A blockchain-based trusted data storage method and apparatus
By selecting multiple AMF and SMF network elements in the RAN equipment to form a blockchain, the problems of data security and reliability in high-reliability and high-trust communication scenarios are solved, and secure and reliable data transmission for terminal access and mobility management is realized.
Patent Information
- Application Number
- CN202311512780.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-14
- Publication Date
- 2025-11-14
- Estimated Expiration
- 2043-11-14
AI Technical Summary
Existing terminal access and mobility management methods are not applicable in high-reliability and high-trust communication scenarios, especially when selecting AMF and SMF network elements, which lack data security and reliability guarantees.
By employing blockchain technology, multiple AMF and SMF network elements are selected through RAN equipment to form a blockchain. The first network element serves as the master node, and the second network element serves as the auxiliary node, thereby achieving synchronous recording and secure transmission of data and ensuring that the data is tamper-proof.
It achieves data security and reliability for terminal access and mobility management in highly reliable and trustworthy communication scenarios, meeting future communication needs.
Smart Images

Figure CN117560743B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a blockchain-based trusted data storage method. Background Technology
[0002] In the process defined by the 3rd Generation Partnership Project (3GPP), after a terminal connects to a base station, it can initiate a registration process with the network. At this time, the base station needs to select an Access and Mobility Management Function (AMF) network element for the terminal to provide access and mobility management services. Afterward, the terminal initiates a session establishment process. At this point, the previously selected AMF network element needs to select a Session Management Function (SMF) network element for the terminal to provide session management services.
[0003] However, with the evolution of communication technology, the approach of selecting a single AMF or SMF network element to provide services to the terminal may not be suitable for future communication scenarios, such as scenarios requiring high data reliability and trustworthiness. Summary of the Invention
[0004] This application provides a blockchain-based trusted data storage method and apparatus to enable the AMF network element selected for the terminal to provide services to the terminal in a blockchain manner, so as to meet the future scenarios of high data reliability and trustworthiness.
[0005] To achieve the above objectives, this application adopts the following technical solution:
[0006] In a first aspect, embodiments of this application provide a blockchain-based trusted data storage method. This method is applied to a RAN device and includes: when a terminal accesses the RAN device, the RAN device requests an NRF network element to discover an AMF network element for the terminal; the RAN device receives an AMF set provided by the NRF network element according to the RAN device's request; the RAN device selects an AMF subset from the AMF set; the RAN device determines the AMF subset as a first blockchain providing access and mobility management services to the terminal, wherein the AMF subset includes at least a first AMF network element and a second AMF network element, the first AMF network element serving as the terminal's AMF network element is the master node in the first blockchain, and the second AMF network element is a secondary node in the first blockchain, the secondary node being used to synchronously record the access and mobility management services provided by the master node to the terminal.
[0007] In one possible design, the RAN device requests the NRF network element to discover AMF network elements for the terminal. This includes: the RAN device sending an AMF discovery request message to the NRF network element, wherein the AMF discovery request message carries the terminal's Network Slice Selection Assistance Information (NSSAI). The RAN device receives the AMF set provided by the NRF network element according to the RAN device's request, including: the RAN device receiving an AMF discovery response message returned by the NRF network element, wherein the AMF discovery response message includes the AMF set, and the first AMF network element and the second AMF network element are AMF network elements selected by the NRF network element that match the terminal's NSSAI.
[0008] It is understandable that in the 3GPP-defined standards, when a RAN device requests an NRF network element to discover an AMF network element, it can provide not only the terminal's NSSAI but also other relevant information. This application can also reuse this information without limitation. Furthermore, in the 3GPP-defined standards, the NRF network element can directly select a serving AMF network element for the terminal. However, the difference in this application's embodiments is that the NRF network element does not have the ability to create a blockchain. If the serving AMF network element is to provide services to the terminal in a blockchain manner, the NRF network element cannot directly select a serving AMF network element. Therefore, the NRF network element can only perform certain screening of AMF network elements under protocol constraints to ensure that the RAN device can still create a first blockchain based on a sufficient number of AMF network elements.
[0009] Optionally, the RAN device selects a subset of AMFs from the AMF set, including: the RAN device probes the availability of AMF network elements in the AMF set, and determines the available AMF network elements in the AMF set as the AMF subset. Available AMF network elements refer to non-faulty AMF network elements; conversely, unavailable AMF network elements are usually faulty AMF network elements. For example, the RAN device sends probe messages to AMF network elements in the AMF set. If it receives a response from an AMF network element, it indicates that the AMF network element is available; otherwise, it is unavailable.
[0010] Optionally, the RAN device identifies the AMF subset as the first blockchain providing access and mobility management services to the terminal, including: the RAN device identifying the AMF subset as the first blockchain providing access and mobility management services to the terminal based on the AMF subset including at least two AMF network elements. Further, the method may include: the RAN device obtaining the load of the first AMF network element from the first AMF network element (e.g., requesting the first AMF network element to provide its current load); the RAN device obtaining the load of the second AMF network element from the second AMF network element (e.g., requesting the second AMF network element to provide its current load); if the load of the first AMF network element is higher than the load of the second AMF network element, the RAN device identifies the first AMF network element as the serving AMF network element of the terminal; based on the first AMF network element being the serving AMF network element of the terminal, the RAN device identifies the first AMF network element as the master node in the first blockchain; and based on the master node being identified in the first blockchain, the RAN device identifies the second AMF network element as the secondary node in the first blockchain.
