expired based on the timestamp and / or expiration time of the CCA3, and verifies whether the NF instance ID of the NF service consumer in the CCA3 matches the NF instance ID in the certificate used to sign the CCA3. In addition to successfully verifying all of the above verification details, the NF service consumer also needs to verify whether the first NF type included in the CCA3 matches the NF type of the NF service producer. Since the first NF type matches the NF type of the NF service producer, the NF service consumer authentication is determined to be successful.

[0716] If the fifth service request message includes CCA5, the NF service producer also needs to authenticate the NF service consumer based on CCA5. The NF service producer verifies the signature of the CCA5, verifies whether the CCA5 is expired based on the timestamp and / or expiration time of the CCA5, and verifies whether the NF instance ID of the NF service consumer in the CCA5 matches the NF instance ID in the certificate used to sign the CCA5. In addition to the successful verification of the above verification contents, the NF service consumer also needs to verify whether the first NF type and the second NF type included in the CCA5 include an NF type that matches the NF type of the NF service producer. Since the first NF type matches the NF type of the NF service producer, the CCA5 authentication is determined to be successful.

[0717] Step 1913: The NF service producer confirms the first access token and the NF service consumer is successfully authenticated, and sends a response message to the SCP for the fifth service request message. The response message to the fifth service request message is used to provide an indication of the first service or indicate the success of the fifth service request.

[0718] It is understandable that if the first access token verification fails and / or the NF service consumer authentication fails, the response message to the fifth service request message indicates that the first service request has failed.

[0719] Step 1914: The SCP receives a response message to the fifth service request message from the NF service producer, and sends a response message to the third service request message to the NF service consumer.

[0720] Using the above embodiment, SCP sends indication information to the NF service consumer. The NF service consumer sends a service request message carrying CCA3 (first NF type) and CCA4 (second NF type) or CCA5 (first NF type and second NF type) according to the indication information, thereby ensuring that the NF service consumer obtains the first service.

[0721] Example 8: Combination Figure 12 In the embodiment shown, the SCP actively requests the client authentication credentials and sends a client authentication credentials request message. The NF service consumer responds to the client authentication credentials request message. The NF service consumer can obtain the first service by adopting but not limited to the following embodiments, such as Figure 20 shown.

[0722] For steps 2001 to 2005 , reference may be made to the descriptions of steps 1901 to 1905 in the above-mentioned embodiment 7.

[0723] Step 2006: The SCP sends a CCA request message to the NF service consumer, including CCA2.

[0724] Step 2007: The NF service consumer sends a response message to the SCP for the CCA request message, where the response message to the CCA request message includes CCA3, or the response message to the CCA request message includes CCA4.

[0725] CCA3 includes the identifier of the NF instance of the NF service consumer, a timestamp, the expiration time of the CCA3, and the second NFtype.

[0726] CCA4 includes the identifier of the NF instance of the NF service consumer, timestamp, expiration time of CCA4, first NF type, and second NF type.

[0727] The first NF type is the NF type of the NF service producer that expects to provide the first service, and the second NF type is the NF type of the NF service producer that expects to provide the second service.

[0728] For example, the NF service consumer authenticates the NRF according to CCA2, and if the NRF authentication is successful, generates CCA3 or CCA4 according to the NF type of the NRF in CCA2.

[0729] Step 2008: The SCP sends a third service request message to the NRF. The third service request message includes CCA3 or CCA4. The third service request message is used to request the second service.

[0730] Step 2009: The NRF receives the third service request message, and authenticates the NF service consumer according to the CCA in the third service request message.

[0731] For example, if the third service request message includes a CCA3, the NRF successfully authenticates the NF service consumer based on the CCA3. The NRF verifies the signature of the CCA3, verifies whether the CCA3 is expired based on the timestamp and / or expiration time of the CCA3, and verifies whether the NF instance ID of the NF service consumer in the CCA3 matches the NF instance ID in the certificate used to sign the CCA3. In addition to successfully verifying all of the above verification details, the NRF also needs to verify whether the second NF type included in the CCA3 matches the NRF's NF type. Since the second NF type matches the NRF's NF type, the NRF determines that the NF service consumer authentication is successful.

