A roaming access method and device

The blockchain system publishes roaming permission information in the 5G network, solving the problem of complexity of roaming access between enterprise private networks, and achieving simplified roaming access control and security improvement.

CN115484583BActive Publication Date: 2025-07-15HUAWEI TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202110600978.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-05-31
Publication Date
2025-07-15
Estimated Expiration
2041-05-31

AI Technical Summary

Technical Problem

In 5G networks, the roaming access process between enterprise private networks is complicated, making it difficult to achieve effective roaming connection and control information exchange, resulting in cumbersome roaming access process.

Method used

The blockchain system publishes and stores roaming permission information, allowing the home network to authorize the roaming permission to visit the network, and terminal devices perform access control in the visiting network, simplifying the roaming architecture and process.

Benefits of technology

There is no need to establish a dedicated roaming connection between private networks, which simplifies the roaming access process and improves the access control efficiency and security of the network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115484583B_ABST
    Figure CN115484583B_ABST
Patent Text Reader

Abstract

This application relates to a roaming access method and apparatus. A first blockchain network element publishes first roaming permission information to a blockchain system, where the first roaming permission information includes roaming permission information of a visited network. The first blockchain network element obtains second roaming permission information of a first terminal device from a blockchain stored in the blockchain system, where the second roaming permission information is the roaming permission information of the first terminal device authorized by a home network of the first terminal device in the visited network, and the second roaming permission information is the whole set or a subset of the first roaming permission information. The first blockchain network element sends the second roaming permission information to the visited network, and the second roaming permission information is used to control access of the first terminal device in the visited network. In the embodiments of this application, the second roaming permission information is placed in the blockchain, so that roaming access control of the terminal device can be completed without establishing a roaming connection between the home network and the visited network, and the roaming process of the terminal device can be simplified.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technologies, and in particular, to a roaming access method and apparatus. Background Art

[0002] In the scenario of the 5th generation (5G) mobile communication technology, there will be more and more private networks coexisting in the 5G network. Some users may only sign contracts within the private network to which the user belongs. According to the current roaming mechanism, when the user roams from private network A to private network B, private network B and private network A need to establish a roaming connection. This roaming connection is used to obtain the control information related to the user's roaming access from private network A. After the roaming connection is established, private network B can obtain the control information related to the user's roaming access in private network A from private network A through this roaming connection. After allowing the UE to roam and access in private network B, the user can communicate normally within private network B.

[0003] In the scenario where there are more and more private network domains such as enterprise private networks, it will be a very complex situation and may be difficult to implement to require dedicated roaming connections to be established between private networks in order to obtain the control information related to the user's roaming access. Summary of the Invention

[0004] Embodiments of this application provide a roaming access method and apparatus, which are used to simplify the process of roaming access.

[0005] In a first aspect, a first roaming access method is provided. This method can be executed by a network device, or by a chip system capable of implementing the functions of the network device, or by a larger device including the network device. Exemplarily, the network device is a first blockchain network element, or is referred to as a first blockchain server. The first blockchain network element is a blockchain network element configured for the network where the first core network device is located. The first core network device can communicate with the first blockchain network element. The network where the first core network device is located is, for example, the visited network of the terminal device. The method includes: publishing first roaming permission information to a blockchain system, where the first roaming permission information includes the roaming permission information of the visited network; obtaining second roaming permission information of a first terminal device from a blockchain stored in the blockchain system, where the second roaming permission information is the roaming permission information of the first terminal device authorized by the home network of the first terminal device in the visited network, and the second roaming permission information is the complete set or subset of the first roaming permission information; and sending the second roaming permission information to the visited network, where the second roaming permission information is used to control the access of the first terminal device in the visited network.

[0006] In the embodiments of the present application, the roaming permission information of the visited network can be published to the blockchain system, and the home network authorizes the roaming of the first terminal device, also according to the roaming permission information of the visited network. The roaming permission information of the home network for the first terminal device in the visited network can also be obtained from the blockchain system. For the visited network, it can use the roaming permission information of the home network for the first terminal device to control the access of the first terminal device in the visited network. It can be seen that the embodiments of the present application can implement the access control of the first terminal device in the visited network through the blockchain system, without the need for pairwise establishment of roaming connections between the visited network and the home network to obtain the control information related to the roaming access of the first terminal device, so as to complete the access control of the terminal device, and simplify the roaming architecture and roaming process.

[0007] In an alternative embodiment, the first roaming permission information includes information indicating the home network of the terminal device allowed to roam in the visited network. The roaming permission information of the visited network can indicate the information of the home network of the terminal device allowed to roam in the visited network, so that other networks can clarify whether the terminal devices in this network can roam in the visited network.

[0008] In an alternative embodiment, the first roaming permission information further includes one or more of the following information of the terminal device capable of roaming in the visited network: the service type allowed to be used, the network slice allowed to be used, the 5QI allowed to be used, or the area allowed to be accessed. If the visited network allows UEs in multiple home networks to roam therein, the roaming permissions granted by the visited network to terminal devices of different home networks may be the same or different. In addition, for one home network capable of roaming in the visited network, the visited network may grant one roaming permission or multiple roaming permissions to this home network. Among them, the parameters included in different roaming permissions and / or the values of the parameters may be different.

[0009] In an alternative embodiment, the method further includes: receiving, from the visited network, identification information of a second block stored in the blockchain system, where the second block stores information indicating the second roaming permission information. Obtaining the second roaming permission information of the terminal device from the blockchain system includes: obtaining the second roaming permission information from the blockchain system according to the identification information of the second block. For example, if the terminal device requests to roam in the visited network, the terminal device may send the identification information of the second block to the visited network. The visited network may send the identification information of the second block to the first blockchain network element. Thus, the first blockchain network element may obtain the second roaming permission information from the blockchain system according to the identification information of the second block, so that roaming access control may be performed on the terminal device according to the second roaming permission information.

[0010] In an alternative embodiment, the second block further stores a key of the first terminal device, and the method further includes: obtaining the key of the first terminal device from the blockchain system according to the identification information of the second block; authenticating the first terminal device using the key of the first terminal device; and sending an authentication result of the first terminal device to the visited network. In the embodiments of the present application, authentication information (for example, if a symmetric encryption algorithm is used, the authentication information includes the key of the terminal device, etc.) is stored in the block, so the first blockchain network element may perform authentication. The first blockchain network element may obtain the authentication information from the block without interacting through the interface between the visited network and the home network of the terminal device, simplifying the roaming architecture and roaming process.

[0011] In an alternative embodiment, the second block further stores a public key of the first terminal device, and the method further includes: obtaining first signature information and first verification information, where the first signature information is signature information encrypted using the private key of the first terminal device; obtaining the public key of the first terminal device from the blockchain system according to the identification information of the second block; authenticating the first terminal device using the public key of the first terminal device, the first signature information, and the first verification information; and sending an authentication result of the first terminal device to the visited network. In the embodiments of the present application, authentication information (for example, if an asymmetric encryption algorithm is used, the authentication information includes the public key of the terminal device, etc.) is stored in the block, so the first blockchain network element may perform authentication. The first blockchain network element may obtain the authentication information from the block without interacting between the visited network and the home network of the terminal device. Therefore, no connection needs to be established between the home network and the visited network of the terminal device, simplifying the roaming architecture and roaming process.

[0012] In an alternative embodiment, when the authentication result is successful authentication, the method further includes: sending second signature information and second verification information to the visited network, where the second signature information is signature information encrypted using the private key of the visited network, and the second signature information and the second verification information are used for the first terminal device to authenticate the visited network. When a terminal device needs to register with a visited network, in addition to the visited network being able to authenticate the terminal device, the terminal device can also authenticate the visited network. Therefore, the first blockchain network element can send the information required for the terminal device to authenticate the visited network to the visited network, and the visited network can forward this information to the terminal device, so that the terminal device can authenticate the visited network based on this information, thereby implementing a two-way authentication process and improving network security.

[0013] In an alternative embodiment, publishing first roaming permission information to the blockchain system includes: sending a first block creation request message to the blockchain system, where the first block creation request message is used to request the creation of a first block, and the first block creation request message includes the first roaming permission information; receiving a first block creation response message from the blockchain system, where the first block creation response message indicates that the first block is successfully created. In the embodiments of the present application, the first roaming permission information can be written into a block, or in other words, the first roaming permission information is published to the blockchain system. Thus, the home network grants the entire set or a subset of the first roaming permissions to the terminal device, without the need for the home network to establish a roaming connection with the visited network to obtain the first roaming permission information, thereby simplifying the roaming access process of the terminal device.

[0014] In an alternative embodiment, the method further includes: the blockchain network element of the visited network records the first block, and the first block stores the identification information of the first block and the first roaming permission information. The blockchain network element of the visited network can record the first block, so as to be able to determine the content stored in the first block.

[0015] In an alternative embodiment, the first block creation request message further includes the public key of the visited network; the first block creation response message further includes the public key of the visited network, and the public key of the visited network is used for the first terminal device to authenticate the visited network when roaming and accessing the visited network. To perform roaming access control on a terminal device, the public key of the visited network can be used for the terminal device to authenticate the visited network. Then the first blockchain network element can publish the public key of the visited network to the blockchain system together, so that authentication information can be obtained through the blockchain system, without the need for the visited network to establish a roaming connection with the home network.

[0016] In an alternative embodiment, the method further includes: receiving a first message from the visited network, where the first message includes the first roaming permission information. Publishing the first roaming permission information to the blockchain system includes: in response to the first message, publishing the first roaming permission information to the blockchain system. Since the first roaming permission information is the roaming permission information of the visited network, the first blockchain network element can obtain the first roaming permission information from the visited network. After obtaining the first roaming permission information, the first blockchain network element can publish the first roaming permission information to the blockchain system.

[0017] In an alternative embodiment, the method further includes: receiving a second block building response message from the blockchain system, where the second block building response message includes the identification information of the second block, the public key of the first terminal device, and the information indicating the second roaming permission information; recording the second block, and the second block further stores the identification information of the second block. After the home network obtains the first roaming permission information through the blockchain system, it can grant all or a subset of the first roaming permission information to the first terminal device, and the roaming permission information granted to the first terminal device is called the second roaming permission information. Then the home network can publish the public key of the first terminal device and the information indicating the second roaming permission information to the blockchain system, so that it can authenticate the first terminal device according to the public key of the first terminal device and authorize the first terminal device according to the information indicating the second roaming permission information.

[0018] In an alternative embodiment, the method further includes: receiving a third block building response message from the blockchain system, where the third block building response message includes the identification information of the third block and the identification information of the second block; recording the third block, and the information stored in the third block includes the identification information of the third block, the information indicating the third roaming permission information, and the identification information of the second block, where the third roaming permission information is the updated roaming permission information of the first terminal device authorized by the home network of the first terminal device in the visited network, the third roaming permission information is different from the second roaming permission information, and is all or a subset of the first roaming permission information. The roaming permission of the terminal device is not necessarily fixed and may be updated. If the roaming permission of the terminal device is updated, then a new block needs to be stored through a new block, which involves creating a new block, and a new block (the third block) can be created through the above process. The third block can also store the identification information of the second block, so as to trace the historical roaming permission information of the terminal device.

[0019] In an alternative embodiment, the information indicating the second roaming permission information includes the identification information of the first block. If the second roaming permission information is stored in the first block, then the identification information of the first block can be used as the information indicating the second roaming permission information, and the second roaming permission information can be determined through the identification information of the first block.

[0020] In a second aspect, a second roaming access method is provided. This method can be executed by a network device, or by a chip system capable of implementing the functions of the network device, or by a larger device including the network device. Exemplarily, the network device is a second blockchain network element, or is referred to as a second blockchain server. The second blockchain network element is a blockchain network element configured for the network where the second core network device is located. The second core network device can communicate with the second blockchain network element. The network where the second core network device is located is, for example, the home network of the terminal device. The method includes: obtaining first roaming permission information from the blockchain system, where the first roaming permission information includes the roaming permission information of the visited network; and publishing second roaming permission information to the blockchain system, where the second roaming permission information is the roaming permission information of the first terminal device authorized by the home network of the first terminal device in the visited network, and the second roaming permission information is the whole set or a subset of the first roaming permission information, and the second roaming permission information is used to control the access of the first terminal device in the visited network.

[0021] In the embodiments of the present application, the home network authorizes the roaming of the first terminal device according to the roaming permission information of the visited network, and publishes the roaming permission information of the authorized first terminal device in the visited network through the blockchain system, so that the visited network can obtain the roaming permission information of the first terminal device authorized by the home network in the visited network through the blockchain system, and control the access of the first terminal device in the visited network. It can be seen that in the embodiments of the present application, there is no need to establish pairwise roaming connections between the visited network and the home network to obtain control information related to the roaming access of the first terminal device, so as to complete the access control of the terminal device, simplifying the roaming architecture and roaming process.

[0022] In an alternative embodiment, the publishing the second roaming permission information to the blockchain system includes: sending a second block creation request message to the blockchain system, where the second block creation request message is used to request the creation of a second block, and the second block is used to store the information indicating the second roaming permission information; and receiving a second block creation response message from the blockchain system, where the second block creation response message indicates the successful creation of the second block.

[0023] In an alternative embodiment, the second roaming permission information includes information for indicating the home network of the terminal device allowed to roam in the visited network.

[0024] In an optional implementation manner, the second roaming permission information further includes one or more of the following information of the terminal device capable of roaming in the visited network in the visited network: the service types allowed to be used, the network slices allowed to be used, the 5QIs allowed to be used, or the areas allowed to be accessed.

[0025] In an optional implementation manner, the second building block response message includes the identification information of the second block and the information indicating the second roaming permission information.

[0026] In an optional implementation manner, the method further includes: receiving the second roaming permission information from the home network; determining the identification information of the first block according to the second roaming permission information, where the first block stores the first roaming permission information. If the home network grants the second roaming permission information to the UE, the home network may send the second roaming permission information to the second blockchain network element, and the second blockchain network element can thereby determine the block storing the second roaming permission information, that is, the first block. Further, the second blockchain network element may publish the identification information of the first block to the blockchain system.

[0027] In an optional implementation manner, the method further includes: receiving the public key of the first terminal device from the home network, where the first public key of the first terminal device is used for the visited network to authenticate the first terminal device; sending the public key of the first terminal device to the blockchain system. For example, the second blockchain network element may publish the identification information of the first block and the public key of the first terminal device to the blockchain system together, so that the visited network can authenticate the first terminal device according to the public key of the first terminal device and authorize the roaming of the first terminal device according to the second roaming permission information.

[0028] In an optional implementation manner, the method further includes: sending the identification information of the second block and the second roaming permission information to the home network, where the identification information of the second block indicates that the second block is successfully created.

[0029] In an alternative embodiment, the method further includes: sending a third block creation request message to the blockchain system, where the third block creation request message is used to request the creation of a third block, the third block creation request message includes the identification information of the second block and the third roaming permission information of the first terminal device, the third roaming permission information is the updated roaming permission information of the first terminal device authorized by the home network of the first terminal device in the visited network, the third roaming permission information is different from the second roaming permission information, and is the complete set or subset of the first roaming permission information, and the third block is used to store information indicating the third roaming permission information; receiving a third block creation response message from the blockchain system, the third block creation response message indicates that the third block is successfully created, and the third block creation response message includes the identification information of the third block and the identification information of the second block.

[0030] In an alternative embodiment, the method further includes: receiving a second message from the home network, where the second message includes the identification information of the second block and the third roaming permission information. The sending the third block creation request message to the blockchain system includes: in response to the second message, sending the third block creation request message to the blockchain system. If the roaming permission information of the terminal device is updated to the third roaming permission information, the home network may send the third roaming permission information to the second blockchain network element. Additionally, the home network may also send the identification information of the second block to the second blockchain network element, and the second blockchain network element may publish the identification information of the second block and the third roaming permission information to the blockchain, so that the original roaming permission information (the second roaming permission information) of the terminal device can be traced through the identification information of the second block.

[0031] In an alternative embodiment, the method further includes: sending a response message to the second message to the home network, where the response message to the second message indicates that the roaming permission of the first terminal device is successfully updated, and the response message to the second message includes the identification information of the third block, the identification information of the second block, and the third roaming permission information.

[0032] In an alternative embodiment, the method further includes: receiving, from the blockchain system, a first block building message, where the first block building message includes identification information of the first block and the first roaming permission information; determining, according to the first roaming permission information, that the visited network is a network in which the terminal device in the home network can roam; establishing, by a blockchain network element in the home network, a third mapping table, where the third mapping table includes a mapping relationship between the identification information of the first block, the first roaming permission information, and the public key of the visited network. For example, if the first roaming permission information is published to the blockchain system by the visited network, the home network can obtain the first roaming permission information from the blockchain system, so as to be able to allocate roaming permissions for the terminal devices in the home network.

[0033] Regarding the technical effects brought by the second aspect or partial embodiments, reference may be made to the introduction of the technical effects of the first aspect or corresponding embodiments.

[0034] In a third aspect, a third roaming access method is provided. This method can be executed by a network device, or by a chip system capable of implementing the functions of the network device, or by a larger device including the network device. Exemplarily, the network device is a first core network device, and the network where the first core network device is located is, for example, the visited network of the terminal device. The first core network device is, for example, an AMF, or it can also be other network elements in the core network. The method includes: receiving, from a first terminal device, a registration request for requesting access to the visited network; obtaining, from a blockchain network element of the visited network, second roaming permission information, where the second roaming permission information is the roaming permission information of the first terminal device authorized by the home network of the first terminal device in the visited network, and the second roaming permission information is the whole set or a subset of the first roaming permission information, and the first roaming permission information includes the roaming permission information of the visited network; controlling the access of the first terminal device in the visited network according to the second roaming permission information.

[0035] In the embodiments of the present application, the visited network obtains the roaming permission information of the first terminal device authorized by the home network from the blockchain network element, and controls the access of the first terminal device in the visited network. It can be seen that in the embodiments of the present application, there is no need to establish pairwise roaming connections between the visited network and the home network to obtain control information related to the roaming access of the first terminal device, so as to complete the access control of the terminal device, simplifying the roaming architecture and roaming process.