[0011] It is understood that the RAN device determines whether to establish a blockchain based on the number of AMF network elements. If there is only one available AMF network element, the RAN device will not establish a blockchain and will execute the procedures defined in 3GPP. Conversely, if there are multiple available AMF network elements, the RAN device will establish a blockchain and execute the procedures defined in this application.
[0012] It's understandable that, due to the immutable nature of blockchain, secondary nodes need to record the primary node's data throughout the entire process, also known as invoices. Therefore, priority must be given to ensuring the performance of secondary nodes, selecting AMF network elements with lower loads as secondary nodes (this is the opposite of the AMF selection logic currently defined by 3GPP). Although the load of the primary node's AMF network elements is higher, it can still meet the requirements of providing access and mobility services to terminals. Furthermore, the trigger condition for the RAN equipment to obtain the load of the AMF network elements is for the RAN equipment to determine the first blockchain, such as assigning a unique identifier to the first blockchain.
[0013] It is also understandable that the AMF subset can include more AMF network elements, such as the third AMF network element, which is implemented in a similar way to the second AMF network element. This can be understood by referring to it, and will not be elaborated further.
[0014] Optionally, the method further includes: the RAN device sending first indication information to a first AMF network element, wherein the first indication information is used to indicate that the first AMF network element needs to act as a master node in the first blockchain to provide access and mobility management services to the terminal. For example, the first indication information includes at least one of the following: an identifier of the first blockchain, an identifier of the terminal, an identifier for indicating that the first AMF network element is a master node in the first blockchain, an identifier for indicating that the first AMF network element is a serving AMF network element, or an identifier for indicating that the second AMF network element is a secondary node in the first blockchain. And, the RAN device sending second indication information to the second AMF network element, wherein the second indication information is used to indicate that the second AMF network element needs to act as a secondary node in the first blockchain to record master node providing access and mobility management services to the terminal. For example, the second indication information includes at least one of the following: an identifier of the first blockchain, an identifier of the terminal, an identifier for indicating that the first AMF network element is a master node in the first blockchain, or an identifier for indicating that the AMF network element is a secondary node in the first blockchain. In this way, the first AMF network element can provide the second AMF network element with the record of the first AMF network element providing access and mobility management services to the terminal according to the first instruction information. Correspondingly, the second AMF network element can save the record of the first AMF network element providing access and mobility management services to the terminal according to the second instruction information.
[0015] It is understood that the above implementations are merely examples. For instance, the AMF network elements in the first blockchain can share the NAS key between the service AMF network element (i.e., the master node) and the terminal. In other words, the records provided by the first AMF network element to the terminal for providing access and mobility management services can be encrypted text protected by the NAS key (e.g., confidentiality and integrity), allowing the second AMF network element to verify them using the NAS key and save them after successful verification.
[0016] In one possible design, the method is further applied to a first AMF network element. The method further includes: when a terminal requests to establish a session, the first AMF network element requests an NRF network element to discover SMF network elements for the terminal; the first AMF network element receives an SMF set provided by the NRF network element according to the request of the first AMF network element; the first AMF network element selects a subset of SMFs from the SMF set; the first AMF network element determines the SMF subset as a second blockchain providing session management services to the terminal, wherein the SMF subset includes at least the first SMF network element and the second SMF network element, the first SMF network element serving as the terminal's service SMF network element is the master node in the second blockchain, and the second SMF network element is a secondary node in the second blockchain, the secondary node being used to synchronously record the session management services provided by the master node to the terminal.
[0017] Optionally, the first AMF network element requests the NRF network element to discover SMF network elements for the terminal, including: the first AMF network element sending an SMF discovery request message to the NRF network element, wherein the SMF discovery request message carries the terminal's Data Network Name (DNN) and Single Network Slice Selection Assistance information (S-NSSAI). The first AMF network element receiving the SMF set provided by the NRF network element according to the request of the first AMF network element includes: the first AMF network element receiving the SMF discovery response message returned by the NRF network element. The SMF discovery response message includes the SMF set, and the first SMF network element and the second SMF network element are SMF network elements selected by the NRF network element that match the terminal's DNN and S-NSSAI.
[0018] It is understandable that in the 3GPP-defined standards, when an AMF network element requests an NRF network element to discover an SMF network element, it can provide not only the terminal's DNN and S-NSSAI, but also other relevant information. This application can also reuse this information without limitation. Furthermore, in the 3GPP-defined standards, the NRF network element can directly select a serving SMF network element for the terminal. However, the difference in this application's embodiments is that the NRF network element does not have the ability to create a blockchain. If the serving SMF network element is to provide services to the terminal in a blockchain manner, the NRF network element cannot directly select a serving AMF network element. Therefore, the NRF network element can only perform certain screening of SMF network elements under protocol constraints to ensure that the AMF network element can still create a second blockchain based on a sufficient number of SMF network elements.
