A method and apparatus for managing communications of a service
By leveraging the collaborative functions of cross-domain management and domain open capability control management, and based on tenant identification and authentication information, the problem of tenants being unable to access operator management services is solved, thereby achieving secure network management capabilities.
Patent Information
- Application Number
- CN202111158256.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-09-30
- Publication Date
- 2025-11-04
- Estimated Expiration
- 2041-09-30
AI Technical Summary
In existing technologies, tenants cannot effectively access the management services provided by operators, resulting in an inability to manage the network and posing data security risks.
By working together with cross-domain management and domain open capability control management functions, and based on tenant identification and authentication information, authorized management services are determined and provided, enabling two-stage authentication for both cross-domain management and domain open management functions to ensure data security.
This enables tenants to securely access the management services offered by the operator, thereby enhancing network management capabilities and data security.
Smart Images

Figure CN115883394B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of wireless communication technology, and in particular to a communication method and apparatus for managing services. Background Technology
[0002] Third-generation mobile communication technology (3 rd The Generation Partnership Project (GPP) proposed a service-based management architecture (SBMA). Management functions (MnFs) are the basic units that make up the SBMA architecture. An MnF is a logical functional unit that provides specific management functions, and the management capabilities provided by an MnF are called management services (MnS). An MnF can act as a management service producer (MnS producer), providing MnS to other MnFs. Similarly, an MnF can also act as a management service consumer (MnS consumer), invoking MnS provided by other MnFs.
[0003] Tenants such as vertical industry customers and slicing users have a need to jointly manage networks with operators. To meet these needs, operators need to open up network management capabilities to tenants. However, currently there are no methods for tenants to obtain open management services, therefore tenants cannot manage the network based on open management services. Summary of the Invention
[0004] This application provides a communication method and apparatus for management services, used to obtain management services opened by operators while satisfying information security requirements.
[0005] Firstly, a communication method for management services is provided. This method can be executed by a cross-domain management function or a chip with a similar cross-domain management function. In this method, the cross-domain management function receives a first message from a first management function for querying authorized management services. This first message includes the tenant's tenant identifier. Based on the tenant identifier, the cross-domain management function determines the management capability information open to the aforementioned tenant and sends the tenant identifier, authentication information, and authorized management service information to the first management function. Here, the management capability information indicates one or more management services, the authorized management service information indicates all or part of the management services within the one or more management services, and the authentication information indicates that the authorization of the management capability information is successful.
[0006] In a second aspect, a communication method for managing services is provided. The method can be performed by a first management function or a chip similar to the first management function. In the method, the first management function can send a first message to a cross-domain management function to query authorized management services. The first management function receives tenant identification, authentication information, and authorized management service information from the cross-domain management function.
[0007] Based on the first aspect and the second aspect, the cross-domain management function can determine management capability information open to the tenant based on the tenant identification, and authorize the management capability information. In this way, the first management function of the tenant can obtain the management services open by the operator, and thus can manage the network of the tenant.
[0008] In a third aspect, a communication method for managing services is provided. The method can be performed by a domain open capability control management function or a chip similar to the domain open capability control management function. In the method, the domain open capability control management function receives the identification of a third management function and first management service information from a cross-domain management function, and receives the identification of a first management function from a first management function. The domain open capability control management function authenticates the first management function according to the identification of the third management function and the identification of the first management function. When the authentication is passed, the domain open capability control management function provides the first management service to the first management function. The first management service information is information of all management services open to the tenant or information of part of the management services.
[0009] Based on the third aspect, when the domain open capability control management function receives a request for a first management service from the first management function, the first management function is authenticated by the information from the cross-domain management function, that is, two authentications of the cross-domain management function and the domain open management function can be implemented, and the security of the data information is improved.
[0010] In a fourth aspect, a communication method for managing services is provided. The method can be performed by the cross-domain management function of the first aspect and the first management function of the second aspect. In the method, the first management function sends a first message to the cross-domain management function to query authorized management services. The cross-domain management function determines management capability information open to the tenant based on the tenant identification, and sends the tenant identification, authentication information, and authorized management service information to the first management function.
[0011] In a fifth aspect, a communication method for managing a service is provided. The method can be performed by the cross-domain management function of the first aspect and the domain exposure capability control management function of the second aspect. The cross-domain management function sends an identification of a third management function and first management service information to the domain exposure capability control management function. The first management function sends an identification of the first management function to the domain exposure capability control management function. The first management function is authenticated by the domain exposure capability control management function according to the identification of the third management function and the identification of the first management function. When the authentication is passed, the domain exposure capability control management function provides the first management service indicated by the first management service information to the first management function.
[0012] In a sixth aspect, a communication apparatus is provided, comprising a processing unit and a transceiver unit.
[0013] The transceiver unit is configured to receive a first message from a first management function to query an authorized management service. The processing unit is configured to determine management capability information exposed to a tenant according to a tenant identification. The transceiver unit is further configured to send the tenant identification, authentication information and the authorized management service information to the first management function.
[0014] In a seventh aspect, a communication apparatus is provided, comprising a processing unit and a transceiver unit.
[0015] The processing unit is configured to generate a first message. The first message is used to query an authorized management service. The transceiver unit is configured to receive a tenant identification, authentication information and the authorized management service information from a cross-domain management function.
[0016] In an eighth aspect, a communication apparatus is provided, comprising a processing unit and a transceiver unit.
[0017] The transceiver unit is configured to receive an identification of a third management function and first management service information from a cross-domain management function. The first management service information is information of all management services exposed to a tenant or information of part of the management services. The transceiver unit is further configured to receive an identification of a first management function from a first management function. The processing unit is configured to authenticate the first management function according to the identification of the third management function and the identification of the first management function, and provide the first management service indicated by the first management service information to the first management function when the authentication is passed.
[0018] In a possible implementation form of the first aspect, the second aspect, the fourth aspect, the sixth aspect and the seventh aspect, the first message further comprises an identification of the first management function. The identification of the first management function can be used for message routing between the first management function and the cross-domain management function. The cross-domain management function can send the tenant identification, the authentication information and the authorized management service information to the first management function corresponding to the identification of the first management function according to the identification of the first management function.
[0019] In a possible implementation of the first aspect, the second aspect, the fourth aspect, the sixth aspect and the seventh aspect, the authorized management service information includes a management service type open to the tenant and a management service version open to the tenant.
[0020] In a possible implementation of the first aspect, the second aspect, the fourth aspect, the sixth aspect and the seventh aspect, the management service type includes one or more of a fault monitoring management service, a performance guarantee management service, a network configuration management service and a heartbeat management service.
[0021] In a possible implementation of the first aspect, the second aspect, the fourth aspect, the sixth aspect and the seventh aspect, the authorized management service information further includes a component type of the management service type; the component type includes at least one of an operation type, a network resource object and data information.
[0022] Based on the above scheme, the cross-domain management function can determine the management service type, the management service version and the component type of the management service type open to the authorized tenant based on the tenant identifier, so that the first management function manages the network of the tenant based on the management capability information.
[0023] In a possible implementation of the first aspect, the cross-domain management function indicates to the domain exposure capability control management function that a first management service is exposed. The first management service is part of the management service or all of the management service indicated by the management capability information. Optionally, the cross-domain management function can send first management service information to the domain exposure capability control management function. The first management service information indicates the first management service.
[0024] In a possible implementation of the first aspect, the cross-domain management function sends an identifier and authentication information of the first management function to the domain exposure capability control management function.
[0025] Based on the above scheme, the cross-domain management function can send the identifier and authentication information of the first management function to the domain exposure capability control management function that provides the management service indicated by the management capability information, so that the domain exposure capability control management function can provide the first management function with the management service.
[0026] In a possible implementation of the first aspect, the cross-domain management function requests the authorized management service from a second management function. The cross-domain management function receives a tenant identifier, authentication information and management capability information from the second management function.
[0027] Based on the above scheme, the cross-domain management function can acquire the management capability information open to the tenant and the authentication information of the tenant through the second management function, and determine the management capability information of the tenant and authenticate the tenant by the second management function.
[0028] In a possible implementation of the first aspect, the cross-domain management function sends an identifier of a domain open capability control management function to the first management function. The domain open capability control management function is configured to provide a first management service.
[0029] Based on the above scheme, the cross-domain management function can send the identifier of the domain open capability control management function providing the first management service to the first management function, so that the first management function can request the first management service from the domain open capability control management function, and the first management function can manage the network of the tenant.
[0030] In a possible implementation of the second aspect, the first management function can receive the identifier of the domain open capability control management function from the cross-domain management function. The first management function sends an identifier of the first management function to the domain open capability control management function, so that the domain open capability control management function authenticates the first management function. The domain open capability control management function is configured to provide the first management service. The first management service is part of the management service or all of the management service indicated by the authorized management service information.
