Data transmission method, apparatus and system
By introducing a unified trust management framework at the business QoT level and the device QoT level, the problem of decoupling between the application side and the network side is solved, end-to-end trusted data transmission is achieved, and network service quality and user experience are improved.
Patent Information
- Application Number
- CN202210699339.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-20
- Publication Date
- 2026-01-02
- Estimated Expiration
- 2042-06-20
AI Technical Summary
In existing technologies, the application side and the network side are decoupled, making it impossible to establish a unified trust management framework. This makes it difficult to achieve end-to-end trusted data transmission, especially since the differences in trust requirements among different business types and end users have not been fully considered.
By introducing a unified trust management framework at the service QoT level and the device QoT level, terminal devices and management devices work together to issue QoT certificates, ensuring trust matching of communication connections. Network devices select appropriate transmission strategies based on trust requirements to achieve trusted transmission.
It improves network service quality and user experience, ensures the trustworthiness and reliability of data transmission, prevents malicious use of trustworthy data transmission services that are incompatible with terminal devices, and optimizes the utilization of network resources.
Smart Images

Figure CN117294769B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of communication, in particular to a data transmission method, device and system. BACKGROUND
[0002] With the development of artificial intelligence, big data, digital twin and other technologies, the value of data is increasingly prominent. Data is called the "oil" of digital economy. Therefore, how to ensure the orderly and reliable flow of data is crucial for the development of digital economy. As the underlying carrier of data flow and transmission, how to realize the secure and reliable transmission of data in the network is a problem that needs to be solved at present. SUMMARY
[0003] The present application provides a data transmission method, device and system, which can realize the secure and reliable transmission of data in the network.
[0004] In a first aspect, a data transmission method is provided. The method comprises: a terminal device obtaining a service quality of trust (QoT) level corresponding to a first service and a destination address of the first service, the service QoT level corresponding to the first service matching a device QoT level of the terminal device. The terminal device obtains a target connection identifier according to the service QoT level corresponding to the first service and the destination address of the first service, the target connection identifier being a connection identifier of a target communication connection established between the terminal device and the destination address of the first service and matching the service QoT level corresponding to the first service. The terminal device sends a service packet of the first service to the destination address of the first service, the service packet comprising the target connection identifier, the target connection identifier being used to indicate that the service packet is transmitted based on the target communication connection.
[0005] In the present application, since the service QoT level corresponding to the service transmitted by the terminal device matches the device QoT level of the terminal device, and the communication connection based on which the service is transmitted matches the service QoT level corresponding to the service, the network side can combine the credibility of the terminal device and the trust requirement of the service on data transmission to provide a matching trusted transmission for the service on the terminal device, thereby improving the service quality of the network and the service experience of the user.
[0006] Optionally, the terminal device stores a connection identifier set. The connection identifier set is used to record connection identifiers of communication connections established by the terminal device. Each connection identifier in the connection identifier set is provided with a destination address and a service QoT level. The terminal device obtains the target connection identifier according to the service QoT level corresponding to the first service and the destination address of the first service, and the implementation process includes: when the connection identifier set does not have a connection identifier corresponding to the destination address of the first service and the service QoT level corresponding to the first service, the terminal device sends a data transmission request to the management device, the data transmission request including the destination address of the first service and a QoT certificate of the terminal device, the QoT certificate including a device QoT level of the terminal device. The terminal device receives a data transmission response sent by the management device, and the data transmission response includes the target connection identifier.
[0007] In the present application, after the terminal device obtains the service QoT level corresponding to the first service and the destination address of the first service, the terminal device first queries whether the connection identifier set stores a connection identifier corresponding to the destination address of the first service and the service QoT level corresponding to the first service. If the connection identifier set stores a connection identifier corresponding to the destination address of the first service and the service QoT level corresponding to the first service, the terminal device takes the connection identifier as the target connection identifier.
[0008] Optionally, the QoT certificate further includes a QoT forwarding policy of the management device for the terminal device, and the QoT forwarding policy includes a highest service QoT level provided by the management device to the terminal device and / or a default service QoT level provided by the management device to the terminal device.
[0009] In the present application, by carrying the QoT forwarding policy of the management device for the terminal device in the QoT certificate, the application side QoT forwarding policy is formulated, so that the application side QoT forwarding policy and the network side QoT forwarding policy are matched as much as possible, so as to improve the service running efficiency.
[0010] Optionally, after the terminal device receives the data transmission response sent by the management device, the terminal device can add a corresponding relationship between the destination address of the first service, the service QoT level corresponding to the first service and the target connection identifier in the connection identifier set.
[0011] Optionally, the data transmission request further includes a service QoT level indication, and the service QoT level indication is used to indicate the service QoT level corresponding to the first service.
[0012] In the present application, if the service QoT level corresponding to the first service is the default service QoT level provided by the management device to the terminal device, the data transmission request can also not include the service QoT level indication. Correspondingly, the management device will directly establish a communication connection corresponding to the default service QoT level.
[0013] Optionally, the terminal device sends the QoT parameters of the terminal device to the management device, the QoT parameters including one or more of device identity information, hardware configuration information, software configuration information, or network access information. The terminal device receives the QoT certificate based on the QoT parameters sent by the management device.
[0014] Optionally, before the terminal device sends the QoT parameters of the terminal device to the management device, the terminal device sends a registration request to the management device. The terminal device receives a QoT authentication request sent by the management device, the QoT authentication request including a QoT parameter indication indicating the QoT parameters required to be provided by the terminal device. One implementation of the terminal device sending the QoT parameters of the terminal device to the management device includes: the terminal device sending a QoT authentication response to the management device, the QoT authentication response including the QoT parameters indicated by the QoT parameter indication.
[0015] Alternatively, the terminal device and the management device can also agree in advance on the QoT parameters required to be provided by the terminal device when issuing the QoT certificate, so that when the terminal device wants to obtain the QoT certificate, the terminal device can directly send the QoT parameters of the terminal device to the management device.
[0016] Optionally, when the QoT certificate meets a certificate update condition, the terminal device sends the latest QoT parameters of the terminal device to the management device. The terminal device receives an updated QoT certificate based on the latest QoT parameters sent by the management device.
[0017] Optionally, the certificate update condition includes one or more of the following: the QoT certificate exceeds a valid period; the QoT parameters of the terminal device change; and the terminal device and / or the management device cannot parse the QoT certificate.
[0018] Optionally, the service message further includes an indication of a service QoT level corresponding to the first service and an integrity verification tag for the indication. The integrity verification tag can be a message authentication code or a digital signature.
[0019] In this application, by carrying the indication of the service QoT level and the integrity verification tag for the indication in the service message, the network device receiving the service message can verify whether the actual service QoT level used by the service message is the same as the real service QoT level of the service, and can also verify whether the service message has been tampered with, thereby improving the reliability and credibility of data transmission.
[0020] Optionally, the terminal device obtains a service QoT level corresponding to the second service, and the service QoT level corresponding to the second service does not match the device QoT level of the terminal device. The terminal device rejects transmission of a service packet of the second service. In this way, malicious use of a trusted data transmission service that does not match the credibility of the terminal device can be avoided, so that the network side can meet the trust requirements of the service and also consider the credibility of the terminal device, thereby realizing trusted transmission of data.
[0021] In a second aspect, a data transmission method is provided. The method includes: a management device receiving a data transmission request sent by a terminal device, the data transmission request including a destination address of a first service and a QoT certificate of the terminal device, the QoT certificate including a device QoT level of the terminal device. The management device establishes a target communication connection between the terminal device and the destination address of the first service based on the QoT certificate, and a service QoT level corresponding to the target communication connection matches the device QoT level of the terminal device. The management device sends a data transmission response to the terminal device, the data transmission response including a target connection identifier, and the target connection identifier is a connection identifier of the target communication connection.
[0022] In the present application, the management device establishes a communication connection for a service on a terminal device that matches the device QoT level of the terminal device, and the management device can consider the credibility of the terminal device and provide matched trusted transmission for the service on the terminal device, thereby improving the service quality of the network and the service experience of the user.
[0023] Optionally, the data transmission request further includes a service QoT level indication, and the service QoT level indication is used to indicate the service QoT level corresponding to the first service. The implementation manner in which the management device establishes the target communication connection between the terminal device and the destination address of the first service based on the QoT certificate includes: when the service QoT level indicated by the service QoT level indication matches the device QoT level of the terminal device, the management device establishes the target communication connection corresponding to the service QoT level indicated by the service QoT level indication.
[0024] In the present application, the management device establishes a communication connection for a service on a terminal device that matches the device QoT level of the terminal device and a service QoT level corresponding to the service, and the management device can consider the credibility of the terminal device and the trust requirements of the service on data transmission, and provide matched trusted transmission for the service on the terminal device, thereby improving the service quality of the network and the service experience of the user.
[0025] Optionally, the QoT certificate further includes a QoT forwarding policy of the management device for the terminal device, and the QoT forwarding policy includes a highest service QoT level provided by the management device to the terminal device and / or a default service QoT level provided by the management device to the terminal device.
[0026] Optionally, the management device receives the QoT parameter of the terminal device sent by the terminal device, the QoT parameter comprising one or more of device identity information, hardware configuration information, software configuration information or network access information. The management device generates a QoT certificate based on the QoT parameter. The management device sends the QoT certificate to the terminal device.
[0027] Optionally, the management device receives a registration request sent by the terminal device. The management device sends a QoT authentication request to the terminal device based on the registration request, the QoT authentication request comprising a QoT parameter indication, the QoT parameter indication being used to indicate the QoT parameter required to be provided by the terminal device. The management device receives the QoT parameter of the terminal device sent by the terminal device, comprising: the management device receives a QoT authentication response sent by the terminal device, the QoT authentication response comprising the QoT parameter indicated by the QoT parameter indication.
[0028] Optionally, the management device receives a path calculation request of the network device, the path calculation request comprising a target connection identifier. The management device determines a target transmission path used by a target communication connection according to a service QoT level corresponding to the target connection identifier, a device QoT level of a network device on the target transmission path matching the service QoT level corresponding to the target connection identifier. The management device sends a path calculation response to the network device, the path calculation response comprising path information of the target transmission path.
[0029] In a third aspect, a data transmission method is provided. The method comprises: a network device receiving a service packet of a first service sent by a terminal device, the service packet comprising a target connection identifier. The network device obtains a target transmission path corresponding to the target connection identifier, a device QoT level of a network device on the target transmission path matching a service QoT level corresponding to the target connection identifier. The network device forwards the service packet based on the target transmission path.
[0030] In this application, the transmission path based on which the network device transmits the service packet matches the service QoT level corresponding to the service packet, so that the network side can consider the trust demand of the service on data transmission, provide a matching trusted transmission for the service on the terminal device, and improve the service quality of the network and the service experience of the user.
[0031] Optionally, an implementation manner of the network device obtaining the target transmission path corresponding to the target connection identifier comprises: the network device sends a path calculation request to the management device, the path calculation request comprising the target connection identifier. The network device receives a path calculation response sent by the management device, the path calculation response comprising path information of the target transmission path.
[0032] Optionally, the service packet further comprises an indication of a service QoT level corresponding to the first service and an integrity verification tag for the indication, and the network device forwards the service packet based on the target transmission path according to an implementation manner of the network device, which comprises: when the service QoT level indicated by the indication in the service packet is the same as a service QoT level corresponding to the target connection identifier, and the integrity verification tag is verified by the network device, the network device forwards the service packet based on the target transmission path.
[0033] In the present application, by carrying the indication of the service QoT level and the integrity verification tag for the indication in the service packet, the network device receiving the service packet can verify whether the service QoT level actually used by the service packet is the same as the service QoT level of the service that is truly matched, and can further verify whether the service packet is tampered, thereby improving the reliability and credibility of data transmission.
[0034] In a fourth aspect, a terminal device is provided. The terminal device includes a plurality of functional modules that interact to implement the method of the first aspect and its embodiments. The plurality of functional modules can be implemented based on software, hardware, or a combination of software and hardware, and the plurality of functional modules can be combined or divided based on specific implementation.
[0035] In a fifth aspect, a management device is provided. The management device includes a plurality of functional modules that interact to implement the method of the second aspect and its embodiments. The plurality of functional modules can be implemented based on software, hardware, or a combination of software and hardware, and the plurality of functional modules can be combined or divided based on specific implementation.
[0036] In a sixth aspect, a network device is provided. The network device includes a plurality of functional modules that interact to implement the method of the third aspect and its embodiments. The plurality of functional modules can be implemented based on software, hardware, or a combination of software and hardware, and the plurality of functional modules can be combined or divided based on specific implementation.