[0019] Furthermore, the first AMF network element selects an SMF subset from the SMF set, including: the RAN equipment determines the SMF network elements in the SMF set that support the access technology used by the terminal access as the SMF subset, such as those supporting 3GPP access or non-3GPP access, based on the access technology used by the terminal access.
[0020] Furthermore, the first AMF network element identifies the SMF subset as the second blockchain providing session management services to the terminal, including: the first AMF network element identifying the SMF subset as the first blockchain providing session management services to the terminal based on the SMF subset including at least two SMF network elements. Based on this, the method further includes: the first AMF network element obtaining the load of the first SMF network element from the first SMF network element (e.g., requesting the first SMF network element to provide its current load); the first AMF network element obtaining the load of the second SMF network element from the second SMF network element (e.g., requesting the second SMF network element to provide its current load); if the load of the first SMF network element is higher than the load of the second SMF network element, the first SMF network element identifies the first SMF network element as the serving SMF network element of the terminal; the first AMF network element identifies the first SMF network element as the master node in the second blockchain based on the fact that the first SMF network element is the serving SMF network element of the terminal; and the first AMF network element identifies the second SMF network element as the auxiliary node in the second blockchain based on the fact that the master node in the second blockchain has been identified.
[0021] It is understood that the basis for whether an AMF network element establishes a blockchain is the number of SMF network elements. If there is only one SMF network element in the SMF subset, the AMF network element will not establish a blockchain and will execute the process defined in 3GPP. Conversely, if there are multiple SMF network elements in the SMF subset, the AMF network element will establish a blockchain and will execute the process defined in this application.
[0022] It's understandable that, due to the immutable nature of blockchain, secondary nodes need to record the primary node's data throughout the entire process, also known as invoices. Therefore, priority must be given to ensuring the performance of secondary nodes, selecting SMF network elements with lower loads as secondary nodes (this is the opposite of the SMF selection logic defined by 3GPP). Although the load of the primary node's SMF network elements is higher, it can still meet the requirement of providing session management services to the terminal. Furthermore, the trigger condition for the AMF network element to obtain the load of the SMF network element is that the AMF network element determines the second blockchain, such as assigning a second blockchain identifier to uniquely identify the second blockchain.
[0023] It is also understandable that the SMF subset can include more SMF network elements, such as the third SMF network element, which is implemented in a similar way to the second SMF network element. This can be understood by referring to it, and will not be elaborated further.
[0024] Optionally, the method further includes: a first AMF network element sending third indication information to a first SMF network element. The third indication information is used to instruct the first SMF network element to act as a master node in the second blockchain to provide session management services to the terminal; for example, the third indication information includes at least one of the following: an identifier of the second blockchain, an identifier of the terminal, an identifier indicating the first SMF network element to act as a master node in the second blockchain, an identifier indicating the SMF network element to act as a service SMF network element, or an identifier indicating the second SMF network element to act as a master-slave node in the second blockchain. The first AMF network element sends fourth indication information to the second SMF network element, wherein the fourth indication information is used to instruct the second SMF network element to act as a slave node in the second blockchain to record master node providing session management services to the terminal; for example, the fourth indication information includes at least one of the following: an identifier of the second blockchain, an identifier of the terminal, an identifier indicating the first SMF network element to act as a master node in the second blockchain, or an identifier indicating the second SMF network element to act as a slave node in the second blockchain.
[0025] It is understood that the above implementations are merely examples. For instance, SMF network elements in the second blockchain can share the key of the serving SMF network element, which can be derived by the first AMF network element using the aforementioned NAS key as an input parameter. In other words, the records of the first SMF network element's session management service for the terminal can be ciphertext protected by this key (e.g., confidentiality and integrity), allowing the second SMF network element to verify them using this key and save them after successful verification.
[0026] Secondly, embodiments of this application provide a blockchain-based trusted data storage device. This device is applied to a RAN device and is configured to: when a terminal accesses the RAN device, the RAN device requests an NRF network element to discover an AMF network element for the terminal; the RAN device receives an AMF set provided by the NRF network element according to the RAN device's request; the RAN device selects an AMF subset from the AMF set; the RAN device determines the AMF subset as a first blockchain that provides access and mobility management services to the terminal, wherein the AMF subset includes at least a first AMF network element and a second AMF network element, the first AMF network element being the service AMF network element of the terminal and the master node in the first blockchain, and the second AMF network element being a secondary node in the first blockchain, the secondary node being used to synchronously record the access and mobility management services provided by the master node to the terminal.
[0027] In one possible design, the device is configured such that: the RAN device sends an AMF discovery request message to the NRF network element, wherein the AMF discovery request message carries the terminal's NSSAI. The device is also configured such that: the RAN device receives an AMF discovery response message returned by the NRF network element, wherein the AMF discovery response message includes an AMF set, and the first AMF network element and the second AMF network element are AMF network elements selected by the NRF network element that match the terminal's NSSAI.
[0028] Optionally, the device is configured such that the RAN equipment detects the availability of AMF network elements in the AMF set and determines the available AMF network elements in the AMF set as a subset of AMFs.