[0031] In a possible implementation of the second aspect, the first management function sends the authentication information to the domain open capability control management function. The authentication information is configured to authenticate the first management function.
[0032] Optionally, the first management function can receive the identifier of the domain open capability control management function from the cross-domain management function. The first management function sends the identifier of the first management function and the authentication information to the domain open capability control management function. The domain open capability control management function is configured to provide the first management service. The first management service is part of the management service or all of the management service indicated by the authorized management service information. The authentication information is configured to authenticate the first management function. The identifier of the first management function is configured to route messages between the first management function and the domain open capability control management function.
[0033] In a possible implementation of the third aspect and the fifth aspect, the domain exposure capability control management function can receive first authentication information from the cross-domain management function, and receive second authentication information from the first management function. The second authentication information is used to indicate authorization of second management service information. The domain exposure capability control management function authenticates the first management function based on the second authentication information and the first authentication information. The first authentication information is used to indicate authorization of first management service information. The first management service is part of the management service indicated by the management capability information or all of the management service information. The second management service information is all of the management service information or part of the management service information exposed to the tenant. The first management service is the same as the second management service, or the first management service is a subset of the second management service.
[0034] Based on the above scheme, the domain exposure capability control management function can authenticate the authentication information from the first management function based on the authentication information from the cross-domain management function, and further improve the security of data information.
[0035] Optionally, the domain exposure capability control management function can receive the identity of the third management function, the first management service information, and the first authentication information from the cross-domain management function, and receive the identity of the first management function and the second authentication information from the first management function. The domain exposure capability control management function can authenticate the first authentication information through the second authentication information. When the authentication is passed, the domain exposure capability control management function can provide the first management service to the first management function. The identity from the first management function is used for message routing between the first management function and the domain exposure capability control management function.
[0036] In a possible implementation of the fourth aspect, the cross-domain management function can further send the identity of the domain exposure capability control management function for providing the first management service to the first management function.
[0037] In a possible implementation of the fourth aspect, the cross-domain management function sends a second message to the domain exposure capability control management function to indicate that the domain exposure capability control management function exposes the first management service.
[0038] In a possible implementation of the fourth aspect, the cross-domain management function sends the identity of the first management function to the domain exposure capability control management function, so that the domain exposure capability control management function authenticates the first management function based on the identity of the first management function. The first management function also sends the identity of the first management function to the domain exposure capability control management function.
[0039] In a possible implementation of the fourth aspect, the cross-domain management function sends authentication information to the domain exposure capability control management function, and the domain exposure capability control management function authenticates the first management function based on the authentication information. The first management function also sends authentication information to the domain exposure capability control management function.
[0040] In a possible implementation of the fifth aspect, the cross-domain management function sends first authentication information to the domain exposure capability control management function. The first management function sends second authentication information to the domain exposure capability control management function. The domain exposure capability control management function authenticates the first management function based on the second authentication information and the first authentication information. The first authentication information is used to indicate authorization of the first management service information, and the second authentication information is used to indicate authorization of the second management service information. The first management service information is the same as the second management service information, or the first management service information is a subset of the second management service information.
[0041] In a possible implementation of the sixth aspect, the transceiver is further configured to send a second message to the domain exposure capability control management function.
[0042] In a possible implementation of the sixth aspect, the transceiver is further configured to send an identifier of the first management function and authentication information to the domain exposure capability control management function.
[0043] In a possible implementation of the sixth aspect, the transceiver is further configured to send a third message to the second management function. The transceiver is further configured to receive a tenant identifier, authentication information, and management capability information from the second management function.
[0044] In a possible implementation of the sixth aspect, the transceiver is further configured to send an identifier of the domain exposure capability control management function to the first management function.
[0045] In a possible implementation of the seventh aspect, the transceiver is further configured to receive an identifier of the domain exposure capability control management function from the cross-domain management function. The transceiver is further configured to send an identifier of the first management function to the domain exposure capability control management function.
[0046] In a possible implementation of the seventh aspect, the transceiver is further configured to send authentication information to the domain exposure capability control management function.
[0047] In a possible implementation of the eighth aspect, the transceiver is further configured to receive first authentication information from the cross-domain management function. The transceiver is further configured to receive second authentication information from the first management function. The processing unit is specifically configured to authenticate the first management function based on the second authentication information and the first authentication information.
[0048] In a ninth aspect, a communication apparatus is provided, which comprises a processor and a memory coupled to the processor. The memory is configured to store a computer program or instructions. The processor is configured to execute the computer program or instructions to perform the method in any possible implementation of the aspects described above. The memory can be within the apparatus or outside the apparatus. The processor can be one or more processors.
[0049] In a tenth aspect, a communication apparatus is provided, which comprises a processor and an interface circuit. The interface circuit is configured to communicate with other apparatuses. The processor is configured to implement the method in any possible implementation of the aspects described above.
[0050] In an eleventh aspect, a communication apparatus is provided. The apparatus comprises a logic circuit and an input / output interface.
[0051] In one example, the input / output interface is configured to input a first message from a first management function. The logic circuit is configured to determine, according to a tenant identifier, management capability information open to the tenant. The input / output interface is further configured to output the tenant identifier, authentication information and authorized management service information to the first management function. For more details of the solution, please refer to the related description of the first aspect above.
[0052] In one example, the input / output interface is configured to input an identifier of a third management function and first management service information from the third management function of the cross-domain management function, and an identifier of the first management function from the first management function. The logic circuit is configured to authenticate the first management function according to the identifier of the third management function and the identifier of the first management function, and provide the first management service indicated by the first management service information to the first management function when the authentication is passed. For more details of the solution, please refer to the related description of the second aspect above.
[0053] In one example, the logic circuit is configured to generate a first message. The input / output interface is configured to output the first message to the cross-domain management function. The input / output interface is further configured to input a tenant identifier, authentication information and authorized management service information from the domain opening capability control management function. For more details of the solution, please refer to the related description of the third aspect above.
[0054] In a twelfth aspect, a chip system is provided, which comprises a processor configured to perform the method in any possible implementation of the aspects described above.
[0055] In a thirteenth aspect, a communication system is provided, which comprises the communication apparatus in the fifth aspect and the communication apparatus in the sixth aspect; or the communication system in the fifth aspect and the communication apparatus in the seventh aspect; or the communication apparatus in the fifth aspect, the communication apparatus in the sixth aspect and the communication apparatus in the seventh aspect.
[0056] In a fourteenth aspect, the present application also provides a computer program product, comprising computer-executable instructions that, when executed on a computer by a communication device, cause the method in any possible implementation of the aspects above to be performed.
[0057] In a fifteenth aspect, the present application also provides a computer-readable storage medium, which stores a computer program or instructions, and when the instructions are executed on a communication device, the method in any possible implementation of the aspects above is implemented. BRIEF DESCRIPTION OF DRAWINGS
[0058] Figure 1 Logical structure diagram for MnF;
[0059] Figure 2 Network management architecture diagram;
[0060] Figure 3 Management capability exposure scenario diagram;
[0061] Figure 4 One of the exemplary flowcharts of the communication method of the management service provided by the embodiment of the present application;
[0062] Figure 5 Tenant registration flowchart provided by the embodiment of the present application;
[0063] Figure 6 One of the exemplary flowcharts of the communication method of the management service provided by the embodiment of the present application;
[0064] Figure 7 One of the exemplary flowcharts of the communication method of the management service provided by the embodiment of the present application;
[0065] Figure 8 Schematic diagram of the communication device provided by the embodiment of the present application;
[0066] Figure 9 Schematic diagram of the electronic device provided by the embodiment of the present application. DETAILED DESCRIPTION
[0067] In order to facilitate understanding of the technical solutions provided by the embodiments of the present application, the following explains and describes the terms in the embodiments of the present application.
[0068] 1) Management Function (MnF), is a logical functional unit to implement specific management tasks or functions (such as parameter configuration of network or network performance data collection, etc.). In the 5G network management technology, a service-based SBMA architecture (Service based Management Architecture, service-based management architecture) is proposed. The basic component of the SBMA architecture is the management function. Referring to Figure 1 , the MnF can provide the management service (MnS) provided by the MnF to other MnF as a management service producer (MnS producer). Similarly, the MnF can also call the MnS provided by other MnF as a management service consumer (MnS consumer). The MnS is called based on the service-based interface between the MnF.
[0069] 2) tenant, represents a group of management service consumers. This group of consumers is related to the management capabilities allowed to access and use. Among them, a group of management service consumers can include one or more management service consumers.
[0070] 3) management capability, refers to the management service that the authorized management service consumer can use.