[0037] In a seventh aspect, a data transmission system is provided, which includes a terminal device, a management device, and a network device. The terminal device is configured to implement the method of the first aspect and its embodiments, the management device is configured to implement the method of the second aspect and its embodiments, and the network device is configured to implement the method of the third aspect and its embodiments.
[0038] In an eighth aspect, a data transmission apparatus is provided, which includes a processor and a memory.
[0039] The memory is configured to store a computer program, and the computer program includes program instructions.
[0040] The processor is configured to invoke the computer program to implement the method in any one of the first aspect to the third aspect and the embodiments thereof.
[0041] In a ninth aspect, a computer-readable storage medium is provided, and the computer-readable storage medium stores instructions thereon. When the instructions are executed by a processor, the method in any one of the first aspect to the third aspect and the embodiments thereof is implemented.
[0042] In a tenth aspect, a computer program product is provided, and the computer program product includes a computer program. When the computer program is executed by a processor, the method in any one of the first aspect to the third aspect and the embodiments thereof is implemented.
[0043] In an eleventh aspect, a chip is provided, and the chip includes programmable logic circuitry and / or program instructions. When the chip is running, the method in any one of the first aspect to the third aspect and the embodiments thereof is implemented. BRIEF DESCRIPTION OF DRAWINGS
[0044] Figure 1 is an application scenario diagram to which a data transmission method provided by an embodiment of the present application relates;
[0045] Figure 2 is an implementation flow diagram of a data transmission method provided by an embodiment of the present application;
[0046] Figure 3 is an implementation flow diagram of another data transmission method provided by an embodiment of the present application;
[0047] Figure 4 is an implementation scenario diagram provided by an embodiment of the present application;
[0048] Figure 5 is a system architecture diagram provided by an embodiment of the present application;
[0049] Figure 6 is a registration flow diagram in a DMM-FE and TLV-FE separation scenario provided by an embodiment of the present application;
[0050] Figure 7 is a registration flow diagram in a DMM-FE and TLV-FE combination scenario provided by an embodiment of the present application;
[0051] Figure 8 is a data transmission flow diagram provided by an embodiment of the present application;
[0052] Figure 9 is a structure diagram of a terminal device provided by an embodiment of the present application;
[0053] Figure 10 FIG. 3 is a structural schematic diagram of another terminal device provided by an embodiment of the present application;
[0054] Figure 11 FIG. 4 is a structural schematic diagram of a management device provided by an embodiment of the present application;
[0055] Figure 12 FIG. 5 is a structural schematic diagram of a network device provided by an embodiment of the present application;
[0056] Figure 13 FIG. 6 is a hardware structural schematic diagram of a terminal device provided by an embodiment of the present application;
[0057] Figure 14 FIG. 7 is a hardware structural schematic diagram of a management device provided by an embodiment of the present application;
[0058] Figure 15 FIG. 8 is a hardware structural schematic diagram of a network device provided by an embodiment of the present application. DETAILED DESCRIPTION
[0059] In order to make the purpose, technical solutions and advantages of the present application clearer, the embodiments of the present application will be further described in detail below with reference to the drawings.
[0060] In recent years, with the rapid development and large-scale commercialization of the fifth-generation mobile communication (5G) technology, the global academic and industrial circles have started to research and explore the next-generation network technology, and numerous researchers and research institutions have carried out a large number of researches and discussions on the vision, architecture and key technologies of future networks. Among them, security and trust have become the research field that many institutions and manufacturers focus on.
[0061] With the development of artificial intelligence, big data, digital twin and other technologies, the value of data is increasingly prominent. Data is called the "oil" of the digital economy. Therefore, how to ensure the orderly and trustworthy flow of data is crucial for the development of the digital economy. As the underlying carrier of data flow and transmission, how to ensure trustworthy networking and data transmission is one of the key enabling technologies for future network trustworthiness.
[0062] Currently, in the field of trusted networking and data transmission, the International Telecommunicatons Union Telecommunication Standardization Sector (ITU-T) has carried out a lot of research work, and is studying or has published several technical standards. For example, ITU-T Y.3052 gives the definition of trust and the basic framework of trust in the field of information and communications technology (ICT). In the scenario of network data transmission, the data sender is the trustor, the network device is the trustee, and the trust refers to the expectation of the data sender that the network device will help it complete data transmission according to the established behavior. For another example, ITU-T Y.3053 proposes a trusted networking architecture based on trust domain, and on this basis proposes a method of trusted data transmission. In this architecture, the network is divided into multiple trust domains, and the entities in a single trust domain trust each other and can directly transmit data without security protection. When entities in different trust domains transmit data, they need to pass through their respective access and delivery control functions for control to achieve trusted data transmission. The trust domain is the full name of the trust-centric network domain.
[0063] However, although a lot of research work has been done in the field of trusted networking and data transmission, there are still many problems to be solved at present, one of which is that the application side and the network side are decoupled, and a unified trust management framework cannot be established to support end-to-end trusted data transmission. With the advent of the 5G era, various new applications have emerged in an endless stream, but the network is still regarded as the pipe of the application and cannot perceive the application. According to the definition of trust in ITU-T Y.3052, trust is highly related to context. In the scenario of network data transmission, different applications represent different contexts. There are many types of applications, and different business types are involved. The trust requirements of data of different business types for the network and the running environment are different.
[0064] Based on this, the application provides a technical solution, which establishes a unified trust management framework for the application side and the network side, realizes unified trust management for the application side and the network side, so that the application side can express the trust requirement of data transmission to the network side, the network side can also judge whether a certain service can use a certain specific data transmission service of a certain trust level, and select a suitable processing strategy, such as access control and routing control, for the service data with different trust requirements. The higher the trust requirement of the service to the network side data transmission is, the higher the trust level of the data transmission service used by the network side should be.
[0065] Quality of service (QoS) and quality of experience (QoE) are defined in ITU-T. QoS is used to reflect the degree that service quality can be achieved in a quantitative manner. QoE is used to reflect the degree that user experiences good or bad service in a quantitative manner. Based on QoS and QoE, the network side can make adjustments according to relevant parameters, and treat different services and users differently, so as to improve the service quality of the network and the service experience of the user. Similarly, different services have different trust requirements for network side data transmission. For example, the trust requirement of payment type service for network side data transmission is higher than that of video type service for network side data transmission. In addition, the network side also needs to distinguish different terminal users to prevent some terminal users from maliciously using trust data transmission services that do not match them, wasting or even destroying network resources. Therefore, in order to realize data trusted transmission, the trust requirement of service for data transmission needs to be quantified, so that the network side can realize customized data transmission service according to different trust requirements. In addition, a unified trust management system for application side and network side needs to be formulated based on a unified trust quantification method. Based on this, the present application proposes the concept of QoT. QoT is used to quantitatively describe the trustworthiness of the device and the trust requirement of the service for network side data transmission. Specifically, the trustworthiness of the device and the trust requirement of the service for network side data transmission can be quantitatively described by grading or scoring. Among them, grading means that QoT is divided into multiple levels, and different QoT levels represent different trustworthiness of the device or different trust requirement of the service for network side data transmission. In the embodiments of the present application, QoT is mainly divided into 5 levels for example. The 5 levels include QoT levels 1-5, and the higher the level, the more trusted the device or the higher the trust requirement of the service for data transmission. The grading method of QoT in the embodiments of the present application is not limited. By dividing different QoT levels, the trust requirement of different types of services for data transmission can be met at various granularities. Scoring means that the trustworthiness of the device is scored according to the trustworthiness of the device or the trust requirement of the service for network side data transmission is scored according to the trust requirement of the service for network side data transmission in a preset scoring interval, and different scores represent different trustworthiness of the device or different trust requirement of the service for network side data transmission. For example, the scoring interval can be 0 to 1, or it can also be 0 to 100, and the range of the scoring interval is not limited in the embodiments of the present application.
[0066] In the embodiments of the present application, a mapping relationship between the QoT score and the QoT level can be set. For example, the preset scoring interval is 0 to 1, and the QoT level is 1-5. Among them, the QoT score 0-0.2 corresponds to the QoT level 1, the QoT score 0.2-0.4 corresponds to the QoT level 2, the QoT score 0.4-0.6 corresponds to the QoT level 3, the QoT score 0.6-0.8 corresponds to the QoT level 4, and the QoT score 0.8-1 corresponds to the QoT level 5. In the specific implementation, the credibility of the device can be scored or the trust requirement of the service can be scored first, and then the corresponding QoT level is determined according to the QoT score obtained by scoring. For example, the credibility score of a certain device is 0.5, and the device corresponds to the QoT level 3. In the present application, the device credibility and the trust requirement of the service for data transmission of the network side are quantitatively described in a hierarchical manner. If the device credibility and the trust requirement of the service for data transmission of the network side are quantitatively described in a scoring manner, the QoT score can be used to replace the description of the QoT level.
[0067] In order to facilitate the understanding of the scheme of the present application by the reader, first, the QoT level involved in the present application is explained and described. The present application involves two concepts of device QoT level and service QoT level.
[0068] The service QoT level is used to represent the trust requirement of the service for data transmission. The higher the service QoT level, the higher the trust requirement of the service for data transmission. The service QoT level is related to the service type. The service QoT level corresponding to each service type can be pre-set. For example, the service QoT level corresponding to the payment type service can be set to 4, the service QoT level corresponding to the user information type service can be set to 3, and the service QoT level corresponding to the multimedia stream service can be set to 2, etc. The network side and the application side can pre-store the corresponding relationship between the service type and the service QoT level.
[0069] The device QoT level is used to represent the credibility of the device. The higher the device QoT level, the more credible the device. The device QoT level is related to the device itself information. For a terminal device, the higher the device QoT level, the higher the service QoT level corresponding to the service that the terminal device can run. For a network device, the higher the device QoT level, the higher the service QoT level corresponding to the service that the network device can forward. In the embodiments of the present application, the credibility of the device also reflects the security of the device, and accordingly, the device QoT level can also be used to represent the security of the device. For a terminal device, the higher the device QoT level, the safer the running environment of the terminal device and / or the network environment in which the terminal device is located. For a network device, the higher the device QoT level, the safer the data transmission service that the network device can provide.
[0070] Optionally, the device QoT level and the service QoT level can be one-to-one correspondence, that is, the device QoT level and the service QoT level have the same division granularity. In this case, for the network device, the network device is usually used to forward the service whose service QoT level is the same as the device QoT level of the network device. For example, the device QoT level of the network device is 3, and the network device can forward the service whose service QoT level is 3. Of course, it is also possible that the network device can forward the service whose service QoT level is lower or slightly higher than the device QoT level of the network device. For the terminal device, the terminal device usually supports the service whose service QoT level is not higher than the device QoT level of the terminal device. For example, the device QoT level of the terminal device is 3, and the terminal device can operate the service whose service QoT level is 1-3. Of course, it is also possible that the terminal device can operate the service whose service QoT level is slightly higher than the device QoT level of the terminal device. For example, the device QoT level of the terminal device is 3, and the terminal device can operate the service whose service QoT level is 1-4. However, when the terminal device operates the service whose service QoT level is 4, there may be a certain security risk due to the device QoT level of the terminal device, and the terminal device can give an alarm prompt at this time. In the embodiment of the application, the service QoT level supported by the terminal device is referred to as the service QoT level matched with the device QoT level of the terminal device. The service QoT level supported by the network device is referred to as the service QoT level matched with the device QoT level of the network device.
[0071] Alternatively, the device QoT level and the service QoT level can also be one-to-many, that is, the division granularity of the device QoT level is coarser than the division granularity of the service QoT level. For example, the device QoT level is divided into 5 levels, and the service QoT level is divided into 10 QoT levels. For the network device, the device QoT level 1 is matched with the service QoT level 1-2, the device QoT level 2 is matched with the service QoT level 3-4, the device QoT level 3 is matched with the service QoT level 5-6, the device QoT level 4 is matched with the service QoT level 7-8, and the device QoT level 5 is matched with the service QoT level 9-10. For the terminal device, the device QoT level 1 is matched with the service QoT level 1-2, the device QoT level 2 is matched with the service QoT level 1-4, the device QoT level 3 is matched with the service QoT level 1-6, the device QoT level 4 is matched with the service QoT level 1-8, and the device QoT level 5 is matched with the service QoT level 1-10.