[0732] For example, if the third service request message includes CCA4, the NRF successfully authenticates the NF service consumer based on CCA4. The NRF verifies the signature of the CCA4, verifies whether the CCA4 is expired based on the timestamp and / or expiration time of the CCA4, and verifies whether the NF instance ID of the NF service consumer in the CCA4 matches the NF instance ID in the certificate used to sign the CCA4. In addition to the successful verification of the above verification contents, the NRF also needs to verify whether the first NF type and the second NF type included in the CCA4 match the NF type of the NRF. Since the second NF type matches the NF type of the NRF, the NRF determines that the NF service consumer authentication is successful.

[0733] Step 2010: The NRF sends a response message to the SCP in response to the third service request message.

[0734] Step 2011: The SCP sends a fourth service request message to the NF service producer. The fourth service request message includes CCA3 and the access token corresponding to the first service, or the fourth service request message includes CCA4 and the access token corresponding to the first service.

[0735] Step 2012: The NF service producer receives the fourth service request message from the SCP and authenticates the NF service consumer based on the CCA in the fourth service request message.

[0736] The NF service producer performs integrity verification on the access token corresponding to the first service. If the integrity verification succeeds, it further verifies the claims in the access token corresponding to the first service. For details, see the relevant content of the claims verification in the access token above.

[0737] If the fourth service request message includes a CCA3, the NF service producer also needs to authenticate the NF service consumer based on the CCA3. The NF service producer verifies the signature of the CCA3, verifies whether the CCA3 is expired based on the timestamp and / or expiration time of the CCA3, and verifies whether the NF instance ID of the NF service consumer in the CCA3 matches the NF instance ID in the certificate used to sign the CCA3. In addition to successfully verifying all of the above verification details, the NF service consumer also needs to verify whether the first NF type included in the CCA3 matches the NF type of the NF service producer. Since the first NF type matches the NF type of the NF service producer, the NF service consumer authentication is determined to be successful.

[0738] If the fourth service request message includes CCA4, the NF service producer also needs to authenticate the NF se...

Claims

1. A communication method, characterized in that: The method includes: The service-consuming network element sends a first service request message to the service communication agent, where the first service request message is used to request a first service from the service-providing network element, and the first service request message includes a first customer authentication credential, where the first customer authentication credential is used to authenticate the service-consuming network element, and the first customer authentication credential includes a first network function type and a second network function type, where the first network function type is a network function type of the service-providing network element, and the second network function type is a network function type of a network element providing a second service; wherein the second service is associated with the first service; The service consuming network element receives a response message to the first service request message from the service communication agent.

2. The method according to claim 1, wherein The second service is used to provide an access token corresponding to the first service, and the access token corresponding to the first service is used to indicate that the service-consuming network element has the authority to obtain the first service.

3. The method according to claim 1 or 2, wherein: Also includes: The service consuming network element determines that there is no available access token corresponding to the first service.

4. The method according to claim 3, wherein The service consumption network element determines that there is no available access token corresponding to the first service, including: The service consumption network element determines that the access token corresponding to the first service is not stored; or The service consumption network element determines that the stored access token corresponding to the first service has expired.

5. The method according to claim 4, wherein Also includes: In a case where the stored access token corresponding to the first service has expired, the service consumption network element deletes the expired access token.

6. The method according to claim 1, wherein The second service is used to provide information about the service providing network element.

7. The method according to claim 6, wherein Also includes: The service consuming network element determines that the first service request message will trigger the service communication agent to request the second service.

8. The method according to claim 7, wherein The service consuming network element determining that the first service request message will trigger the service communication agent to request the second service includes: The service consuming network element determines that the first service request message will trigger the service communication agent to request the second service based on one or more of the following: The context of the first terminal device is not stored, and the first terminal device is associated with the first service; or, the context of the first service is not stored; or, the service providing network element belongs to the first slice and the context corresponding to the first slice is not stored; or, the service consuming network element communicates with the service communication agent for the first time.

9. The method according to claim 3, wherein Also includes: The service consumption network element determines to use the indirect communication mode of mode D to request the first service.