[0071] 4) management service, the interface service provided by the management function to the outside is called management service. The management service can include one or more of the alarm management service, the performance guarantee management service, the network configuration management service and the heartbeat management service. The alarm management service can include services such as querying alarm information, alarm notification or querying alarm sending times. The performance guarantee management service can include services such as creating performance data measurement tasks, data file preparation completion notification or flow data reporting. The network configuration management service can include services such as network parameter configuration, network parameter modification or query network configuration parameters. The heartbeat management service can include services such as heartbeat period notification, and the main function is to realize the health detection of the communication parties.
[0072] The management service includes component types, such as component type A (management service component type A), component type B (management service component type B) and component type C (management service component type C). Among them:
[0073] Management service component type A is network management operation and notification. The management operation can include configuration management operation (such as network configuration parameter modification or network configuration parameter query, etc.), performance management operation (such as performance measurement task creation or performance data reporting) and alarm management operation (such as alarm query or alarm clearing, etc.). The notification can include data file notification and managed object creation notification, etc. The data file notification is used for the notification of data file preparation completion. The managed object creation notification is used for the notification of managed object instance creation completion. The managed object refers to the object managed by the management function in the service-based management architecture. The managed object includes base station device, wireless cell or frequency point, etc.
[0074] Management service component type B refers to network resource model information. The network resource refers to network device (such as base station device, etc.), network function (such as wireless network control plane function, wireless network user plane function, etc.), wireless network resource (such as wireless network cell, frequency spectrum, physical resource block, etc.). The network resource model is the model obtained by modeling the above network resource based on the network resource model modeling method.
[0075] Management service component type C refers to corresponding performance data and alarm information. The performance data includes service delay, jitter, bit error rate, cell physical resource block (PRB) utilization or bandwidth, etc. The alarm information can include communication failure, processing error, environmental failure, device failure or operation invalidity, etc.
[0076] For the convenience of understanding the technical solutions provided by the embodiments of the present application, the technical solutions provided by the embodiments of the present application are explained and described below by means of the accompanying drawings.
[0077] Figure 2 The figure is a network management architecture schematic diagram. The functions of part of the network elements in the figure are briefly introduced and described below.
[0078] Among them, MnF#1…MnF#n, MnF#a…MnF#z refer to a plurality of different management functions responsible for specific management tasks or functions. For example, Figure 2The exposure governance management function (EGMF) is an MnF that implements the management of exposure control functions. Optionally, other MnFs that implement specific functions can also be defined, such as a management data analysis function (MDAF) or a data coordination and collection function (DCCF), and the present application does not make specific limitations.
[0079] The management functions within the cross domain management function (cross domain management) are management functions that implement cross-domain and cross-vendor network management, such as a network management system (NMS) of an operator.
[0080] The domain management function can include one or more MnFs, and a domain exposure governance management function (domain EGMF). The domain exposure governance management function is a management function that implements single-domain and single-vendor network element management, such as a radio access network (RAN) element management system (EMS) or a 5G core network (5G core) element management system (5G CORE EMS).
[0081] A shared operator refers to an operator that shares a network with a main operator in a network sharing scenario. The operation administration and maintenance (OAM) of the shared operator can perform operation and maintenance and management on the resources of the shared network.
[0082] A third party is a management function assigned to a tenant by an operator. The operation, administration, and maintenance of the third party can perform operation and maintenance and management on the network of the tenant.
[0083] Figure 2 The various management functions can communicate based on a service-oriented interface protocol such as the hypertext transfer protocol (HTTP), or can communicate based on a management communication interface protocol such as the simple object access protocol (SOAP).
[0084] The management capability exposed to the tenant in the management capability exposure technology is one or more of the above management services, or one or more operations of a certain management service (i.e., one or more component types A), or one or more network management resource information of a certain management service (i.e., one or more component types B), or component type C describes all or part of performance data, etc. That is, through the management capability exposure, the tenant can realize the ability to manage the network through the exposed management service. For example, the management operation on the network resource information described by the management service component type B (such as the configuration management on the network) can be realized through the exposed management service component type A. The performance data and alarm information described by the management service component type C and the like can also be obtained through the exposed management service component type A.
[0085] Currently, in the SBMA architecture, the EGMF provides the exposure control function of the management capability, that is, the EGMF can provide the function of controlling the exposure of the management capability, that is, the EGMF can control which management capability is exposed and can also decide whether to expose the management capability to the outside; the EGMF can also provide the exposure of the management capability to the outside (such as directly exposing the management data of the network through the EGMF). The cooperation relationship between the EGMF and the MnF is as shown in Figure 3
[0086] Among them, MnF 1 refers to a logical management function in the first operator management system that provides a specific management function service. MnF 2 refers to a logical management function in the second operator management system. Third-party operation and maintenance and management refers to a logical management function in a third-party operation and maintenance system or a third-party management system.
[0087] The above Figure 3 Two management capability exposure scenarios are described:
[0088] Scenario 1: Management function 2 (MnF 2) obtains the management service (MnS) provided by management function 1 (MnF 1) through the exposure of the capability control management function (EGMF) capability.
[0089] Among them, the management function 2 (MnF 2) can obtain the management service (MnS) provided by the management function 1 (MnF 1) through the exposure of the capability control management function 2 (EGMF2) capability.
[0090] Scenario 2: A third-party operation administration and maintenance (OAM) obtains a management service (MnS) provided by a management function 1 (MnF 1) through an exposure of capability control management function (EGMF) capability exposure.
[0091] In which, the third-party operation administration and maintenance (OAM) can obtain a management service (MnS) provided by a management function 1 (MnF 1) through an exposure of capability control management function 1 (EGMF1) capability exposure.
[0092] In Figure 3 , it is proposed that the EGMF provides the function of exposing the management capability, but it does not propose how the tenant obtains the exposed management capability through the EGMF. In addition, the above-mentioned EGMF is the core control function of the management capability exposure. The above-mentioned EGMF provides the control of the exposed management capability and the unified export of the exposed management capability. However, some tenants have high requirements for data security, and therefore based on the consideration of data security, the tenant does not want to expose the operation data of the network to the operator, but based on the above-mentioned management capability exposure mechanism, the tenant manages the network through the EGMF of the network management system (i.e. cross-domain management system) of the operator, so that the network management system of the operator can perceive the data information of the tenant, thereby causing the data leakage of the tenant and bringing the problem of data security.
[0093] Therefore, the embodiment of the present application provides a communication method of a management service. Referring to Figure 4 , the exemplary flowchart of the communication method of the management service provided by the embodiment of the present application includes the following operations. The first management function in the embodiment of the present application can be understood as a network management function in the OAM system authorized to represent the tenant, and the first management function is a consumer of the management service. For example, it can be a network configuration management service consumer, or a performance guarantee management service consumer, etc.
[0094] S401: The first management function sends a first message to a cross-domain management function, and the corresponding cross-domain management function receives the first message.
[0095] The first message can be a management service discovery request, including a tenant identifier of the tenant. The tenant identifier is used to identify the tenant. The tenant identifier is an identifier allocated by the cross-domain management function for the tenant. The first message is used to query the management service available to the tenant, or in other words, the first message is used to request the available management service of the tenant. The tenant identifier is used to identify the identity information of the tenant.
[0096] Optionally, the first message can further comprise an identity of the first management function. The identity of the first management function can be used for message routing between the first management function and the cross-domain management function. The cross-domain management function can send the tenant identity, the authentication information and the authorized management service information to the first management function corresponding to the identity of the first management function according to the identity of the first management function. In this way, the cross-domain management function can determine the message routing address of the first management function (e.g., determine the IP (Internet Protocol) address of the first management function based on the identity of the first management function) according to the identity of the first management function, and send the information to the first management function according to the message routing address of the first management function.
[0097] It should be noted that the identity of the first management function can also be sent to the cross-domain management function through a message different from the first message, which is not limited in the present application. Optionally, the cross-domain management function can be a cross-domain EGMF.
[0098] In an example, the first message can further comprise first indication information. The first indication information can be used to indicate the first message, i.e., the first indication information can indicate that the first message is used to query the management services available to the tenant. In an example, the first indication information can be a message name or a service-oriented API (application programming interface) of the first management function.
[0099] S402: The cross-domain management function determines the management capability information opened to the tenant according to the tenant identity.
[0100] The cross-domain management function can determine the management capability information opened to the tenant from the subscription information of the tenant. The management capability information can be information describing a management service, which is used to indicate one or more management services, such as the identity or name of the management service, which is not limited in the present application.
[0101] In an example, the subscription information of the tenant can be configured in the network management system of the operator. The subscription information can be used to limit the management services available to the tenant, and can also be used to authenticate and verify the identity of the tenant. In the embodiment of the present application, the subscription information can be configured in the cross-domain management function and maintained and managed by the cross-domain management function. Optionally, the subscription information can also be configured in the MnF and maintained and managed by the MnF. The cross-domain management function can request the subscription information of the tenant from the MnF, which is not limited in the present application.