[0072] Alternatively, the device QoT level and the service QoT level can also be one-to-many, that is, the division granularity of the device QoT level is coarser than the division granularity of the service QoT level. For example, the device QoT level is divided into 5 levels, and the service QoT level is divided into 10 QoT levels. For the network device, the device QoT level 1 is matched with the service QoT level 1-2, the device QoT level 2 is matched with the service QoT level 3-4, the device QoT level 3 is matched with the service QoT level 5-6, the device QoT level 4 is matched with the service QoT level 7-8, and the device QoT level 5 is matched with the service QoT level 9-10. For the terminal device, the device QoT level 1 is matched with the service QoT level 1-2, the device QoT level 2 is matched with the service QoT level 1-4, the device QoT level 3 is matched with the service QoT level 1-6, the device QoT level 4 is matched with the service QoT level 1-8, and the device QoT level 5 is matched with the service QoT level 1-10.
[0073] The application embodiments do not limit the division manner of the service QoT level and the device QoT level. In addition, the service QoT level matched by the device QoT level of the terminal device and the service QoT level matched by the device QoT level of the network device respectively depend on the decision of the network side, and the application embodiments do not limit this.
[0074] On the basis of uniformly dividing the device QoT level and the service QoT level on the application side and the network side, the application proposes a technical solution. After the terminal device obtains the service QoT level corresponding to a service, in the case that the service QoT level corresponding to the service matches the device QoT level of the terminal device, the terminal device obtains a connection identifier of a communication connection established between the terminal device and a destination address of the service, which matches the service QoT level corresponding to the service, and then carries the connection identifier in a service packet of the service sent to the destination address of the service, to instruct the network device receiving the service packet to transmit the service packet based on the communication connection corresponding to the connection identifier. Since the service QoT level corresponding to the service transmitted by the terminal device matches the device QoT level of the terminal device, and the communication connection based on which the service is transmitted matches the service QoT level corresponding to the service, the network side can combine the credibility of the terminal device and the trust requirement of the service on data transmission to provide matched trusted transmission for the service on the terminal device, thereby improving the service quality of the network and the service experience of the user.
[0075] The application scene, the method flow, the function module, the software device, the hardware device, the system and the like are described below.
[0076] The application scene related to the application embodiments is described below by way of example.
[0077] For example, Figure 1 is an application scene diagram of a data transmission method provided by the application embodiments. As shown in Figure 1 , the application scene includes a terminal device 101, a network device 102 and a management device 103. Figure 1 The number of various devices in the application scene is only used for example description, and does not limit the application scene related to the application embodiments.
[0078] Optionally, the data transmission method provided by the application embodiments can be applied to a mobile cellular network or an Internet Protocol (IP) network. The IP network includes a data center network (DCN), a metropolitan area network, a wide area network or a campus network, etc.
[0079] In a mobile cellular network, the terminal device 101 can be a user equipment (UE), an access terminal, a subscriber unit, a subscriber station, a mobile station, a mobile, a remote station, a remote terminal, a mobile device, a wireless communication device, a user agent, or a user device. Alternatively, the terminal device 101 can also be a cellular phone, a cordless phone, a Session Initiation Protocol (SIP) phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), a handheld device with wireless communication function, a computing device, or other processing device connected to a wireless modem, an in-vehicle device, a wearable device, a terminal device in a 5G system (5GS), or a terminal device in a future evolved public land mobile network (PLMN), etc. The network device 102 can be an access network device. The access network device is used to provide a wireless communication function for the terminal device 101. The terminal device 101 can establish a communication relationship between the access network device and the core network device. The access network device can be various forms of macro base stations, micro base stations, relay stations, access points, etc. The management device 103 can be a core network device. The function of the core network device is mainly to provide user connection, management of users, and completion of service bearing, and to provide an interface to an external network as a bearing network. For example, the core network device can include an access and mobility management function (AMF) entity, a user plane function (UPF) entity, a session management function (SMF) entity, etc.
[0080] In an IP network, the terminal device 101 can be a workstation, such as a computer, a server, or a virtual machine (VM), etc. The network device 102 can be a router, a switch, or a firewall, etc. The management device 103 can be a network controller, a network management device, a gateway, or other device with control capability. The management device 103 is connected to the network device 102 through a wired network or a wireless network. The management device 103 is used to manage and control the network device 102.
[0081] The method flow of the embodiments of the present application is described below.
[0082] Optionally, the technical scheme of the present application mainly includes two implementation stages, namely, a registration stage and a data transmission stage. In the registration stage, the network side performs trust evaluation on the terminal device, and issues a QoT certificate for the terminal device according to the evaluation result, so as to perform QoT authorization management on the terminal device through the QoT certificate. In the data transmission stage, the terminal device uses the QoT certificate to establish a communication connection with the network side, and the network side decides whether to allow the establishment of the communication connection according to the QoT certificate of the terminal device, so as to realize the function of access control. In a mobile cellular network, the communication connection can refer to a session. In an IP network, the communication connection can refer to a tunnel. The following embodiments of the present application will describe the implementation process of the registration stage and the data transmission stage in detail.
[0083] In an embodiment of the present application, the implementation process of the registration stage is provided. For example, Figure 2 is a schematic diagram of an implementation process of a data transmission method 200 provided by an embodiment of the present application. The method 200 only shows the implementation process of the registration stage. As shown in Figure 2 , the method 200 includes steps 201 to 205.
[0084] Step 201: The terminal device sends a registration request to the management device.
[0085] The registration request is used for the terminal device to apply to the management device to initiate the registration process. Optionally, the registration request includes a device identifier of the terminal device. The device identifier of the terminal device can uniquely identify the terminal device. For example, the device identifier of the terminal device can be a device serial number of the terminal device, a media access control (MAC) address of the terminal device, an IP address of the terminal device, or an international mobile equipment identity (IMEI) of the terminal device. Optionally, the registration request also includes a user identifier of the terminal device. For example, the user identifier can be a subscription permanent identifier (SUPI).
[0086] Step 202: The management device sends a QoT authentication request to the terminal device based on the registration request, and the QoT authentication request includes a QoT parameter indication.
[0087] The QoT parameter indication is used to indicate the QoT parameters required to be provided by the terminal device. Optionally, the QoT parameters include one or more of device identity information, hardware configuration information, software configuration information, or network access information. The device identity information includes a device identifier. The device identity information can also include a user identifier and / or an original equipment manufacturer (OEM) identifier. The hardware configuration information includes, but is not limited to, a device type, a hardware version, a trusted execution environment (TEE) capability, or a secure or trusted boot capability. The software configuration information includes, but is not limited to, an operating system (OS) version or patches. The network access information includes, but is not limited to, a radio access technology (RAT), a security level, or an access point location. The radio access technology includes, but is not limited to, long term evolution (LTE), 5G, or wireless local area network (WLAN).
[0088] Optionally, the QoT parameter indication can be in a bitmap format. For example, a bit corresponding to a mandatory parameter can be set to 1, and a bit corresponding to an optional parameter can be set to 0. For example, the management device requires the terminal device to provide 8 QoT parameters, the first 4 QoT parameters are mandatory parameters, and the last 4 QoT parameters are optional parameters. The QoT parameter indication can be set to 11110000.
[0089] Optionally, the QoT authentication request further includes a random number. By carrying the random number in the QoT authentication request, it is helpful for the terminal device to identify a replay attack.
[0090] Optionally, the QoT authentication request further includes a device identifier of the terminal device and / or a user identifier of the terminal device.
[0091] In step 203, the terminal device sends a QoT authentication response to the management device, the QoT authentication response including the QoT parameters indicated by the QoT parameter indication.
[0092] Optionally, after receiving the QoT authentication request sent by the management device, the terminal device parses the QoT parameter indication and collects the corresponding parameter information, and packs the parameter information into a QoT parameter list, and then sends a QoT authentication response carrying the QoT parameter list to the management device based on the QoT authentication request.
[0093] Optionally, before the terminal device sends the QoT authentication response to the management device, the terminal device and the management device can first perform authentication and key agreement, and agree on a pair of asymmetric keys or a symmetric key. The embodiments of the present application take the terminal device and the management device sharing a symmetric key k as an example for illustration. In this way, the terminal device can use the symmetric key k to encrypt the QoT parameters of the terminal device for transmission, so as to improve the transmission confidentiality and security of the QoT parameters.
[0094] Optionally, if the QoT authentication request includes a random number, the QoT authentication response can also include the random number.
[0095] In the embodiments of the present application, the terminal device and the management device can also agree on the QoT parameters required to be provided by the terminal device when issuing the QoT certificate in advance. In this way, when the terminal device wants to obtain the QoT certificate, the terminal device can directly send the QoT parameters of the terminal device to the management device. That is, the above steps 201 to 203 can be replaced by: the terminal device sends the QoT parameters of the terminal device to the management device.
[0096] Step 204, the management device generates the QoT certificate of the terminal device based on the QoT parameters sent by the terminal device.
[0097] The QoT certificate of the terminal device includes the device QoT level of the terminal device. The management device performs trust evaluation on the terminal device according to the QoT parameters of the terminal device, and issues a QoT certificate for the terminal device using its own private key according to the evaluation result. For example, the trust evaluation standard of the management device on the terminal device can be as shown in Table 1.
[0098] Table 1
[0099]
[0100] In Table 1, "a>b" means that the device QoT level corresponding to a is higher than the device QoT level corresponding to b. Whether the OEM is trusted can be judged by the management device itself.
[0101] Optionally, after determining the device QoT level of the terminal device, the management device can further determine the service QoT level allowed to be used by the terminal device and the default service QoT level used by the terminal device. For example, the QoT forwarding policy set by the management device for terminal devices with different device QoT levels can be as shown in Table 2.
[0102] Table 2
[0103]
[0104] Referring to Table 2, the management device can set a mapping relationship between the QoT score and the device QoT level of the terminal device. When performing trust evaluation on the terminal device, the management device can first score the terminal device according to the QoT parameter of the terminal device, and then take the device QoT level corresponding to the QoT score obtained by the scoring as the device QoT level of the terminal device. Alternatively, the management device can also directly determine the device QoT level of the terminal device according to the QoT parameter of the terminal device, that is, the QoT score item in Table 2 can not be set.
[0105] Optionally, the QoT certificate of the terminal device further includes a QoT forwarding policy of the management device for the terminal device, and the QoT forwarding policy includes a highest service QoT level provided by the management device to the terminal device and / or a default service QoT level provided by the management device to the terminal device. For example, the QoT certificate of the terminal device can be based on the certificate format of X.509, and the QoT capability is extended using an extension field. For example, the content of the QoT certificate of the terminal device can be represented as follows:
[0106]
[0107] 1. OS version of the terminal device
[0108] 2. Device serial number of the terminal device
[0109] 3. Signature algorithm
[0110] 4. Signature hash algorithm
[0111] 5. Issuer: domain name or domain ID
[0112] 6. Validity period: xx / xx / xx-xx / xx / xx
[0113] 7. User: user ID
[0114] 8. Public key
[0115] 9. QoT information of the terminal device
[0116] 9.1 Verification result (device QoT level = 3)
[0117] 9.2 QoT parameter used
[0118] 9.3 Supported service QoT level: 1-4
[0119] 9.4 Default service QoT level: 2
[0120] 10. Digital signature
[0121]
[0122] Optionally, if the QoT parameter in the QoT authentication response is encrypted by the symmetric key k, the management device decrypts the QoT parameter in the QoT authentication response by the symmetric key k to obtain the QoT parameter of the terminal device after receiving the QoT authentication response.
[0123] Optionally, if the QoT authentication response carries the random number, the management device verifies the freshness of the message based on the random number in the QoT authentication response after receiving the QoT authentication response. After the verification is passed, the management device performs the trust evaluation on the terminal device. By carrying the random number in the QoT authentication response, on the one hand, the management device can perform the message freshness verification, and on the other hand, it is helpful for the management device to identify the replay attack.
[0124] Step 205, the management device sends the QoT certificate to the terminal device.
[0125] After receiving the QoT certificate sent by the management device, the terminal device stores the QoT certificate. The application on the terminal device can perceive the information in the QoT certificate of the terminal device and set the local QoT forwarding policy. For example, the QoT forwarding policy set by the application for the terminal device with different device QoT levels can be as shown in Table 3.
[0126] Table 3
[0127]
[0128]
[0129] Referring to Table 3, the processing policy "allow" means that the application can run the corresponding service QoT level service. The processing policy "allow and warn" means that the application can run the corresponding service QoT level service but will alert the user. The processing policy "prohibit" means that the application is prohibited to run the corresponding service QoT level service. The QoT forwarding policy on the application side can be manually changed by the user, for example, the user can manually change the processing policy corresponding to the service QoT level.