[0036] In an alternative embodiment, the method further includes: receiving, from a terminal device, identification information of a second block, where the second block stores information indicating second roaming permission information. Obtaining the second roaming permission information from a blockchain network element of the visited network includes: sending the identification information of the second block to the blockchain network element of the visited network, and receiving the second roaming permission information from the blockchain network element of the visited network.

[0037] In an alternative embodiment, the second roaming permission information includes information for indicating a home network of a terminal device allowed to roam in the visited network.

[0038] In an alternative embodiment, the second roaming permission information further includes one or more of the following information of the terminal device capable of roaming in the visited network: service types allowed to be used, network slices allowed to be used, 5QI allowed to be used, or areas allowed to be accessed.

[0039] In an alternative embodiment, the method further includes: receiving, from the first terminal device, identification information of a first block, where the first block stores the first roaming permission information.

[0040] In an alternative embodiment, the method further includes: receiving, from the first terminal device, first signature information and first verification information, where the first signature information is signature information encrypted using a private key of the first terminal device, and the first signature information and the first verification information are used for authenticating the first terminal device.

[0041] In an alternative embodiment, the method further includes: receiving, from a blockchain network element of the visited network, an authentication result of the first terminal device.

[0042] In an alternative embodiment, when the authentication result is successful authentication, the method further includes: receiving, from a blockchain network element of the visited network, second signature information and second verification information, where the second signature information is signature information encrypted using a private key of the visited network, and the second signature information and the second verification information are used for authenticating the visited network; and sending the second signature information and the second verification information to the first terminal device.

[0043] In an alternative embodiment, the method further includes: sending the first roaming permission information to a blockchain network element of the visited network, where the first roaming permission information is used to trigger the creation of the first block; and receiving, from the blockchain network element of the visited network, identification information of the first block.

[0044] Regarding the technical effects brought about by the third aspect or various optional implementations, reference may be made to the introduction to the technical effects of the first aspect or corresponding implementations.

[0045] In a fourth aspect, a fourth roaming access method is provided, which can be executed by a network device, or by a chip system capable of realizing the functions of the network device, or by a larger device including the network device. Exemplarily, the network device is a second core network device, and the network where the second core network device is located is, for example, the home network of the terminal device. The second core network device is, for example, an AMF, or it can also be other network elements in the core network. The method includes: sending second roaming permission information to a blockchain network element of the home network of the first terminal device, the second roaming permission information is the roaming permission information of the first terminal device authorized by the home network in the visited network, and the second roaming permission information is a full set or subset of the first roaming permission information, the first roaming permission information includes the roaming permission information of the visited network, the second roaming permission information is used to trigger the creation of a second block, and the second block is used to store information indicating the second roaming permission information; receiving identification information of the second block from the blockchain network element of the home network.

[0046] In the embodiment of the present application, the home network sends the roaming authority information of the first terminal device authorized by the home network to the blockchain network element, so that the visited network can obtain the roaming authority information of the first terminal device authorized by the home network through the blockchain system, and control the access of the first terminal device to the visited network accordingly. It can be seen that the embodiment of the present application does not require the visited network and the home network to establish a roaming connection between each other to obtain the control information related to the roaming access of the first terminal device, thereby completing the access control of the terminal device and simplifying the roaming architecture and roaming process.

[0047] In an optional implementation, the second roaming authority information includes information for indicating a home network of the terminal device that is allowed to roam in the visited network.

[0048] In an optional embodiment, the second roaming permission information also includes one or more of the following information in the visited network for indicating the terminal device capable of roaming in the visited network: allowed service type, allowed network slice, allowed 5QI, or allowed access area.

[0049] In an optional implementation, the method further includes: receiving, from the first terminal device, roaming authority information requested by the first terminal device; and determining the second roaming authority information according to the roaming authority information requested by the first terminal device.

[0050] In an alternative embodiment, the method further includes: receiving, from the first terminal device, a public key of the first terminal device; and sending the public key of the first terminal device to a blockchain network element of the home network, where the public key of the first terminal device is used for authenticating the first terminal device.

[0051] In an alternative embodiment, the method further includes: sending, to the first terminal device, identification information of the second block.

[0052] In an alternative embodiment, the method further includes: receiving, from a blockchain network element of the home network, a public key of the visited network; and sending the public key of the visited network to the first terminal device, where the public key of the visited network is used for authenticating the visited network.

[0053] In an alternative embodiment, the method further includes: sending the identification information of the second block and third roaming permission information of the first terminal device to a blockchain network element of the home network, where the third roaming permission information is roaming permission information updated by the first terminal device authorized by the home network in the visited network, the third roaming permission information is different from the second roaming permission information, and is a complete set or subset of the first roaming permission information; and receiving, from the blockchain network element of the home network, identification information of a third block and the identification information of the second block, where the third block is used for storing information indicating the third roaming permission information.

[0054] In an alternative embodiment, the method further includes: receiving, from a blockchain network element of the home network, the public key of the visited network corresponding to the third roaming permission information.

[0055] Regarding the technical effects brought by the fourth aspect or various alternative embodiments, reference may be made to the introduction of the technical effects of the first aspect or the corresponding embodiments, or reference may be made to the introduction of the technical effects of the second aspect or the corresponding embodiments.

[0056] In a fifth aspect, a fifth roaming access method is provided. This method can be executed by a terminal device, or by a chip system, or by a larger device including the terminal device, and the chip system can implement the functions of the terminal device. The method includes: a first terminal device sends identification information of a second block to a visited network, and the identification information of the second block enables the visited network to obtain second roaming permission information and control the access of the first terminal device in the visited network according to the second roaming permission information. The second roaming permission information is the roaming permission information of the first terminal device authorized by the home network of the first terminal device in the visited network, and the second roaming permission information is the whole set or a subset of the first roaming permission information. The first roaming permission information includes the roaming permission information of the visited network.

[0057] In an embodiment of the present application, the visited network obtains the roaming permission information of the first terminal device authorized by the home network from the blockchain network element according to the identification information of the second block carried by the first terminal device, and controls the access of the first terminal device in the visited network. It can be seen that in the embodiment of the present application, it is not necessary to establish pairwise roaming connections between the visited network and the home network to obtain control information related to the roaming access of the first terminal device, so as to complete the access control of the terminal device, and simplify the roaming architecture and roaming process.

[0058] In an optional implementation manner, the second roaming permission information includes information indicating the home network of the terminal device allowed to roam in the visited network.

[0059] In an optional implementation manner, the second roaming permission information further includes one or more of the following information of the terminal device capable of roaming in the visited network: the service type allowed to be used, the network slice allowed to be used, the 5QI allowed to be used, or the area allowed to be accessed.

[0060] In an optional implementation manner, the second block is used to store information indicating the second roaming permission information.

[0061] In an optional implementation manner, the method further includes: the first terminal device receives second signature information and second verification information from the visited network, and the second signature information is signature information encrypted using the private key of the visited network; the first terminal device authenticates the visited network according to the public key of the visited network, the second signature information, and the second verification information.

[0062] In an optional implementation manner, the method further includes: the first terminal device receives the public key of the visited network from the home network.

[0063] In an alternative embodiment, the method further includes: the first terminal device sending first signature information and first verification information to the visited network, where the first signature information is signature information encrypted using the private key of the terminal device, and the first signature information and the first verification information are used for authenticating the first terminal device.

[0064] In an alternative embodiment, the method further includes: the first terminal device sending the public key of the first terminal device to the home network, where the public key of the first terminal device is used by the visited network to authenticate the first terminal device.

[0065] In an alternative embodiment, the method further includes: the first terminal device sending roaming permission information applied for by the first terminal device to the home network; the first terminal device receiving, from the home network, identification information of the second block, where the second block stores information indicating the second roaming permission information.

[0066] Regarding the technical effects brought by the fifth aspect or various alternative embodiments, reference may be made to the introduction of the technical effects of the first aspect or the corresponding embodiments, or reference may be made to the introduction of the technical effects of the second aspect or the corresponding embodiments.

[0067] Sixth aspect, a communication device is provided. The communication device may be the network device described in any one of the first aspect to the fifth aspect above. The communication device has the functions of the above network device. The network device is, for example, the first blockchain network element described in any one of the first aspect to the fifth aspect, or the second blockchain network element described in any one of the first aspect to the fifth aspect, or the first core network device described in any one of the first aspect to the fifth aspect, or the second core network device described in any one of the first aspect to the fifth aspect. In an alternative implementation, the communication device includes a baseband device and a radio frequency device. In another alternative implementation, the communication device includes a processing unit (sometimes also referred to as a processing module) and a transceiver unit (sometimes also referred to as a transceiver module). The transceiver unit can implement a sending function and a receiving function. When the transceiver unit implements the sending function, it can be referred to as a sending unit (sometimes also referred to as a sending module), and when the transceiver unit implements the receiving function, it can be referred to as a receiving unit (sometimes also referred to as a receiving module). The sending unit and the receiving unit may be the same functional module, and this functional module is called the transceiver unit, and this functional module can implement the sending function and the receiving function; or, the sending unit and the receiving unit may be different functional modules, and the transceiver unit is a general term for these functional modules.

[0068] In an alternative implementation, the communication device includes a storage unit, and the processing unit can be coupled to the storage unit and execute programs or instructions in the storage unit to enable the communication device to perform the functions of the above-mentioned network device.

[0069] In an alternative embodiment, the communication device includes: a processor, coupled to a memory, for executing instructions in the memory to implement the method performed by the network device according to any one of the first to fifth aspects. Optionally, the communication device further includes other components, such as antennas, input / output modules, interfaces, etc. These components can be hardware, software, or a combination of software and hardware.

[0070] In a seventh aspect, a communication device is provided. The communication device can be the terminal device according to any one of the first to fifth aspects. The communication device has the functions of the above-mentioned terminal device. In an alternative implementation, the communication device includes a baseband device and a radio frequency device. In another alternative implementation, the communication device includes a processing unit (sometimes also referred to as a processing module) and a transceiver unit (sometimes also referred to as a transceiver module). For the implementation of the transceiver unit, reference can be made to the relevant description in the sixth aspect.

[0071] In an alternative implementation, the communication device includes a storage unit, and the processing unit can be coupled to the storage unit and execute programs or instructions in the storage unit to enable the communication device to perform the functions of the above-mentioned terminal device.

[0072] In an alternative embodiment, the communication device includes: a processor, coupled to a memory, for executing instructions in the memory to implement the method performed by the terminal device according to any one of the first to fifth aspects. Optionally, the communication device further includes other components, such as antennas, input / output modules, interfaces, etc. These components can be hardware, software, or a combination of software and hardware.

[0073] In an eighth aspect, a communication system is provided. The communication system may include a communication device capable of implementing the functions of the first blockchain network element according to any one of the first to fifth aspects described in the sixth aspect, and a communication device capable of implementing the functions of the first core network device according to any one of the first to fifth aspects described in the sixth aspect.

[0074] In a ninth aspect, a communication system is provided. The communication system may include a communication device capable of implementing the functions of the second blockchain network element according to any one of the first to fifth aspects described in the sixth aspect, and a communication device capable of implementing the functions of the second core network device according to any one of the first to fifth aspects described in the sixth aspect.

[0075] In a tenth aspect, there is provided a computer-readable storage medium for storing a computer program or instructions, which, when run, implement the methods executed by the first blockchain network element, the second blockchain network element, the first core network device, the second core network device, or the terminal device in the above aspects.

[0076] In an eleventh aspect, there is provided a computer program product containing instructions, which, when run on a computer, implement the methods described in the above aspects. Description of the Drawings

[0077] Figure 1 It is a schematic diagram of the network architecture for the local breakout roaming scenario;

[0078] Figure 2 It is a flowchart of the signaling interaction when the UE roams;

[0079] Figure 3 It is a schematic diagram of an application scenario of an embodiment of the present application;

[0080] Figure 4 It is a flowchart of the first roaming access method provided by an embodiment of the present application;

[0081] Figure 5 It is a schematic diagram of a roaming access method in an embodiment of the present application;

[0082] Figure 6 It is a flowchart of the second roaming access method provided by an embodiment of the present application;

[0083] Figure 7 It is a flowchart of the third roaming access method provided by an embodiment of the present application;

[0084] Figure 8 It is another schematic diagram of a roaming access method in an embodiment of the present application;

[0085] Figure 9 It is a flowchart of the fourth roaming access method provided by an embodiment of the present application;

[0086] Figure 10 It is a flowchart of the fifth roaming access method provided by an embodiment of the present application;

[0087] Figure 11 It is a schematic block diagram of a communication device provided by an embodiment of the present application;

[0088] Figure 12 It is a schematic block diagram of a terminal device provided by an embodiment of the present application;

[0089] Figure 13 It is a schematic block diagram of a network device provided by an embodiment of the present application. Detailed implementation manners

[0090] In order to make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the embodiments of this application will be further described in detail below with reference to the accompanying drawings.

[0091] The following is an explanation of some terms in the embodiments of this application to facilitate the understanding of those skilled in the art.

[0092] In the embodiments of this application, a terminal device is a device with wireless transceiver functions, which can be a fixed device, a mobile device, a handheld device, a wearable device, a vehicle-mounted device, or a wireless device (such as a communication module or a chip system, etc.) built into the above devices. The terminal device is used to connect people, things, machines, etc., and can be widely used in various scenarios, such as but not limited to the following scenarios: cellular communication, device-to-device (D2D) communication, vehicle-to-everything (V2X) communication, machine-to-machine / machine-type communications (M2M / MTC), Internet of Things (IoT), virtual reality (VR), augmented reality (AR), industrial control, self-driving, remote medical, smart grid, smart furniture, smart office, smart wearables, smart transportation, smart city, drones, robots, and other scenarios of terminal devices. The terminal device may sometimes be referred to as a user equipment (UE), a terminal, an access station, a UE station, a remote station, a wireless communication device, or a user device, etc. For the sake of convenience of description, the terminal device will be described by taking the UE as an example in the embodiments of this application.

[0093] The network device in the embodiment of this application includes, for example, an access network device and / or a core network device. The access network device is a device with wireless transceiver functions and is used to communicate with the terminal device. The access network device includes, but is not limited to, base stations (BTS, Node B, eNodeB / eNB, or gNodeB / gNB), transmission reception points (TRP) in the above-mentioned communication system, base stations evolved by 3GPP in the future, access nodes in a wireless fidelity (WiFi) system, wireless relay nodes, wireless backhaul nodes, etc. The base station can be: a macro base station, a micro base station, a pico base station, a small station, a relay station, etc. Multiple base stations can support the network of the same access technology mentioned above or the networks of different access technologies mentioned above. The base station can include one or more co-located or non-co-located transmission and reception points. The network device can also be a radio controller, a centralized unit (CU), and / or a distributed unit (DU) in a cloud radio access network (CRAN) scenario. The network device can also be a server, a wearable device, or a vehicle-mounted device, etc. For example, the network device in vehicle to everything (V2X) technology can be a road side unit (RSU). The following takes the base station as an example to illustrate the access network device. The multiple network devices in the communication system can be base stations of the same type or base stations of different types. The base station can communicate with the terminal device or communicate with the terminal device through a relay station. The terminal device can communicate with multiple base stations in different access technologies. The core network device is used to implement functions such as mobility management, data processing, session management, policy, and charging. The device names for implementing core network functions in systems with different access technologies can be different, and this application does not limit this. Taking the 5G system as an example, the core network device includes: an access and mobility management function (AMF), a unified data management (UDM), or a user plane function (UPF), etc.

[0094] In the embodiments of the present application, the device for implementing the functions of a network device may be the network device itself or a device capable of supporting the network device to implement such functions, such as a chip system, and this device may be installed in the network device. In the technical solutions provided in the embodiments of the present application, the case where the device for implementing the functions of the network device is the network device itself is taken as an example to describe the technical solutions provided in the embodiments of the present application.

[0095] The embodiments of the present application relate to blockchain. Among them, a block can store data, and multiple blocks are connected in sequence to form a chain, which is called a blockchain. The main features of the blockchain are as follows:

[0096] 1. Distributed: A blockchain is replicated into multiple copies and maintained on different member servers respectively.

[0097] 2. Tamper-proof: Each block in the blockchain calculates a hash value based on the data stored in the block. Each block in the blockchain records the hash value of the previous block and its own hash value. If the content stored in a block changes, the hash value of the block changes. The next block stores the hash value of the block before the change. When the next block verifies the changed hash of the block based on the hash value before the change, the verification will fail.

[0098] 3. Traceable: Blocks are connected to form a blockchain, and the entire change history of the blockchain can be traced forward according to the connection order of the blocks in the blockchain.

[0099] The embodiments of the present application also relate to the concept of a private network, which is briefly introduced as follows. A non-public network (NPN) can also be understood as a private network, which is a non-public 5G network. An NPN can be realized relying on the support of a public land mobile network (PLMN). An NPN realized relying on the support of a PLMN is called a public network integrated NPN (PNI-NPN); alternatively, an NPN can also be realized without relying on the network functions of a PLMN. An NPN realized without relying on the support of a PLMN is called a standalone NPN (SNPN).

[0100] PNI-NPN can be implemented using network slices in the PLMN or a proprietary data network name (DNN). To prevent unauthorized UEs from attempting to access and select PNI-NPN, the PNI-NPN additionally uses the Closed Access Group (CAG) function. Some UEs allowed to access the PNI-NPN can be configured with available CAG IDs and CAG indicators, and the CAG indicator can indicate that the UE is only allowed to access the 5GS through CAG cells. The subscribed data of the UE stored in the UDM will also include the available CAG ID and CAG indicator of the UE. The CAG cell will broadcast the CAG IDs supported by the cell, and the UE determines whether it can access the cell based on the received CAG ID.

[0101] The SNPN is independently deployed and does not depend on the PLMN network. The SNPN is identified using the PLMN ID + Network Identifier (NID), where the PLMN ID can be an inherent value reserved by a third-party operator or a specific value of the PLMN operator deploying this SNPN. In the SNPN, the cells belonging to the SNPN broadcast the PLMN ID + NID, and the UE selects a cell based on the broadcast information and the network selection information configured for the UE. The network selection information configured for the UE may include the PLMN ID + NID. For example, if the UE determines that the configured network selection information is different from the PLMN ID and / or NID broadcast by the cell, the UE will not access the cell.