[0102] In another example, the cross-domain management function can authenticate the tenant based on the tenant identity, i.e., the first authentication. For example, the cross-domain management function can query and obtain the authorized management capability information open to the tenant from the subscription information of the tenant according to the tenant identity, and generate corresponding authentication information. The authentication information can be used to indicate that the authorization of the management capability information is passed.
[0103] If the subscription information does not include the authorized management capability information open to the tenant, the authentication information can be used to indicate that the authorization of the management capability information is failed.
[0104] It should be noted that the subscription information can directly include the authorized management capability information open to the tenant, i.e., the subscription information indicates which management capability information is authorized to be open to the tenant. Alternatively, the subscription information can not directly include the authorized management capability information open to the tenant, and the cross-domain management function can process the subscription information to determine the authorized management capability information open to the tenant.
[0105] Optionally, the authentication information can further include an authorization pass validity period, which can be used to indicate the validity period of the authorized management capability information open to the tenant. If the authentication information exceeds the validity period, the first management function can no longer use the open management service, and needs to request authorization from the cross-domain management function again. Optionally, the authentication information can further include an identifier of the cross-domain management function. The authentication information can further include a use range of the authorized management capability information, which is used to indicate that the open management capability is used in a specific area indicated by the use range. If the first management function is not in the use range, the first management function cannot use the open management capability.
[0106] In a possible implementation, the cross-domain management function can be an exposure governance management function (EGMF) or other devices similar to the function of the cross-domain EGMF, such as a chip or a network element. The cross-domain EGMF receives a tenant identity from a first management function. The cross-domain EGMF can send a third message to a second management function. The third message can be an authorization authentication request message, and the tenant identity can be carried in the third message. The second management function authenticates the tenant based on the tenant identity. The foregoing third message can be used to request an authorized management service. The second management function can be configured with subscription information of the tenant, and the second management function determines authorized management service information open to the tenant based on the subscription information, and generates authentication information. The authentication information is as described above, and will not be described here. The second management function can send the authentication information, the authorized management service information, and the tenant identity to the cross-domain EGMF.
[0107] The second management function can be an access control management function (ACMF) or other device similar to the ACMF function, such as a chip or a network element. The ACMF can be responsible for managing tenant information, such as tenant information registration, de-registration, or tenant information modification. The ACMF can also be responsible for managing the permissions of tenants, such as permission control of authorized management services opened to tenants. The permission control can be control of the type of management services or the type of components opened to tenants. The ACMF can also authenticate tenants or authorize and authenticate the first management function of the tenants.
[0108] S403: The cross-domain management function sends the tenant identifier, the authentication information, and the authorized management service information to the first management function, and the corresponding first management function receives the tenant identifier, the authentication information, and the authorized management service information.
[0109] The authorized management service information is information of part of the management services or information of all the management services indicated by the management capability information determined by the cross-domain management function based on the subscription information of the tenant. The authorized management service information can include one or more of the types of management services, such as an alarm management service, a performance guarantee management service, a network configuration management service, and a heartbeat management service. The authorized management information can also include at least one of the management service version and the component type. For example, the authorized management information includes component type A, component type B, and component type C, which can be referred to the foregoing description of the management services.
[0110] The authentication information can be used to indicate that the authorization of the management capability information is passed. The tenant identifier, the authentication information, and the authorized management service information can be carried in the same message and sent to the first management function, such as in a management service discovery response. Alternatively, the tenant identifier, the authentication information, and the authorized management service information can also be carried in different messages and sent to the first management function, which is not limited in the present application.
[0111] In the following, the authorized management service information is introduced in Table 1.
[0112] Table 1: Parameters included in the authorized management service information
[0113]
[0114] The authorized management service information in Table 1 can be in the format of an Information Object Class (IOC), and the IOC of the authorized management service information in Table 1 can be managed through an object instance management message (such as a CreateMOI message).
[0115] The authorized management service information in Table 1 can refer to the description of the management service above.
[0116] For example, the authorized management service information includes a management service type of network configuration management service, a management service version of 3GPP R16, a component type A of creation of the network configuration management service, a component type B of a wireless cell A, and a component type C of cell PRB utilization. The authorized management service information can refer to the network configuration management service of the cell PRB utilization of the wireless cell A, and the network configuration management service is of a version conforming to the 3GPP R16 standard.
[0117] For another example, the authorized management service information includes a management service type of performance guarantee management service, a management service version of 3GPP R17, a component type A of creation of a performance data measurement task, a component type B of a base station device 1, and a component type C of service latency. The authorized management service information can refer to the performance data measurement task of the service latency of the base station device 1.
[0118] Based on the above scheme, the first management function can obtain the open management service through the domain EGMF to manage the network of the tenant.
[0119] In one example, in order to guarantee the information security of the operator, the cross-domain management function can perform conversion processing on the authorized management service information exposed to the tenant, that is, the cross-domain management function does not directly send the authorized management service information to the first management function. For example, the cross-domain management function can perform encryption processing on the authorized management service (MnS data) information exposed to the tenant, or the cross-domain management function can perform format conversion on the authorized management service information (MnS data) exposed to the tenant, and the converted management service information exposed to the tenant is referred to as exposure MnS, which is sent to the first management function. The exposure MnS is the exposure management service information after conversion processing on the authorized management service information exposed to the tenant, such as aggregation processing or binary encoding of the performance data of the authorized management service information component type C.
[0120] The cross-domain management function can send a second message to the domain EGMF or MnF, and the second message can be used to instruct the domain EGMF or MnF to expose the first management service. For example, the second message can be a capability exposure authorization notification. The first management service here can be all or part of the management services indicated by the management capability information described above.
[0121] The cross-domain management function can also send the first management service information to the domain EGMF or MnF. The first management service information here is the information of all or part of the management services exposed to the tenant. For example, the first management service information can be part or all of the authorized management service information described above. The domain EGMF or MnF can provide the first management service indicated by the first management service information to the first management function.
[0122] In one example, the cross-domain management function sends the identifier of the third management function to the domain EGMF or MnF. If the cross-domain management function has authenticated the first management function, the identifier of the third management function can be consistent with the identifier of the first management function.
[0123] Optionally, the cross-domain management function can also send the aforementioned authentication information (referred to as first authentication information) to the domain EGMF or MnF, which is used by the domain EGMF or MnF to authenticate the first management function. The first authentication information is used to indicate that the authorization of the first management service information is passed.
[0124] In a possible implementation, the cross-domain management function can further send the identity of the domain EGMF to the first management function. The identity of the domain EGMF can also be carried in the management service discovery response. The domain EGMF can be an EGMF in the radio domain network element management system, or can also be an EGMF in the core network domain network element management system. The identity of the domain EGMF can be an IP address of the EGMF, or a uniform resource locator (URL) address, etc. Alternatively, the cross-domain management function can send the identity of the MnF to the first management function. The domain EGMF or the MnF here can provide all or part of the management services in the management services indicated by the management capability information to the tenant.
[0125] The first management function can receive the identity of the domain EGMF from the cross-domain management function, and the domain EGMF indicated by the identity of the domain EGMF can provide the first management service indicated by the first management service information to the first management function. The first management function can request all or part of the first management services from the domain EGMF according to the authentication information, the tenant identity, and the first management service information from the cross-domain management function. The first management function can send the identity of the first management function to the domain EGMF indicated by the identity of the domain EGMF. The identity of the first management function can be used by the domain EGMF to authenticate the first management function. Alternatively, the first management function can send a management service invocation request to the domain EGMF to request all or part of the first management services. The management service invocation request can carry the identity of the first management function.
[0126] It should be noted that the first management function can select the corresponding management service according to the requirement from the authorized management service information from the cross-domain management function. For example, it is assumed that the first management function needs to monitor the performance of the network, and the management service type open to the tenant in the authorized management service information includes the performance guarantee management service, and then the first management function can request to invoke the performance guarantee management service to measure the performance of the network, so as to achieve the purpose of monitoring the performance of the network.
[0127] The domain EGMF receives the first management function identifier from the first management function. The domain EGMF receives the third management function identifier from the cross-domain management function. The domain EGMF authenticates the first management function according to the first management function identifier and the third management function identifier, i.e., the second authentication. Specifically, if the first management function identifier and the third management function identifier are consistent, the domain EGMF can consider that the first management function passes the authentication, and provides the first management function with all or part of the management services in the first management service. In this way, the domain EGMF authenticates the first management function through the information from the cross-domain management function when the first management function requests all or part of the management services in the first management service, i.e., the twice authentication of the cross-domain management function and the domain EGMF can be implemented, and the security of the data information is improved.