[0029] Optionally, the device is configured such that: the RAN device determines the AMF subset as a first blockchain providing access and mobility management services to the terminal, based on the AMF subset including at least two AMF network elements. Furthermore, the device is configured to: obtain the load of the first AMF network element from the first AMF network element (e.g., requesting the first AMF network element to provide its current load); obtain the load of the second AMF network element from the second AMF network element (e.g., requesting the second AMF network element to provide its current load); if the load of the first AMF network element is higher than the load of the second AMF network element, the RAN device determines the first AMF network element as the serving AMF network element of the terminal; based on the fact that the first AMF network element is the serving AMF network element of the terminal, the RAN device determines the first AMF network element as the master node in the first blockchain; and based on the fact that the master node in the first blockchain has been determined, the RAN device determines the second AMF network element as the secondary node in the first blockchain.
[0030] Optionally, the apparatus is configured such that: the RAN device sends first indication information to a first AMF network element, wherein the first indication information is used to instruct the first AMF network element to act as a master node in the first blockchain to provide access and mobility management services to the terminal. For example, the first indication information includes at least one of the following: an identifier of the first blockchain, an identifier of the terminal, an identifier for instructing the first AMF network element to act as a master node in the first blockchain, an identifier for instructing the first AMF network element to act as a serving AMF network element, or an identifier for instructing the second AMF network element to act as a secondary node in the first blockchain. Furthermore, the RAN device sends second indication information to the second AMF network element, wherein the second indication information is used to instruct the second AMF network element to act as a secondary node in the first blockchain to record master node records for providing access and mobility management services to the terminal. For example, the second indication information includes at least one of the following: an identifier of the first blockchain, an identifier of the terminal, an identifier for instructing the first AMF network element to act as a master node in the first blockchain, or an identifier for instructing the AMF network element to act as a secondary node in the first blockchain.
[0031] In one possible design, the device is also applied to a first AMF network element, which is configured to: when a terminal requests to establish a session, the first AMF network element requests an NRF network element to discover SMF network elements for the terminal; the first AMF network element receives an SMF set provided by the NRF network element according to the request of the first AMF network element; the first AMF network element selects a subset of SMFs from the SMF set; the first AMF network element determines the SMF subset as a second blockchain that provides session management services for the terminal, wherein the SMF subset includes at least the first SMF network element and the second SMF network element, the first SMF network element serving as the terminal's service SMF network element is the master node in the second blockchain, and the second SMF network element is a secondary node in the second blockchain, the secondary node being used to synchronously record the session management services provided by the master node to the terminal.
[0032] Optionally, the device is configured to: send an SMF discovery request message to an NRF network element, wherein the SMF discovery request message carries the terminal's DNN and S-NSSAI. The device is also configured to: receive an SMF discovery response message returned by the NRF network element. The SMF discovery response message includes a set of SMFs, and the first and second SMF network elements are SMF network elements selected by the NRF network element that match the terminal's DNN and S-NSSAI.
[0033] Furthermore, the device is configured such that the RAN equipment determines the SMF set as a subset of SMFs that support the access technology used by the terminal access, such as supporting 3GPP access or non-3GPP access, based on the access technology used by the terminal access.
[0034] Furthermore, the device is configured such that: a first AMF network element, based on the fact that the SMF subset includes at least two SMF network elements, identifies the SMF subset as a first blockchain providing session management services to the terminal. Based on this, the device is configured such that: the first AMF network element obtains the load of the first SMF network element from the first SMF network element (e.g., requests the first SMF network element to provide its current load); the first AMF network element obtains the load of the second SMF network element from the second SMF network element (e.g., requests the second SMF network element to provide its current load); if the load of the first SMF network element is higher than the load of the second SMF network element, the first SMF network element identifies the first SMF network element as the serving SMF network element for the terminal; based on the fact that the first SMF network element is the serving SMF network element for the terminal, the first AMF network element identifies the first SMF network element as the master node in the second blockchain; and based on the fact that the master node in the second blockchain has been identified, the first AMF network element identifies the second SMF network element as a secondary node in the second blockchain.
[0035] Optionally, the device is configured such that: a first AMF network element sends a third indication message to a first SMF network element. The third indication message indicates that the first SMF network element needs to act as a master node in the second blockchain to provide session management services to the terminal; for example, the third indication message includes at least one of the following: an identifier of the second blockchain, an identifier of the terminal, an identifier indicating that the first SMF network element acts as a master node in the second blockchain, an identifier indicating that the SMF network element acts as a serving SMF network element, or an identifier indicating that the second SMF network element acts as a master-slave node in the second blockchain. The first AMF network element sends a fourth indication message to the second SMF network element, wherein the fourth indication message indicates that the second SMF network element needs to act as a slave node in the second blockchain to record master node providing session management services to the terminal; for example, the fourth indication message includes at least one of the following: an identifier of the second blockchain, an identifier of the terminal, an identifier indicating that the first SMF network element acts as a master node in the second blockchain, or an identifier indicating that the second SMF network element acts as a slave node in the second blockchain.
[0036] Thirdly, embodiments of this application provide a computer-readable storage medium storing program code, which, when executed by the computer, performs the method described in the first aspect.