[0102] In the embodiments of this application, for the number of nouns, unless otherwise specified, it means "singular noun or plural noun", that is, "one or more". "At least one" means one or more, and "multiple" means two or more. "And / or" describes the association relationship of associated objects and indicates that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone, where A and B can be singular or plural. The character " / " generally represents an "or" relationship between the preceding and following associated objects. For example, A / B means: A or B. "At least one (item)" or its similar expression refers to any combination of these items, including any combination of single item (item) or plural items (items). For example, at least one (item) of a, b, or c means: a, b, c, a and b, a and c, b and c, or a and b and c, where a, b, and c can be single or multiple.

[0103] Please refer to Figure 1, which is a schematic diagram of the network architecture for the local offload roaming scenario. In this network architecture, the UE will roam, so it includes two regions: the visited public land mobile network (VPLMN) and the home public land mobile network (HPLMN). The VPLMN includes network elements such as the network slice selection function (NSSF), network exposure function (NEF), network function repository function (NRF), policy control function (PCF), application function (AF), AMF, session management function (SMF), and visited security edge protection proxy (vSEPP). These network elements can communicate with each other based on the service-based approach. In addition, the AMF can communicate with the terminal device through the N1 interface, the AMF can communicate with the (R)AN through the N2 interface, the SMF can communicate with the UPF through the N4 interface, the terminal device and the (R)AN can communicate with each other, the (R)AN and the UPF can communicate through the N3 interface, and the UPF and the DN can communicate through the N6 interface. The HPLMN includes network elements such as the UDM, NRF, PCF, authentication server function (AUSF), NEF, network slice specific authentication and authorization function (NSSAAF), and home security edge protection proxy (hSEPP). These network elements can also communicate with each other based on the service-based approach. The vSEPP and the hSEPP can communicate through the N32 interface. During roaming, the UE accesses the VPLMN, and the core network elements such as AMF and SMF in the VPLMN and HPLMN are connected through the vSEPP and the hSEPP, so that the network elements in the VPLMN can communicate with the network elements in the HPLMN.

[0104] Taking Figure 1 the architecture shown as an example, the signaling interaction process of UE roaming can refer toFigure 2 .

[0105] S21. The HPLMN establishes a roaming connection with the VPLMN.

[0106] For example, a roaming connection is established between a corresponding network element in the HPLMN and a corresponding network element in the VPLMN. This step is, for example, a configuration process performed according to a roaming agreement between operators.

[0107] S22. The subscribed UE initiates a service request to the VPLMN in the visited domain, which contains the encrypted authentication information of the HPLMN. For example, if the VPLMN is a 5G network, the UE can initiate a service request to the AMF in the VPLMN. The encrypted authentication information of the HPLMN can be used by the network to authenticate the UE.

[0108] S23. The VPLMN queries the HPLMN for the subscription information of the UE. For example, if the HPLMN is a 5G network, the VPLMN may query the UDM in the HPLMN for the subscription information of the UE.

[0109] S24. The HPLMN authenticates the UE.

[0110] For example, the HPLMN decrypts the encrypted authentication information of the HPLMN, and then verifies the decrypted information to obtain the authentication result of the UE.

[0111] S25. The HPLMN sends the authentication result to the VPLMN.

[0112] The authentication result indicates that the UE is successfully authenticated or failed. If the authentication result indicates that the authentication is successful, the HPLMN may also send authorization information to the VPLMN.

[0113] S26. If the VPLMN determines that the authentication is successful, the UE is allowed to access the VPLMN. If the authentication result received by the VPLMN in S25 indicates that the UE is successfully authenticated, the VPLMN may allow the UE to access the VPLMN and allow the UE to perform services through the VPLMN.

[0114] S27. The VPLMN sends a charging data record (CDR) of the UE to a data clearing house (DCH).

[0115] Among them, the CDR can be sent to the DCH by the network element responsible for billing in the VPLMN. For example, if the VPLMN is a 5G network, the network element responsible for billing in the VPLMN is the policy and charging rules function (PCRF).

[0116] The DCH is a network element trusted by both the VPLMN and the HPLMN. The DCH can be set in the VPLMN or the HPLMN, or it can also be set outside the HPLMN and the VPLMN.

[0117] S28. The DCH sends the CDR to the HPLMN. The DCH verifies the received CDR. If the verification is successful, it sends the CDR to the HPLMN.

[0118] S29. The HPLMN pays the fees for this UE to the VPLMN. The HPLMN can pay the fees generated by this UE's roaming in the VPLMN to the VPLMN according to this CDR.

[0119] Through the above process, the UE can realize roaming in the VPLMN. However, for step S21, if the HPLMN and / or the VPLMN is a private network, then pairwise negotiation of the roaming agreement between private networks is required, so as to establish a roaming connection according to this roaming agreement. Since the number of private networks is large, establishing pairwise roaming connections between private networks is a very complex process.

[0120] In view of this, the technical solution of the embodiment of the present application is provided. In the embodiment of the present application, the roaming permission information of the visited network can be published to the blockchain system, and the home network authorizes the roaming of the first terminal device, also according to the roaming permission information of the visited network. Therefore, the roaming permission information of the home network authorizing the first terminal device in the visited network can also be obtained from the blockchain system. And the blockchain system can be accessed by each network. Thus, for the visited network, it can use the roaming permission information of the home network authorizing the first terminal device in the visited network to control the access of the first terminal device in the visited network. It can be seen that the embodiment of the present application can realize the access control of the first terminal device in the visited network through the blockchain system, without the visited network and the home network establishing a roaming connection for obtaining the control information related to the roaming access of the first terminal device. That is to say, the embodiment of the present application can complete the access control of the terminal device without the home network and the visited network establishing a roaming connection. Especially when the home network and / or the visited network is a private network, since there is no need to establish pairwise roaming connections between private networks, it can enable the private network to better support the roaming of the terminal device and simplify the roaming process.

[0121] The technical solution provided by the embodiment of the present application can be applied to the 5G system, such as the NR system, or can also be applied to the next-generation mobile communication system or other similar communication systems, and the specific is not limited.

[0122] Please refer to Figure 3, which is a schematic diagram of an application scenario of an embodiment of the present application. Suppose there are multiple private networks, and an access point (AP) and a core network are deployed in each private network. At the same time, a blockchain network element is configured for each private network, and multiple blockchain network elements can belong to a consortium blockchain ( Figure 3 The cloud shape in represents the consortium blockchain), which is used for the interaction of roaming information. This consortium blockchain can also be understood as a blockchain system. Alternatively, multiple private networks can also share a single blockchain network element, which can simplify the network structure. For ease of understanding, each embodiment of the present application still takes the example of configuring a separate blockchain network element for each private network. The AP is, for example, an access point in a wireless fidelity (WiFi) system or a fixed broadband system (also known as a wireline access system), or it can also be an access network device in a 3rd generation partnership project (3GPP) network (for the introduction of the access network device, please refer to the previous text), etc. The core network of the private network may include one or more network elements, and there are no restrictions on the number and type of network elements included in the core network of the private network. A blockchain network element can be an independent network element located in the private network corresponding to the blockchain network element, or it can also be a functional module in a certain network element deployed in the private network corresponding to the blockchain network element. There is no need to establish a dedicated roaming protocol and roaming connection between the core networks of each private network, and the UE can roam between private networks. Figure 3 FIG. 1 describes Private Network 1 and Private Network 2. Private Network 1 includes AP1 and Core Network 1, and Private Network 2 includes AP2 and Core Network 2. A blockchain network element 1 is configured for Private Network 1, and a blockchain network element 2 is configured for Private Network 2. Blockchain network element 1 and blockchain network element 2 belong to a consortium blockchain, and this consortium blockchain may also include other blockchain network elements. As an example, Private Network 1 is the home network of the UE, and Private Network 2 is the visited network of the UE.

[0123] The method provided by the embodiments of the present application will be described below in conjunction with the accompanying drawings. In the accompanying drawings corresponding to each embodiment of the present application, all steps represented by dashed lines are optional steps. It should be noted that when introducing each embodiment of this article, it is all based on the application in Figure 3 the network architecture shown in FIG. For example, the first blockchain network element described in each embodiment of the present application is the blockchain network element configured for the visited network of the UE, and can also be called the blockchain network element of the visited network. For example, the first blockchain network element is the blockchain network element 2 in the network architecture shown in Figure 3 FIG. 2; the second blockchain network element described in each embodiment of the present application is the blockchain network element configured for the home network of the UE, and can also be called the blockchain network element of the home network. For example, the second blockchain network element is the blockchain network element in the network architecture shown in Figure 3The blockchain network element 1 in the network architecture shown; the first core network device described in the embodiments of the present application is the core network device of the visited network of the UE. For example, the first core network device is Figure 3 a device within core network 2 in the network architecture shown. For example, the first core network device is an AMF or an SMF, or it can also be other network elements, or it can also include multiple network elements. The steps executed by the first core network device can be executed by one or several of the multiple network elements; the second core network device described in the embodiments of the present application is the core network device of the home network of the UE. For example, the second core network device is Figure 3 a device within core network 1 in the network architecture shown. For example, the second core network device is an AMF or an SMF, or it can also be other network elements, or it can also include multiple network elements. The steps executed by the first core network device can be executed by one or several of the multiple network elements.

[0124] It should be noted that the first core network devices involved in the embodiments of the present application introduced hereinafter can be network elements of the same type. For example, they are all AMFs, or they can also be network elements of different types. For example, in some embodiments, the first core network device is an AMF, and in some embodiments, the first core network device is an SMF. Similarly, the second core network devices involved in the embodiments of the present application introduced hereinafter can be network elements of the same type. For example, they are all AMFs, or they can also be network elements of different types. For example, in some embodiments, the second core network device is an AMF, and in some embodiments, the second core network device is an SMF. In addition, the first core network device and the second core network device within the same embodiment can be network elements of the same type, for example, they are all AMFs, or they can also be network elements of different types.

[0125] In the embodiments of the present application, the home network can be the second core network device within the home network, or the access network device within the home network, or other network elements within the home network; the visited network can be the first core network device within the visited network, or the access network device within the visited network, or other network elements within the visited network.

[0126] The embodiments of the present application provide a first roaming access method. Please refer to Figure 4 for the flowchart of this method.

[0127] S401. The visited network sends message 1 to the first blockchain network element.

[0128] Correspondingly, the first blockchain network element receives message 1 from the first core network device.

[0129] For example, the first core network device in the visited network sends Message 1 to the first blockchain network element, or alternatively, the access network device in the visited network sends Message 1 to the first blockchain network element, or alternatively, other network elements in the visited network send Message 1 to the first blockchain network element. The embodiments of the present application do not limit this. Message 1 may also be referred to as the first message. Message 1 may include first roaming permission information, and the first roaming permission information includes, for example, the roaming permission information of the visited network. Optionally, Message 1 may further include the identifier of the visited network, and the identifier of the visited network is, for example, the ID of the visited network.

[0130] The first roaming permission information may include terminal device information indicating permission (or ability) to roam in the visited network. For example, the first roaming permission information includes the identifiers of one or more home networks, indicating that the terminal devices of the home networks corresponding to these identifiers are permitted to roam in the visited network. Optionally, the first roaming permission information may further include one or more of the following information when the terminal device capable of roaming in the visited network roams in the visited network: the service type allowed (or capable) to be used, the network slice allowed (or capable) to be used, the 5G Quality of Service Identifier (5QI) allowed (or capable) to be used, or the area allowed (or capable) to be accessed. Among them, if a certain roaming permission information does not include a certain parameter, then for the home network using this roaming permission information (or the UE within the home network), it can be considered that there is no restriction on this parameter, and a suitable object can be selected according to the network situation. For example, the first roaming permission information includes roaming permission information 1, indicating that the UE can use roaming permission information 1; roaming permission information 1 does not include the allowed network slice, indicating that when the UE roams in the visited network, there is no restriction on selecting the network slice, that is, a suitable network slice can be selected according to network factors and the like.

[0131] Among them, if the visited network allows UEs in multiple home networks to roam therein, the roaming permissions granted by the visited network to UEs in different home networks may be the same or different. In addition, for a home network capable of roaming in the visited network, the visited network may grant one type of roaming permission or multiple types of roaming permissions to this home network. Among them, the parameters included in different roaming permissions may be different. Optionally, the values of the same parameter included in different roaming permissions may also be different. For example, one type of roaming permission includes the allowed network slice, while another type of roaming permission does not include the allowed network slice, which is an example of the difference in the parameters included in these two types of roaming permissions. Another example is that both types of roaming permissions include the allowed network slice, but the allowed network slices included in these two types of roaming permissions are different, which is an example of the difference in the values of the parameters included in these two types of roaming permissions.

[0132] For example, if the first roaming permission information includes the identifiers of PLMN B and PLMN C, it indicates that UEs of PLMN B can roam within the visited network, and UEs of PLMN C can also roam within the visited network. Additionally, the roaming permission information of the visited network may further include information about network slice 1 that UEs within PLMN B are permitted to use within the visited network and the permitted 5QI. Moreover, it may also include information about area 1 that UEs within PLMN C are permitted to use within the visited network, information about network slice 2 that is permitted to be used, and the permitted QoS. It can be seen that the roaming permissions granted by the visited network to PLMN B and PLMN C are different, which is manifested in different roaming permission parameters and different values of the same parameter (such as the permitted network slice). Another example is that if the visited network grants two types of roaming permissions to PLMN B, then the first roaming permission information may include roaming permission information 1 and roaming permission information 2 for UEs within PLMN B within the visited network. Roaming permission information 1 may include, for example, that the permitted network slice is network slice 1, and roaming permission information 2 may include, for example, that the permitted network slice is network slice 2.

[0133] The visited network sends message 1 to the first blockchain network element so that the first blockchain network element can publish the first roaming permission information to the blockchain system, for example, write the first roaming permission information into the corresponding block. Thus, when the home network of the UE configures roaming permissions for the UE, it can obtain the roaming permission information of the visited network through the blockchain without establishing a roaming connection between the visited network and the home network of the UE.

[0134] The embodiments of this application do not limit the time when the visited network sends message 1. For example, the visited network can send message 1 to the first blockchain network element after deploying the first blockchain network element, or the first core network device can also send message 1 when the first blockchain network element joins Figure 3 the shown consortium blockchain, or the first core network device can also send message 1 to the first blockchain network element in other situations.

[0135] Message 1 can also be used to update the roaming permission information of the visited network. For example, if the first blockchain network element has established a block for storing the roaming permission information of the visited network, the visited network can send Message 1 to the first blockchain network element to update the roaming permission information of the visited network. At this time, Message 1 can also include the identification information of the fourth block, where the fourth block stores the original roaming permission information of the visited network. In this case, the first roaming permission information included in Message 1 can also be referred to as the new roaming permission information of the visited network. For the content of the original roaming permission information of the visited network, reference can also be made to the introduction of the roaming permission information of the visited network in the above text. The identification information of the fourth block can indicate the fourth block. For example, if the fourth block belongs to the first blockchain, the identification information of the fourth block can include the identification of the fourth block and the identification of the fourth block within the first blockchain.

[0136] Among them, S401 is an optional step.

[0137] S402. The first blockchain network element publishes the first roaming permission information to the blockchain system.

[0138] Optionally, after obtaining the first roaming permission information, the first blockchain network element can publish the first roaming permission information to the blockchain system, so that other networks can obtain the first roaming permission information from the blockchain system. If a UE needs to roam in the visited network, the home network of the UE can grant the UE the roaming permission in the visited network according to the first roaming permission information in the blockchain system, without establishing a roaming connection between the visited network and the home network of the UE.

[0139] The first blockchain network element publishes the first roaming permission information to the blockchain system, which can be implemented through several steps such as S4021, S4022, and S4023 as follows.

[0140] S4021. The first blockchain network element sends Message 2.

[0141] Correspondingly, one or more blockchain network elements in the blockchain system receive the Message 2. Figure 4 Taking the third blockchain network element and the second blockchain network element both receiving Message 2 as an example. Among them, the second blockchain network element is the blockchain network element configured for the home network of the UE, and can also be referred to as the blockchain network element of the home network. Regarding how the third blockchain network element and the second blockchain network element will process after receiving Message 2, reference can be made to the introduction of S4022.

[0142] Message 2 can also be referred to as the first block creation request message. Whether it is to store the roaming permission information for accessing the visited network in the blockchain or to update the original roaming permission information of the visited network in the blockchain, a new block needs to be created. Therefore, Message 2 can request the creation of a block. For example, Message 2 includes the first roaming permission information. The first blockchain network element can broadcast Message 2 within the blockchain system, and some or all of the blockchain network elements within the blockchain system can receive this Message 2.

[0143] In addition, the first blockchain network element can generate the public key of the visited network, the private key of the visited network, and the second authentication information according to the identifier of the visited network and / or the first roaming permission information included in Message 2. These information can be used for the UE to authenticate the visited network when roaming and accessing the visited network. In addition to carrying the first roaming permission information in Message 2, optionally, the first blockchain network element can also carry the public key of the visited network in Message 2. However, for the private key of the visited network and the second authentication information, the first blockchain network element does not need to send them to the blockchain system, but can store them by itself.

[0144] It should be noted that the embodiment of the present application can use an asymmetric encryption algorithm to perform identity authentication between the UE and the visited network. Alternatively, the embodiment of the present application can also use other encryption algorithms, such as using a symmetric encryption algorithm, to perform identity authentication between the UE and the visited network. Exemplarily, the first blockchain network element can generate the key of the visited network and the second authentication information. Then, the first blockchain network element can carry the key of the visited network in Message 2, and the second authentication information still does not need to be sent and can be stored by itself.

[0145] Optionally, for different roaming permission information, the visited network can have different public keys respectively. For example, the first roaming permission information includes the identifiers of PLMN B and PLMN C, the roaming permission information 1 of the UE in PLMN B within the visited network, and also includes the roaming permission information 2 of the UE in PLMN C within the visited network. Then, the roaming permission information 1 can correspond to a public key of the visited network (for example, called public key 1), and the roaming permission information 2 can correspond to a public key of the visited network (for example, called public key 2). Public key 1 and public key 2 may be the same or different. It can be seen that if the first roaming permission information includes multiple roaming permission information, the first blockchain network element can generate the corresponding public key, private key, and second authentication information according to different roaming permission information respectively.

[0146] In addition, if Message 1 includes the identifier information of the fourth block, optionally, Message 2 can also include the identifier information of the fourth block.