[0128] Optionally, the first management function can also send the authentication information (referred to as the second authentication information) to the domain EGMF. If the cross-domain management function authenticates the first management function, the second authentication information here can be the same as the first authentication information. The second authentication information is used to authenticate the first management function. Optionally, the second authentication information can also be sent in the management service invocation request, or be sent through a message different from the management service invocation request, which is not limited in the present application. The above second authentication information is used to indicate that the authorization of the second management service information passes. The second management service information here can be the same as the authorized management service information, or can also be a subset of the authorized management service information. The first management service that the domain EGMF can provide for the first management function can be part or all of the management services indicated by the second management service information. If the domain EGMF can provide the first management function with all the management services indicated by the authorized management service information, the first management service is the same as the management services indicated by the second management service information, and if the domain EGMF can provide the first management function with part of the management services indicated by the authorized management service information, the first management service is the same as the part of the management services.
[0129] Optionally, the domain EGMF receives first authentication information from the cross-domain management function. The first authentication information is used to indicate authorization of the first management service information. The first management service information is the same as the second management service information, or the first management service information is a subset of the second management service information. The domain EGMF receives second authentication information from the first management function. The second authentication information is used to indicate authorization of the second management service information. The domain EGMF can authenticate the first management function based on the second authentication information and the first authentication information. For example, if the second authentication information and the first authentication information are consistent, the domain EGMF can consider that the first management function is authenticated and provide the first management service for the first management function. Since the first authentication information is from the cross-domain management function, the first authentication information is authenticated by the cross-domain management function and is authorized. Therefore, the domain EGMF authenticates the first management function based on the first authentication information and the second authentication information, which can be considered as the domain EGMF can determine whether the first management function is the first management function authorized by the cross-domain management function.
[0130] The second authentication information and the first authentication information are consistent, which means that the second management service indicated by the second authentication information to be authorized is the same as the first management service indicated by the first authentication information to be authorized, or the second management service is a subset of the first management service. In other words, the first management function indicated by the second authentication information to be authorized is the same as the first management function indicated by the first authentication information to be authorized.
[0131] Optionally, the domain EGMF can also determine whether the management service requested by the first management function is the type of management service that is authenticated, that is, whether it is the type of management service included in the first management service information.
[0132] The second authentication information, the identifier of the first management function sent by the first management function to the domain EGMF, and the first management service information can be sent in the management service invocation request or sent through a message different from the management service invocation request, which is not limited in the present application.
[0133] In another example, the first management function can send the identifier of the first management function and the second authentication information to the domain EGMF. The domain EGMF can authenticate the first management function based on the second authentication information and the first authentication information. The identifier of the first management function can be used for message routing between the domain EGMF and the first management function. The domain EGMF can determine the first management function corresponding to the identifier based on the identifier of the first management function, and communicate with the first management function corresponding to the identifier.
[0134] Based on the above scheme, the first management function requesting the management service is authenticated twice again by the domain EGMF, which can improve the security of the data information of the tenant.
[0135] Optionally, the first management function can receive an identifier of an MnF from the cross-domain management function, the MnF can be used to provide the first management function with the first management service. The first management function can then request all or part of the first management service from the MnF, and the first management function is authenticated for the second time by the MnF. The second authentication of the first management function by the MnF can refer to the aforementioned second authentication of the first management function by the domain EGMF, which will not be repeated here.
[0136] In a possible implementation, the first management function can also perform tenant registration. The first function can send a request for tenant registration to the cross-domain management function to implement tenant registration. Hereinafter, the process of tenant registration is introduced. Figure 5 . Figure 5 The tenant registration process provided by the embodiments of the present application includes the following operations.
[0137] S501: The operator network management system sends a tenant registration request to the cross-domain management function, and the corresponding cross-domain management function receives the tenant registration request.
[0138] The tenant registration request can carry a customer identifier. The customer identifier can be used to identify the identity information of the tenant, which can be a tenant name or a digital identifier representing the tenant.
[0139] Optionally, the tenant registration request can also carry tenant profile information. The tenant profile information is used to describe the basic information of the tenant, and can include the business requirements of the tenant, such as latency, reliability, and resource isolation requirements.
[0140] It should be noted that the tenant registration process initiated by the operator network management system can be triggered by a request from the business support system (BSS) of the tenant, such as a request message triggered by the BSS of the vertical industry to the operator network management system, or an artificial operation triggered by the operator's operation and maintenance personnel based on the portal interface to the BSS.
[0141] In one example, the operator network management system can send a tenant registration request to the cross-domain management function through an API provided by the cross-domain management function. Specifically, the API can be a newly added tenant management service API, or an API for creating and managing network resource management objects defined, or other interface APIs, which are not limited in the present application.
[0142] S502: The cross-domain management function obtains the configured subscription information.
[0143] Optionally, the operator and the tenant can complete a business agreement offline, such as a business agreement of network service guarantee provided by the operator to the tenant, a management service open to the tenant, network resource information available or operated by the tenant, and the like, and complete the configuration of the subscription information of the tenant in the network management system of the operator.
[0144] The cross-domain management function can obtain the subscription information of the tenant from the configured subscription information based on the customer identifier in the tenant registration request. The cross-domain management function can allocate a corresponding tenant identifier to the tenant. The tenant identifier is allocated by the cross-domain management function, and can be used by the first management function to obtain the management capability information of the tenant and manage the network of the tenant.
[0145] It should be noted that if the subscription information of the tenant is managed by the MnF, the cross-domain control opening function needs to obtain the subscription information of the tenant from the MnF through the interface API provided by the MnF after receiving the tenant registration request of the network management system of the operator.
[0146] In an example, if the cross-domain management function can obtain the subscription information of the tenant, it can be considered that the tenant registration is successful, and if the cross-domain management function cannot obtain the subscription information of the tenant, it can be considered that the identity of the tenant is not legal, and the tenant registration fails.
[0147] S503: The cross-domain management function sends a response message of tenant registration to the network management system of the operator.
[0148] The response message can include the tenant registration result, that is, the response message can indicate that the tenant registration of the network management system of the operator is successful or the tenant registration fails. If the response message indicates that the tenant registration is successful, the response message can further include the tenant identifier allocated to the tenant by the cross-domain control opening function.
[0149] Optionally, the network management system of the operator can send the tenant registration result to the network management system of the customer. The network management system of the operator can also send the tenant identifier to the network management system of the customer.
[0150] The communication method of the management service provided by the application will be described below through specific embodiments.
[0151] Referring to Figure 6 The example flowchart of the communication method of the management service provided by the embodiment of the application can include the following operations. Figure 6In the domain management function network element, an exposure governance management function (EGMF) is deployed.
[0152] S601: A business support system (BSS) in the operator network management system sends a tenant registration request to an access control management function (ACMF), and the corresponding ACMF receives the tenant registration request.
[0153] It should be noted that the ACMF herein can be Figure 4 The second management function (ACMF) in the method embodiment shown is responsible for authenticating the tenant and authorizing and authenticating the first management function of the tenant.
[0154] The tenant registration request can be used to request registration of the tenant, which can be seen from, for example Figure 5 The related description in the method embodiment shown will not be repeated here.
[0155] S602: The ACMF acquires configured subscription information.
[0156] The manner in which the ACMF acquires the configured subscription information and authenticates the tenant can be seen from, for example Figure 5 The related description in the method embodiment shown will not be repeated here.
[0157] S603: The ACMF sends a response message of tenant registration to the BSS in the operator network management system.
[0158] The response message can include a tenant registration result, that is, the response message can indicate that the BSS in the operator network management system registers the tenant successfully or fails to register the tenant. If the response message indicates that the tenant is registered successfully, the response message can further include a tenant identifier allocated by the ACMF for the tenant.
[0159] S604: An operation administration and maintenance (OAM) sends a management service discovery request to a first exposure governance management function (EGMF).
[0160] The management service discovery request can carry a tenant identifier of the tenant and an identifier of the OAM. The first EGMF can be an EGMF in the cross-domain management function.
[0161] It should be noted that the first EGMF here can be Figure 4 The cross-domain management function or the cross-domain EGMF in the method embodiment shown can be an OAM. Figure 4 The first management function in the method embodiment shown.
[0162] S605: The first EGMF sends a tenant identifier to an access control management function (ACMF).
[0163] Optionally, the first EGMF can send an authorization authentication request to the ACMF to request the ACMF to authenticate the tenant based on the tenant identifier, and determine the management service open to the tenant. The authorization authentication request can carry the tenant identifier.
[0164] S606: The ACMF authenticates the tenant identifier based on the tenant identifier, and determines the management capability information open to the tenant.
[0165] The manner in which the ACMF authenticates the tenant and determines the management capability information can be referred to the related description in the method embodiment shown, which will not be described here. Figure 4
[0166] S607: The ACMF sends the tenant identifier, the authorized management service information, and the authentication information to the first EGMF.