10. The method according to any one of claims 1, 2, 4, 5, 6, 7 and 8, wherein: Also includes: The service consumption network element determines to use the indirect communication mode of mode D to request the first service.

11. The method according to claim 3, wherein Also includes: The service consuming network element sends a second service request message to the service communication agent, where the second service request message is used to request the first service, the second service request message includes a second customer authentication credential, the second customer authentication credential includes the first network function type, and the second customer authentication credential is used to authenticate the service consuming network element; The service consumption network element receives a response message to the second service request message from the service communication agent, where the response message to the second service request message includes indication information; The service consumption network element sends a first service request message to the service communication agent, including: The service consumption network element sends the first service request message to the service communication agent according to the indication information.

12. The method according to claim 10, wherein Also includes: The service consuming network element sends a second service request message to the service communication agent, where the second service request message is used to request the first service, the second service request message includes a second customer authentication credential, the second customer authentication credential includes the first network function type, and the second customer authentication credential is used to authenticate the service consuming network element; The service consumption network element receives a response message to the second service request message from the service communication agent, where the response message to the second service request message includes indication information; The service consumption network element sends a first service request message to the service communication agent, including: The service consumption network element sends the first service request message to the service communication agent according to the indication information.

13. The method according to any one of claims 1, 2, 4, 5, 6, 7, 8, and 9, wherein: Also includes: The service consuming network element sends a second service request message to the service communication agent, where the second service request message is used to request the first service, the second service request message includes a second customer authentication credential, the second customer authentication credential includes the first network function type, and the second customer authentication credential is used to authenticate the service consuming network element; The service consumption network element receives a response message to the second service request message from the service communication agent, where the response message to the second service request message includes indication information; The service consumption network element sends a first service request message to the service communication agent, including: The service consumption network element sends the first service request message to the service communication agent according to the indication information.

14. The method according to claim 11 or 12, wherein: The indication information includes a third customer authentication credential, and the third customer authentication credential includes the second network function type; wherein the third customer authentication credential is used to authenticate the network element providing the second service; The service consumption network element sending the first service request message to the service communication agent according to the indication information includes: In a case where the network element providing the second service is successfully authenticated according to the third client authentication credential, the service-consuming network element sends the first service request message to the service communication agent.

15. The method according to claim 13, wherein The indication information includes a third customer authentication credential, and the third customer authentication credential includes the second network function type; wherein the third customer authentication credential is used to authenticate the network element providing the second service; The service consumption network element sending the first service request message to the service communication agent according to the indication information includes: In a case where the network element providing the second service is successfully authenticated according to the third client authentication credential, the service-consuming network element sends the first service request message to the service communication agent.

16. The method according to claim 3, wherein The network element providing the second service is a network storage function network element.

17. The method according to claim 10, wherein The network element providing the second service is a network storage function network element.

18. The method according to claim 13, wherein The network element providing the second service is a network storage function network element.

19. The method according to claim 14, wherein The network element providing the second service is a network storage function network element.

20. The method according to any one of claims 1, 2, 4, 5, 6, 7, 8, 9, 11, 12, and 15, wherein: The network element providing the second service is a network storage function network element.

21. The method according to claim 3, wherein The first customer authentication credential further includes one or more of the following: an identifier of the service consumption network element or validity period information, wherein the validity period information is used to represent the validity period of the first customer authentication credential.

22. The method according to claim 10, wherein The first customer authentication credential further includes one or more of the following: an identifier of the service consumption network element or validity period information, wherein the validity period information is used to represent the validity period of the first customer authentication credential.

23. The method according to claim 13, wherein The first customer authentication credential further includes one or more of the following: an identifier of the service consumption network element or validity period information, wherein the validity period information is used to represent the validity period of the first customer authentication credential.

24. The method of claim 14, wherein: The first customer authentication credential further includes one or more of the following: an identifier of the service consumption network element or validity period information, wherein the validity period information is used to represent the validity period of the first customer authentication credential.

25. The method of claim 20, wherein: The first customer authentication credential further includes one or more of the following: an identifier of the service consumption network element or validity period information, wherein the validity period information is used to represent the validity period of the first customer authentication credential.