[0147] S4022. The third blockchain network element creates the first block, and the first block stores the first roaming permission information.

[0148] The first block belongs to the first blockchain, and the first blockchain is maintained in the third blockchain network element. Among them, the first blockchain may be replicated multiple times and stored in some or all of the blockchain network elements in the blockchain system. Therefore, the first blockchain is maintained in some or all of the blockchain network elements. For example, the first blockchain network element maintains the first blockchain, and the third blockchain network element also maintains the first blockchain.

[0149] After the first blockchain network element broadcasts Message 2, some or all of the blockchain network elements in the blockchain system perform a consensus verification process. The consensus verification process can be understood as that some or all of the blockchain network elements in the blockchain system reach a consensus on whether to generate a certain block. The following briefly introduces the consensus verification process.

[0150] After some or all of the blockchain network elements in the blockchain system receive Message 2, since Message 2 is a request to create a block, some or all of the blockchain network elements determine the inspection node. Among some or all of these blockchain network elements, if some blockchain network elements have higher permissions, some or all of the blockchain network elements may determine one of the blockchain network elements with higher permissions as the inspection node; or, among some or all of these blockchain network elements, if there is no blockchain network element with higher permissions, some or all of the blockchain network elements determine a blockchain network element from some or all of the blockchain network elements as the inspection node, and the determination method is, for example, the proof of work (PoW) algorithm, the proof of stake (PoS) algorithm, or the delegated proof of stake (DPoS) algorithm, etc. For example, in the embodiment of the present application, the determined inspection node is the third blockchain network element, and the third blockchain network element and the first blockchain network element may be the same network element or different network elements; the third blockchain network element and the second blockchain network element may be the same network element or different network elements.

[0151] For a blockchain network element that has received Message 2 within the blockchain system, it will verify Message 2. If Message 2 is a request to create a block, then for the blockchain network element that receives Message 2, verifying Message 2 may mean verifying the reason for creating the block indicated by Message 2. For example, it can be verified whether the reason for creating the block conforms to the corresponding smart contract. If the reason for creating the block conforms to the smart contract, then the verification of Message 2 is successful; if the reason for creating the block does not conform to the smart contract, then the verification of Message 2 fails. A smart contract, also known as a digital contract, is an event-driven, stateful program that is recognized by multiple parties (such as some or all of the blockchain network elements within a consortium blockchain), runs on the blockchain, and can automatically execute according to preset conditions. In terms of the embodiments of this application, the smart contract includes, for example, the reason for creating a block. If the reason for creating a certain block conforms to the smart contract, for example, the reason for creating the block is the same as the reason configured in the smart contract, then the block can be created; if the reason for creating a certain block does not conform to the smart contract, then the block cannot be created. If a blockchain network element successfully verifies Message 2, then the blockchain network element can broadcast a confirmation request within the blockchain system, and the confirmation request can indicate that the verification of Message 2 is successful. For the third blockchain network element, it can receive confirmation requests from one or more blockchain network elements. Of course, as a blockchain network element within the blockchain system, the third blockchain network element may also receive Message 2, and then the third blockchain network element will also verify Message 2. If the verification is successful, the third blockchain network element will also broadcast a confirmation request within the blockchain system. That is to say, for the blockchain network elements within the blockchain system, it is possible to receive confirmation requests from other blockchain network elements. However, except for the inspection node (such as the third blockchain network element), if a blockchain network element receives a confirmation request from other blockchain network elements, it does not have to process it. If the inspection node receives a confirmation request from other blockchain network elements, it can verify some or all of the received confirmation requests. It can be understood that because all the blockchain network elements within the blockchain system can know which blockchain network element is the inspection node, if the inspection node receives a confirmation request from other blockchain network elements, it can process it, while for a blockchain network element that is not an inspection node, if it receives a confirmation request from other blockchain network elements, it does not have to process it.

[0152] The third blockchain network element verifies the received confirmation request. If the verification is successful, a new block can be generated; if the verification fails, generating a new block is rejected. The third blockchain network element verifies the received confirmation request. One verification method is that if the number of confirmation requests received by the third blockchain network element is greater than or equal to the first threshold (or if the number of confirmation requests received by the third blockchain network element is greater than the first threshold), then the third blockchain network element successfully verifies the received confirmation request; while if the number of confirmation requests received by the third blockchain network element is less than the first threshold (or if the number of confirmation requests received by the third blockchain network element is less than or equal to the first threshold), then the third blockchain network element fails to verify the received confirmation request. The first threshold is, for example, equal to the number of blockchain network elements included in the blockchain system, or can also be less than the number of blockchain network elements included in the blockchain system.

[0153] If the third blockchain network element successfully verifies the received confirmation request, the third blockchain network element can generate a new block in the first blockchain it maintains. For example, the generated new block is called the first block, and the third blockchain network element can store corresponding information in the first block. For example, the information stored in the first block is called the content information of the first block, then the content information of the first block includes, for example, the first roaming permission information, and can also include the identification information of the first block. The identification information of the first block can indicate the first block. For example, the identification information of the first block includes the identification of the first block and the identification of the first block within the first blockchain. Optionally, the content information of the first block can also include the public key of the visited network and / or the identification of the visited network. Additionally optionally, if message 2 includes the identification information of the fourth block, then the third blockchain network element can also store the identification information of the fourth block in the first block. Storing the identification information of the fourth block in the first block is equivalent to establishing a mapping relationship between the fourth block storing the original roaming permission information of the visited network and the first block storing the new roaming permission information of the visited network, so that the original roaming permission information of the visited network can be traced based on the first block.

[0154] In an embodiment of the present application, the first roaming permission information includes, for example, all the roaming permission information of the visited network. That is to say, it includes all the roaming permission information of the home networks that can roam in the visited network granted by the visited network. The first roaming permission information can be stored in one block, or the first roaming permission information can also be stored in multiple blocks. If the first roaming permission information is stored in multiple blocks, then, for example, one block can store all the roaming permission information of the visited network granted to one home network, and the roaming permission information of the visited network granted to different home networks is stored in different blocks; or, one block can store part of the roaming permission information of the visited network granted to one home network, the roaming permission information of the visited network granted to one home network is stored in at least two blocks, and the roaming permission information of the visited network granted to different home networks is also stored in different blocks. For example, if the visited network grants a home network multiple types of roaming permission information, where different roaming permission information corresponds to different services, then the roaming permission information corresponding to different services can be stored in the same block or separately stored in different blocks. Another example, if the visited network grants a home network multiple types of roaming permission information, where different roaming permission information corresponds to different service areas, then the roaming permission information corresponding to different service areas can be stored in the same block or separately stored in different blocks. Another example, if the visited network grants a home network multiple types of roaming permission information, where different roaming permission information corresponds to different service areas and different roaming permission information corresponds to different services, then these several types of roaming permission information can be stored in one block or separately stored in different blocks.

[0155] As can be seen from the above introduction, the first roaming permission information included in Message 2 may need to be stored in one block, or may also need to be stored in multiple blocks. If it needs to be stored in multiple blocks, then the third blockchain network element can generate multiple new blocks, and these multiple new blocks can be used to store the first roaming permission information included in Message 2. For example, the first roaming permission information may include multiple parts, and different parts are stored in different blocks. Optionally, the public key of the visited network corresponding to the roaming permission information stored in each block can also be stored in each block. For example, the first block is one of these multiple new blocks. If the third blockchain network element wants to generate multiple new blocks, the generation method is similar to the method of generating the first block. In an embodiment of the present application, an example is given where the first roaming permission information included in Message 2 is stored in one block (the first block).

[0156] S4023. The third blockchain network element sends Message 3.

[0157] Correspondingly, some or all of the blockchain network elements in the blockchain system receive the Message 3.

[0158] For example, if the third blockchain network element broadcasts message 3 within the blockchain system, some or all of the blockchain network elements within the blockchain system can receive this message 3. Figure 4 Taking the first blockchain network element and the second blockchain network element both receiving message 3 as an example. For example, message 3 can also be referred to as the first block building response message. Message 3 can indicate that the first block is successfully built. For example, message 3 includes the content information of the first block, and the content information of the first block can refer to the introduction in the previous text. That is to say, the third blockchain network element can broadcast the corresponding information of the newly created first block.

[0159] If the third blockchain network element stores the identification information of the fourth block in the first block, then optionally, message 3 can also include the identification information of the fourth block. For example, the content information of the first block included in message 3 includes the identification information of the fourth block.

[0160] If the third blockchain network element generates multiple blocks including the first block, then optionally, message 3 can include the information of these multiple blocks, and the information of each block is similar to that of the first block, which will not be elaborated here.

[0161] Through S4021 - S4023, the first blockchain network element publishes the first roaming permission information to the blockchain system, and all blockchain network elements within the blockchain system can obtain the first roaming permission information from the blockchain. Or, the first blockchain network element may not execute S4021 - S4023, but publish the first roaming permission information to the blockchain system through other means.

[0162] Optionally, after receiving message 3, the second blockchain network element can send the first roaming permission information to the home network, so that the home network can grant the corresponding roaming permission to the UE according to the first roaming permission information. For example, the home network can grant part or all of the first roaming permission information to the UE, and the roaming permission granted by the home network to the UE within the visited network is the second roaming permission.

[0163] Optionally, after receiving message 3, the first blockchain network element can record the first block, for example, record the content information of the first block. Similarly, all blockchain network elements that receive message 3 can record the first block, so as to achieve the effect of "replicating" the blockchain within multiple blockchain network elements. In addition, the first blockchain network element can also send the identification information of the first block to the visited network, indicating that the first block is successfully created, or indicating that the roaming permission information of the visited network is successfully published. Correspondingly, the visited network receives the identification information of the first block from the first blockchain network element. If the message 3 received by the first blockchain network element includes the identification information of multiple blocks, then optionally, the first blockchain network element can send the identification information of these multiple blocks to the visited network. This application embodiment takes message 3 including the identification information of the first block as an example.

[0164] The visited network may also send the identification information of the first block to the UE, so that when the UE registers in the visited network, it can send the identification information of the first block to the visited network. For the introduction of this process, please refer to the description of S404 below.

[0165] S403. The first blockchain network element obtains the second roaming permission information of the UE from the blockchain stored in the blockchain system. The second roaming permission information is the roaming permission information of the UE authorized by its home network in the visited network, and the second roaming permission information is the complete set or subset of the first roaming permission information.

[0166] The visited network may grant one or more types of roaming permission information to the home network of the UE, and these roaming permission information are included in the first roaming permission information. The home network of the UE may grant some or all of the roaming permission information granted by the visited network to the UE. When the UE roams in the visited network, it can use the roaming permissions granted by the home network, that is, the roaming permissions indicated by the second roaming permission information. For example, the first roaming permission information includes roaming permission information 1, roaming permission information 2, and roaming permission information 3. The visited network grants roaming permission information 1 and roaming permission information 2 to the home network, and the home network may grant roaming permission information 1 to the UE, then roaming permission information 1 serves as the second roaming permission information. Different roaming permission information may have different included parameters (for example, one type of roaming permission information includes the network slice that can be used, and another type of roaming permission information does not include this parameter), and / or different roaming permission information may have different values of the same parameter (for example, one type of roaming permission information includes the network slice that can be used as slice 1, and another type of roaming permission information includes the network slice that can be used as slice 2).

[0167] Optionally, before executing S403, S404 and S405 may also be executed.

[0168] S404. The UE sends message 4 to the visited network.

[0169] Correspondingly, the visited network receives message 4 from the UE.

[0170] For example, the UE sends Message 4 to a first core network device within the visited network, or the UE may also send Message 4 to an access network device within the visited network. Exemplarily, Message 4 may be a registration request, which can be used to request access to the visited network; or, Message 4 may be a session establishment request, which is used to request the establishment of a session for the UE. For example, Message 4 includes identification information of a second block. The identification information of the second block can indicate the second block. For example, the identification information of the second block includes the identification of the second blockchain and the identification of the second block within the second blockchain. The second blockchain can be maintained in the first blockchain network element, or rather, the second blockchain can be maintained in each blockchain network element of all or part of the blockchain network elements included in the blockchain system. The first blockchain and the second blockchain can be the same blockchain, or they can also be different blockchains. Regarding the second block, for example, the generation process thereof will be introduced in other embodiments hereinafter.

[0171] The second block may store first indication information, and the first indication information can indicate second roaming permission information. For example, the visited network grants one or more types of roaming permission information to the home network, and the home network can grant some or all of these roaming permission information to the UE. The roaming permission information granted to the UE is the second roaming permission information. That is to say, the second roaming permission information can be determined through the second block, so as to enable roaming access control for the UE.

[0172] The first indication information includes, for example, the identification information of a first block. That is to say, the second block may store the identification information of the first block, and the first block stores the first roaming permission information. The first roaming permission information can be indexed through the second block. The roaming permission information indicated by the first indication information is the roaming permission information of the UE authorized by the home network in the visited network. The first indication information may include the identification information of the first block. That is to say, the first roaming permission information stored in the first block can also be used as the content of the second roaming permission information. If the first block stores the entire set of the first roaming permission information, then the first roaming permission information and the second roaming permission information have the same content. If the first block stores partial information of the first roaming permission information, then the second roaming permission information is a proper subset of the first roaming permission information. For the first blockchain network element, if the second block is determined, the second roaming permission information can also be correspondingly determined, so as to control the roaming access of the UE according to the second roaming permission information.

[0173] Optionally, in addition to including the identification information of the second block, message 4 may further include the identification information of the first block. For example, the first roaming permission information may be stored in multiple blocks, including the first block, and the second roaming permission information corresponds to the roaming permission information stored in the first block. In addition to storing the identification information of the first block, the second block may also store the identification information of other blocks among the multiple blocks. If the UE does not send the identification information of the first block to the visited network, and the second block stores the identification information of multiple blocks, it may be inconvenient for the visited network (or the first blockchain network element) to determine which block's stored roaming permission information the UE is exactly requesting. Therefore, the UE may send the identification information of the first block to the visited network together, so that the visited network (or the first blockchain network element) can clearly know that the roaming permission information requested by the UE is stored in the first block.

[0174] For example, if the UE can obtain the identification information of the block for storing the first roaming permission information, and the UE has arrived at the visited network and has determined the roaming permission to be requested, then in addition to sending the identification information of the second block to the visited network, the UE may also send the identification information of the first block to the visited network. Thus, the visited network can directly determine the roaming permission information stored in the first block.

[0175] In addition, if the UE is to roam within the visited network, the network needs to authenticate the UE. Optionally, message 4 may further include signature information (e.g., referred to as the first signature information) encrypted using the private key of the UE and first verification information. The first signature information and the first verification information can be used to authenticate the UE, or in other words, the network can authenticate the UE based on the first signature information and the first verification information. For example, the UE can generate the public key of the UE, the private key of the UE, and the first verification information. The UE can use the private key of the UE to encrypt the first verification information to obtain the first signature information. The UE can send the first signature information and the first verification information to the visited network, and then the visited network can send the first signature information and the first verification information to the first blockchain network element. The network element (e.g., the first blockchain network element) used to authenticate the UE can use the public key of the UE to decrypt the first signature information to obtain decryption information, e.g., referred to as the first decryption information. The network element can compare the first decryption information with the first verification information included in message 4. If the two are consistent, the authentication of the UE is successful; if the two are inconsistent, the authentication of the UE fails. Alternatively, the UE can perform a hash process on the first verification information to obtain a digest, and use the private key of the UE to encrypt the digest to obtain the first signature information. The UE can send the first signature information and the first verification information to the first core network device, and then the first core network device can send the first signature information and the first verification information to the first blockchain network element. The network element (e.g., the first blockchain network element) used to authenticate the UE can perform a hash process on the received first verification information to obtain a digest, and the network element can use the public key of the UE to decrypt the first signature information to obtain decryption information, e.g., referred to as the first decryption information. The network element can compare the first decryption information with the obtained digest. If the two are consistent, the authentication of the UE is successful; if the two are inconsistent, the authentication of the UE fails.

[0176] Optionally, for different roaming privilege information, the UE may generate different public keys and private keys respectively. For example, the home network of the UE is the network corresponding to the second PLMN, and the visited network grants the UE roaming privilege information 1 and roaming privilege information 2 within the second PLMN, and the home network grants both the roaming privilege information 1 and the roaming privilege information 2 to the UE. Then the UE can generate a public key and the corresponding private key for the roaming privilege information 1, and can also generate a public key and the corresponding private key for the roaming privilege information 2. Alternatively, the UE only needs to generate a set of public key and the corresponding private key, and this public key and private key are applicable to any roaming privilege of the UE in the visited network granted by the home network. After the UE generates the public key, it can send the public key to the home network, for example, send it to the core network device (such as the second core network device) or the access network device in the home network, and the home network can send the public key of the UE to the second blockchain network element, so that the public key of the UE can be stored in the blockchain through the second blockchain network element. Since the UE can generate different public keys for different roaming privileges, if the UE generates multiple public keys, the multiple public keys can be stored in one block or in different blocks. For example, the roaming privilege currently requested by the UE is stored in the first block, and the second block stores the identification information of the first block. Then the public key corresponding to the roaming privilege currently requested by the UE (or, if the symmetric encryption method is adopted, the key corresponding to the roaming privilege currently requested by the UE) can be stored in the second block. This part of the content will be introduced in the generation process of the second block described in other embodiments hereinafter. And the private key of the UE can be stored by the UE itself and does not need to be stored in the blockchain. In this embodiment of the application, the asymmetric encryption algorithm is taken as an example. Alternatively, in this embodiment of the application, the symmetric encryption algorithm can also be adopted, then the UE can generate a key corresponding to the roaming privilege information, and can store the key in the blockchain through the second blockchain network element.

[0177] Message 4 may further include the identification of the UE, and the identification of the UE is, for example, the ID of the UE. Alternatively, message 4 may also include the identification of the UE, without including the identification information of the first block and without including the identification information of the second block. For example, the visited network stores the correspondence between the identification of the UE and the identification information of the corresponding block. For example, the visited network stores the correspondence between the identification of the UE and the identification information of the second block, or stores the correspondence between the identification of the UE, the identification information of the first block, and the identification information of the second block. When the visited network receives the identification of the UE, it can know the identification of the corresponding block. This can avoid carrying too much information in message 4 and can save signaling overhead.