[0167] Optionally, the tenant identifier, the authorized management service information, and the authentication information can be sent to the first EGMF through the same message, such as an authorization authentication request response message. Alternatively, the tenant identifier, the authorized management service information, and the authentication information can be sent to the first EGMF through different messages.
[0168] Optionally, the first EGMF can perform S608: The first EGMF performs conversion processing on the authorized management service information. The manner in which the first EGMF performs conversion processing on the authorized management service information can be referred to the related description in the method embodiment shown, which will not be described here. Figure 4
[0169] S609: The first EGMF sends a management service discovery response to the OAM.
[0170] The management service discovery response can include the tenant identifier, the identifier of the OAM, the authorized management service information, and the authentication information. The management service discovery response can also include the identifier of the second EGMF in the domain management function.
[0171] It should be noted that the explanation of the above management service discovery response can be referred to the related description in the method embodiment shown.Figure 4 The related description in the method embodiment is shown and will not be repeated here.
[0172] S610: The first EGMF sends a capability exposure authorization notification to a second EGMF in the domain management function.
[0173] The capability exposure authorization notification can include the identity of the OAM, authentication information, and first management service information. The explanation of the above capability exposure authorization notification can be referred to Figure 4 The related description in the method embodiment is shown and will not be repeated here.
[0174] The second EGMF here can be the aforementioned Figure 4 The domain EGMF in the method embodiment is shown.
[0175] S611: The OAM sends a management service invocation request to the second EGMF according to the second EGMF identity.
[0176] The management service invocation request can include the identity of the OAM and authentication information. The management service invocation request is used to request to invoke the second management service. The second management service here can be part or all of the management services indicated by the authorized management service information. The second management service is all or part of the first management service. The explanation of the above management service invocation request can be referred to Figure 4 The related description in the method embodiment is shown and will not be repeated here.
[0177] S612: The second EGMF can authenticate the OAM based on the authentication information in S611 and the authentication information in S610.
[0178] The method for the second EGMF to authenticate the OAM can be referred to the related description in the method embodiment as shown in Figure 4 The related description in the method embodiment is shown and will not be repeated here.
[0179] When the authentication is passed, the second EGMF can perform S613: The second EGMF requests to invoke the second management service to the MnF capable of providing the second management service.
[0180] S614: The second EGMF sends a management service invocation result to the OAM.
[0181] The second EGMF can send the management service invocation result to the OAM if the authentication in S612 is passed. The management service invocation result can include network resource model data, network performance management data, or network alarm information. The management service invocation result can indicate authentication failure if the authentication in S612 is not passed.
[0182] Please refer toFigure 7 An exemplary flowchart of the communication method of the management service provided by the embodiments of the present application can include the following operations. Figure 7 In the illustrated embodiment, the domain management function does not deploy an exposure governance management function (EGMF).
[0183] S701-S708 are similar to S601-S608, and refer to S601-S608.
[0184] S709: The first EGMF sends a management service discovery response to an operation administration and maintenance (OAM).
[0185] It should be noted that the first EGMF here can be Figure 4 The cross-domain management function or the cross-domain EGMF in the illustrated method embodiment. The OAM can be Figure 4 The first management function in the illustrated method embodiment.
[0186] The management service discovery response can include a tenant identifier, an identifier of the OAM, authorized management service information, and authentication information. The management service discovery response can also include an identifier of an MnF in the domain management function. The MnF here can be an MnF for providing the management service indicated by the authorized management service information. The management service discovery response can include an identifier of one MnF or identifiers of multiple MnFs.
[0187] Optionally, the management service discovery response can include a correspondence between each authorized management service information and the identifier of the MnF, that is, the management service discovery response can be used to determine which MnF provides the management service indicated by each authorized management service information.
[0188] The above management service discovery response can refer to Figure 4 The related description in the illustrated method embodiment.
[0189] Suppose that the management services indicated by the authorized management service information are provided by a management function 1 (MnF1) and a management function 2 (MnF2), respectively.
[0190] S710: The first EGMF sends a capability exposure authorization notification to the MnF1 and the MnF2 in the domain management function.
[0191] The capability exposure authorization notification sent to the MnF1 can include the identifier of the OAM, the authentication information, and the first management service information; and the capability exposure authorization notification sent to the MnF2 can include the identifier of the OAM, the authentication information, and the second management service information.
[0192] It should be noted that the first management service information can be part of the authorized management service information, and the second management service information can be part of the authorized management service information. Here, the first management service information and the second management service information can be different, that is, the management services indicated by the authorized management service information provided by the MnF1 and the MnF2 for the OAM respectively.
[0193] The above explanation of the capability exposure authorization notification can be referred to Figure 4 the related description in the method embodiment shown.
[0194] Suppose the OAM wants to invoke the first management service, the following S711 can be performed.
[0195] S711: The OAM sends a management service invocation request to the MnF1 according to the identifier of the MnF1.
[0196] The management service invocation request can include the identifier of the OAM and the authentication information. The management service invocation request is used to request to invoke the first management service indicated by the first management service information. The first management service is a management service provided by the MnF1.
[0197] S712: The MnF1 can authenticate the OAM based on the authentication information and the identifier of the OAM in S711, and the authentication information and the identifier of the OAM in S710.
[0198] The MnF1 can determine whether the identifier of the OAM is an OAM authorized by the ACMF. For example, the MnF1 can determine whether the identifier of the OAM in S711 is consistent with the identifier of the OAM in S710, and if so, it can be considered that the authentication is passed, and if not, it can be considered that the authentication is not passed.
[0199] The MnF1 can also determine whether the management service requested by the OAM is an ACMF authenticated management service type. For example, the MnF1 can determine whether the first management service requested by the OAM is a management service in the management services indicated by the first management service information in S710, and if so, it can be considered that the authentication is passed, and if not, it can be considered that the authentication is not passed.
[0200] The method for the MnF1 to authenticate the OAM can be referred to Figure 4 the related description in the method embodiment shown, which will not be repeated here.
[0201] Upon successful authentication, MnF1 can execute S713: MnF1 sends the management service call result to OAM.
[0202] If authentication in S712 succeeds, MnF1 can send a management service call result to OAM. The management service call result may include network resource model data, network performance data, or network alarm information. If authentication in S712 fails, the management service call result can indicate that authentication failed.
[0203] It should be noted that if OAM wants to call the second management service, in S711 OAM can send a management service call request to MnF2 to request the call to the second management service. Then, in S712, MnF2 authenticates OAM. Similarly, in S713, MnF2 sends the management service call result to OAM.
[0204] Figures 8-9 The diagram illustrates the possible communication devices provided in the embodiments of this application. These communication devices can be used to implement the cross-domain management function, the first management function, or the domain open capability control management function in the above method embodiments, and thus can also achieve the beneficial effects of the above method embodiments.
[0205] like Figure 8 As shown, the communication device 800 includes a processing unit 810 and a transceiver unit 820. The communication device 800 is used to implement the above-mentioned... Figure 4 The operation of the first management function and the cross-domain management function in the method embodiment shown.
[0206] When the communication device 800 is used to implement the first management function: the processing unit 810 generates a first message. This first message includes a tenant identifier. The transceiver unit 820 sends the first message and receives the tenant identifier, authentication information, and authorized management service information from the cross-domain management function.
[0207] In one design, transceiver unit 820 is also used to: receive an identifier from the domain open capability control management function of the cross-domain management function; and send an identifier of the first management function to the domain open capability control management function.
[0208] In one design, the transceiver unit 820 is also used to: send authentication information to the domain open capability control management function; the authentication information is used to authenticate the first management function.
[0209] When the communication apparatus 800 is configured to implement the operation of the cross-domain management function: the transceiver 820 is configured to receive a first message from a first management function. The first message includes a tenant identifier. The processing unit 810 is configured to determine network management capability information open to the tenant according to the tenant identifier. The transceiver 820 is further configured to send the tenant identifier, authentication information and authorized management service information to the first management function.
[0210] In one design, the transceiver 820 is further configured to send a second message to the domain open capability control management function.
[0211] In one design, the transceiver 820 is further configured to send the identity of the first management function and the authentication information to the domain open capability control management function.
[0212] In one design, the transceiver 820 is further configured to send a third message to the second management function; and receive the tenant identifier, authentication information and management capability information from the second management function.
[0213] In one design, the transceiver 820 is further configured to send the identity of the domain open capability control management function to the first management function.
[0214] When the communication apparatus 800 is configured to implement the operation of the domain open capability control management function: the transceiver 820 is configured to receive the identity of a third management function and first management service information from a cross-domain management function; the transceiver 820 is further configured to receive the identity of the first management function from the first management function; the processing unit 810 is configured to authenticate the first management function according to the identity of the third management function and the identity of the first management function; and the processing unit 810 is further configured to provide the first management service indicated by the first management service information to the first management function when the authentication is passed.