[0037] In summary, the above method and apparatus have the following technical effects:
[0038] During the selection of AMF network elements, the RAN equipment can select multiple AMF network elements of the terminal as a blockchain, such as the first blockchain. The first AMF network element is the service AMF network element of the terminal and is the master node in the first blockchain. The second AMF network element is the auxiliary node in the first blockchain. The auxiliary node is used to synchronously record the access and mobility management services provided by the master node to the terminal. In this way, the AMF network elements selected for the terminal can provide services to the terminal in a blockchain manner to meet the future scenarios of high data reliability and high trustworthiness. Attached Figure Description
[0039] Figure 1 This is a schematic diagram of the architecture of a 5G system;
[0040] Figure 2 This is a schematic diagram of the architecture of the communication system provided in the embodiments of this application;
[0041] Figure 3 A flowchart illustrating a blockchain-based trusted data storage method provided in this application embodiment;
[0042] Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0043] 1. Fifth generation (5G) mobile communication system:
[0044] Figure 1 A schematic diagram of the 5G system architecture, such as Figure 1 As shown, a 5G system includes an access network (AN) and a core network (CN), and may also include terminals.
[0045] The aforementioned terminal can be a terminal with transceiver capabilities, or a chip or chip system that can be installed on the terminal. This terminal can also be referred to as user equipment (UE), access terminal, user unit, user station, mobile station (MS), mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication equipment, user agent, or user equipment. The terminals in the embodiments of this application may be mobile phones, cellular phones, smartphones, tablets, wireless data cards, personal digital assistants (PDAs), wireless modems, handsets, laptop computers, machine-type communication (MTC) terminals, computers with wireless transceiver capabilities, virtual reality (VR) terminals, augmented reality (AR) terminals, wireless terminals in industrial control, wireless terminals in self-driving, wireless terminals in remote medical care, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, wireless terminals in smart homes, vehicle-mounted terminals, roadside units (RSUs) with terminal functions, etc. The terminal of this application may also be an on-board module, on-board unit, on-board component, on-board chip or on-board unit that is built into a vehicle as one or more components or units.
[0046] The aforementioned AN is used to implement access-related functions. It can provide network access functionality for authorized users in a specific area and determine transmission links of different quality according to user level and service requirements to transmit user data. The AN forwards control signals and user data between the terminal and the CN. The AN may include: access network element, also known as radio access network (RAN) equipment.
[0047] RAN equipment can be devices that provide access for terminals. For example, RAN equipment can include: 5G, such as a gNB in a New Radio (NR) system, or one or a group of antenna panels (including multiple antenna panels) of a 5G base station; or, network nodes constituting a gNB, transmission and reception point (TRP) or transmission point (TP), or transmission measurement function (TMF), such as a building base band unit (BBU), or a centralized unit (CU) or distributed unit (DU), an RSU with base station functionality, or a wired access gateway, or a 5G core network element. Alternatively, RAN equipment can also include access points (APs) in Wireless Fidelity (WiFi) systems, wireless relay nodes, wireless backhaul nodes, various forms of macro base stations, micro base stations (also known as small cells), relay stations, access points, wearable devices, vehicle-mounted equipment, etc. Alternatively, the RAN equipment may also include next-generation mobile communication systems, such as 6G access network elements, such as 6G base stations, or in next-generation mobile communication systems, the network equipment may have other naming methods, all of which are covered within the protection scope of the embodiments of this application, and this application does not limit them in any way.
[0048] The Network Center (CN) is primarily responsible for maintaining the subscription data of the mobile network and providing terminals with functions such as session management, mobility management, policy management, and security authentication. The CN mainly includes the following network elements: User Plane Function (UPF) network elements, Authentication Server Function (AUSF) network elements, Access and Mobility Management Function (AMF) network elements, Session Management Function (SMF) network elements, Network Slice Selection Function (NSSF) network elements, Network Exposure Function (NEF) network elements, Network Function Repository Function (NRF) network elements, Policy Control Function (PCF) network elements, Unified Data Management (UDM) network elements, Application Function (AF) network elements, and Network Slice-Specific and SNPN Authentication and Authorization Function (NSSAAF) network elements.
[0049] The UPF (User-Defined Provider) network element is primarily responsible for user data processing (forwarding, receiving, billing, etc.). For example, a UPF network element can receive user data from a data network (DN) and forward it to the terminal through an access network element. A UPF network element can also receive user data from a terminal through an access network element and forward it to the DN. DN network elements refer to the operator's network that provides data transmission services to users. Examples include Internet Protocol (IP), IP Multimedia Service (IMS), and the Internet.
[0050] AUSF network elements can be used to perform security authentication for terminals.
[0051] AMF network elements are primarily responsible for mobility management in mobile networks. This includes tasks such as user location updates, user network registration, and user handover.
[0052] SMF (Service Provider Function) elements are primarily responsible for session management in mobile networks. This includes session establishment, modification, and release. Specific functions include assigning Internet Protocol (IP) addresses to users and selecting a UPF (User Provider Function) to provide packet forwarding capabilities.
[0053] The PCF network element primarily supports providing a unified policy framework to control network behavior, providing policy rules to the control layer network functions, and is also responsible for acquiring user subscription information related to policy decisions. The PCF network element can provide policies to the AMF and SMF network elements, such as Quality of Service (QoS) policies and slice selection policies.
[0054] NSSF network elements can be used to select network slices for terminals.