[0130] Optionally, when the QoT certificate of the terminal device meets the certificate update condition, the terminal device sends the latest QoT parameter of the terminal device to the management device. The management device generates an updated QoT certificate based on the latest QoT parameter of the terminal device. Then, the management device sends the updated QoT certificate to the terminal device. After receiving the updated QoT certificate sent by the management device, the terminal device stores the updated QoT certificate and considers the original QoT certificate invalid. After the QoT certificate of the terminal device is changed, the application on the terminal device adjusts the QoT forwarding policy according to the updated QoT certificate.
[0131] Optionally, the certificate update procedure can be triggered by the terminal device, and the implementation process of the certificate update can refer to steps 201 to 205 described above. Alternatively, the certificate update procedure can also be triggered by the management device, and the implementation process of the certificate update can refer to steps 202 to 205 described above. Embodiments of the present application will not be described again.
[0132] Optionally, the certificate update condition of the QoT certificate includes one or more of the following: the QoT certificate exceeds the valid period; the QoT parameter of the terminal device changes; the terminal device and / or the management device cannot parse the QoT certificate. For example, the valid period of the QoT certificate issued by the management device is 24 hours, and after the QoT certificate expires, the terminal device or the management device can trigger the certificate update procedure. For another example, during the valid period of the original QoT certificate, the terminal device undergoes system update, restart, network standard switching (for example, switching from WLAN to 5G), or base station switching, etc., and the terminal device can trigger the certificate update procedure. If the original QoT certificate of the terminal device is invalid due to the change of the QoT parameter of the terminal device or the terminal device and / or the management device cannot parse the original QoT certificate of the terminal device, the management device also needs to revoke the original QoT certificate of the terminal device.
[0133] In another embodiment of the present application, an implementation procedure of the data transmission phase is provided. For example, Figure 3 is an implementation procedure diagram of a data transmission method 300 provided by an embodiment of the present application. The method 300 shows the implementation procedure of the data transmission phase. As shown in Figure 3 , the method 300 includes steps 301 to 305.
[0134] Step 301, the terminal device obtains the service QoT level corresponding to the first service and the destination address of the first service.
[0135] The service QoT level corresponding to the first service matches the device QoT level of the terminal device.
[0136] The user starts an application on the terminal device and selects a service, and the application determines the service QoT level corresponding to the service selected by the user according to the corresponding relationship between the locally preset service type and the service QoT level. For example, the QoT forwarding strategy set on the application side is shown in Table 3, and there are the following three possible cases.
[0137] The first possible case is that the processing strategy corresponding to the service QoT level corresponding to the service selected by the user is allowed. Then the application directly generates a service message (message) and sends it by the terminal device. The service message includes an indication of the service QoT level required for transmitting the service message, a destination (destination), and service data (data).
[0138] In the second possible case, the processing strategy corresponding to the service QoT level corresponding to the service selected by the user is to allow and warn. The application explicitly sends a warning to the user, prompting the user that the service QoT level corresponding to the service selected by the user is higher than the device QoT level of the terminal device (for example, the device QoT level of the terminal device is 2, and the service QoT level corresponding to the service selected by the user is 3), and gives the user options (for example, including continue or stop), and the user selects whether to continue running the service. If the user chooses to continue, the application generates a service message and sends it by the terminal device. If the user chooses to stop, the application stops running the service. Optionally, the application explicitly sends a warning to the user, which can be to display warning information and user options on the application interface.
[0139] In the above-mentioned first possible case and second possible case, the service QoT level corresponding to the service selected by the user is considered to match the device QoT level of the terminal device.
[0140] In the third possible case, the processing strategy corresponding to the service QoT level corresponding to the service selected by the user is to prohibit. The application explicitly informs the user of the denial of service. The application can also explicitly inform the reason for the denial, which is that the service QoT level corresponding to the service currently selected by the user does not match the device QoT level of the terminal device.
[0141] In step 302, the terminal device obtains a target connection identifier according to the service QoT level corresponding to the first service and the destination address of the first service.
[0142] The target connection identifier is the connection identifier of the target communication connection established between the terminal device and the destination address of the first service, which matches the service QoT level corresponding to the first service.
[0143] Optionally, the terminal device stores a connection identifier set, which is used to record the connection identifiers of the communication connections established by the terminal device, and each connection identifier in the connection identifier set is correspondingly provided with a destination address and a service QoT level. After the terminal device obtains the service QoT level corresponding to the first service and the destination address of the first service, it first queries whether the connection identifier set stores a connection identifier corresponding to the destination address of the first service and the service QoT level corresponding to the first service. When there is no connection identifier corresponding to the destination address of the first service and the service QoT level corresponding to the first service in the connection identifier set, the following steps 3021 to 3023 are performed.
[0144] In step 3021, the terminal device sends a data transmission request to the management device, and the data transmission request includes the destination address of the first service and the QoT certificate of the terminal device.
[0145] After receiving the data transmission request sent by the terminal device, the management device establishes a target communication connection between the terminal device and the destination address of the first service based on the QoT certificate in the data transmission request. Alternatively, after receiving the data transmission request sent by the terminal device, the management device can first verify whether the QoT certificate in the data transmission request is valid, and then establish the corresponding communication connection in the case that the QoT certificate is valid.
[0146] Alternatively, the data transmission request can also not include the service QoT level indication if the service QoT level corresponding to the first service is a default service QoT level provided by the management device to the terminal device.
[0147] In the case that the data transmission request includes the service QoT level indication, when the service QoT level indicated by the service QoT level indication matches the device QoT level of the terminal device, the management device establishes a communication connection corresponding to the service QoT level indicated by the service QoT level indication. When the service QoT level indicated by the service QoT level indication does not match the device QoT level of the terminal device, the management device refuses to establish a communication connection corresponding to the service QoT level indicated by the service QoT level indication. Alternatively, the management device can obtain the device QoT level of the terminal device from the QoT certificate of the terminal device.
[0148] In the case that the data transmission request does not include the service QoT level indication, the management device establishes a communication connection corresponding to the default service QoT level provided to the terminal device. Alternatively, the management device can obtain the default service QoT level provided to the terminal device from the QoT certificate of the terminal device.
[0149] In step 3022, the terminal device receives the data transmission response sent by the management device, and the data transmission response includes a target connection identifier.
[0150] Alternatively, the data transmission response can also include some QoT policies, such as whether the terminal device is allowed to transmit services with a service QoT level lower than the service QoT level corresponding to the target communication connection based on the target communication connection, and the like.
[0151] In step 3023, the terminal device adds a correspondence relationship between the destination address of the first service, the service QoT level corresponding to the first service and the target connection identifier in the connection identifier set.
[0152] In this way, when the terminal device needs to subsequently transmit a service whose destination address is the same as that of the first service and whose service QoT level is the same as that corresponding to the first service, the terminal device can directly obtain the target connection identifier from the connection identifier set, indicating that the terminal device has established a target communication connection that meets the QoT requirement.
[0153] At step 303, the terminal device sends a service message of the first service to the destination address of the first service, the service message including the target connection identifier.
[0154] The target connection identifier in the service message of the first service is used to indicate that the service message is transmitted based on the target communication connection.
[0155] Optionally, the service message of the first service further includes an indication of the service QoT level corresponding to the first service and an integrity verification tag for the indication. Optionally, the integrity verification tag for the indication can be a message authentication code (MAC) calculated by the terminal device on the indication using a symmetric key k, or can also be a signature of the terminal device on the indication using a private key. The integrity verification tag is used to verify the message integrity and whether it is tampered.
[0156] Optionally, a QoT header is extended in the message header of the service message of the first service to carry the indication of the service QoT level corresponding to the first service. The indication of the service QoT level corresponding to the first service can be specifically the service QoT level corresponding to the first service, or can also be the service type of the first service, and the network side can determine the service QoT level corresponding to the first service based on a pre-set correspondence between the service type and the service QoT level according to the service type of the first service.
[0157] After the network device receives the service message of the first service, the following steps 304 to 305 are performed. Optionally, in the case where the service message received by the network device includes the indication of the service QoT level corresponding to the first service and the integrity verification tag for the indication, the network device first verifies the integrity verification tag, and performs the following steps 304 to 305 on the premise that the verification is passed. Otherwise, the network device directly discards the service message.
[0158] At step 304, the network device obtains a target transmission path corresponding to the target connection identifier, the device QoT level of the network device on the target transmission path matching the service QoT level corresponding to the target connection identifier.
[0159] In a possible implementation, the implementation of step 304 includes that the network device sends a path calculation request to the management device, where the path calculation request includes the target connection identifier. The network device receives a path calculation response sent by the management device, where the path calculation response includes the path information of the target transmission path.
[0160] Correspondingly, for the management device, after receiving the path calculation request from the network device, the management device determines the target transmission path used by the target communication connection according to the service QoT level corresponding to the target connection identifier, where the device QoT level of the network device on the target transmission path matches the service QoT level corresponding to the target connection identifier. Then the management device sends a path calculation response to the network device.
[0161] Optionally, the management device is responsible for the QoT information management of the whole life cycle of the network device, including initialization, modification, update, storage, distribution, deletion, and the like of the device QoT level. The management device can determine the device QoT level of each network device according to the software configuration information, the hardware configuration information, the runtime state, the reliability of the manufacturer, and the historical forwarding performance, and the like of the network device.
[0162] In another possible implementation, after establishing the target communication connection, the management device determines the target transmission path used by the target communication connection, and then carries the path information of the target transmission path in a data transmission response sent to the terminal device. The data transmission response is forwarded to the terminal device by the network device. Here, the network device can be an edge device through which the terminal device accesses the network.
[0163] In one case, after receiving the data transmission response sent by the management device to the terminal device, the network device parses the data transmission response, and obtains and stores the correspondence between the target transmission path and the target connection identifier. In this way, after receiving the service packet carrying the target connection identifier, the network device can directly use the target transmission path to transmit the service packet.
[0164] In another case, after receiving the data transmission response sent by the management device, the terminal device parses the data transmission response, and obtains and stores the correspondence between the target transmission path and the target connection identifier. Then the terminal device carries the path information of the target transmission path in the service packet, for example, adds a label list to the packet header of the service packet to carry the path information. In this way, the network device receiving the service packet can directly obtain the path information of the target transmission path from the service packet.
[0165] Step 305: The network device forwards the service packet based on the target transmission path.
[0166] Optionally, when the service QoT level indicated by the indication of the service QoT level carried in the service message is the same as the service QoT level corresponding to the target connection identifier, and the network device passes the integrity verification tag for the indication, the network device forwards the service message based on the target transmission path. Optionally, each network device through which the service message passes can perform the verification process, or only the edge device of each domain through which the service message passes can perform the verification process, and the embodiments of the present application do not limit this.
[0167] In the embodiments of the present application, by carrying the indication of the service QoT level and the integrity verification tag for the indication in the service message, the network device can verify whether the service QoT level actually used by the service message is the same as the service QoT level that truly matches the service, and can further verify whether the service message is tampered, thereby improving the reliability and credibility of data transmission.
[0168] In some embodiments, the terminal device obtains a service QoT level corresponding to a second service, and the service QoT level corresponding to the second service does not match the device QoT level of the terminal device. The terminal device refuses to transmit a service message of the second service.
[0169] Since the QoT forwarding policy on the application side can be manually changed by the user, the QoT forwarding policy on the application side may allow the running of a service with a service QoT level that does not match the device QoT level of the terminal device. For example, the device QoT level of the terminal device is 3, the QoT forwarding policy on the network side is that the device QoT level 3 matches the service QoT level 1-4, and the QoT forwarding policy on the application side is to prohibit the running of a service with a service QoT level of 5. At this time, if the user starts the application on the terminal device and selects a service with a service QoT level of 5, the application will explicitly inform the user of the denial of service. If the user manually changes the QoT forwarding policy on the application side, modifies the processing strategy corresponding to the service QoT level 5 to be allowed, and restarts the application and selects the service, the application will generate a service message and prepare to be sent by the terminal device. However, on the network side, the service QoT level corresponding to the service does not match the device QoT level of the terminal device, so the terminal device will refuse to transmit the service message of the service, avoiding the malicious use of the trusted data transmission service that does not match the credibility of the terminal device by the user, so that the network side can meet the trust requirements of the service and consider the credibility of the terminal device, thereby realizing the trusted transmission of data.