[0178] S405. The visited network sends message 5 to the first blockchain network element.

[0179] Correspondingly, the first blockchain network element receives Message 5 from the first core network device.

[0180] For example, the first core network device in the visited network sends Message 5 to the first blockchain network element, or it can also be that the access network device in the visited network sends Message 5 to the first blockchain network element. Message 5 can be used to request authentication and / or authorization for the UE. To authorize the UE, the roaming permission information of the visited network is required, so it is also considered that Message 5 can be used to obtain the roaming permission information of the visited network. For example, Message 5 includes the identification information of the second block.

[0181] Optionally, after receiving Message 4, the visited network queries the registration information of the UE according to the ID of the UE included in Message 4. For example, if the network where the visited network is located is a 5G network, the visited network can query the registration information of the UE in the UDM according to the ID of the UE. The UE is registered in its home network and not in the visited network, so the visited network cannot query the registration information of the UE. In the case where the registration information of the UE cannot be queried, the visited network cannot perform roaming access control on the UE, then the visited network can send Message 5 to the first blockchain network element to perform roaming access control on the UE through the first blockchain network element. The first blockchain network element stores information for performing roaming access control on the UE (for example, the second roaming permission information stored in the blockchain maintained by the first blockchain network element can be used to authorize the roaming of the UE), then the first blockchain network element can perform roaming access control on the UE.

[0182] Message 5 includes the identification information of the second block, and the second block stores the first indication information, so that after receiving Message 5, the first blockchain network element can obtain the second roaming permission information from the blockchain system according to the identification information of the second block, or in other words, obtain the second roaming permission information from the blockchain according to the identification information of the second block.

[0183] Optionally, if Message 4 includes the first signature information and the first verification information, then Message 5 can also include the first signature information and the first verification information. Additionally optionally, if Message 4 includes the identification information of the first block, then Message 5 can also include the identification information of the first block.

[0184] S406. The first blockchain network element sends Message 6 to the visited network.

[0185] Correspondingly, the visited network receives Message 6 from the first blockchain network element.

[0186] Message 6 includes second roaming permission information. The first blockchain network element may send Message 6 to the first core network device in the visited network, or the first blockchain network element may also send Message 6 to the access network device in the visited network. After executing S403, S406 may be executed.

[0187] After the first blockchain network element obtains the second roaming permission information, it may send the second roaming permission information to the visited network, so that the visited network can authorize the roaming of the UE in the visited network according to the second roaming permission information.

[0188] S407: The visited network controls the access of the UE in the visited network according to the second roaming permission information.

[0189] The first core network device in the visited network controls the access of the UE in the visited network, or it may also be the access network device in the visited network that controls the access of the UE in the visited network.

[0190] For example, the visited network may grant all the roaming permissions indicated by the second roaming permission information to the UE, or the visited network may also grant some of the roaming permissions indicated by the second roaming permission information to the UE. The embodiments of the present application do not limit this.

[0191] S407 may occur during the registration process of the UE, or it may also occur after successful registration, for example, during the session establishment process or other processes.

[0192] After the visited network sends Message 5 (S405) to the first blockchain network element and before the first blockchain network element obtains the second roaming permission information of the UE from the blockchain stored in the blockchain system (S403), optionally, the first blockchain network element may also perform processes such as authenticating the UE, that is, execute S408.

[0193] S408: The first blockchain network element authenticates the UE.

[0194] Exemplarily, the first blockchain network element authenticates the UE according to the public key of the UE. After the first blockchain network element obtains the identification information of the second block included in Message 5, the first blockchain network element may query the content stored in the second block according to the identification information of the second block to obtain the public key of the UE from the content stored in the second block.

[0195] Alternatively, the first blockchain network element may not need to query the content stored in the second block. For example, the first blockchain network element stores a first mapping table, and the first mapping table includes the content information of the second block, and the content information of the second block may include the content stored in the second block, such as the identification information of the second block stored in the second block, the public key of the UE, and the identification information of the first block. Then, the first blockchain network element can query the first mapping table according to the identification information of the second block, and thus obtain the public key of the UE. Optionally, the first mapping table may further include the identification of the UE, so it can be considered that the first mapping table includes the mapping relationship between the identification of the UE and the content information of the second block. Thus, the first blockchain network element can also obtain the content information of the second block by querying the first mapping table according to the identification of the UE. Regarding the generation process of the first mapping table, it will be introduced in other embodiments later. Generally speaking, the method of querying the mapping table takes less time and has higher efficiency than the method of querying the block.

[0196] After obtaining the public key of the UE, the first blockchain network element can authenticate the UE according to the public key of the UE, the first signature information, and the first verification information. The authentication process can refer to the introduction in S404.

[0197] If the first blockchain network element successfully authenticates the UE, the first blockchain network element can obtain the private key of the visited network according to the identification information of the first block. Additionally, it can also obtain the second verification information, and use the private key of the visited network to encrypt the second verification information to obtain the signature information encrypted with the private key of the visited network. Or, perform a hash process on the second verification information to obtain a digest, and use the private key of the visited network to encrypt the digest to obtain the signature information encrypted with the private key of the visited network. Among them, the signature information encrypted with the private key of the visited network is, for example, called the second signature information. The first blockchain network element can send the second signature information and the second verification information to the visited network for the UE to authenticate the visited network. Among them, the first blockchain network element can generate the public key of the visited network, the private key of the visited network, and the second verification information. The first blockchain network element can store the public key of the visited network in the first block, while the private key of the visited network and the second verification information do not have to be stored in the block. For the second verification information, the first blockchain network element can save it or generate it in a timely manner according to the usage requirements. As introduced above, for different roaming authorities, the first blockchain network element can generate different public keys and private keys respectively. The roaming authority information of the visited network stored in a block and the public key of the visited network stored in the block correspond to each other. For example, a block can store the roaming authority information 1 granted by the visited network to PLMN A and the public key A corresponding to the roaming authority information 1. Additionally, this block can also store the roaming authority information 2 granted by the visited network to PLMN A and the public key B corresponding to the roaming authority information 1. Additionally, the first blockchain network element can also obtain a second mapping table. The second mapping table can include the mapping relationship between the content information of the first block and the private key of the visited network. The content information of the first block can include the content stored in the first block, such as including the identification information of the first block stored in the first block, the public key of the visited network, and the first roaming authority information, etc. Then, the first blockchain network element can obtain the private key of the visited network from the second mapping table according to the identification information of the first block.

[0198] After executing S408, S403 can be executed. After executing S403, S406 can be executed. At this time, in addition to including the second roaming authority information, message 6 can also indicate the authentication result of the UE. For example, the authentication result indicated by message 6 is called the first authentication result, and the first authentication result is authentication success or authentication failure.

[0199] If the first authentication result is authentication success, in addition to indicating the first authentication result, message 6 further includes second roaming permission information. That is to say, when the first blockchain network element authenticates the UE, if the authentication passes, the first blockchain network element can determine the second roaming permission information according to the content stored in the first block (or, according to the second mapping table). Then, the first blockchain network element can send the second roaming permission information to the visited network. If the first authentication result is authentication failure, at this time, message 6 may not include the second roaming permission information, and the visited network does not have to authorize the UE's roaming. In the embodiments of the present application, taking the first authentication result being authentication success as an example, so the message 6 in S405 includes the second roaming permission information.

[0200] In addition, the authentication may be two-way. In addition to the visited network authenticating the UE, the UE can also authenticate the visited network. Therefore, if the first authentication result is authentication success, in addition to indicating the first authentication result, optionally, message 6 may further include second signature information and second verification information, and the second verification information and the second signature information can be used by the UE to authenticate the visited network. In addition, optionally, message 6 may further include the ID of the UE.

[0201] Before executing S407, optionally, S409 and S410 may also be executed.

[0202] S409: The visited network sends the second signature information and the second verification information to the UE.

[0203] Correspondingly, the UE receives the second signature information and the second verification information from the visited network.

[0204] For example, the first core network device in the visited network sends the second signature information and the second verification information to the UE, or the access network device in the visited network sends the second signature information and the second verification information to the UE.

[0205] If the first authentication result is authentication success, the visited network may send the second signature information and the second verification information to the UE. If the first authentication result is authentication failure, then S409 can be replaced with: The first core network device sends the information of authentication failure to the UE. Correspondingly, the UE receives the information of authentication failure from the first core network device.

[0206] S410: The UE authenticates the visited network according to the second signature information and the second verification information.

[0207] The UE has obtained the public key of the visited network in advance. For example, the public key of the visited network is sent to the UE by the home network (for example, refer to what will be introduced later Figure 7In the embodiment shown, S707). For example, if the second signature information is obtained by encrypting the second verification information using the private key of the visited network, the UE can decrypt the second signature information using the public key of the visited network to obtain decryption information. For example, this decryption information is referred to as the second decryption information. The UE compares the second decryption information with the second verification information. If the two are consistent, the authentication of the visited network is successful. If the two are inconsistent, the authentication of the visited network fails. Or, for example, the second signature information is obtained by encrypting a digest (obtained by hashing the second verification information) using the private key of the visited network. The UE can decrypt the second signature information using the public key of the visited network to obtain decryption information. For example, this decryption information is referred to as the second decryption information. And the UE performs a hash process on the second verification information to obtain a digest. The UE compares the second decryption information with the obtained digest. If the two are consistent, the authentication of the visited network is successful. If the two are inconsistent, the authentication of the visited network fails.

[0208] If in S410 the first core network device sends the second signature information and the second verification information to the UE, then execute S410. And if in S409 the first core network device sends an authentication failure message to the UE, then there is no need to execute S410, nor is it necessary to execute the subsequent steps. The process ends, and the UE cannot roam in the visited network.

[0209] It should be noted that in various embodiments of the present application, the processes of the visited network authenticating the UE and the UE authenticating the visited network are described by taking the asymmetric key method of public key and private key as an example. In actual use, the visited network authenticating the UE or the UE authenticating the visited network can also use a symmetric key for authentication.

[0210] After executing S407, optionally, S411 can also be executed.

[0211] S411: The visited network and the UE continue to execute the registration process.

[0212] Optionally, if the UE authenticates the visited network successfully, the visited network and the UE can continue to execute the registration process. Or rather, the corresponding network element in the core network of the UE's visited network can continue to execute the registration process with the UE.

[0213] If the result of executing the registration process is successful registration, the UE can roam within the visited network. If the result of executing the registration process is failed registration, the UE cannot roam within the visited network. The process of the registration process will not be elaborated here. And if the UE authenticates the visited network fails, there is no need to execute S411, the process ends, and the UE cannot roam in the visited network.

[0214] It should be noted that if the message 4 in S404 is a session establishment request, S411 can be replaced by a process in which the visited network establishes a session for the UE.

[0215] Among them, S401, S4021 - S4023, S404 - S405, S408 - S411 are all optional steps.

[0216] Exemplarily, Figure 4 The process of authorizing the UE introduced in the illustrated embodiment can also be more vividly represented by Figure 5 as follows. Figure 5 In [figure], the cloud shape represents the blockchain system. The squares represented by A, B, D, roaming permission 1, and roaming permission 2, etc. in it represent multiple blocks in a blockchain. For example, the blockchain is the first blockchain, and the first blockchain stores the roaming permission 1 of the visited network and the roaming permission 2 of the visited network. For example, the block used to store the roaming permission 1 is Figure 4 the first block described in the illustrated embodiment, and it is also the roaming permission within the visited network granted by the home network to the Figure 5 UE shown in [figure]. The roaming permission 2 is another roaming permission of this visited network, and the UE does not use the roaming permission 2. Figure 5 Networks A, B, C, and D in [figure] represent four different networks. For example, network B is the visited network of the UE. Figure 5 The consensus verification (also known as reaching a consensus) process represented in the first blockchain in [figure] can refer to the introduction in the Figure 4 illustrated embodiment. When the UE initiates registration in the visited network, the core network device ( Figure 4 core network device B in [figure]) in the visited network obtains the second roaming permission information from the blockchain network element. For example, it is Figure 5 the roaming permission 1 shown in [figure]. Thus, the core network device B can authorize the roaming of the UE according to the roaming permission 1, enabling the UE to roam in network B.

[0217] In summary, through the technical solution of the embodiment of the present application, if the UE wants to roam, the blockchain network element of the visited network obtains the roaming permission information of the UE authorized by the home network of the UE from the blockchain system, and performs access control on the UE accordingly. The access control includes, for example, access authentication and / or authorization, etc. There is no need to establish pairwise roaming connections between the visited network and the home network, which simplifies the roaming architecture and enables the private network to better support the roaming of the UE.

[0218] Figure 4The embodiments described involve the process of creating a first block. After creating the first block, corresponding steps can also be executed. The following introduces the second roaming access method provided by the embodiments of this application, and some optional steps after creating the first block will be introduced through this method. In the embodiments of this application, the home network can be a second core network device within the home network, an access network device within the home network, or other network elements within the home network; the visited network can be a first core network device within the visited network, an access network device within the visited network, or other network elements within the visited network. Please refer to Figure 6 , which is the flowchart of this method. For example, this method can occur after Figure 4 S4023 in the embodiment shown.

[0219] S601. The first blockchain network element establishes or updates the second mapping table.

[0220] If the first blockchain network element has not yet established the second mapping table, the first blockchain network element can establish the second mapping table according to Message 3. The second mapping table can include the identification information of the first block, and optionally also includes the private key of the corresponding visited network. In this case, if the first blockchain network element needs to obtain the content stored in the first block, it can query the content stored in the first block according to the identification information of the first block in the second mapping table (for example, query the content information of the first block recorded); alternatively, the second mapping table can include the content information of the first block, and optionally also includes the private key of the corresponding visited network. In this case, the first blockchain network element can obtain the content stored in the first block according to the second mapping table, reducing the process of querying the block and improving the query efficiency. Optionally, the second mapping table further includes the identification of the visited network. As an example, the second mapping table can include the content information of the first block, the private key of the visited network, the identification of the visited network, the identification of the first block, the public key of the visited network, and the second verification information.

[0221] If Message 3 includes information of multiple blocks, the second mapping table as above can correspondingly include information of multiple blocks, which will not be elaborated here.

[0222] Alternatively, if the first blockchain network element has established a second mapping table, the first blockchain network element may update the second mapping table according to Message 3. At this time, in addition to the above content, the second mapping table may further include the identification information of the fourth block. Among them, the second mapping table may only include the identification information of the fourth block and not include other relevant information of the fourth block. Or, in addition to the identification information of the fourth block, the second mapping table may further include other information stored in the fourth block, such as the old public key of the visited network, etc. The old public key of the visited network is also the public key of the visited network. The old public key of the visited network corresponds to the original roaming permission information of the visited network stored in the fourth block, and the current public key of the visited network corresponds to the first roaming permission information stored in the first block. Equivalently, through the second mapping table, a mapping relationship between the fourth block and the first block can be established. Even if the first blockchain network element receives the identification information of the fourth block in the subsequent process, it can also index to the first block based on this.

[0223] S602. The second blockchain network element establishes or updates a third mapping table.

[0224] Of course, after receiving Message 3, the second blockchain network element may also record the first block (if Message 3 includes information about the first block), for example, record the content information of the first block. Or, if Message 3 includes information about multiple blocks, then the second blockchain network element may record these multiple blocks.

[0225] In addition, after receiving Message 3, the second blockchain network element may determine whether the home network is within the roaming permission range of the visited network, or in other words, determine whether a UE in the home network can roam within the visited network. The home network is the network corresponding to the second blockchain network element, that is, the network where the second core network device is located. Exemplarily, if the first roaming permission information included in Message 3 includes the identification of the home network, it indicates that a UE in the home network can roam within the visited network. If the first roaming permission information does not include the identification of the home network, it indicates that a UE in the home network cannot roam within the visited network.

[0226] If the home network is within the roaming permission range of the visited network, the second blockchain network element may establish a third mapping table (if the second blockchain network element has not established a third mapping table) or update the third mapping table (if the second blockchain network element has already established a third mapping table). If the home network is not within the roaming permission range of the visited network, the second blockchain network element does not need to establish a third mapping table, and at this time, the third mapping table does not exist either, so there is no situation of updating the third mapping table.

[0227] If the second blockchain network element establishes a third mapping table, the second blockchain network element may establish the third mapping table according to Message 3. The third mapping table may include the identification information of the first block. In this case, if the second blockchain network element needs to obtain the content stored in the first block, it may query the content stored in the first block according to the identification information of the first block in the second mapping table, for example, query the content information of the recorded first block; alternatively, the third mapping table may include the content information of the first block. In this case, the second blockchain network element can obtain the content stored in the first block according to the third mapping table, reducing the process of querying the block and improving the query efficiency. As an example, the third mapping table includes the identification information of the first block, the first roaming permission information, and the public key of the visited network. Optionally, the third mapping table further includes the identification of the visited network. As another example, the third mapping table may include the identification of the visited network, the identification of the first block, the public key of the visited network, the private key of the visited network, the roaming permission information of the visited network, and the second authentication information.

[0228] If Message 3 includes the information of multiple blocks, the above-mentioned third mapping table may correspondingly include the information of multiple blocks, which will not be elaborated here.

[0229] If the second blockchain network element updates the third mapping table, in addition to including the above content, the third mapping table may further include the identification information of the fourth block. Among them, the third mapping table may only include the identification information of the fourth block and not include other relevant information of the fourth block; or, in addition to including the identification information of the fourth block, the third mapping table may further include other information in the content information of the fourth block, for example, further include the old public key of the visited network and / or the original roaming permission information of the visited network, etc. The introduction of the old public key of the visited network and other content can be referred to the previous text. Equivalently, through the third mapping table, a mapping relationship between the fourth block and the first block can be established. If the second blockchain network element receives the identification information of the fourth block in the subsequent process, it can also index to the first block accordingly.

[0230] Among them, Figure 6 The illustrated embodiments are optional embodiments, so each step in this embodiment is an optional step. For the sake of understanding, in Figure 6 these steps are still represented by solid lines.

[0231] Through the solution provided by the embodiments of the present application, the blockchain network element can establish a corresponding mapping table, which, for example, includes the information stored in the block. Then, when it is necessary to obtain the information stored in the block, it can be obtained by querying the mapping table without querying the block, which can improve the query efficiency.