[0055] NEF network elements can be used to support the opening of capabilities and events.
[0056] UDM network elements can be used to store user data, such as subscription data, authentication / authorization data, etc.
[0057] AF network elements primarily support interaction with CN to provide services, such as influencing data routing decisions, policy control functions, or providing third-party services to the network side.
[0058] The technical solutions in this application will now be described with reference to the accompanying drawings.
[0059] Please see Figure 2 This application provides a communication system, which includes RAN equipment and AMF network elements.
[0060] In this communication system, during the selection of AMF network elements, the RAN equipment can select multiple AMF network elements of the terminal as a blockchain, such as the first blockchain. The first AMF network element is the serving AMF network element of the terminal and is the master node in the first blockchain. The second AMF network element is the auxiliary node in the first blockchain. The auxiliary node is used to synchronously record the access and mobility management services provided by the master node to the terminal. In this way, the AMF network elements selected for the terminal can provide services to the terminal in a blockchain manner to meet the future scenarios of high data reliability and high trustworthiness.
[0061] For details, please refer to the following method implementation examples.
[0062] Please see Figure 3 This application provides a blockchain-based trusted data storage method. This method is applicable to communication between access and mobility management network elements and terminal groups. The method's process includes:
[0063] S301, when a terminal accesses a RAN device, the RAN device requests an NRF network element to discover an AMF network element for the terminal.
[0064] S302, the RAN device receives the AMF set provided by the NRF network element according to the request of the RAN device.
[0065] In one possible design, the RAN device requests the NRF network element to discover AMF network elements for the terminal. This includes: the RAN device sending an AMF discovery request message to the NRF network element, wherein the AMF discovery request message carries the terminal's Network Slice Selection Assistance Information (NSSAI). The RAN device receives the AMF set provided by the NRF network element according to the RAN device's request, including: the RAN device receiving an AMF discovery response message returned by the NRF network element, wherein the AMF discovery response message includes the AMF set, and the first AMF network element and the second AMF network element are AMF network elements selected by the NRF network element that match the terminal's NSSAI.
[0066] It is understandable that in the 3GPP-defined standards, when a RAN device requests an NRF network element to discover an AMF network element, it can provide not only the terminal's NSSAI but also other relevant information. This application can also reuse this information without limitation. Furthermore, in the 3GPP-defined standards, the NRF network element can directly select a serving AMF network element for the terminal. However, the difference in this application's embodiments is that the NRF network element does not have the ability to create a blockchain. If the serving AMF network element is to provide services to the terminal in a blockchain manner, the NRF network element cannot directly select a serving AMF network element. Therefore, the NRF network element can only perform certain screening of AMF network elements under protocol constraints to ensure that the RAN device can still create a first blockchain based on a sufficient number of AMF network elements.
[0067] S303, the RAN device selects a subset of AMFs from the AMF set.
[0068] RAN devices can probe the availability of AMF network elements within an AMF set, identifying available AMF network elements as a subset of AMFs. Available AMF network elements are those that are not faulty; conversely, unavailable AMF network elements are typically faulty. For example, if a RAN device sends a probe message to an AMF network element in the AMF set and receives a response, it indicates that the AMF network element is available; otherwise, it is unavailable.
[0069] S304, the RAN equipment identifies the AMF subset as the first blockchain to provide access and mobility management services for terminals.
[0070] The AMF subset includes at least a first AMF network element and a second AMF network element. The first AMF network element, as the service AMF network element of the terminal, is the master node in the first blockchain. The second AMF network element is the auxiliary node in the first blockchain. The auxiliary node is used to synchronously record the access and mobility management services provided by the master node to the terminal.
[0071] Specifically, the RAN device can determine the AMF subset as the first blockchain providing access and mobility management services to the terminal, based on the AMF subset including at least two AMF network elements. On this basis, the RAN device can obtain the load of the first AMF network element (e.g., requesting the first AMF network element to provide its current load); the RAN device can obtain the load of the second AMF network element (e.g., requesting the second AMF network element to provide its current load); if the load of the first AMF network element is higher than the load of the second AMF network element, the RAN device can determine the first AMF network element as the serving AMF network element for the terminal; based on the fact that the first AMF network element is the serving AMF network element for the terminal, the RAN device can determine the first AMF network element as the master node in the first blockchain; and based on the fact that the master node in the first blockchain has been determined, the RAN device can determine the second AMF network element as the auxiliary node in the first blockchain.
[0072] It is understood that the RAN device determines whether to establish a blockchain based on the number of AMF network elements. If there is only one available AMF network element, the RAN device will not establish a blockchain and will execute the procedures defined in 3GPP. Conversely, if there are multiple available AMF network elements, the RAN device will establish a blockchain and execute the procedures defined in this application.
[0073] It's understandable that, due to the immutable nature of blockchain, secondary nodes need to record the primary node's data throughout the entire process, also known as invoices. Therefore, priority must be given to ensuring the performance of secondary nodes, selecting AMF network elements with lower loads as secondary nodes (this is the opposite of the AMF selection logic currently defined by 3GPP). Although the load of the primary node's AMF network elements is higher, it can still meet the requirements of providing access and mobility services to terminals. Furthermore, the trigger condition for the RAN equipment to obtain the load of the AMF network elements is for the RAN equipment to determine the first blockchain, such as assigning a unique identifier to the first blockchain.