[0170] Optionally, when the terminal device receives a service message whose service QoT level does not match the device QoT level of the terminal device, the terminal device can decide to reject transmission by itself. For example, in a case where the QoT certificate of the terminal device includes the service QoT level provided by the management device to the terminal device, after the terminal device obtains the service message, the terminal device can determine, based on the QoT certificate of the terminal device, whether the service QoT level carried in the service message belongs to the service QoT level provided by the management device to the terminal device. If not, the terminal device determines that the service QoT level does not match the device QoT level of the terminal device, and at this time, the terminal device can reject transmission of the corresponding service packet.
[0171] Alternatively, when the terminal device receives a service message from an application, the terminal device can send a data transmission request to the management device, where the data transmission request includes the QoT certificate of the terminal device, a service QoT level indication, and a destination address. The management device determines that the service QoT level indicated by the service QoT level indication does not belong to the service QoT level matched by the device QoT level of the terminal device, that is, the management device determines that the service QoT level indicated by the service QoT level indication does not match the device QoT level of the terminal device, and at this time, the management device can send a rejection transmission response to the terminal device. The terminal device rejects transmission of the corresponding service packet based on the rejection transmission response.
[0172] For example, Figure 4 is an implementation scenario provided by an embodiment of the present application. As shown in Figure 4 , the implementation scenario includes a terminal device 401, network devices 402A-402F, and servers 403A-403C. It is assumed that the terminal device 401 is authorized to use data transmission services with service QoT levels 1-4. The terminal device 401 and the server 403A have established a communication connection 1 with a service QoT level 4, and the transmission path used by the communication connection 1 includes the network device 402A and the network device 402B. The terminal device 401 and the server 403B have established a communication connection 2 with a service QoT level 3, and the transmission path used by the communication connection 2 includes the network device 402C and the network device 402D. The terminal device 401 and the server 403C have established a communication connection 3 with a service QoT level 2, and the transmission path used by the communication connection 3 includes the network device 402E and the network device 402F. It is assumed that a multimedia stream service corresponds to a service QoT level 2, a user information service corresponds to a service QoT level 3, and a payment service corresponds to a service QoT level 4.
[0173] Referring to Figure 4, the terminal device 401 can send a service message of a payment type service to the server 403A through the communication connection 1. The terminal device 401 can send a service message of a user information type service to the server 403B through the communication connection 2. The terminal device 401 can send a service message of a multimedia stream service to the server 403C through the communication connection 3. However, when an application on the terminal device 401 needs to transmit a service message with a service QoT level of 5, the terminal device 401 will refuse to transmit the service message because the network side does not authorize the terminal device to use the data transmission service with a service QoT level of 5.
[0174] In summary, in the data transmission method provided in the embodiments of the present application, after the terminal device obtains the service QoT level corresponding to a service, if the service QoT level corresponding to the service matches the device QoT level of the terminal device, the terminal device obtains a connection identifier of a communication connection that matches the service QoT level corresponding to the service and is established between the terminal device and a destination address of the service, and then carries the connection identifier in a service message of the service sent to the destination address of the service, to instruct a network device receiving the service message to transmit the service message based on the communication connection corresponding to the connection identifier. Since the service QoT level corresponding to the service transmitted by the terminal device matches the device QoT level of the terminal device, and the communication connection based on which the service is transmitted matches the service QoT level corresponding to the service, the network side can provide matched trusted transmission for the service on the terminal device in combination with the trustworthiness of the terminal device and the trust requirement of the service on data transmission, thereby improving the service quality of the network and the service experience of the user.
[0175] The above data transmission method is exemplarily described by taking a mobile cellular network as an example. For example, the system architecture involved in the above data transmission method can be implemented based on the functional architecture in Y.3053. Figure 5 is a schematic diagram of a system architecture provided in an embodiment of the present application. As shown in Figure 5 , the main body of the system architecture is a trust domain. Each trust domain includes three main functional sets, which are access and delivery control functions, domain administration functions, and trust management functions. The trust domain can be connected with external trust domains and applications / services through reference points. The applications / services can also be connected through reference points, thereby forming an end-to-end reference architecture.
[0176] Please continue to refer to Figure 5, applications / services are connected through reference point Tx. Reference point Tx is a logical reference point that enables end-to-end request / response information to be exchanged reliably and securely between applications / services in order to establish a trusted network. Trust domains are connected through reference point Tp and reference point Td. Reference point Tp is a control plane interface that enables request / response information to be exchanged reliably and securely between trust domains. Reference point Td is a data plane interface that provides reliable and secure cross-domain data transfer. Trust domains are connected to applications / services through reference point Ts. Reference point Ts enables request / response information to be exchanged reliably and securely between trust domains and applications / services. The definition and functions of reference points can refer to Y.3053, which will not be described herein.
[0177] Please continue to see Figure 5, the access and distribution control function set includes a trust based routing support functional entity (TRS-FE), a data transport and processing functional entity (DPT-FE), an accessing / peering control support functional entity (APCS-FE), a trust based tunneling support functional entity (TTS-FE), and an ID-based routing support functional entity (IRS-FE). The domain management function set includes an ID-locator mapping support functional entity (ILMS-FE), a domain membership management functional entity (DMM-FE), a domain policy management functional entity (DPM-FE), and a domain application and service management functional entity (DASM-FE). The trust management function set includes a trust verification support functional entity (TVS-FE), a trust level validation functional entity (TLV-FE), and a trust information lifecycle management functional entity (TILM-FE). Compared with the Y.3053 functional architecture, the DASM-FE, the TRS-FE, and the TTS-FE are new functional entities. In addition, the system architecture enhances the three functional entities of the TVS-FE, the TLV-FE, and the TILM-FE.
[0178] TVS-FE: In Y.3053, TVS-FE is responsible for collecting information of network elements within the trust domain, which is used for evaluating the trust level of the network elements. The present application enhances the QoT information collection capability on the basis of the original function of the functional entity, i.e. the functional entity can determine and collect information of the network elements for QoT evaluation. Herein, the network devices and terminal devices are collectively referred to as network elements.
[0179] TLV-FE: In Y.3053, TLV-FE is responsible for evaluating the trust level of the network elements. The present application enhances the QoT level evaluation capability on the basis of the original function of the functional entity. The capability can be realized in two ways: 1) directly evaluating the device QoT level of the network elements according to the QoT evaluation model; 2) first evaluating the trust level of the network elements according to the definition of Y.3053, and then mapping the trust level to the device QoT level.
[0180] TILM-FE: In Y.3053, TILM-FE is responsible for the lifecycle management of trust information within the trust domain, such as the creation, distribution, modification, and deletion of trust values. The present application enhances the QoT information lifecycle management capability on the basis of the original function, including the creation, distribution, modification, and deletion of the device QoT level of the network elements.
[0181] DASM-FE: responsible for managing the QoT classification of services, and performing session management according to the QoT level of the services and the QoT certificate of the terminal device.
[0182] TRS-FE: according to the QoT information carried by the service packets and the QoT policy of the session, realizing QoT-based routing planning and control, such as path calculation.
[0183] TTS-FE: according to the QoT policy of the session and the QoT information carried by the service packets, realizing QoT-based end-to-end tunnel management, including establishment, maintenance, modification, and release.
[0184] Figure 5 The roles of other functional entities in the illustrated trust domain can refer to Y.3053, which will not be described herein.
[0185] Please refer to Figure 5 , the application / service is built-in with a QoT module, which is used to provide QoT processing capability for the application. For example, obtaining the QoT certificate of the terminal device, setting or modifying the QoT forwarding policy on the application side, etc.
[0186] Under the system architecture shown in Figure 5 , the management device is realized by one or more functional entities. The following embodiments of the present application illustrate the specific implementation process of the above-mentioned method 200 and method 300.
[0187] For example, Figure 6 This is a schematic diagram of the registration process in a DMM-FE and TLV-FE separation scenario provided in the embodiments of this application. For example... Figure 6 As shown, the registration process includes steps 601 to 610.
[0188] Step 601: The terminal device sends a registration request to the DMM-FE.
[0189] The registration request includes the device identifier of the terminal device. Optionally, the registration request may also include the user identifier of the terminal device. The explanation of step 601 can be found in step 201 above, and will not be repeated here in this embodiment.
[0190] Step 602: The DMM-FE sends a QoT evaluation request signaling to the TLV-FE.
[0191] The QoT evaluation request signaling includes the device identifier of the terminal device. Optionally, the QoT evaluation request signaling also includes the user identifier of the terminal device.
[0192] Step 603: The TLV-FE sends a QoT authentication request to the terminal device, which includes QoT parameter indication.
[0193] The explanation of step 603 can be found in step 202 above, and will not be repeated here in the embodiments of this application.
[0194] Step 604: The terminal device sends a QoT authentication response to the TLV-FE, which includes the QoT parameter indicated by the QoT parameter indicator.
[0195] The explanation of step 604 can be found in step 203 above, and will not be repeated here in the embodiments of this application.
[0196] Step 605: The TLV-FE performs a QoT evaluation on the terminal device based on the QoT parameters sent by the terminal device, and obtains a QoT evaluation result, which includes the device QoT level of the terminal device.
[0197] Step 606: TLV-FE sends the QoT evaluation result to DMM-FE.
[0198] Step 607: DMM-FE uses its private key to issue a QoT certificate for the terminal device. The QoT certificate includes the QoT evaluation result.
[0199] The explanation of steps 605 to 607 above can be found in step 204 above, and will not be repeated here in the embodiments of this application.
[0200] Step 608: DMM-FE sends the QoT certificate to the terminal device.
[0201] The explanation of this step 608 can refer to the step 205 described above, and the embodiments of the present application will not be described here.
[0202] Step 609, the DMM-FE sends a QoT certificate update message to the DASM-FE, and the QoT certificate update message includes the device identifier of the terminal device and the QoT certificate of the terminal device.
[0203] Step 610, the DASM-FE generates the QoT forwarding policy of the terminal device on the network side according to the QoT certificate update message.
[0204] Optionally, the QoT forwarding policy of the terminal device on the network side includes the highest service QoT level allowed to be used by the terminal device and / or the service QoT level by default used by the terminal device.
[0205] For another example, Figure 7 FIG. 7 is a schematic diagram of a registration process in a combined scenario of a DMM-FE and a TLV-FE according to an embodiment of the present application. Figure 7 In the figure, the combined DMM-FE and TLV-FE are simply referred to as DMM-FE / TLV-FE. As shown in the figure, the registration process includes the following steps 701 to 708. Figure 7
[0206] Step 701, the terminal device sends a registration request to the DMM-FE / TLV-FE.
[0207] The registration request includes the device identifier of the terminal device. Optionally, the registration request also includes the user identifier of the terminal device. The explanation of this step 701 can refer to the step 201 described above, and the embodiments of the present application will not be described here.
[0208] Step 702, the DMM-FE / TLV-FE sends a QoT authentication request to the terminal device, and the QoT authentication request includes a QoT parameter indication.
[0209] The explanation of this step 702 can refer to the step 202 described above, and the embodiments of the present application will not be described here.
[0210] Step 703, the terminal device sends a QoT authentication response to the DMM-FE / TLV-FE, and the QoT authentication response includes the QoT parameter indicated by the QoT parameter indication.
[0211] The explanation of this step 703 can refer to the step 203 described above, and the embodiments of the present application will not be described here.
[0212] Step 704, the DMM-FE / TLV-FE performs QoT evaluation on the terminal device based on the QoT parameter sent by the terminal device, and obtains a QoT evaluation result, which includes a device QoT level of the terminal device.
[0213] Step 705, the DMM-FE / TLV-FE issues a QoT certificate for the terminal device using a private key, and the QoT certificate includes the QoT evaluation result.
[0214] The explanation of the above steps 704 to 705 can refer to the above step 204, and the embodiments of the present application will not be repeated here.
[0215] Step 706, the DMM-FE / TLV-FE sends the QoT certificate to the terminal device.
[0216] The explanation of this step 706 can refer to the above step 205, and the embodiments of the present application will not be repeated here.
[0217] Step 707, the DMM-FE / TLV-FE sends a QoT certificate update message to the DASM-FE, and the QoT certificate update message includes a device identifier of the terminal device and a QoT certificate of the terminal device.
[0218] Step 708, the DASM-FE generates a QoT forwarding policy of the terminal device on the network side according to the QoT certificate update message.
[0219] Optionally, the QoT forwarding policy of the terminal device on the network side includes a highest service QoT level allowed to be used by the terminal device and / or a service QoT level by default used by the terminal device.
[0220] It is worth noting that the update process of the QoT certificate of the terminal device can refer to the above Figure 6 or Figure 7 registration process shown in the embodiments of the present application, and the embodiments of the present application will not be repeated here.