[0232] As introduced above, the second roaming permission information is the roaming permission information of the UE authorized by the home network for the UE in the visited network. In order for the visited network to control the roaming access of the UE according to the second roaming permission information, the home network also needs to publish the second roaming permission information to the blockchain system. The following introduces the third roaming access method provided by the embodiments of this application. Through this method, the home network can publish the second roaming permission information to the blockchain system. In the embodiments of this application, the home network can be the second core network device in the home network, or the access network device in the home network, or other network elements in the home network; the visited network can be the first core network device in the visited network, or the access network device in the visited network, or other network elements in the visited network. Please refer to Figure 7 , which is the flowchart of this method.

[0233] S701. The second blockchain network element obtains the first roaming permission information from the blockchain system.

[0234] For example, the second blockchain network element can obtain the first roaming permission information through Message 3 in S4023 of the embodiment shown in Figure 4 . Therefore, S701 and S4023 of the embodiment shown in Figure 4 can be considered the same step. Or, S701 can also be considered as a step after S4023. For the introduction of the first roaming permission information and other contents, please refer to the embodiment shown in Figure 4 .

[0235] S702. The second blockchain network element publishes the second roaming permission information to the blockchain system. For the introduction of the second roaming permission information and other contents, please refer to the embodiment shown in Figure 4 .

[0236] Optionally, before the second blockchain network element publishes the second roaming permission information to the blockchain system, several steps such as S703 to S705 can also be executed.

[0237] S703. The UE sends Message 7 to the home network.

[0238] Correspondingly, the home network receives Message 7 from the UE.

[0239] Message 7 can be used to request roaming, such as requesting access.

[0240] According to Figure 4As can be seen from the embodiments shown, the home network can obtain the first roaming permission information from the second blockchain network element. Then, the home network can allocate part or all of the first roaming permission information to the UE. The home network can send the allocated roaming permission information to the UE, and the allocated roaming permission information includes one or more types. The UE can decide whether to roam. If it is determined to roam, the UE can determine the roaming permissions that need to be requested under the visited network, and the UE generates a public key, a private key, and first authentication information corresponding to the roaming permissions. Regarding the public key of the UE and other content, reference can be made to Figure 4 the introduction of the embodiments shown. Message 7 can include the public key of the UE. If the home network allocates multiple roaming permissions for the UE under the visited network, optionally, Message 7 can also include the roaming permission information requested by the UE this time, and the roaming permission information requested by the UE this time corresponds to the public key of the UE included in Message 7.

[0241] Among them, if the UE corresponds to one type of roaming permission information under the visited network, the public key, private key, and first authentication information of the UE correspond to the roaming permission information, and the UE does not need to send the roaming permission information to the home network either. At this time, Message 7 may not include the roaming permission information requested by the UE this time; if the UE corresponds to multiple types of roaming permission information under the visited network, for example, the public key of the UE corresponds to one type of roaming permission information, the UE can send this type of roaming permission information to the home network, and the roaming permission information requested by the UE this time included in Message 7 is this type of roaming permission information.

[0242] For example, the roaming permission information requested by the UE this time may include one or more of the following information when the UE roams in the visited network: the service type requested to be used, the network slice requested to be used, the 5QI requested to be used, or the area requested to be accessed. Optionally, the roaming permission information requested by the UE this time may also include the identifier of the visited network. For example, the visited network grants roaming permission information 1 and roaming permission information 2 in the roaming permission information of the visited network to the home network. The roaming permission information requested by the UE this time may be roaming permission information 1, and the home network can grant roaming permission information 1 to the UE according to the roaming permissions of the visited network. Roaming permission information 1 includes, for example, the network slice 1 requested to be used and the area 1 requested to be accessed. Optionally, it also includes the identifier of the visited network.

[0243] Optionally, if the home network determines that the UE needs or can roam within a certain visited network, the home network sends a trigger message to the UE. After receiving the trigger message, the UE executes S703.

[0244] For another example, the home network can decide whether the UE roams. If the home network determines that the UE needs to or can roam within a certain visited network, the home network allocates roaming permissions for the UE under the visited network according to the first roaming permission information of the visited network, and sends the allocated roaming permission information to the UE. After receiving the roaming permission information, the UE can generate a corresponding public key, private key, and first verification information. The UE can send the public key of the UE generated to the home network through Message 7. If there are multiple types of roaming permission information sent by the home network to the UE, the UE can generate the public key of the UE according to one of the roaming permission information, and can send the public key of the UE and the corresponding roaming permission information to the home network through Message 7, indicating that the roaming permission information is the roaming permission information requested by the UE this time.

[0245] Optionally, Message 7 may further include the identifier of the UE.

[0246] S704. The home network sends Message 8 to the second blockchain network element.

[0247] Correspondingly, the second blockchain network element receives Message 8 from the home network.

[0248] After receiving Message 7, the home network can send Message 8 to the second blockchain network element. For example, Message 8 may include second roaming permission information. Optionally, Message 8 may further include the public key of the UE. Additionally optionally, Message 8 may further include the identifier of the UE.

[0249] If the message 7 includes the roaming permission information requested by the UE, optionally, the home network may determine the second roaming permission information according to the roaming permission information requested by the UE. For example, the home network audits the roaming permission information requested by the UE to determine whether the roaming permission can be granted to the UE. If the roaming permission information can be granted to the UE, the second roaming permission information carried in the message 8 is the same as the roaming permission information requested by the UE; if the roaming permission information cannot be granted to the UE, the visited network may determine the roaming permission that can be granted to the UE, and the second roaming permission information is the roaming permission that can be granted to the UE. At this time, the second roaming permission information carried in the message 8 is different from the roaming permission information requested by the UE. For example, the second roaming permission information is a subset of the roaming permission information requested by the UE, or the second roaming permission information is completely different from the roaming permission information requested by the UE (for example, the included parameters are different, or the values of the same parameter included are different). Or, if the message 7 includes the roaming permission information requested by the UE, the home network may also not audit the roaming permission information requested by the UE, but directly send the roaming permission information requested by the UE to the second blockchain network element. Then, the second roaming permission information carried in the message 8 is the same as the roaming permission information requested by the UE.

[0250] S705. The second blockchain network element determines the identification information of the first block according to the second roaming permission information. Regarding the identification information of the first block and other content, reference can be made to Figure 4 the description of the embodiments shown.

[0251] The second blockchain network element receives the public key of the UE, and the public key of the UE can be used to authenticate the UE. That is to say, the authentication information of the UE includes the public key of the UE. The second blockchain network element can publish the public key of the UE to the blockchain system, so that the authentication information of the UE can be obtained through the blockchain system, without the home network and the visited network establishing a dedicated roaming connection to obtain this information.

[0252] When publishing the public key of the UE, the second blockchain network element may also publish the information corresponding to the public key of the UE for indicating the second roaming permission information. Thus, through the blockchain system, not only can the public key of the UE be obtained, but also the second roaming permission can be obtained according to the information for indicating the second roaming permission information. In this way, both the authentication and authorization of the UE can be completed, and thus the roaming access control of the UE can be achieved. The second roaming permission information is the whole set or a subset of the first roaming permission information. Therefore, the information for indicating the second roaming permission information can be described by the identification information of the block storing the first roaming permission information. Therefore, the second blockchain network element may determine the identification information of the first block storing the first roaming permission information corresponding to the second roaming permission information.

[0253] It should be noted that the first roaming permission information corresponding to the second roaming permission information may also be stored in more than one block, and the first block is just one of them. At this time, the second blockchain network element may determine the identification information of one or more blocks according to the second roaming permission information, and these one or more blocks are all used to store the first roaming permission information corresponding to the second roaming permission information. In the embodiment of the present application, taking the second blockchain network element determining the identification information of the first block as an example, that is, taking the number of these one or more blocks as 1.

[0254] As a possible implementation manner, the second blockchain network element may query Figure 6 the third mapping table established in the embodiment shown, and obtain the identification of the block storing the first roaming permission information corresponding to the second roaming permission information. Or, the third mapping table may only include the identification information of the first block, and not include other information in the content information of the first block. Then, the second blockchain network element may query the content stored in the first block according to the identification information of the first block. If it is determined that the roaming permission information stored in the first block is consistent with the second roaming permission information, the identification information of the first block may be determined.

[0255] Optionally, the second blockchain network element may publish the second roaming permission information to the blockchain system through several steps such as S7021 to S7023.

[0256] S7021. The second blockchain network element sends Message 9.

[0257] Correspondingly, one or more blockchain network elements in the blockchain system receive Message 9.

[0258] The first blockchain network element may broadcast Message 9 within the blockchain system, so that some or all of the blockchain network elements in the blockchain system can receive this Message 9. Figure 7Taking the example that both the fourth blockchain network element and the first blockchain network element receive Message 9, the fourth blockchain network element will be introduced in subsequent steps. Message 9 can also be referred to as the second block creation request message. Since information such as the UE's information needs to be stored in the blockchain, a new block needs to be created, so Message 9 can be used to request block creation.

[0259] Exemplarily, Message 9 may include the public key of the UE and information indicating the second roaming permission information. Optionally, Message 9 may further include the identifier of the visited network. It is worth noting that at this time, the information indicating the second roaming permission information can be described by the identifier information of the first block storing the first roaming permission information, that is to say, the information indicating the second roaming permission information included in Message 9 can actually be the identifier information of the first block.

[0260] S7022. The fourth blockchain network element creates a second block. The second block belongs to the second blockchain, and the second blockchain is maintained in the fourth blockchain network element.

[0261] Among them, the second blockchain may be replicated multiple times and stored in some or all of the blockchain network elements in the blockchain system. Therefore, the second blockchain is maintained in some or all of the blockchain network elements. For example, the fourth blockchain network element maintains the second blockchain, and the second blockchain network element also maintains the second blockchain. The second blockchain and the first blockchain may be the same blockchain or different blockchains.

[0262] After the second blockchain network element broadcasts Message 9, some or all of the blockchain network elements in the blockchain system perform a consensus verification process. For the consensus verification process, reference can be made to Figure 4 the embodiments shown. For example, the fourth blockchain network element is an inspection node, and the fourth blockchain network element and Figure 4 the third blockchain network element in the embodiments shown may be the same blockchain network element or different blockchain network elements.

[0263] If the fourth blockchain network element successfully verifies the received confirmation request, the fourth blockchain network element may generate a new block in the second blockchain it maintains. For example, the generated new block is called the second block. The fourth blockchain network element may store the content information of the second block in the second block. The content information of the second block may include, for example, the identification information of the second block and the information indicating the second roaming permission information. Among them, the information indicating the second roaming permission information may be described in the form of the identification information of the first block. If the second blockchain network element determines the information of multiple blocks according to the second roaming permission information, then the content information of the second block may include the identification information of these multiple blocks, and the first block is included in these multiple blocks. The identification information of the second block may indicate the second block. For example, the identification information of the second block includes the identification of the second blockchain and the identification of the second block in the second blockchain. Optionally, the content information of the second block may further include one or more of the following: the public key of the UE, the identification of the home network, or the identification of the UE.

[0264] S7023. The fourth blockchain network element sends Message 10.

[0265] Correspondingly, some or all blockchain network elements in the blockchain system receive Message 10.

[0266] The fourth blockchain network element may broadcast Message 10 in the blockchain system, so that some or all blockchain network elements in the blockchain system can receive the Message 10. Figure 7 Taking the first blockchain network element and the second blockchain network element both receiving Message 10 as an example. Message 10 may also be called the second block creation response message, and Message 10 may indicate that the second block is successfully created. For example, Message 10 includes the content information of the second block. That is to say, the fourth blockchain network element may broadcast the corresponding information of the newly created second block.

[0267] Through the above process, the second blockchain network element publishes the second roaming permission information to the blockchain system, so that all blockchain network elements in the blockchain system can obtain the second roaming permission information.

[0268] S706. The second blockchain network element indicates to the home network that the second block is successfully created.

[0269] Correspondingly, the second core network device receives the indication that the second block is successfully created from the second blockchain network element.

[0270] Exemplarily, the second blockchain network element sends the identification information of the second block and the second roaming permission information to the home network. Correspondingly, the second core network device receives the identification information of the second block and the second roaming permission information from the second blockchain network element.

[0271] As a possible implementation, the second roaming permission information sent by the second blockchain network element to the home network is an indication information indicating the second roaming permission information. For example, the identification information of the first block can be used as the indication information indicating the second roaming permission information and sent to the home network. Optionally, if the second blockchain network element determines multiple blocks storing the first roaming permission information based on the second roaming permission information of the UE, the second blockchain network element may send the identification information of these multiple blocks to the home network, and the first block is included in these multiple blocks. Optionally, the second blockchain network element may also send the public key of the visited network and / or the identification of the visited network to the home network. The public key of the visited network and / or the identification of the visited network are stored in the first block, and the second blockchain network element can determine the content stored in the first block after determining the identification information of the first block.

[0272] S707. The home network sends Message 11 to the UE.

[0273] Correspondingly, the UE receives Message 11 from the home network.

[0274] Message 11 may include the second roaming permission information and the identification information of the second block, indicating the roaming permission information obtained by the UE. Optionally, the home network may also send the public key of the visited network and / or the identification of the visited network to the UE.

[0275] The UE determines the second roaming permission information, so that when the UE performs roaming, it can clearly know what permissions the UE can specifically have. And in Figure 4 the embodiment shown, it is introduced that when the UE requests roaming in the visited network, it can send Message 4 to the visited network. Message 4 may include the identification information of the second block. It can be understood that the UE obtains the identification information of the second block through S707, so that when requesting roaming in the visited network, it can send the identification information of the second block to the visited network.

[0276] S708. The first blockchain network element establishes a first mapping table.

[0277] After receiving Message 10, the first blockchain network element may record the second block, such as recording the content information of the second block, etc.

[0278] In addition, after receiving Message 10, the first blockchain network element can determine whether the home network is within the roaming permission range of the visited network. If the home network is within the roaming permission range of the visited network, the first blockchain network element may establish a first mapping table, and if the home network is not within the roaming permission range of the visited network, the first blockchain network element does not need to establish a first mapping table.

[0279] As an alternative implementation for the first blockchain network element to determine whether the home network is within the roaming authority of the visited network, the first blockchain network element may query Figure 4 the second mapping table described in the embodiment shown. If the second mapping table includes the identification information of the first block, it indicates that the home network is within the roaming authority of the visited network. If the second mapping table does not include the identification information of the first block, it indicates that the home network is not within the roaming authority of the visited network. Alternatively, as another alternative implementation for the first blockchain network element to determine whether the home network is within the roaming authority of the visited network, the first blockchain network element may query the content stored in the first block according to the identification information of the first block to obtain the first roaming authority information stored in the first block. Then, the first blockchain network element may determine whether the home network is within the roaming authority of the visited network according to the first roaming authority information. For example, if the first roaming authority information includes the identification of the home network, it indicates that the UEs in the home network can roam within the visited network. If the first roaming authority information does not include the identification of the home network, it indicates that the UEs in the home network cannot roam within the visited network.

[0280] The first mapping table may include the identification information of the second block. In this case, if the first blockchain network element needs to obtain the content stored in the second block, it may query the content information of the second block recorded. Alternatively, the first mapping table may include the content information of the second block. In this case, the first mapping table includes the content stored in the second block, and the first blockchain network element can obtain the content stored in the second block without querying the second block, reducing the process of querying blocks and improving the query efficiency. Optionally, the first mapping table may also include the ID of the UE. As an example, the first mapping table may include the ID of the UE, the identification of the second block, the public key of the UE, and the identification information of the first block.

[0281] For example, Figure 7 the process of creating the second block can also be more vividly represented by Figure 8 to indicate. Figure 8 In which the cloud shape represents the blockchain system, and the squares represented by A1, B1, C1, C2, D1, etc. are multiple blocks in a blockchain. For example, this blockchain is the second blockchain, and the second blockchain may store the first roaming authority information of the UE. Figure 8 Networks A, B, C, and D in represent four different networks. For example, network C is the home network of the UE. Figure 8 The consensus verification (or reaching consensus) process represented in the first blockchain refers to the consensus verification mechanism. When the UE has a roaming requirement, the core network device within the home network ( Figure 8The core network device in C) sends information such as the public key of the UE to the blockchain network element, and the blockchain network element stores the information such as the public key of the UE in the blockchain, for example, stores it in a newly created second block.

[0282] Figure 7 In the illustrated embodiment, S7012 to S7023, S703, S705, S707, S708, etc. are all optional steps, which are Figure 7 indicated by a dotted line in.

[0283] Through the solution provided by the embodiments of the present application, the roaming permission information of the UE authorized by the home network is stored in the blockchain. Thus, during the process of the UE accessing from the visited network, the visited network can obtain the roaming permission information of the UE through the blockchain, and can also obtain information such as the public key of the UE, so as to implement access control for the UE, such as access authentication and / or authorization, without establishing pairwise roaming connections between the home network and the visited network to obtain this information, which simplifies the roaming architecture and also simplifies the roaming access process of the UE.

[0284] The roaming permission of the UE within the visited network may be updated, which may involve the possible need to create a new block to update the roaming permission of the UE. For this reason, the embodiments of the present application provide a fourth roaming access method to introduce the update process of the roaming permission of the UE. In the embodiments of the present application, the home network may be a second core network device within the home network, or an access network device within the home network, or other network elements within the home network; the visited network may be a first core network device within the visited network, or an access network device within the visited network, or other network elements within the visited network. Please refer to Figure 9 , which is the flowchart of this method. For example, Figure 9 the illustrated embodiment occurs after Figure 7 the illustrated embodiment.

[0285] S901. The home network sends message 12 to the second blockchain network element.

[0286] Correspondingly, the second blockchain network element receives message 12 from the home network. Message 12 may also be referred to as the second message. Message 12 may request to update the roaming permission of the UE.

[0287] The home network can trigger an update to the roaming permissions of the UE. For example, the first roaming permission information includes roaming permission information 1 and roaming permission information 2 granted by the visited network to the home network. The home network previously granted roaming permission information 1 to the UE, and the home network can trigger the granting of roaming permission information 2 to the UE, and no longer grant roaming permission information 1 to the UE. When triggering an update to the roaming permissions of the UE, the home network can send message 12 to the second blockchain network element. For example, message 12 may include the identification information of the second block and the updated roaming permission information of the UE, such as the third roaming permission information. The roaming permission indicated by the third roaming permission information is the updated roaming permission of the UE authorized by the home network in the visited network. The third roaming permission information is the complete set or subset of the first roaming permission information, and the third roaming permission information is different from the second roaming permission information.