[0074] It is also understandable that the AMF subset can include more AMF network elements, such as the third AMF network element, which is implemented in a similar way to the second AMF network element. This can be understood by referring to it, and will not be elaborated further.
[0075] Optionally, the RAN device may send first indication information to the first AMF network element, wherein the first indication information is used to instruct the first AMF network element to act as the master node in the first blockchain to provide access and mobility management services to the terminal. For example, the first indication information includes at least one of the following: an identifier of the first blockchain, an identifier of the terminal, an identifier for instructing the first AMF network element to act as the master node in the first blockchain, an identifier for instructing the first AMF network element to act as a serving AMF network element, or an identifier for instructing the second AMF network element to act as a secondary node in the first blockchain. Furthermore, the RAN device may send second indication information to the second AMF network element, wherein the second indication information is used to instruct the second AMF network element to act as a secondary node in the first blockchain to record the master node providing access and mobility management services to the terminal. For example, the second indication information includes at least one of the following: an identifier of the first blockchain, an identifier of the terminal, an identifier for instructing the first AMF network element to act as the master node in the first blockchain, or an identifier for instructing the AMF network element to act as a secondary node in the first blockchain. In this way, the first AMF network element can provide the second AMF network element with the record of the first AMF network element providing access and mobility management services to the terminal according to the first instruction information. Correspondingly, the second AMF network element can save the record of the first AMF network element providing access and mobility management services to the terminal according to the second instruction information.
[0076] It is understood that the above implementations are merely examples. For instance, the AMF network elements in the first blockchain can share the NAS key between the service AMF network element (i.e., the master node) and the terminal. In other words, the records provided by the first AMF network element to the terminal for providing access and mobility management services can be encrypted text protected by the NAS key (e.g., confidentiality and integrity), allowing the second AMF network element to verify them using the NAS key and save them after successful verification.
[0077] In summary, during the selection of AMF network elements, RAN equipment can select multiple AMF network elements of the terminal as a blockchain, such as the first blockchain. The first AMF network element serves as the service AMF network element of the terminal and is the master node in the first blockchain. The second AMF network element is a secondary node in the first blockchain. The secondary node is used to synchronously record the access and mobility management services provided by the master node to the terminal. In this way, the AMF network elements selected for the terminal can provide services to the terminal in a blockchain manner to meet the future scenarios of high data reliability and high trustworthiness.
[0078] In one possible design, the method is also applied to the first AMF network element, and the method further includes:
[0079] Step 1: When the terminal requests to establish a session, the first AMF network element requests the NRF network element to discover the SMF network element for the terminal.
[0080] Step 2: The first AMF network element receives the SMF set provided by the NRF network element according to the request of the first AMF network element.
[0081] The first AMF network element requests the NRF network element to discover SMF network elements for the terminal, including: the first AMF network element sending an SMF discovery request message to the NRF network element, wherein the SMF discovery request message carries the terminal's Data Network Name (DNN) and Single Network Slice Selection Assistance information (S-NSSAI). The first AMF network element receives a set of SMFs provided by the NRF network element according to the first AMF network element's request, including: the first AMF network element receiving an SMF discovery response message returned by the NRF network element. The SMF discovery response message includes a set of SMFs, and the first and second SMF network elements are SMF network elements selected by the NRF network element that match the terminal's DNN and S-NSSAI.
[0082] It is understandable that in the 3GPP-defined standards, when an AMF network element requests an NRF network element to discover an SMF network element, it can provide not only the terminal's DNN and S-NSSAI, but also other relevant information. This application can also reuse this information without limitation. Furthermore, in the 3GPP-defined standards, the NRF network element can directly select a serving SMF network element for the terminal. However, the difference in this application's embodiments is that the NRF network element does not have the ability to create a blockchain. If the serving SMF network element is to provide services to the terminal in a blockchain manner, the NRF network element cannot directly select a serving AMF network element. Therefore, the NRF network element can only perform certain screening of SMF network elements under protocol constraints to ensure that the AMF network element can still create a second blockchain based on a sufficient number of SMF network elements.
[0083] Step 3: The first AMF element selects a subset of SMFs from the SMF set.
[0084] The RAN equipment determines the SMF set as a subset of SMFs based on the access technology used by the terminal access. This subset includes SMFs that support the access technology used by the terminal access, such as those supporting 3GPP access or non-3GPP access.
[0085] Step 4: The first AMF network element identifies the SMF subset as the second blockchain that provides session management services for the terminal.
[0086] The SMF subset includes at least a first SMF network element and a second SMF network element. The first SMF network element, as the service SMF network element of the terminal, is the master node in the second blockchain. The second SMF network element is the auxiliary node in the second blockchain. The auxiliary node is used to synchronously record the session management services provided by the master node to the terminal.