26. The method according to any one of claims 1, 2, 4, 5, 6, 7, 8, 9, 11, 12, 15, 16, 17, 18, and 19, wherein The first customer authentication credential further includes one or more of the following: an identifier of the service consumption network element or validity period information, wherein the validity period information is used to represent the validity period of the first customer authentication credential.

27. A communication method, characterized in that: The method includes: A first network element receives a first service request message from a service communication agent, where the first service request message is used to request a first service from the first network element, and the first service request message includes a first customer authentication credential, where the first customer authentication credential is used to authenticate the service-consuming network element, wherein the first customer authentication credential includes multiple network function types; The first network element authenticates the service consumption network element according to the first customer authentication credential; The first network element authenticates the service consumption network element according to the first customer authentication credential, including: the first network element determines whether its own network function type matches one or more of the multiple network function types; The first network element sends a response message to the service communication agent in response to the first service request message according to the authentication result.

28. The method of claim 27, wherein: The first network element sends a response message to the service communication agent according to the authentication result for the first service request message, including: When the authentication result is successful, the first network element sends a response message to the service communication agent for the first service request message, where the response message to the first service request message is used to indicate provision of the first service; Alternatively, when the authentication result is authentication failure, the first network element sends a response message to the service communication agent for the first service request message, where the response message to the first service request message indicates that requesting the first service has failed.

29. The method according to claim 27 or 28, wherein: The multiple network function types include a first network function type and a second network function type, the first network function type is the network function type of the first network element, the second network function type is the network function type of the network element providing a second service, and the second service is associated with the first service.

30. The method of claim 29, wherein: The second service is used to provide an access token corresponding to the first service, wherein the access token corresponding to the first service is used to indicate that the service consuming network element has the authority to obtain the first service; Alternatively, the second service is used to provide information about the first network element.

31. The method of claim 29, wherein: The network element providing the second service is a network storage function network element.

32. The method of claim 30, wherein: The network element providing the second service is a network storage function network element.

33. The method according to claim 27 or 28, wherein: The first service is used to provide an access token corresponding to a second service, wherein the access token corresponding to the second service is used to indicate that the service consuming network element has permission to obtain the second service, and the second service is associated with the first service; Alternatively, the first service is used to provide information of a network element that provides a second service, and the second service is associated with the first service.

34. The method of claim 33, wherein: The first network element is a network storage function network element.

35. The method of claim 29, wherein: Also includes: The first network element receives a second service request message from the service communication agent, where the second service request message is used to request the first service from the first network element, the second service request message includes a second client authentication credential, and the second client authentication credential includes a third network function type; In the case that the third network function type does not match the network function type of the first network element, the first network element sends a response message to the second service request message to the service communication agent, and the response message to the second service request message includes indication information, wherein the indication information is used to trigger the first service request message.

36. The method of claim 33, wherein: Also includes: The first network element receives a second service request message from the service communication agent, where the second service request message is used to request the first service from the first network element, the second service request message includes a second client authentication credential, and the second client authentication credential includes a third network function type; In the case that the third network function type does not match the network function type of the first network element, the first network element sends a response message to the second service request message to the service communication agent, and the response message to the second service request message includes indication information, wherein the indication information is used to trigger the first service request message.

37. The method according to any one of claims 27, 28, 30, 31, 32, and 34, wherein: Also includes: The first network element receives a second service request message from the service communication agent, where the second service request message is used to request the first service from the first network element, the second service request message includes a second client authentication credential, and the second client authentication credential includes a third network function type; In the case that the third network function type does not match the network function type of the first network element, the first network element sends a response message to the second service request message to the service communication agent, and the response message to the second service request message includes indication information, wherein the indication information is used to trigger the first service request message.

38. The method according to claim 35 or 36, wherein The indication information includes a third client authentication credential used to authenticate the first network element, and the third client authentication credential includes a network function type of the first network element.

39. The method of claim 37, wherein: The indication information includes a third client authentication credential used to authenticate the first network element, and the third client authentication credential includes a network function type of the first network element.