[0221] For another example, Figure 8 is a data transmission process schematic diagram provided by the embodiments of the present application. As shown in Figure 8 , the data transmission process includes the following steps 801 to 813.
[0222] Step 801, the terminal device obtains a service QoT level corresponding to a service and a destination address of the service.
[0223] The explanation of this step 801 can refer to the above step 301, and the embodiments of the present application will not be repeated here.
[0224] Step 802, the terminal device sends a session establishment request to the DASM-FE, and the session establishment request includes a destination address of the service, a service QoT level corresponding to the service, and a QoT certificate of the terminal device.
[0225] The session establishment request is used to request the network side to establish a session.
[0226] Step 803, the DASM-FE verifies whether the QoT certificate of the terminal device in the session establishment request is valid, and judges whether the service QoT level corresponding to the service matches a device QoT level of the terminal device based on a QoT forwarding policy of the terminal device on the network side.
[0227] Step 804, when the QoT certificate of the terminal device is valid, and the service QoT level corresponding to the service matches the device QoT level of the terminal device, the DASM-FE establishes a session connection based on the session establishment request.
[0228] Step 805, the DASM-FE sends a session establishment response to the terminal device, and the session establishment response includes a session identifier.
[0229] In the mobile cellular network, the data transmission request in the above step 302 corresponds to the session establishment request in the step 802. The data transmission response in the above step 302 corresponds to the session establishment response in the step 805. The connection identifier in the above step 302 corresponds to the session identifier in the step 805.
[0230] The above steps 802 to 805 can be referred to the above step 302, and the embodiments of the present application will not be described here.
[0231] Step 806, the terminal device sends a service packet, and the service packet includes the session identifier, an indication of the service QoT level corresponding to the service, and an integrity verification tag corresponding to the indication.
[0232] The explanation of this step 806 can be referred to the above step 303, and the embodiments of the present application will not be described here.
[0233] Step 807, after the network device receives the service packet, the network device verifies the integrity verification tag.
[0234] Step 808, after the network device verifies the integrity verification tag, the network device sends a path calculation request to the TRS-FE, and the path calculation request includes the session identifier and the destination address of the service.
[0235] Step 809, the TRS-FE queries the service QoT level corresponding to the session identifier from the DASM-FE.
[0236] Step 810, the DASM-FE replies to the TRS-FE with a session identifier corresponding to a service QoT level.
[0237] Step 811, the TRS-FE determines a transmission path according to the service QoT level corresponding to the session identifier, wherein a device QoT level of a network device on the transmission path matches the service QoT level corresponding to the session identifier.
[0238] Step 812, the TRS-FE sends a path computation response to the network device, wherein the path computation response includes path information of the transmission path.
[0239] The above steps 807 to 812 can be explained with reference to the above step 304, and the embodiments of the present application will not be repeated here.
[0240] Step 813, the network device forwards a service packet based on the transmission path.
[0241] The explanation of this step 813 can be referred to the above step 305, and the embodiments of the present application will not be repeated here.
[0242] The virtual device related to the embodiments of the present application is exemplified as follows.
[0243] For example, Figure 9 is a structural schematic diagram of a terminal device provided by the embodiments of the present application. As shown in Figure 9 , the terminal device 900 includes:
[0244] The processing module 901 is configured to obtain a service QoT level corresponding to a first service and a destination address of the first service, wherein the service QoT level corresponding to the first service matches a device QoT level of the terminal device.
[0245] The processing module 901 is further configured to obtain a target connection identifier according to the service QoT level corresponding to the first service and the destination address of the first service, wherein the target connection identifier is a connection identifier of a target communication connection established between the terminal device and the destination address of the first service, and the target communication connection is used to transmit the service packet based on the target communication connection.
[0246] The sending module 902 is configured to send a service packet of the first service to the destination address of the first service, wherein the service packet includes the target connection identifier, and the target connection identifier is used to indicate that the service packet is transmitted based on the target communication connection.
[0247] Optionally, the terminal device stores a connection identifier set, wherein the connection identifier set is used to record connection identifiers of communication connections established by the terminal device, and each connection identifier in the connection identifier set is correspondingly provided with a destination address and a service QoT level. Figure 10As shown, the terminal device further includes a receiving module 903. The processing module 901 is configured to, when there is no connection identifier corresponding to the service QoT level of the first service and the destination address of the first service in the connection identifier set, send, by the sending module 901, a data transmission request to the management device, and receive, by the receiving module 902, a data transmission response sent by the management device, the data transmission request including the destination address of the first service and a QoT certificate of the terminal device, the QoT certificate including a device QoT level of the terminal device, and the data transmission response including a target connection identifier.
[0248] Optionally, the QoT certificate further includes a QoT forwarding policy of the management device for the terminal device, and the QoT forwarding policy includes a highest service QoT level provided by the management device to the terminal device and / or a default service QoT level provided by the management device to the terminal device.
[0249] Optionally, the processing module 901 is further configured to, after the terminal device receives the data transmission response sent by the management device, add, in the connection identifier set, a correspondence between the destination address of the first service, the service QoT level corresponding to the first service, and the target connection identifier.
[0250] Optionally, the data transmission request further includes a service QoT level indication, and the service QoT level indication is used to indicate the service QoT level corresponding to the first service.
[0251] Optionally, the sending module 902 is configured to send, to the management device, a QoT parameter of the terminal device, and the QoT parameter includes one or more of device identity information, hardware configuration information, software configuration information, or network access information. The receiving module 903 is configured to receive a QoT certificate based on the QoT parameter and sent by the management device.
[0252] Optionally, the sending module 902 is further configured to, before sending the QoT parameter of the terminal device to the management device, send a registration request to the management device. The receiving module 903 is further configured to receive a QoT authentication request sent by the management device, and the QoT authentication request includes a QoT parameter indication used to indicate the QoT parameter required to be provided by the terminal device. The sending module 902 is configured to send, to the management device, a QoT authentication response including the QoT parameter indicated by the QoT parameter indication.
[0253] Optionally, the sending module 902 is further configured to, when the QoT certificate satisfies a certificate update condition, send, to the management device, a latest QoT parameter of the terminal device. The receiving module 903 is further configured to receive an updated QoT certificate based on the latest QoT parameter and sent by the management device.
[0254] Optionally, the certificate update condition comprises one or more of the following: the QoT certificate is out of a valid period; a QoT parameter of the terminal device is changed; the terminal device and / or the management device cannot parse the QoT certificate.
[0255] Optionally, the service packet further comprises an indication of a service QoT level corresponding to the first service and an integrity verification tag for the indication.
[0256] Optionally, the processing module 901 is further configured to obtain a service QoT level corresponding to a second service, and the service QoT level corresponding to the second service does not match the device QoT level of the terminal device. The processing module 901 is further configured to reject transmission of a service packet of the second service.
[0257] For example, Figure 11 is a structural schematic diagram of a management device provided by an embodiment of the present application. As Figure 11 shown, the management device 1100 comprises:
[0258] The receiving module 1101 is configured to receive a data transmission request sent by a terminal device, the data transmission request comprising a destination address of a first service and a QoT certificate of the terminal device, the QoT certificate comprising a device QoT level of the terminal device.
[0259] The processing module 1102 is configured to establish a target communication connection between the terminal device and the destination address of the first service based on the QoT certificate, a service QoT level corresponding to the target communication connection matching the device QoT level of the terminal device.
[0260] The sending module 1103 is configured to send a data transmission response to the terminal device, the data transmission response comprising a target connection identifier, the target connection identifier being a connection identifier of the target communication connection.
[0261] Optionally, the data transmission request further comprises a service QoT level indication, the service QoT level indication being used to indicate a service QoT level corresponding to the first service. The processing module 1102 is configured to establish a target communication connection corresponding to the service QoT level indicated by the service QoT level indication when the service QoT level indicated by the service QoT level indication matches the device QoT level of the terminal device.
[0262] Optionally, the QoT certificate further comprises a QoT forwarding policy of the management device for the terminal device, the QoT forwarding policy comprising a highest service QoT level provided by the management device to the terminal device and / or a default service QoT level provided by the management device to the terminal device.
[0263] Optionally, the receiving module 1101 is further configured to receive a QoT parameter of the terminal device, the QoT parameter comprising one or more of device identity information, hardware configuration information, software configuration information, or network access information. The processing module 1102 is further configured to generate a QoT certificate based on the QoT parameter. The sending module 1103 is further configured to send the QoT certificate to the terminal device.
[0264] Optionally, the receiving module 1101 is further configured to receive a registration request sent by the terminal device. The sending module 1103 is further configured to send a QoT authentication request to the terminal device based on the registration request, the QoT authentication request comprising a QoT parameter indication, the QoT parameter indication being used to indicate the QoT parameter required to be provided by the terminal device. The receiving module 1101 is configured to receive a QoT authentication response sent by the terminal device, the QoT authentication response comprising the QoT parameter indicated by the QoT parameter indication.
[0265] Optionally, the receiving module 1101 is further configured to receive a path calculation request of the network device, the path calculation request comprising a target connection identifier. The processing module 1102 is further configured to determine a target transmission path used by the target communication connection according to a service QoT level corresponding to the target connection identifier, a device QoT level of a network device on the target transmission path matching the service QoT level corresponding to the target connection identifier. The sending module 1103 is further configured to send a path calculation response to the network device, the path calculation response comprising path information of the target transmission path.
[0266] For example, Figure 12 is a structural schematic diagram of a network device provided by an embodiment of the present application. As shown in Figure 12 the network device 1200 comprises:
[0267] The receiving module 1201 is configured to receive a service packet of a first service sent by a terminal device, the service packet comprising a target connection identifier.
[0268] The processing module 1202 is configured to acquire a target transmission path corresponding to the target connection identifier, a device quality of trust QoT level of a network device on the target transmission path matching a service QoT level corresponding to the target connection identifier.
[0269] The sending module 1203 is configured to forward the service packet based on the target transmission path.
[0270] Optionally, the processing module 1202 is configured to send a path calculation request to a management device through the sending module 1203, the path calculation request comprising the target connection identifier. The receiving module 1201 is configured to receive a path calculation response sent by the management device, the path calculation response comprising path information of the target transmission path.
[0271] Optionally, the service packet further comprises an indication of a service QoT level corresponding to the first service and an integrity verification tag for the indication. The sending module 1203 is configured to forward the service packet based on the target transmission path when the indicated service QoT level is the same as a service QoT level corresponding to the target connection identifier and the network device passes the integrity verification tag.
[0272] With regard to the apparatus in the above-described embodiments, the specific manners in which various modules perform operations have been described in detail in the embodiments of the method, and thus will not be described in detail here.
[0273] The hardware structure to which the embodiments of the present application relate will be described below.
[0274] For example, Figure 13 is a hardware structure schematic diagram of a terminal device provided by an embodiment of the present application. As shown in Figure 13 the terminal device 1300 includes a processor 1301 and a memory 1302, and the memory 1301 and the memory 1302 are connected through a bus 1303. Figure 13 The processor 1301 and the memory 1302 are described independently of each other. Alternatively, the processor 1301 and the memory 1302 are integrated together.
[0275] The memory 1302 is configured to store a computer program, and the computer program includes an operating system and program code. The memory 1302 is various types of storage media, such as a read-only memory (ROM), a random access memory (RAM), an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM), a flash memory, an optical memory, a register, an optical disc storage, a light disc storage, a magnetic disk or other magnetic storage devices.
[0276] The processor 1301 is a general-purpose processor or a special-purpose processor. The processor 1301 can be a single-core processor or a multi-core processor. The processor 1301 includes at least one circuit to perform the actions performed by the terminal device in the above method embodiments provided by the embodiments of the present application.
[0277] Optionally, the terminal device 1300 further includes a network interface 1304 connected with the processor 1301 and the memory 1302 through the bus 1303. The network interface 1304 can enable the terminal device 1300 to communicate with the network side. The processor 1301 can interact with the network side through the network interface 1304 to register the QoT certificate and perform data transmission, etc.
[0278] Optionally, the terminal device 1300 further includes an input / output (I / O) interface 1305 connected with the processor 1301 and the memory 1302 through the bus 1303. The processor 1301 can receive input commands or data, etc. through the I / O interface 1305. The I / O interface 1305 is used for the terminal device 1300 to connect input devices such as a keyboard and a mouse. Optionally, in some possible scenarios, the network interface 1304 and the I / O interface 1305 are collectively referred to as a communication interface.