[0215] In one design, the transceiver 820 is further configured to receive first authentication information from the cross-domain management function; and receive second authentication information from the first management function; and the processing unit 810 is specifically configured to authenticate the first management function based on the second authentication information and the first authentication information.
[0216] For more detailed description of the processing unit 810 and the transceiver 820, please refer to the related description in the method embodiments shown in Figures 4-7 directly.
[0217] As Figure 9As shown, the electronic device 900 includes a processor 910 and an interface circuit 920. The processor 910 and the interface circuit 920 are coupled to each other. It can be understood that the interface circuit 920 can be a transceiver or an input / output interface. Optionally, the electronic device 900 can further include a memory 930 for storing instructions executed by the processor 910 or storing input data required by the processor 910 for executing instructions or storing data generated after the processor 910 executes instructions.
[0218] When the electronic device 900 is used to implement the method shown above, the processor 910 is configured to implement the functions of the processing unit 810, and the interface circuit 920 is configured to implement the functions of the transceiving unit 820. Figures 4 to 7
[0219] When the communication device is a module applied to the first management function, the module implements the operations of the first management function in the method embodiments. The module receives information from other modules (such as a radio frequency module or an antenna) in the first management function, and the information is sent to the first management function by the cross-domain management function; or the module sends information to other modules (such as a radio frequency module or an antenna) in the first management function, and the information is sent to the cross-domain management function by the first management function.
[0220] When the communication device is a module applied to the cross-domain management function, the module implements the operations of the cross-domain management function in the method embodiments. The module receives information from other modules (such as a radio frequency module or an antenna) in the cross-domain management function, and the information is sent to the cross-domain management function by the first management function; or the module sends information to other modules (such as a radio frequency module or an antenna) in the cross-domain management function, and the information is sent to the first management function by the cross-domain management function.
[0221] It can be understood that the processor in the embodiments of the present application can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, transistor logic devices, hardware components or any combination thereof. The general-purpose processor can be a microprocessor or any conventional processor.
[0222] The method steps in the embodiments of the present application can be realized by hardware or by a processor executing software instructions. The software instructions can be composed of corresponding software modules, which can be stored in a random access memory, a flash memory, a read-only memory, a programmable read-only memory, an erasable programmable read-only memory, an electrically erasable programmable read-only memory, a register, a hard disk, a mobile hard disk, a CD-ROM, or any other form of storage medium well known in the art. An exemplary storage medium is coupled to the processor, so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be an integral part of the processor. The processor and the storage medium can be located in an ASIC. In addition, the ASIC can be located in a base station or a terminal. Of course, the processor and the storage medium can also exist as discrete components in the base station or the terminal.
[0223] In the above embodiments, all or part of the embodiments can be realized by software, hardware, firmware, or any combination thereof. When realized by software, all or part of the embodiments can be realized in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer programs or instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present application are performed. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user equipment, or other programmable apparatus. The computer programs or instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another computer-readable storage medium, for example, the computer programs or instructions can be transferred from one website, computer, server, or data center to another website, computer, server, or data center through a wired or wireless manner. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server, data center, etc. that integrates one or more available media. The available medium can be a magnetic medium, for example, a floppy disk, a hard disk, a magnetic tape; an optical medium, for example, a digital video disc; or a semiconductor medium, for example, a solid-state disk. The computer-readable storage medium can be a volatile or non-volatile storage medium, or can include both volatile and non-volatile storage media.
[0224] In various embodiments of the present application, the terms and / or descriptions of different embodiments are consistent and can be referred to each other if there is no special description and logical conflict. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.
[0225] In the present application, "at least one" means one or more, "multiple" means two or more. The "and / or" describes the relationship between the associated objects, which means that there can be three kinds of relationships, for example, A and / or B, which can represent: A exists alone, A and B exist together, B exists alone, where A, B can be singular or plural. In the text description of the present application, the character " / ", generally indicates that the associated objects before and after are in an "or" relationship; in the formula of the present application, the character " / ", indicates that the associated objects before and after are in a "division" relationship. "Including at least one of A, B and C" can mean: including A; including B; including C; including A and B; including A and C; including B and C; including A, B and C.
[0226] It can be understood that various numerical numbers involved in the embodiments of the present application are only distinguished for convenience of description, and are not used to limit the scope of the embodiments of the present application. The size of the serial number of the above processes does not mean the order of execution, and the execution order of the processes should be determined according to its function and inherent logic.
Claims
1. A communication method for management services, characterized in that, include: The cross-domain management function receives the first message from the first management function; The first message is used to query the authorized management service, and the first message includes the tenant's tenant identifier; wherein, the first message also includes the identifier of the first management function, and the identifier of the first management function is used for message routing between the first management function and the cross-domain management function; The cross-domain management function sends a third message to the second management function; the third message is used to request authorized management services, and the third message includes the tenant identifier; The cross-domain management function receives the tenant identifier, authentication information, and management capability information from the second management function; the management capability information is used to indicate one or more management services, and the authentication information is used to indicate that the authorization of the management capability information is approved. The cross-domain management function sends the tenant identifier, the authentication information, and the authorized management service information to the first management function; The authorized management service information indicates some or all of the management services in the one or more management services.
2. The method according to claim 1, characterized in that, The authorized management service information includes the types of management services and the versions of management services available to the tenant.
3. The method according to claim 2, characterized in that, The management service types include one or more of the following: fault monitoring management service, performance assurance management service, network configuration management service, and heartbeat management service.
4. The method according to claim 2 or 3, characterized in that, The authorized management service information also includes the component types of the management service type; the component types include operation types, network resource objects, and data information.
5. The method according to any one of claims 1 to 3, characterized in that, Also includes: The cross-domain management function sends a second message to the domain open capability control management function; The second message is used to instruct the domain open capability control management function to open a first management service, which is a part or all of the management services indicated by the authorized management service information.
6. The method according to claim 5, characterized in that, Also includes: The cross-domain management function sends the identifier of the first management function and the authentication information to the domain open capability control management function.
7. The method according to any one of claims 1 to 3, 6, characterized in that, Also includes: The cross-domain management function sends the identifier of the domain open capability control management function to the first management function; The domain open capability control and management function is used to provide the first management service; The first management service is a part or all of the management services indicated by the authorized management service information.
8. A communication method for management services, characterized in that, include: The Domain Open Capability Control and Management function receives the identifier of the third management function and the first management service information from the cross-domain management function; The first management service information is information about all or part of the management services that are open to the tenant; The domain open capability control management function receives an identifier from the first management function. The domain open capability control and management function authenticates the first management function based on the identifier of the third management function and the identifier of the first management function; Upon successful authentication, the domain open capability control management function provides the first management function with the first management service indicated by the first management service information.
9. The method according to claim 8, characterized in that, Also includes: The domain open capability control and management function receives first authentication information from the cross-domain management function; The first authentication information is used to indicate that the authorization of the first management service information is successful; The first management service information is information about all or part of the management services that are available to the tenant; The domain open capability control and management function receives second authentication information from the first management function; The second authentication information is used to indicate that the authorization for the second management service information has been granted; The second management service information is information on all or part of the management services available to the tenant; The domain open capability control management function authenticates the first management function based on the identifier of the third management function and the identifier of the first management function, including: The domain open capability control and management function authenticates the first management function based on the second authentication information and the first authentication information.
10. A communication method for a management service, characterized in that, include: The first management function sends a first message to the cross-domain management function; the first message is used to query the authorized management service, and the first message includes the tenant identifier of the tenant; the first message also includes the identifier of the first management function, and the identifier of the first management function is used for message routing between the first management function and the cross-domain management function; The first management function receives a tenant identifier, authentication information, and authorized management service information from the cross-domain management function; the authentication information is used to indicate that the authorization of the management capability information is passed, and the management capability information is used to indicate one or more management services; wherein, the authentication information and the authorized management service information are obtained by the cross-domain management function from the second management function; The authorized management service information indicates some or all of the management services from one or more management services that are open to the tenant.
11. The method according to claim 10, characterized in that, The authorized management service information includes the types of management services and the versions of management services available to the tenant.
12. The method according to claim 11, characterized in that, The management service types include one or more of the following: fault monitoring management service, performance assurance management service, network configuration management service, and heartbeat management service.
13. The method according to claim 11 or 12, characterized in that, The authorized management service information also includes the component types of the management service type; the component types include operation types, network resource objects, and data information.
14. The method according to any one of claims 10 to 12, characterized in that, Also includes: The first management function receives an identifier from the domain open capability control management function of the cross-domain management function; The domain open capability control and management function is used to provide the first management service; The first management service is a part or all of the management services indicated by the authorized management service information; The first management function sends its identifier to the domain open capability control management function; The identifier of the first management function is used to authenticate the first management function.