[0288] Optionally, message 12 may further include the public key of the UE and / or the ID of the UE. Exemplarily, if the UE is currently within the scope of the home network, message 12 may further include the new public key of the UE and / or the ID of the UE; and if the UE is currently not within the scope of the home network, for example, the UE has roamed to the visited network, then message 12 may include the old public key of the UE and / or the ID of the UE. As introduced above, different roaming permissions may correspond to different keys. Since the roaming permissions of the UE have been updated, the UE may also generate new keys for the updated roaming permissions. If the UE is currently still within the scope of the home network, then the new public key of the UE is the public key generated by the UE for the third roaming permission information, and the old public key of the UE is the public key generated by the UE for the second roaming permission information. And if the UE has roamed to the visited network, then although the roaming permissions have been updated, the UE cannot obtain the third roaming permission information and cannot generate the key corresponding to the third roaming permission information. Therefore, message 12 may continue to include the old public key of the UE. Alternatively, for the UE, it is also possible that all the roaming permission information granted by the home network corresponding to the visited network corresponds to the same set of public and private keys. Then, even if the roaming permission information of the UE is updated, the UE does not need to generate new public and private keys. Then, what message 12 includes can be the old public key of the UE and / or the ID of the UE.

[0289] As a possible implementation manner, before S901, the home network obtains the public key of the UE corresponding to the third roaming permission information from the UE.

[0290] The identification information of the second block can be referred to Figure 4 In the introduction of the embodiments shown, the content included in the third roaming permission information is the same as Figure 4The content included in the first roaming permission information described in the illustrated embodiment is similar, except that the included parameters or the values of the parameters may be different. Therefore, reference can be made to Figure 4 the introduction of the illustrated embodiment.

[0291] S902. The second blockchain network element sends Message 13.

[0292] Correspondingly, some or all of the blockchain network elements in the blockchain system receive Message 13.

[0293] For example, the second blockchain network element broadcasts Message 13 in the blockchain system. Therefore, some or all of the blockchain network elements in the blockchain system can receive Message 13. Figure 7 Taking the first blockchain network element and the second blockchain network element both receiving Message 13 as an example. Exemplarily, Message 13 can also be referred to as the third block creation request message. Since the roaming permission of the UE needs to be updated, a new block needs to be created. Therefore, Message 13 can request to create a block.

[0294] For example, Message 13 includes the identification information of the second block and the third roaming permission information. Optionally, Message 13 may further include one or more of the following: the new public key of the UE (or, the old public key of the UE. It depends on the content included in Message 12), the identification of the home network, or the ID of the UE. Among them, the third roaming permission information can be described by the identification information of the fifth block. The fifth block stores the roaming permission information of the visited network corresponding to the third roaming permission information. The second blockchain network element can determine the identification information of the fifth block according to the third roaming permission information. For example, the roaming permissions granted by the visited network to the UE's home network include roaming permission information 1 and roaming permission information 2. The UE originally applied roaming permission information 1, and roaming permission information 1 is stored in the first block. The identification information of the first block can be stored in the second block. Now the UE's roaming permission is updated to roaming permission information 2, and roaming permission information 2 may still be stored in the first block. Then the identification information of the first block can be stored in the newly created block; or, the permissions corresponding to roaming permission information 2 may also be stored in other blocks, such as stored in the fifth block. Then the identification information of the fifth block can be stored in the newly created block. Storing different roaming permission information in different blocks can avoid confusion between roaming permissions and is more conducive to management. Therefore, in the embodiment of the present application, taking roaming permission information 2 stored in the fifth block as an example, Message 13 may include the identification information of the fifth block. In addition, the fifth block can also store the public key corresponding to the roaming permission of the visited network.

[0295] S903. The fifth blockchain network element creates the third block. The third block belongs to the second blockchain, and the second blockchain is also maintained in the fifth blockchain network element.

[0296] After the second blockchain network element broadcasts message 13, some or all of the blockchain network elements in the blockchain system perform a consensus verification process. For the consensus verification process, reference can be made to Figure 4 the embodiments shown. For example, the fifth blockchain network element is an inspection node. The fifth blockchain network element and Figure 6 the third blockchain network element in the embodiments shown can be the same blockchain network element or different blockchain network elements; the fifth blockchain network element and Figure 7 the fourth blockchain network element in the embodiments shown can be the same blockchain network element or different blockchain network elements.

[0297] If the fifth blockchain network element successfully verifies the received confirmation request, the fifth blockchain network element can generate a new block in the second blockchain it maintains. For example, the generated new block is called the third block. The fifth blockchain network element can store the content information of the third block in the third block. The content information of the third block includes, for example, the identification information of the third block, the new public key of the UE (or, the old public key of the UE), and the identification information of the second block. Optionally, the content information of the third block can further include one or more of the following: the second indication information, the identification of the visited network, or the ID of the UE. The identification information of the third block can indicate the third block. For example, the identification information of the third block includes the identification of the third block and the identification of the third block within the second blockchain. The second indication information can indicate the third roaming permission information. For example, the second indication information includes the identification information of the fifth block, and the fifth block stores the third roaming permission information.

[0298] S904. The fifth blockchain network element sends message 14.

[0299] Correspondingly, some or all of the blockchain network elements in the blockchain system receive message 14. For example, the fifth blockchain network element can broadcast message 14 within the blockchain system, and then some or all of the blockchain network elements in the blockchain system can receive this message 14. Figure 9 Taking the first blockchain network element and the second blockchain network element both receiving message 14 as an example. For example, message 14 can also be called the third block creation response message. Message 14 can include the content information of the third block. That is to say, the fifth blockchain network element can broadcast the corresponding information of the newly created third block.

[0300] S905. The second blockchain network element sends a response message to the home network for message 12.

[0301] Correspondingly, the home network receives the response message for message 12 from the second blockchain network element.

[0302] The response message of Message 12 may indicate that the roaming permission of the UE has been successfully updated. For example, the response message of Message 12 includes the identification information of the third block, the identification information of the second block, and the third roaming permission information. Optionally, the second blockchain network element may also send one or more of the following to the home network: the new public key of the visited network, the ID of the UE, or the identification of the visited network.

[0303] S906. The home network sends the third roaming permission information and the identification information of the third block to the UE.

[0304] Correspondingly, the UE receives the third roaming permission information and the identification information of the third block from the home network.

[0305] Optionally, the home network may also send the new public key of the visited network to the UE.

[0306] If the UE is located in the home network, the UE can receive this information from the home network; while if the UE is located in the visited network and not in the home network, the UE may not be able to receive this information from the home network. Figure 9 Take this as an example.

[0307] S907. The first blockchain network element updates the first mapping table.

[0308] Of course, after receiving Message 14, the first blockchain network element may also record the third block, for example, record the content information of the third block.

[0309] In addition, after receiving Message 14, the first blockchain network element may update the first mapping table. For example, the updated first mapping table may include the correspondence between the identification information of the second block and the identification information of the third block. In this case, if the first blockchain network element needs to obtain the content stored in the second block (or, the third block), it can query the content of the second block (or, the third block); or, the updated first mapping table may include the mapping relationship between the identification information of the second block and the content information of the third block. In this case, the updated first mapping table includes the content stored in the third block, and the first blockchain network element can obtain the content stored in the corresponding block without querying the block, reducing the process of querying the block and improving the query efficiency. As an example, the updated first mapping table may include the ID of the UE, the identification of the second block, the identification of the third block, the new public key (or, the old public key) of the UE, and the identification information of the fifth block.

[0310] Figure 9 The shown embodiments mainly update the roaming permission of the UE and involve creating a new block (the third block). Therefore, S901~S902, S905~S907 can all be regarded as optional steps. Figure 9It is represented by a dashed line in the figure. Alternatively, it can also be considered that Figure 9 The illustrated embodiment is an optional embodiment, that is to say, any step in this embodiment is an optional step.

[0311] Through the above process, the roaming permission of the UE is updated, and a third block is newly created to store information such as the key of the UE corresponding to the third roaming permission information, so that the visited network can use the third roaming permission to authorize the UE and authenticate the UE using the key corresponding to the third roaming permission, etc. Thus, even if the roaming permission of the UE is updated, the corresponding block can be updated in time, and the blockchain network element can authenticate and / or authorize the UE based on the updated information, without establishing a roaming connection between the home network and the visited network to obtain this information, simplifying the roaming architecture and the roaming access process of the UE.

[0312] In addition, in Figure 9 the S906 of the illustrated embodiment introduces that although the roaming permission of the UE is updated, the UE may not be aware of the update situation. Next, the fifth roaming access method is provided in the embodiments of the present application. Through this method, it is introduced how to realize the registration in the visited network for a UE that is not aware of the update situation when the roaming permission of the UE is updated. In the embodiments of the present application, the home network can be the second core network device in the home network, or the access network device in the home network, or other network elements in the home network; the visited network can be the first core network device in the visited network, or the access network device in the visited network, or other network elements in the visited network. Please refer to Figure 10 , which is the flowchart of this method.

[0313] S1001. The UE roams to the visited network and registers in the visited network. For example, the UE can send message 15 to the visited network. Correspondingly, the visited network can receive message 15 from the UE. Message 15 can also be called a registration request, and this registration request can be used to request access to the visited network.

[0314] Figure 4 The roaming registration process of the UE has been introduced in the illustrated embodiment. For example Figure 4 the illustrated embodiment is the roaming registration process performed without executing Figure 9 the illustrated embodiment. Figure 10 The illustrated embodiment is applicable to the following scenario: after executing Figure 9 the illustrated embodiment, and when the UE has not received the third roaming permission information yet, when the UE performs roaming registration from the visited network, it can execute Figure 10 the illustrated embodiment. Among them, before the UE executes Figure 10 the illustrated embodiment, it may have executed Figure 4In the illustrated embodiment, the UE later ends roaming from the visited network. For example, after executing Figure 4 the illustrated embodiment, Figure 9 the process of the illustrated embodiment occurs. Then, if the UE wants to roam in the visited network again, the embodiment shown in Figure 10 can be executed. Alternatively, before the UE executes Figure 10 the illustrated embodiment, it does not execute Figure 4 the illustrated embodiment.

[0315] For more information about S1001, reference can be made to Figure 4 S404 in the illustrated embodiment. For example, the content included in message 15 can be referred to the introduction of message 4.

[0316] S1002. The visited network sends message 16 to the first blockchain network element.

[0317] Correspondingly, the first blockchain network element receives message 16 from the visited network. The visited network can query the registration information of the UE. However, the UE is registered in its home network and not in the visited network of the UE. Therefore, the visited network cannot query the registration information of the UE. Then the visited network can send message 16 to the first blockchain network element. The first blockchain network element stores information for authenticating and / or authorizing the UE. Then the first blockchain network element can authenticate and / or authorize the UE. For example, message 16 includes the identification information of the second block. Optionally, the UE can send signature information (such as the so-called first signature information) encrypted with the private key of the UE (the old private key corresponding to the old public key of the UE) to the visited network in message 15. Then message 16 can also include the first signature information and the first verification information. Additionally optionally, message 16 can also include the identification information of the first block. For more information about S1002, reference can be made to Figure 4 S404 in the illustrated embodiment. For example, the content included in message 16 can be referred to the introduction of message 5.

[0318] It can be seen that although the third block has been created in the Figure 9 illustrated embodiment, for example, when the UE is in the visited network and does not receive content such as the identification information of the third block from the home network (such as Figure 9 S906 in the illustrated embodiment), therefore, when the UE requests roaming, the identification information of the second block is still sent to the visited network instead of the identification information of the third block.

[0319] S1003. The first blockchain network element authenticates the UE based on the old public key of the UE.

[0320] At this time, the first mapping table maintained by the first blockchain network element is updated (reference can be made to Figure 9In the case of the embodiment shown), the first blockchain network element queries the content of the second block according to the identification information of the second block to obtain the old public key of the UE. The first blockchain network element can authenticate the UE according to the old public key of the UE and the first authentication information. For the authentication process, reference can be made to Figure 4 S404 in the embodiment shown.

[0321] If the first blockchain network element successfully authenticates the UE, the first blockchain network element can obtain the private key of the visited network according to the identification information of the first block (the private key corresponding to the second roaming permission information is obtained at this time), and use the private key of the visited network to encrypt the second authentication information (or encrypt the digest of the second authentication information using the private key of the visited network) to obtain the signature information encrypted with the private key of the visited network (for example, called the second signature information). And the first blockchain network element can send the second signature information and the second authentication information to the first core network device for the UE to authenticate the visited network. For more content about this process, reference can also be made to Figure 4 the embodiment shown.

[0322] S1004. The first blockchain network element sends Message 17 to the visited network.

[0323] Correspondingly, the visited network receives Message 17 from the first blockchain network element. Message 17 can indicate the authentication result of the UE. For example, the authentication result indicated by Message 17 is called the second authentication result, and the second authentication result is authentication success or authentication failure.

[0324] If the second authentication result is authentication success, in addition to indicating the second authentication result, Message 17 can also include the second roaming permission information stored in the first block. Optionally, if the second authentication result is authentication success, Message 17 can also include the second signature information and the second authentication information.

[0325] For more content about S1004, reference can also be made to Figure 4 S406 in the embodiment shown. For example, the content included in Message 17 can be referred to the introduction of Message 6. When referring to S406, "the first authentication result" can be replaced with "the second authentication result".

[0326] S1005. The visited network sends the second signature information and the second authentication information to the UE.

[0327] Correspondingly, the UE receives the second signature information and the second authentication information from the visited network.

[0328] For more content about S1005, reference can be made to Figure 4 S409 in the embodiment shown. Among them, S1005 is an optional step.

[0329] S1006. The UE authenticates the visited network according to the second signature information and the second verification information.

[0330] For more content about S1006, reference can be made to Figure 4 S410 in the embodiment shown.

[0331] S1007. The visited network controls the access of the UE in the visited network according to the second roaming permission information. The second roaming permission information is, for example, received by the visited network through message 17 in S1004. For example, the first core network device in the visited network controls the access of the UE in the visited network according to the second roaming permission information, or alternatively, it can also be that the access network device in the visited network controls the access of the UE in the visited network according to the second roaming permission information.

[0332] The second roaming permission information here is still the roaming permission information of the visited network before the UE updates, that is, the roaming permission information of the visited network stored in the first block. That is to say, since the UE is not aware that the roaming permission has been updated, the UE requests the original roaming permission, so the visited network can continue to control the access of the UE in the visited network according to the original roaming permission.

[0333] For more content about S1007, reference can be made to Figure 4 S406 shown.

[0334] S1008. The visited network and the UE continue to execute the registration process.

[0335] S1008 can be referred to Figure 4 S411 in the embodiment shown. If the UE fails to authenticate the visited network, then S1008 does not need to be executed, the process ends, and the UE cannot roam in the visited network.

[0336] S1009. The first blockchain network element sends the third roaming permission information to the visited network.

[0337] Correspondingly, the visited network receives the third roaming permission information from the first blockchain network element.

[0338] If the UE has accessed the visited network (for example, the execution result of S1008 is that the UE is successfully registered in the visited network, or the first blockchain network element receives S1002), and the first blockchain network element discovers that the roaming permission information of the UE has been updated (for example, the first blockchain network element determines that the first mapping table has been updated. Specifically, for example, after the first blockchain network element receives message 16 described in S1002, it can query the updated first mapping table (the updated first mapping table can be referred to Figure 9In the S907) of the illustrated embodiment, if it is determined that the third block has been created, and it is determined that the roaming permission information of the UE has been updated, then the first blockchain network element may execute S1009, that is, the first blockchain network element may send the third roaming permission information to the visited network. Optionally, the first blockchain network element may also send the identifier of the UE to the visited network, so that the visited network can identify the UE corresponding to the third roaming permission information.

[0339] S1009 may occur after S1008, or S1009 may also occur before S1008. For example, in one way, after the first blockchain network element sends message 17 to the visited network, since it is determined that the roaming permission information of the UE has been updated, S1009 may be executed. Or, S1009 and S1004 may be combined into one message.

[0340] S1010: The visited network sends the third roaming permission information to the UE.

[0341] Correspondingly, the UE receives the third roaming permission information from the visited network.

[0342] For example, the visited network may initiate a UE registration update process, or initiate a UE deregistration process, etc., to send the third roaming permission information to the UE. In Figure 9 In S906 of the illustrated embodiment, the UE may not receive the third roaming permission information from the second core network device, while in S1010, the UE can obtain the third roaming permission information from the visited network. The UE thus obtains updated roaming permission information. If the UE roams from the visited network this time and then roams to the visited network next time, it can request to use the third roaming permission information.

[0343] If S1009 occurs after S1008, then S1010 may be executed after S1009. Or, if S1009 occurs before S1008, then S1010 may be executed after S1008, that is, after the UE successfully registers to the visited network, the visited network may send the third roaming permission information to the UE; or, if S1009 occurs before S1008, then S1010 may be executed during the execution of S1008, or it can be considered that S1008 and S1010 can be combined, that is, the visited network can send the third roaming permission information to the UE during the registration process of the UE. For example, when the visited network sends a registration success message to the UE, it can carry the third roaming permission information in the registration success message and send it to the UE.

[0344] Figure 10The illustrated embodiments mainly introduce the roaming authorization of the UE and the process of updating the roaming permission information for the UE. Therefore, S1001 to S1006 and S1008 therein can all be regarded as optional steps, which are represented by dashed lines in Figure 10 . Alternatively, it can also be considered that Figure 10 the illustrated embodiment is an optional embodiment, that is to say, any step in this embodiment is an optional step.

[0345] In the embodiments of the present application, although the UE still sends the identification information of the second block rather than the identification information of the third block to the visited network when requesting roaming, since the updated first mapping table stores the mapping relationship between the identification information of the second block and the identification information of the third block, the first blockchain network element can still index to the third block, thereby completing the access control for the UE, such as access authentication and / or authorization, etc.

[0346] It is worth noting that in the embodiments of the present application, asymmetric encryption algorithms are used for authentication between the UE and the visited network. Of course, the embodiments of the present application are not limited to this, and symmetric encryption algorithms can also be used to replace the asymmetric encryption algorithms for authentication.