[0279] Optionally, the terminal device 1300 further includes a display 1306 connected with the processor 1301 and the memory 1302 through the bus 1303. The display 1306 can be used to display intermediate results and / or final results, etc. generated by the processor 1301 executing the above method, for example, to display an alarm prompt. In a possible implementation manner, the display 1306 is a touch display screen to provide a human-computer interaction interface.
[0280] The bus 1303 is any type of communication bus for realizing the interconnection of internal devices of the terminal device 1300. For example, a system bus. The above devices in the terminal device 1300 are interconnected through the bus 1303 in the embodiments of the present application, and optionally, the above devices in the terminal device 1300 are connected in communication with each other in other connection manners, for example, the above devices in the terminal device 1300 are interconnected through a logic interface in the terminal device 1300.
[0281] The above devices can be respectively arranged on independent chips, or at least part or all of them can be arranged on the same chip. Whether to arrange each device on a separate chip or to integrate them on one or more chips often depends on the needs of product design. The embodiments of the present application do not limit the specific implementation form of the above devices.
[0282] Figure 13 The terminal device 1300 shown is only exemplary, and in the implementation process, the terminal device 1300 includes other components, which are not listed one by one herein. Figure 13 The terminal device 1300 shown can realize data transmission by executing all or part of the steps of the methods provided in the above embodiments.
[0283] For example, Figure 14 is a hardware structure schematic diagram of a management device provided by an embodiment of the present application. As shown in Figure 14 The management device 1400 includes a processor 1401 and a memory 1402, and the memory 1401 and the memory 1402 are connected through a bus 1403. Figure 14 The processor 1401 and the memory 1402 are described independently. Alternatively, the processor 1401 and the memory 1402 are integrated together.
[0284] The memory 1402 is used to store a computer program, and the computer program includes an operating system and a program code. The memory 1402 is various types of storage media, such as a ROM, a RAM, an EEPROM, a CD-ROM, a flash memory, an optical storage, a register, an optical disc storage, an optical disc storage, a magnetic disc or other magnetic storage devices.
[0285] The processor 1401 is a general-purpose processor or a special-purpose processor. The processor 1401 can be a single-core processor or a multi-core processor. The processor 1401 includes at least one circuit to perform the actions performed by the management device in the above method embodiments provided by the embodiments of the present application.
[0286] Alternatively, the management device 1400 further includes a network interface 1404 connected with the processor 1401 and the memory 1402 through the bus 1403. The network interface 1404 can realize the communication between the management device 1400 and the application side. The processor 1401 can interact with the application side through the network interface 1404 to issue a QoT certificate to a terminal device and perform communication connection and the like.
[0287] Alternatively, the management device 1400 further includes an I / O interface 1405 connected with the processor 1401 and the memory 1402 through the bus 1403. The processor 1401 can receive input commands or data and the like through the I / O interface 1405. The I / O interface 1405 is used to connect input devices of the management device 1400, such as a keyboard and a mouse. Alternatively, in some possible scenarios, the network interface 1404 and the I / O interface 1405 are collectively referred to as a communication interface.
[0288] Alternatively, the management device 1400 further includes a display 1406 connected with the processor 1401 and the memory 1402 through the bus 1403. The display 1406 can be used to display intermediate results and / or final results and the like generated by the processor 1401 executing the above method, such as displaying an alarm prompt. In a possible implementation manner, the display 1406 is a touch display screen to provide a human-computer interaction interface.
[0289] The bus 1403 is any type of communication bus, for example, a system bus, for interconnecting the internal components of the management device 1400. The above-mentioned components in the management device 1400 are interconnected by the bus 1403, for example. Alternatively, the above-mentioned components in the management device 1400 are communicatively connected to each other by means other than the bus 1403, for example, the above-mentioned components in the management device 1400 are interconnected by means of a logical interface in the management device 1400.
[0290] The above-mentioned components can be respectively arranged on separate chips, or at least partially or entirely arranged on the same chip. Whether the components are arranged on separate chips or integrated on one or more chips depends on the product design requirement. The embodiments of the present application do not limit the specific implementation form of the above-mentioned components.
[0291] Figure 14 The management device 1400 shown is only exemplary. In the implementation process, the management device 1400 includes other components, which are not listed one by one herein. Figure 14 The management device 1400 shown can achieve data transmission by executing all or part of the steps of the method provided by the above-mentioned embodiments.
[0292] For example, Figure 15 is a hardware structure schematic diagram of a network device provided by an embodiment of the present application. As shown in Figure 15 The network device 1500 includes a processor 1501 and a memory 1502, and the memory 1501 and the memory 1502 are connected by a bus 1503. Figure 15 The processor 1501 and the memory 1502 are independent of each other. Alternatively, the processor 1501 and the memory 1502 are integrated together.
[0293] The memory 1502 is used to store a computer program, and the computer program includes an operating system and program code. The memory 1502 is various types of storage media, for example, ROM, RAM, EEPROM, CD-ROM, flash memory, optical storage, register, optical disc storage, optical disc storage, magnetic disk or other magnetic storage devices.
[0294] The processor 1501 is a general-purpose processor or a special-purpose processor. The processor 1501 can be a single-core processor or a multi-core processor. The processor 1501 includes at least one circuit to perform the actions performed by the network device in the above-mentioned method embodiments provided by the embodiments of the present application.
[0295] Optionally, the network device 1500 further includes a network interface 1504 connected with the processor 1501 and the memory 1502 through the bus 1503. The network interface 1504 can enable the network device 1500 to communicate with the application side and the management device. The processor 1501 can receive service packets from the application side and forward the service packets through the network interface 1504.
[0296] Optionally, the network device 1500 further includes an I / O interface 1505 connected with the processor 1501 and the memory 1502 through the bus 1503. The processor 1501 can receive input commands or data through the I / O interface 1505. The I / O interface 1505 is used for the network device 1500 to connect with input devices such as a keyboard and a mouse. Optionally, in some possible scenarios, the network interface 1504 and the I / O interface 1505 are collectively referred to as a communication interface.
[0297] Optionally, the network device 1500 further includes a display 1506 connected with the processor 1501 and the memory 1502 through the bus 1503. The display 1506 can be used to display intermediate results and / or final results generated by the processor 1501 in executing the above method, for example, to display an alarm prompt. In a possible implementation manner, the display 1506 is a touch display screen to provide a human-computer interaction interface.
[0298] The bus 1503 is any type of communication bus for realizing interconnection of internal devices of the network device 1500. For example, a system bus. The above devices inside the network device 1500 are interconnected through the bus 1503 in the embodiments of the present application, and optionally, the above devices inside the network device 1500 are connected in communication with each other in other connection manners, for example, the above devices inside the network device 1500 are interconnected through a logical interface inside the network device 1500.
[0299] The above devices can be respectively arranged on independent chips, or at least part or all of the above devices can be arranged on the same chip. Whether to arrange each device on a separate chip or to integrate the devices on one or more chips often depends on the needs of product design. The embodiments of the present application do not limit the specific implementation forms of the above devices.
[0300] Figure 15 The network device 1500 shown is only exemplary, and in the implementation process, the network device 1500 includes other components, which are not listed one by one herein. Figure 15 The network device 1500 shown can realize data transmission by executing all or part of the steps of the method provided in the above embodiments.
[0301] The embodiments of the present application further provide a data transmission system, comprising a terminal device, a management device and a network device. The terminal device is configured to perform the actions performed by the terminal device in the method embodiments. The management device is configured to perform the actions performed by the management device in the method embodiments. The network device is configured to perform the actions performed by the network device in the method embodiments.
[0302] The embodiments of the present application further provide a computer readable storage medium, which stores instructions. When the instructions are executed by a processor, the actions performed by the terminal device, the management device or the network device in the method embodiments are implemented.
[0303] The embodiments of the present application further provide a computer program product, which comprises a computer program. When the computer program is executed by a processor, the actions performed by the terminal device, the management device or the network device in the method embodiments are implemented.
[0304] Those skilled in the art can understand that all or part of the steps of the above embodiments can be completed by hardware, or can be instructed by a program to complete the related hardware, and the program can be stored in a computer readable storage medium, and the storage medium mentioned above can be a read-only memory, a disk or an optical disk.
[0305] In the embodiments of the present application, the terms "first", "second" and "third" are only for descriptive purposes, and cannot be understood as indicating or implying relative importance.
[0306] In the present application, the term "and / or" is only used to describe the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B, which means that there are three cases of A alone, A and B together, and B alone. In addition, the character " / " in this paper generally represents an "or" relationship between the associated objects before and after it.
[0307] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data for analysis, stored data, displayed data, etc.) and signals involved in the present application are all authorized by the user or fully authorized by all parties, and the collection, use and processing of related data need to comply with relevant laws, regulations and standards of relevant countries and regions. For example, the device identity information, device identifier, user identifier, QoT parameter and the like involved in the present application are obtained under sufficient authorization.
[0308] The above only describes the optional embodiments of the present application, and does not limit the present application. Any modification, equivalent replacement, improvement, etc. made within the concept and principles of the present application shall be included in the protection scope of the present application.
Claims
1. A data transmission method, characterized by, The method comprises: The terminal device acquires a service trust quality QoT level corresponding to a first service and a destination address of the first service, and the service QoT level corresponding to the first service matches a device QoT level of the terminal device; The terminal device acquires a target connection identifier according to the service QoT level corresponding to the first service and the destination address of the first service, and the target connection identifier is a connection identifier of a target communication connection established between the terminal device and the destination address of the first service and matching the service QoT level corresponding to the first service; The terminal device sends a service packet of the first service to the destination address of the first service, and the service packet comprises the target connection identifier, and the target connection identifier is used to indicate that the service packet is transmitted based on the target communication connection.
2. The method of claim 1, wherein, The terminal device stores a connection identifier set, and the connection identifier set is used to record connection identifiers of communication connections established by the terminal device, and each connection identifier in the connection identifier set is correspondingly provided with a destination address and a service QoT level, and the terminal device acquires a target connection identifier according to the service QoT level corresponding to the first service and the destination address of the first service, comprising: When there is no connection identifier corresponding to the service QoT level corresponding to the first service and the destination address of the first service in the connection identifier set, the terminal device sends a data transmission request to a management device, and the data transmission request comprises the destination address of the first service and a QoT certificate of the terminal device, and the QoT certificate comprises a device QoT level of the terminal device; The terminal device receives a data transmission response sent by the management device, and the data transmission response comprises the target connection identifier.
3. The method of claim 2, wherein, The QoT certificate further comprises a QoT forwarding policy of the management device for the terminal device, and the QoT forwarding policy comprises a highest service QoT level provided by the management device to the terminal device and / or a default service QoT level provided by the management device to the terminal device.
4. The method according to claim 2 or 3, characterized in that, After the terminal device receives the data transmission response sent by the management device, the method further comprises: The terminal device adds a corresponding relationship among the destination address of the first service, the service QoT level corresponding to the first service and the target connection identifier in the connection identifier set.
5. The method according to any one of claims 2 to 4, characterized in that, The data transmission request further comprises a service QoT level indication, and the service QoT level indication is used to indicate the service QoT level corresponding to the first service.
6. The method according to any one of claims 2 to 5, characterized in that, The method further comprises: The terminal device sends a QoT parameter of the terminal device to the management device, and the QoT parameter comprises one or more of device identity information, hardware configuration information, software configuration information or network access information; The terminal device receives the QoT certificate obtained based on the QoT parameter and sent by the management device.
7. The method of claim 6, wherein, Before the terminal device sends the QoT parameter of the terminal device to the management device, the method further comprises: The terminal device sends a registration request to the management device; The terminal device receives a QoT authentication request sent by the management device, the QoT authentication request comprising a QoT parameter indication, the QoT parameter indication being used to indicate a QoT parameter required to be provided by the terminal device; The terminal device sends the QoT parameter of the terminal device to the management device, comprising: The terminal device sends a QoT authentication response to the management device, the QoT authentication response comprising the QoT parameter indicated by the QoT parameter indication.
8. The method according to claim 6 or 7, characterized in that, The method further comprises: When the QoT certificate meets a certificate update condition, the terminal device sends the latest QoT parameter of the terminal device to the management device; The terminal device receives an updated QoT certificate based on the latest QoT parameter sent by the management device.
9. The method of claim 8, wherein, The certificate update condition comprises one or more of: The QoT certificate exceeds a valid period; The QoT parameter of the terminal device is changed; The terminal device and / or the management device cannot parse the QoT certificate.
10. The method according to any one of claims 1 to 9, characterized in that, The service packet further comprises an indication of a service QoT level corresponding to the first service and an integrity verification tag for the indication.