15. The method according to claim 14, characterized in that, Also includes: The first management function sends the authentication information to the domain open capability control management function; the authentication information is used to authenticate the first management function.
16. A communication method for a management service, characterized in that, include: The first management function sends a first message to the cross-domain management function; the first message is used to query the authorized management service, and the first message includes the tenant identifier of the tenant; wherein, the first message also includes the identifier of the first management function, and the identifier of the first management function is used for message routing between the first management function and the cross-domain management function; The cross-domain management function sends a third message to the second management function; the third message is used to request authorized management services, and the third message includes the tenant identifier; The cross-domain management function receives the tenant identifier, authentication information, and management capability information from the second management function; the management capability information is used to indicate one or more management services, and the authentication information is used to indicate that the authorization of the management capability information is approved. The cross-domain management function sends the tenant identifier, the authentication information, and the authorized management service information to the first management function; the authorized management service information indicates some or all of the management services in the one or more management services.
17. The method according to claim 16, characterized in that, The cross-domain management function sends the identifier of the domain open capability control management function to the first management function; the domain open capability control management function is used to provide the first management service; The first management service is a part or all of the management services indicated by the authorized management service information.
18. The method according to claim 16 or 17, characterized in that, Also includes: The cross-domain management function sends a second message to the domain open capability control management function; The second message is used to instruct the domain open capability control management function to open a first management service, which is a part or all of the management services indicated by the authorized management service information.
19. The method according to claim 18, characterized in that, Also includes: The cross-domain management function sends the identifier of the first management function to the domain open capability control and management function, and the identifier of the first management function is used by the domain open capability control and management function to authenticate the first management function; The first management function sends its identifier to the domain open capability control management function.
20. The method according to claim 19, characterized in that, Also includes: The cross-domain management function sends the authentication information to the domain open capability control and management function, and the authentication information is used by the domain open capability control and management function to authenticate the first management function; The first management function sends the authentication information to the domain open capability control management function.
21. A communication method for a management service, characterized in that, include: The cross-domain management function sends the identifier of the third management function and the first management service information to the domain open capability control management function: the first management service information is information on all or part of the management services open to the tenant; The domain open capability control management function of the first management function item sends the identifier of the first management function, which is used to authenticate the first management function; The domain open capability control and management function authenticates the first management function based on the identifier of the third management function and the identifier of the first management function; Upon successful authentication, the domain open capability control management function provides the first management function with the first management service indicated by the first management service information.
22. The method according to claim 21, characterized in that, Also includes: The cross-domain management function sends the first authentication information to the domain open capability control management function; The first authentication information is used to indicate that the authorization of the first management service information is successful; The first management service information is information about all or part of the management services that are available to the tenant; The first management function sends the second authentication information to the domain open capability control management function; the second authentication information is used to indicate that the authorization of the second management service information is approved; The second management service information is information on all or part of the management services available to the tenant; The domain open capability control management function authenticates the first management function based on the identifier of the third management function and the identifier of the first management function, including: The domain open capability control and management function authenticates the first management function based on the second authentication information and the first authentication information.
23. A communication device, characterized in that, include: Processing unit and transceiver unit; The transceiver unit is used to receive a first message from the first management function; The first message is used to query the authorized management service, and the first message includes the tenant's tenant identifier; the first message also includes the identifier of the first management function; the identifier of the first management function is used for message routing between the first management function and the communication device; The processing unit is used to determine the management capabilities information that are open to the tenant based on the tenant identifier; The management capability information is used to indicate one or more management services; The processing unit determines the management capability information open to the tenant based on the tenant identifier; when the management capability information is used to instruct one or more management services, the transceiver unit is further configured to: send a third message to the second management function; the third message is used to request authorized management services, and the third message includes the tenant identifier; and receive the tenant identifier, authentication information, and management capability information from the second management function. The management capability information is used to indicate one or more management services, and the authentication information is used to indicate that the authorization of the management capability information is passed. The transceiver unit is further configured to send the tenant identifier, the authentication information, and the authorized management service information to the first management function; the authorized management service information indicates some or all of the management services in the one or more management services.
24. The apparatus according to claim 23, characterized in that, The authorized management service information includes the types of management services and the versions of management services available to the tenant.
25. The apparatus according to claim 24, characterized in that, The management service types include one or more of the following: fault monitoring management service, performance assurance management service, network configuration management service, and heartbeat management service.
26. The apparatus according to claim 24 or 25, characterized in that, The authorized management service information also includes the component types of the management service type; the component types include operation types, network resource objects, and data information.
27. The apparatus according to any one of claims 23-24, characterized in that, The transceiver unit is also used for: Send a second message to the domain open capability control and management function; the second message is used to instruct the domain open capability control and management function to open a first management service, the first management service being some or all of the management services indicated by the authorized management service information.
28. The apparatus according to claim 27, characterized in that, The transceiver unit is also used for: Send the identifier of the first management function and the authentication information to the domain open capability control management function.
29. The apparatus according to any one of claims 23-24 and 28, characterized in that, The transceiver unit is also used for: Send the identifier of the domain open capability control management function to the first management function; the domain open capability control management function is used to provide the first management service; The first management service is a part or all of the management services indicated by the authorized management service information.
30. A communication device, characterized in that, include: Transceiver unit and processing unit; The transceiver unit is used to receive the identifier of the third management function and the first management service information from the cross-domain management function; The first management service information is information about all or part of the management services that are open to the tenant; The transceiver unit is further configured to receive an identifier of the first management function from the first management function; The processing unit is configured to authenticate the first management function based on the identifier of the third management function and the identifier of the first management function; The processing unit is further configured to provide the first management service indicated by the first management service information to the first management function when authentication is successful.
31. The apparatus according to claim 30, characterized in that, The transceiver unit is also used for: Receive first authentication information from the cross-domain management function; the first authentication information is used to indicate that the authorization of the first management service information is approved; the first management service information is information on all or part of the management services open to the tenant; receive second authentication information from the first function; The second authentication information is used to indicate that the authorization for the second management service information is approved; the second management service information is information on all or part of the management services that are open to the tenant. The processing unit is specifically used to: authenticate the first management function based on the second authentication information and the first authentication information.
32. A communication device, characterized in that, include: Transceiver unit and processing unit; The processing unit is configured to generate a first message; the first message is used to query authorized management services, and the first message includes a tenant identifier of the tenant; the first message also includes an identifier of a first management function, and the identifier of the first management function is used for message routing between the first management function and the cross-domain management function; The transceiver unit is used to send the first message to the cross-domain management function; The transceiver unit is further configured to receive tenant identifiers, authentication information, and authorized management service information from the cross-domain management function; the authentication information is used to indicate that the authorization of management capability information is passed, and the management capability information is used to indicate one or more management services; wherein, the authentication information and the authorized management service information are obtained by the cross-domain management function from the second management function; the authorized management service information indicates some or all of the management services among the one or more management services opened to the tenant.
33. The apparatus according to claim 32, characterized in that, The authorized management service information includes the types of management services and the versions of management services available to the tenant.
34. The apparatus according to claim 33, characterized in that, The management service types include one or more of the following: fault monitoring management service, performance assurance management service, network configuration management service, and heartbeat management service.
35. The apparatus according to claim 33 or 34, characterized in that, The authorized management service information also includes the component types of the management service type; the component types include operation types, network resource objects, and data information.
36. The apparatus according to any one of claims 32 to 34, characterized in that, The transceiver unit is also used for: Receives an identifier from the domain open capability control management function of the cross-domain management function; the domain open capability control management function is used to provide a first management service; The first management service is a part or all of the management services indicated by the authorized management service information; Send the identifier of the first management function to the domain open capability control and management function; The identifier of the first management function is used to authenticate the first management function.
37. The apparatus according to claim 35, characterized in that, The transceiver unit is also used for: The authentication information is sent to the domain open capability control and management function; the authentication information is used to authenticate the first management function.
38. A communication device, characterized in that, The device includes a processor and an interface circuit. The interface circuit is used to receive signals from other communication devices besides the communication device and transmit them to the processor, or to send signals from the processor to other communication devices besides the communication device. The processor is used to implement the method as described in any one of claims 1 to 7, or the method as described in any one of claims 8 to 9, or the method as described in any one of claims 10 to 15, through logic circuits or executing code instructions.
39. A communication system, characterized in that, It includes the communication device as described in any one of claims 23 to 29, the communication device as described in any one of claims 30 to 31, and the communication device as described in any one of claims 32 to 37.
40. A computer-readable storage medium, characterized in that, The storage medium stores a computer program or instructions, which, when executed by a communication device, implement the method as described in any one of claims 1 to 7, or the method as described in any one of claims 8 to 9, or the method as described in any one of claims 10 to 15.
Citation Information
Patent Citations
Authority control method and device
CN106878084A