40. The method of claim 29, wherein The first customer authentication credential further includes an identifier of the service consumption network element and validity period information of the first customer authentication credential; the validity period information of the first customer authentication credential is used to indicate the validity period of the first customer authentication credential; The first network element authenticates the service consuming network element according to the first customer authentication credential, further comprising one or more of the following: The first network element verifies whether the signature of the first customer authentication certificate is passed, verifies whether the first customer authentication certificate is expired based on the validity time information included in the first customer authentication certificate, or verifies whether the identifier of the service consumption network element in the first customer authentication certificate is the same as the identifier of the network element in the certificate used to sign the first customer authentication certificate.

41. The method of claim 33, wherein: The first customer authentication credential further includes an identifier of the service consumption network element and validity period information of the first customer authentication credential; the validity period information of the first customer authentication credential is used to indicate the validity period of the first customer authentication credential; The first network element authenticates the service consuming network element according to the first customer authentication credential, further comprising one or more of the following: The first network element verifies whether the signature of the first customer authentication certificate is passed, verifies whether the first customer authentication certificate is expired based on the validity time information included in the first customer authentication certificate, or verifies whether the identifier of the service consumption network element in the first customer authentication certificate is the same as the identifier of the network element in the certificate used to sign the first customer authentication certificate.

42. The method of claim 37, wherein: The first customer authentication credential further includes an identifier of the service consumption network element and validity period information of the first customer authentication credential; the validity period information of the first customer authentication credential is used to indicate the validity period of the first customer authentication credential; The first network element authenticates the service consuming network element according to the first customer authentication credential, further comprising one or more of the following: The first network element verifies whether the signature of the first customer authentication certificate is passed, verifies whether the first customer authentication certificate is expired based on the validity time information included in the first customer authentication certificate, or verifies whether the identifier of the service consumption network element in the first customer authentication certificate is the same as the identifier of the network element in the certificate used to sign the first customer authentication certificate.

43. The method of claim 38, wherein The first customer authentication credential further includes an identifier of the service consumption network element and validity period information of the first customer authentication credential; the validity period information of the first customer authentication credential is used to indicate the validity period of the first customer authentication credential; The first network element authenticates the service consuming network element according to the first customer authentication credential, further comprising one or more of the following: The first network element verifies whether the signature of the first customer authentication certificate is passed, verifies whether the first customer authentication certificate is expired based on the validity time information included in the first customer authentication certificate, or verifies whether the identifier of the service consumption network element in the first customer authentication certificate is the same as the identifier of the network element in the certificate used to sign the first customer authentication certificate.

44. The method according to any one of claims 27, 28, 30, 31, 32, 34, 35, 36, and 39, wherein: The first customer authentication credential further includes an identifier of the service consumption network element and validity period information of the first customer authentication credential; the validity period information of the first customer authentication credential is used to indicate the validity period of the first customer authentication credential; The first network element authenticates the service consuming network element according to the first customer authentication credential, further comprising one or more of the following: The first network element verifies whether the signature of the first customer authentication certificate is passed, verifies whether the first customer authentication certificate is expired based on the validity time information included in the first customer authentication certificate, or verifies whether the identifier of the service consumption network element in the first customer authentication certificate is the same as the identifier of the network element in the certificate used to sign the first customer authentication certificate.

45. A communication device, characterized in that Comprising means for performing the method of any one of claims 1 to 26.

46. A communication device, characterized in that Comprising means for performing the method of any one of claims 27 to 44.

47. A communication device, characterized in that The communication device includes a processor and a memory; the memory is used to store computer-executable instructions. When the device is running, the processor executes the computer-executable instructions stored in the memory, so that the communication device executes the method according to any one of claims 1 to 26.

48. A communication device, characterized in that The communication device includes a processor and a memory; the memory is used to store computer-executable instructions. When the device is running, the processor executes the computer-executable instructions stored in the memory to enable the communication device to perform the method described in any one of claims 27-44.

49. A computer-readable storage medium, characterized in that The storage medium stores a computer program or instruction, and when the computer program or instruction is executed by the communication device, the method according to any one of claims 1 to 44 is implemented.

Citation Information

Patent Citations

  • Communication method and communication device

    WO2020221219A1