11. The method according to any one of claims 1 to 10, characterized in that, The method further comprises: The terminal device obtains a service QoT level corresponding to a second service, the service QoT level corresponding to the second service not matching a device QoT level of the terminal device; The terminal device refuses to transmit a service packet of the second service.
12. A data transmission method, characterized by, The method comprises: The management device receives a data transmission request sent by a terminal device, the data transmission request comprising a destination address of a first service and a trust quality QoT certificate of the terminal device, the QoT certificate comprising a device QoT level of the terminal device; The management device establishes a target communication connection between the terminal device and the destination address of the first service based on the QoT certificate, a service QoT level corresponding to the target communication connection matching the device QoT level of the terminal device; The management device sends a data transmission response to the terminal device, the data transmission response comprising a target connection identifier, the target connection identifier being a connection identifier of the target communication connection.
13. The method of claim 12, wherein, The data transmission request further comprises a service QoT level indication, the service QoT level indication being used to indicate a service QoT level corresponding to the first service, the management device establishing a target communication connection between the terminal device and the destination address of the first service based on the QoT certificate, comprising: When the service QoT level indicated by the service QoT level indication matches the device QoT level of the terminal device, the management device establishes the target communication connection corresponding to the service QoT level indicated by the service QoT level indication.
14. The method according to claim 12 or 13, characterized in that, The QoT certificate further comprises a QoT forwarding policy of the management device for the terminal device, the QoT forwarding policy comprising a highest service QoT level provided by the management device to the terminal device and / or a default service QoT level provided by the management device to the terminal device.
15. The method according to any one of claims 12 to 14, characterized in that, The method further comprises: The management device receives the QoT parameter of the terminal device sent by the terminal device, and the QoT parameter comprises one or more of device identity information, hardware configuration information, software configuration information or network access information; The management device generates the QoT certificate based on the QoT parameter; The management device sends the QoT certificate to the terminal device.
16. The method of claim 15, wherein, The method further comprises: The management device receives a registration request sent by the terminal device; The management device sends a QoT authentication request to the terminal device based on the registration request, and the QoT authentication request comprises a QoT parameter indication for indicating the QoT parameter required to be provided by the terminal device; The management device receives the QoT parameter of the terminal device sent by the terminal device, and the QoT parameter comprises: The management device receives a QoT authentication response sent by the terminal device, and the QoT authentication response comprises the QoT parameter indicated by the QoT parameter indication.
17. The method of any one of claims 12 to 16, wherein, The method further comprises: The management device receives a path calculation request of a network device, and the path calculation request comprises the target connection identifier; The management device determines a target transmission path used by the target communication connection according to the service QoT level corresponding to the target connection identifier, and the device QoT level of the network device on the target transmission path matches the service QoT level corresponding to the target connection identifier; The management device sends a path calculation response to the network device, and the path calculation response comprises path information of the target transmission path.
18. A data transmission method, characterized by, The method comprises: A network device receives a service packet of a first service and a destination address of the first service sent by a terminal device, and the service packet comprises a target connection identifier; The network device acquires a target transmission path corresponding to the target connection identifier, and the device quality of trust (QoT) level of the network device on the target transmission path matches the service QoT level corresponding to the target connection identifier; The network device forwards the service packet based on the target transmission path.
19. The method of claim 18, wherein, The network device acquires the target transmission path corresponding to the target connection identifier, comprising: The network device sends a path calculation request to a management device, and the path calculation request comprises the target connection identifier; The network device receives a path calculation response sent by the management device, and the path calculation response comprises path information of the target transmission path.
20. The method of claim 18 or 19, wherein, The service packet further comprises an indication of the service QoT level corresponding to the first service and an integrity verification tag for the indication, and the network device forwards the service packet based on the target transmission path, comprising: When the service QoT level indicated by the indication is the same as the service QoT level corresponding to the target connection identifier, and the integrity verification tag is verified by the network device, the network device forwards the service packet based on the target transmission path.
21. A terminal device, comprising: The terminal device comprises: The processing module is configured to obtain a service trust quality QoT level corresponding to a first service, the service QoT level corresponding to the first service matching a device QoT level of the terminal device; The processing module is further configured to obtain a target connection identifier according to the service QoT level corresponding to the first service and a destination address of the first service, the target connection identifier being a connection identifier of a target communication connection established between the terminal device and the destination address of the first service and matching the service QoT level corresponding to the first service; The sending module is configured to send a service packet of the first service to the destination address of the first service, the service packet including the target connection identifier, the target connection identifier being used to indicate that the service packet is transmitted based on the target communication connection.
22. The terminal device of claim 21, wherein, The terminal device stores a connection identifier set, the connection identifier set being used to record connection identifiers of communication connections established by the terminal device, and each connection identifier in the connection identifier set is correspondingly provided with a destination address and a service QoT level, and the terminal device further includes a receiving module; The processing module is configured to, when there is no connection identifier corresponding to the service QoT level corresponding to the first service and the destination address of the first service in the connection identifier set, send a data transmission request to a management device through the sending module and receive a data transmission response sent by the management device through the receiving module, the data transmission request including the destination address of the first service and a QoT certificate of the terminal device, the QoT certificate including the device QoT level of the terminal device, and the data transmission response including the target connection identifier.
23. The terminal device of claim 22, wherein, The QoT certificate further includes a QoT forwarding policy of the management device for the terminal device, and the QoT forwarding policy includes a highest service QoT level provided by the management device to the terminal device and / or a default service QoT level provided by the management device to the terminal device.
24. The terminal device of claim 22 or 23, wherein The processing module is further configured to add a corresponding relationship among the destination address of the first service, the service QoT level corresponding to the first service, and the target connection identifier in the connection identifier set after the terminal device receives the data transmission response sent by the management device.
25. The terminal device according to any one of claims 22 to 24, characterized by, The data transmission request further includes a service QoT level indication, and the service QoT level indication is used to indicate the service QoT level corresponding to the first service.
26. The terminal device of any one of claims 22 to 25, wherein The sending module is configured to send a QoT parameter of the terminal device to the management device, the QoT parameter including one or more of device identity information, hardware configuration information, software configuration information, or network access information; The receiving module is configured to receive the QoT certificate of the management device based on the QoT parameter.
27. The terminal device of claim 26, wherein The sending module is further configured to send a registration request to the management device before sending the QoT parameter of the terminal device to the management device. The receiving module is further configured to receive a QoT authentication request sent by the management device, the QoT authentication request comprising a QoT parameter indication, the QoT parameter indication being used to indicate the QoT parameter required to be provided by the terminal device. The sending module is configured to send a QoT authentication response to the management device, the QoT authentication response comprising the QoT parameter indicated by the QoT parameter indication.
28. The terminal device of claim 26 or 27, wherein: The sending module is further configured to send the latest QoT parameter of the terminal device to the management device when the QoT certificate meets a certificate update condition. The receiving module is further configured to receive an updated QoT certificate sent by the management device based on the latest QoT parameter.
29. The terminal device of claim 28, wherein, The certificate update condition comprises one or more of the following: The QoT certificate is out of a valid period; The QoT parameter of the terminal device is changed; The terminal device and / or the management device cannot parse the QoT certificate.
30. The terminal device according to any one of claims 21 to 29, characterized by, The service packet further comprises an indication of a service QoT level corresponding to the first service and an integrity verification tag calculated based on the indication.
31. The terminal device of any of claims 21 to 30, wherein: The processing module is further configured to obtain a service QoT level corresponding to a second service, the service QoT level corresponding to the second service not matching a device QoT level of the terminal device. The processing module is further configured to reject transmission of a service packet of the second service.
32. A management device, comprising: The management device comprises: A receiving module configured to receive a data transmission request sent by a terminal device, the data transmission request comprising a destination address of a first service and a trust quality QoT certificate of the terminal device, the QoT certificate comprising a device QoT level of the terminal device. A processing module configured to establish a target communication connection between the terminal device and the destination address of the first service based on the QoT certificate, a service QoT level corresponding to the target communication connection matching the device QoT level of the terminal device. A sending module configured to send a data transmission response to the terminal device, the data transmission response comprising a target connection identifier, the target connection identifier being a connection identifier of the target communication connection.
33. The management device according to claim 32, wherein The data transmission request further comprises a service QoT level indication, the service QoT level indication being used to indicate a service QoT level corresponding to the first service, and the processing module is configured to: When the service QoT level indicated by the service QoT level indication matches the device QoT level of the terminal device, establish the target communication connection corresponding to the service QoT level indicated by the service QoT level indication.
34. The management device according to claim 32 or 33, characterized by The QoT certificate further includes a QoT forwarding policy of the management device for the terminal device, the QoT forwarding policy including a highest service QoT level provided by the management device to the terminal device and / or a default service QoT level provided by the management device to the terminal device.
35. The management device of any one of claims 32-34, wherein: The receiving module is further configured to receive QoT parameters of the terminal device sent by the terminal device, the QoT parameters including one or more of device identity information, hardware configuration information, software configuration information, or network access information; The processing module is further configured to generate the QoT certificate based on the QoT parameters; The sending module is further configured to send the QoT certificate to the terminal device.
36. The management device of claim 35, wherein: The receiving module is further configured to receive a registration request sent by the terminal device; The sending module is further configured to send a QoT authentication request to the terminal device based on the registration request, the QoT authentication request including a QoT parameter indication indicating QoT parameters required to be provided by the terminal device; The receiving module is configured to receive a QoT authentication response sent by the terminal device, the QoT authentication response including the QoT parameters indicated by the QoT parameter indication.
37. The management device of any one of claims 32-36, wherein: The receiving module is further configured to receive a path computation request of a network device, the path computation request including the target connection identifier; The processing module is further configured to determine a target transmission path used by the target communication connection according to a service QoT level corresponding to the target connection identifier, a device QoT level of a network device on the target transmission path matching the service QoT level corresponding to the target connection identifier; The sending module is further configured to send a path computation response to the network device, the path computation response including path information of the target transmission path.
38. A network device, comprising: The network device includes: A receiving module configured to receive a service packet of a first service sent by a terminal device, the service packet including a target connection identifier; A processing module configured to obtain a target transmission path corresponding to the target connection identifier, a device quality of trust (QoT) level of a network device on the target transmission path matching a service QoT level corresponding to the target connection identifier; A sending module configured to forward the service packet based on the target transmission path.
39. The network device of claim 38, wherein, The processing module is configured to: send, by the sending module, a path computation request to a management device, the path computation request including the target connection identifier; receive, by the receiving module, a path computation response sent by the management device, the path computation response including path information of the target transmission path.
40. The network device of claim 38 or 39, wherein, The service packet further includes an indication of a service QoT level corresponding to the first service and an integrity verification tag calculated based on the indication, and the sending module is configured to: When the service QoT level indicated by the indication is the same as the service QoT level corresponding to the target connection identifier, and the integrity verification tag is verified by the network device, the service packet is forwarded based on the target transmission path.
41. A data transmission system, characterized by The application further provides a terminal device, a management device and a network device. The application further provides a terminal device, a management device and a network device.
42. A data transmission device, comprising: The application further provides a terminal device, a management device and a network device. The application further provides a terminal device, a management device and a network device. The application further provides a terminal device, a management device and a network device. The application further provides a terminal device, a management device and a network device.
43. A computer-readable storage medium, comprising: The application further provides a terminal device, a management device and a network device.
44. A computer program product, characterised in that, The application further provides a terminal device, a management device and a network device. The application further provides a terminal device, a management device and a network device. The application further provides a terminal device, a management device and a network device. The application further provides a terminal device, a management device and a network device. The application further provides a terminal device, a management device and a network device. The application further provides a terminal device, a management device and a network device. The application further provides a terminal device, a management device and a network device. The application further provides a terminal device, a management device and a network device. The application further provides a terminal device, a management device and a network device. The application further provides a terminal device, a management device and a network device. The application further provides a terminal device, a management device and a network device. The application further provides a terminal device, a management device and a network device. The application further provides a terminal device, a management device and a network device. The application further provides a terminal device, a management device and a network device. The application further provides a terminal device, a management device and a network device. The application further provides a terminal device, a management device and a network device. The application further provides a terminal device, a management device and a network device. The application further provides a terminal device, a management device and a network device. The application further provides a terminal device, a management device and a network device. The application further provides a terminal device, a management device and a network device. The application further provides a terminal device, a management device and a network device. The application further provides a terminal device, a management device and a network device. The application further provides a terminal device, a management device and a network device. The application further provides a terminal device, a management device and
Citation Information
Patent Citations
Data transmission method and related equipment
CN115706977A