[0347] Figure 11 The structural schematic diagram of a communication device provided by the embodiments of the present application is given. The communication device 1100 may be Figure 4 the communication device or the chip system of the communication device described in the illustrated embodiment Figure 6 shown, Figure 7 the illustrated embodiment Figure 9 shown, Figure 10 the communication device or the chip system of the communication device described in the illustrated embodiment, for implementing the method corresponding to the communication device in the above method embodiments. Alternatively, the communication device may also be Figure 4 the communication device or the chip system of the communication device described in the illustrated embodiment Figure 6 shown, Figure 7 the illustrated embodiment Figure 9 shown, Figure 10 the chip system of the communication device described in the illustrated embodiment, for implementing the method corresponding to the communication device in the above method embodiments. The communication device includes, for example Figure 4 the communication device or the chip system of the communication device described in the illustrated embodiment Figure 6 shown, Figure 7 the illustrated embodiment Figure 9 shown, Figure 10 the first blockchain network element, the second blockchain network element, the first core network device, the second core network device or the UE described in the illustrated embodiment, or one or more of them. The specific functions can be referred to the descriptions in the above method embodiments.

[0348] The communication device 1100 includes one or more processors 1101. The processor 1101 can also be referred to as a processing unit and can implement certain control functions. The processor 1101 can be a general-purpose processor or a dedicated processor, etc. For example, it includes: a baseband processor, a central processor, etc. The baseband processor can be used to process communication protocols and communication data. The central processor can be used to control the communication device 1100, execute software programs, and / or process data. Different processors can be independent devices or can be provided in one or more processing circuits. For example, they can be integrated on one or more application-specific integrated circuits.

[0349] Optionally, the communication device 1100 includes one or more memories 1102 for storing instructions 1104, and the instructions 1104 can be run on the processor, enabling the communication device 1100 to execute the methods described in the above method embodiments. Optionally, data can also be stored in the memory 1102. The processor and the memory can be provided separately or integrated together.

[0350] Optionally, the communication device 1100 can include instructions 1103 (sometimes also referred to as code or program), and the instructions 1103 can be run on the processor, enabling the communication device 1100 to execute the methods described in the above embodiments. Data can be stored in the processor 1101.

[0351] Optionally, the communication device 1100 can further include a transceiver 1105 and an antenna 1106. The transceiver 1105 can be referred to as a transceiver unit, transceiver, transceiver circuit, transceiver, input / output interface, etc., and is used to implement the transceiver function of the communication device 1100 through the antenna 1106.

[0352] Optionally, the communication device 1100 can further include one or more of the following components: a wireless communication module, an audio module, an external memory interface, an internal memory, a universal serial bus (USB) interface, a power management module, an antenna, a speaker, a microphone, an input / output module, a sensor module, a motor, a camera, or a display screen, etc. It can be understood that in some embodiments, the communication device 1100 can include more or fewer components, or some components are integrated, or some components are split. These components can be implemented by hardware, software, or a combination of software and hardware.

[0353] In the embodiments of the present application, the processor 1101 and the transceiver 1105 described may be implemented on an integrated circuit (IC), an analog IC, a radio frequency integrated circuit (RFID), a mixed-signal IC, an application specific integrated circuit (ASIC), a printed circuit board (PCB), or an electronic device, etc. To implement the communication device described herein, it may be an independent device (e.g., an independent integrated circuit, a mobile phone, etc.), or it may be a part of a larger device (e.g., a module or a system-on-chip that can be embedded in other devices, etc.), or it may be a larger device that includes the corresponding device (e.g., a blockchain network element or a core network device, etc.).

[0354] Embodiments of the present application provide a terminal device, which can be used in each of the foregoing embodiments for convenience of description, this terminal device is referred to as a UE. The terminal device includes means, units, and / or circuits corresponding to the UE functions described in the embodiments shown in Figure 4 the embodiments shown, Figure 6 the embodiments shown, Figure 7 the embodiments shown, Figure 9 the embodiments shown or Figure 10 the embodiments shown. For example, the terminal device includes a transceiver module for supporting the terminal device to implement the transceiver function, and a processing module for supporting the terminal device to process signals.

[0355] Figure 12 FIG. shows a schematic structural diagram of a terminal device provided by an embodiment of the present application.

[0356] The terminal device 1200 is applicable to the architecture shown in any one of the drawings in Figure 3 , Figure 5 or Figure 8 . For ease of explanation, Figure 12 only the main components of the terminal device 1200 are shown. As shown in Figure 12 , the terminal device 1200 includes a processor, a memory, a control circuit, an antenna, and an input / output device. The processor is mainly used for processing communication protocols and communication data, and controlling the entire terminal device 1200, executing software programs, and processing the data of the software programs. The memory is mainly used for storing software programs and data. The control circuit is mainly used for the conversion between baseband signals and radio frequency signals and the processing of radio frequency signals. The antenna is mainly used for receiving and transmitting radio frequency signals in the form of electromagnetic waves. The input / output device, such as a touch screen, a display screen, a microphone, a keyboard, etc., is mainly used for receiving data input by the user and outputting data to the user.

[0357] Those skilled in the art can understand that, for ease of description, Figure 12 only one memory and one processor are shown. In some embodiments, the terminal device 1200 may include multiple processors and memories. The memory may also be referred to as a storage medium or a storage device, etc., and the embodiments of the present application do not limit this.

[0358] In one example, an antenna with transceiver function and a control circuit may be regarded as the transceiver unit 1210 of the terminal device 1200, and a processor with processing function may be regarded as the processing unit 1220 of the terminal device 1200. As Figure 12 shown, the terminal device 1200 includes a transceiver unit 1210 and a processing unit 1220. The transceiver unit may also be referred to as a transceiver, a transceiver machine, a transceiver device, etc. Optionally, the device in the transceiver unit 1210 for implementing the receiving function may be regarded as the receiving unit, and the device in the transceiver unit 1210 for implementing the sending function may be regarded as the sending unit, that is, the transceiver unit 1210 includes a receiving unit and a sending unit. Exemplarily, the receiving unit may also be referred to as a receiver, a receiver circuit, etc., and the sending unit may be referred to as a transmitter, a transmitter circuit, etc.

[0359] The embodiments of the present application also provide a network device, which can be used in the foregoing various embodiments. The network device includes means, units, and / or circuits for implementing the functions of the first blockchain network element described in the embodiments shown in Figure 4 the embodiments shown, Figure 6 the embodiments shown, Figure 7 the embodiments shown, Figure 9 the embodiments shown or Figure 10 the embodiments shown. Or, the network device includes means, units, and / or circuits for implementing the functions of the second blockchain network element described in the embodiments shown in Figure 4 the embodiments shown, Figure 6 the embodiments shown, Figure 7 the embodiments shown, Figure 9 the embodiments shown or Figure 10 the embodiments shown. Or, the network device includes means, units, and / or circuits for implementing the functions of the first core network device described in the embodiments shown in Figure 4 the embodiments shown, Figure 6 the embodiments shown, Figure 7 the embodiments shown, Figure 9 the embodiments shown or Figure 10 the embodiments shown. Or, the network device includes means, units, and / or circuits for implementing the functions of the first core network device described in the embodiments shown in Figure 4 the embodiments shown, Figure 6 the embodiments shown, Figure 7 the embodiments shown,Figure 9 the illustrated embodiment or Figure 10 means, units and / or circuits for the functions of the second core network device described in the illustrated embodiment.

[0360] Please refer to Figure 13 , which is a schematic diagram of the network device. For example, the network device is network device 1300. Network device 1300 is a software module or a chip system. The chip system can be composed of chips or can include chips and other discrete devices. For example, network device 1300 includes a transceiver unit 1302 and a processing unit 1301. The transceiver unit 1302 is used to support the first blockchain network element, the second blockchain network element, the first core network device or the second core network device to implement the transceiver function. The transceiver unit 1302 can also be referred to as a communication interface, a communication unit or an input / output interface, etc.; the processing unit 1301 is used to support the first blockchain network element, the second blockchain network element, the first core network device or the second core network device to process signals.

[0361] The division of functional units in the embodiments of the present application is illustrative, only a logical function division. In actual implementation, there may be other division methods. In addition, in the embodiments of the present application, each functional unit can be integrated in one processor, can also exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.

[0362] When several embodiments provided in the present application are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the embodiments of the present application. The aforementioned computer-readable storage medium can be any available medium that a computer can access. Taking this as an example but not limited to: the computer-readable medium can include a random access memory (RAM), a read-only memory (ROM), or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer.

[0363] The above is only the specific implementation manner of the present application, but the protection scope of the embodiments of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed in the embodiments of the present application can easily think of changes or substitutions, which should all be covered by the protection scope of the embodiments of the present application. Therefore, the protection scope of the embodiments of the present application should be subject to the protection scope of the claims.

Claims

1. A roaming access method, characterized in that, Including: Releasing first roaming permission information to a blockchain system, where the first roaming permission information includes roaming permission information for a visited network, and where the first roaming permission information is released by the visited network; Obtaining, from a blockchain stored in the blockchain system, second roaming permission information of a first terminal device, where the second roaming permission information is roaming permission information for the first terminal device authorized by a home network of the first terminal device in the visited network, the second roaming permission information indicates roaming permissions that the first terminal device can use within the visited network, and the second roaming permission information is a complete set or subset of the first roaming permission information; Sending the second roaming permission information to the visited network, where the second roaming permission information is used to control access of the first terminal device to the visited network.

2. The method according to claim 1, characterized in that, The first roaming permission information includes information indicating a home network of a terminal device permitted to roam in the visited network.

3. The method according to claim 2, characterized in that The first roaming permission information further includes one or more of the following information of the terminal device capable of roaming in the visited network: Service types permitted to be used, Network slices permitted to be used, 5G Quality of Service Indicator 5QI permitted to be used, or Regions permitted to be accessed.

4. The method according to any one of claims 1 to 3, characterized in that The method further includes: receiving, from the visited network, identification information of a second block stored in the blockchain system, where the second block stores information indicating the second roaming permission information; Obtaining the second roaming permission information of the terminal device from the blockchain system includes: obtaining the second roaming permission information from the blockchain system according to the identification information of the second block.

5. The method according to claim 4, characterized in that The second block further stores a key of the first terminal device, and the method further includes: Obtaining the key of the first terminal device from the blockchain system according to the identification information of the second block; Authenticating the first terminal device using the key of the first terminal device; Sending an authentication result of the first terminal device to the visited network.

6. The method according to claim 4, characterized in that The second block further stores a public key of the first terminal device, and the method further includes: Obtaining first signature information and first verification information, where the first signature information is signature information encrypted using a private key of the first terminal device; Obtaining the public key of the first terminal device from the blockchain system according to the identification information of the second block; Authenticating the first terminal device using the public key of the first terminal device, the first signature information, and the first verification information; Sending an authentication result of the first terminal device to the visited network.

7. The method according to claim 6, characterized in that, In the case where the authentication result is successful authentication, the method further includes: Sending second signature information and second verification information to the visited network, where the second signature information is signature information encrypted using a private key of the visited network, and the second signature information and the second verification information are used for the first terminal device to authenticate the visited network.

8. The method according to any one of claims 4 to 7, characterized in that, The issuing of the first roaming authority information to the blockchain system includes: Sending a first block creation request message to the blockchain system, where the first block creation request message is used to request creation of a first block, and the first block creation request message includes the first roaming authority information; A first block creation response message is received from the blockchain system, where the first block creation response message indicates that the first block is successfully created.

9. The method according to claim 8, characterized in that The first block creation request message further includes a public key of the visited network; The first building block response message also includes a public key of the visited network, and the public key of the visited network is used for the first terminal device to authenticate the visited network when roaming access from the visited network.

10. The method according to claim 8 or 9, characterized in that: The method further includes: receiving a first message from the visited network, the first message including the first roaming authority information; Publishing first roaming permission information to the blockchain system includes: publishing the first roaming permission information to the blockchain system in response to the first message.

11. The method according to any one of claims 4 to 10, characterized in that, The method further comprises: receiving a second block building response message from the blockchain system, the second block building response message including identification information of the second block, a public key of the first terminal device, and information indicating the second roaming authority information; The second block is recorded, where the second block also stores identification information of the second block.

12. A roaming access method, characterized in that, include: Acquire first roaming authority information from the blockchain system, where the first roaming authority information includes roaming authority information of a visited network, wherein the first roaming authority information is issued by the visited network; Publish second roaming permission information to the blockchain system, where the second roaming permission information is roaming permission information of the first terminal device in the visited network authorized by the home network of the first terminal device, where the second roaming permission information indicates roaming permission that the first terminal device can use in the visited network, and the second roaming permission information is the full set or a subset of the first roaming permission information, where the second roaming permission information is used to control access of the first terminal device to the visited network.

13. The method according to claim 12, wherein Release the second roaming permission information to the blockchain system, including: Sending a second block creation request message to the blockchain system, where the second block creation request message is used to request creation of a second block, where the second block is used to store information indicating the second roaming authority information; A second block creation response message is received from the blockchain system, wherein the second block creation response message indicates that the second block is successfully created.

14. The method according to claim 12 or 13, characterized in that, The second roaming authority information includes information for indicating a home network of the terminal device that is allowed to roam in the visited network.

15. The method according to claim 14, characterized in that, The second roaming permission information also includes one or more of the following information in the visited network for indicating the terminal device capable of roaming in the visited network: the type of service allowed, the network slice allowed, the 5G service quality identifier 5QI allowed, or the area allowed to be accessed.

16. The method according to claim 13, wherein The second block response message includes the identification information of the second block and the information indicating the second roaming permission information.

17. The method according to claim 16, wherein The method further includes: Receiving the second roaming permission information from the home network; Determining the identification information of the first block according to the second roaming permission information, where the first block stores the first roaming permission information.

18. The method according to claim 17, wherein The method further includes: Receiving the public key of the first terminal device from the home network, where the first public key of the first terminal device is used for the visited network to authenticate the first terminal device; Sending the public key of the first terminal device to the blockchain system.

19. The method according to claim 17 or 18, characterized in that, The method further includes: Sending the identification information of the second block and the second roaming permission information to the home network, where the identification information of the second block indicates the successful creation of the second block.

20. The method according to any one of claims 17 to 19, characterized in that, The method further includes: Receiving a first block creation message from the blockchain system, where the first block creation message includes the identification information of the first block and the first roaming permission information; Determining, according to the first roaming permission information, that the visited network is a network where the terminal device in the home network can roam; The blockchain network element of the home network establishes a third mapping table, where the third mapping table includes the mapping relationship between the identification information of the first block, the first roaming permission information, and the public key of the visited network.

21. A roaming access method, characterized in that Includes: The first terminal device sends the identification information of the second block to the visited network, where the identification information of the second block enables the visited network to obtain the second roaming permission information and control the access of the first terminal device in the visited network according to the second roaming permission information. The second roaming permission information is the roaming permission information of the first terminal device authorized by the home network of the first terminal device in the visited network. The second roaming permission information indicates the roaming permission that the first terminal device can use in the visited network, and the second roaming permission information is the whole set or subset of the first roaming permission information. The first roaming permission information includes the roaming permission information of the visited network, and the first roaming permission information is issued by the visited network.

22. The method according to claim 21, wherein The second roaming permission information includes the information used to indicate the home network of the terminal device allowed to roam in the visited network.

23. The method according to claim 22, characterized in that, The second roaming permission information further includes one or more of the following information of the terminal device capable of roaming in the visited network: the service type allowed to be used, the network slice allowed to be used, the 5G service quality identifier 5QI allowed to be used, or the area allowed to be accessed.

24. The method according to any one of claims 21 to 23, characterized in that The second block is used to store the information indicating the second roaming permission information.

25. The method according to any one of claims 21 to 24, characterized in that The method further includes: The first terminal device receives second signature information and second verification information from the visited network, where the second signature information is the signature information encrypted using the private key of the visited network; The first terminal device authenticates the visited network according to the public key of the visited network, the second signature information, and the second verification information.

26. The method according to claim 25, characterized in that, The method further includes: The first terminal device receives the public key of the visited network from the home network.

27. The method according to any one of claims 21 to 26, characterized in that, The method further includes: The first terminal device sends first signature information and first verification information to the visited network, where the first signature information is signature information encrypted using the private key of the terminal device, and the first signature information and the first verification information are used for authenticating the first terminal device.

28. The method according to claim 27, wherein The method further includes: The first terminal device sends the public key of the first terminal device to the home network, and the public key of the first terminal device is used by the visited network to authenticate the first terminal device.

29. The method according to any one of claims 21 to 28, characterized in that The method further includes: The first terminal device sends roaming permission information applied for by the first terminal device to the home network; The first terminal device receives the identification information of the second block from the home network, and the second block stores information indicating the second roaming permission information.

30. A communication device, characterized in that, Includes: A processor and a memory; The memory is used to store one or more computer programs, and the one or more computer programs include computer execution instructions. When the communication device runs, the processor executes the one or more computer programs stored in the memory, so that the communication device executes the method according to any one of claims 1 to 11.

31. A communication device, characterized in that, Includes: A processor and a memory; The memory is used to store one or more computer programs, and the one or more computer programs include computer execution instructions. When the communication device runs, the processor executes the one or more computer programs stored in the memory, so that the communication device executes the method according to any one of claims 12 to 20.

32. A communication device, characterized in that, Includes: A processor and a memory; The memory is used to store one or more computer programs, and the one or more computer programs include computer execution instructions. When the communication device runs, the processor executes the one or more computer programs stored in the memory, so that the communication device executes the method according to any one of claims 21 to 29.

33. A computer-readable storage medium, characterized in that, The computer-readable storage medium is used to store a computer program, and when the computer program runs on a computer, the computer executes the method according to any one of claims 1 to 29.

34. A computer program product, characterized in that, The computer program product includes a computer program, and when the computer program runs on a computer, the computer executes the method according to any one of claims 1 to 29.

35. A chip system, characterized in that, The chip system includes: A processor and an interface, and the processor is used to call and run instructions from the interface. When the processor executes the instructions, the method according to any one of claims 1 to 11 is implemented, or the method according to any one of claims 12 to 20 is implemented, or the method according to any one of claims 21 to 29 is implemented.

Citation Information

Patent Citations

  • Roaming management method based on blockchain and network access node

    CN111885586A