[0087] Specifically, the first AMF network element, based on the fact that the SMF subset includes at least two SMF network elements, determines the SMF subset as the first blockchain providing session management services for the terminal. Furthermore, the method includes: the first AMF network element obtaining the load of the first SMF network element from the first SMF network element (e.g., requesting the first SMF network element to provide its current load); the first AMF network element obtaining the load of the second SMF network element from the second SMF network element (e.g., requesting the second SMF network element to provide its current load); if the load of the first SMF network element is higher than the load of the second SMF network element, the first SMF network element determines the first SMF network element as the serving SMF network element for the terminal; based on the fact that the first SMF network element is the serving SMF network element for the terminal, the first AMF network element determines the first SMF network element as the master node in the second blockchain; and based on the fact that the master node in the second blockchain has been determined, the first AMF network element determines the second SMF network element as the auxiliary node in the second blockchain.
[0088] It is understood that the basis for whether an AMF network element establishes a blockchain is the number of SMF network elements. If there is only one SMF network element in the SMF subset, the AMF network element will not establish a blockchain and will execute the process defined in 3GPP. Conversely, if there are multiple SMF network elements in the SMF subset, the AMF network element will establish a blockchain and will execute the process defined in this application.
[0089] It's understandable that, due to the immutable nature of blockchain, secondary nodes need to record the primary node's data throughout the entire process, also known as invoices. Therefore, priority must be given to ensuring the performance of secondary nodes, selecting SMF network elements with lower loads as secondary nodes (this is the opposite of the SMF selection logic defined by 3GPP). Although the load of the primary node's SMF network elements is higher, it can still meet the requirement of providing session management services to the terminal. Furthermore, the trigger condition for the AMF network element to obtain the load of the SMF network element is that the AMF network element determines the second blockchain, such as assigning a second blockchain identifier to uniquely identify the second blockchain.
[0090] It is also understandable that the SMF subset can include more SMF network elements, such as the third SMF network element, which is implemented in a similar way to the second SMF network element. This can be understood by referring to it, and will not be elaborated further.
[0091] Optionally, the first AMF network element sends a third indication message to the first SMF network element. This third indication message instructs the first SMF network element to act as a master node in the second blockchain to provide session management services to the terminal. For example, the third indication message includes at least one of the following: an identifier of the second blockchain, an identifier of the terminal, an identifier instructing the first SMF network element to act as a master node in the second blockchain, an identifier instructing the SMF network element to act as a service SMF network element, or an identifier instructing the second SMF network element to act as a master-slave node in the second blockchain. The first AMF network element sends a fourth indication message to the second SMF network element, wherein the fourth indication message instructs the second SMF network element to act as a slave node in the second blockchain to record master node providing session management services to the terminal. For example, the fourth indication message includes at least one of the following: an identifier of the second blockchain, an identifier of the terminal, an identifier instructing the first SMF network element to act as a master node in the second blockchain, or an identifier instructing the second SMF network element to act as a slave node in the second blockchain.
[0092] It is understood that the above implementations are merely examples. For instance, SMF network elements in the second blockchain can share the key of the serving SMF network element, which can be derived by the first AMF network element using the aforementioned NAS key as an input parameter. In other words, the records of the first SMF network element's session management service for the terminal can be ciphertext protected by this key (e.g., confidentiality and integrity), allowing the second SMF network element to verify them using this key and save them after successful verification.
[0093] It can also be understood that the blockchain involved in this application embodiment is divided at the granularity of network functions, and blockchains with different functions are isolated from each other. For example, the first blockchain is the blockchain for load access and mobility management services, and the second blockchain is the blockchain for load session management services. The two can be logically and physically isolated from each other to ensure data security.
[0094] In other words, during the selection of SMF network elements, AMF network elements can select multiple SMF network elements of the terminal as blockchains, such as a second blockchain. The first SMF network element, as the service SMF network element of the terminal, is the master node in the second blockchain, and the second SMF network element is the auxiliary node in the second blockchain. The auxiliary node is used to synchronously record the session management services provided by the master node to the terminal. In this way, the SMF network elements selected for the terminal can provide services to the terminal in a blockchain manner to meet the future scenarios of high data reliability and high trustworthiness.
[0095] The above combination Figure 3 The methods provided in the embodiments of this application are described in detail. The following describes a blockchain-based trusted data storage device for performing the methods provided in the embodiments of this application.
[0096] This device is applied to a RAN device and is configured to: when a terminal accesses the RAN device, the RAN device requests an NRF network element to discover an AMF network element for the terminal; the RAN device receives an AMF set provided by the NRF network element according to the RAN device's request; the RAN device selects an AMF subset from the AMF set; the RAN device determines the AMF subset as the first blockchain that provides access and mobility management services for the terminal, wherein the AMF subset includes at least a first AMF network element and a second AMF network element, the first AMF network element being the service AMF network element of the terminal and the master node in the first blockchain, and the second AMF network element being the auxiliary node in the first blockchain, the auxiliary node being used to synchronously record the access and mobility management services provided by the master node to the terminal.
[0097] In one possible design, the device is configured such that: the RAN device sends an AMF discovery request message to the NRF network element, wherein the AMF discovery request message carries the terminal's NSSAI. The device is also configured such that: the RAN device receives an AMF discovery response message returned by the NRF network element, wherein the AMF discovery response message includes an AMF set, and the first AMF network element and the second AMF network element are AMF network elements selected by the NRF network element that match the terminal's NSSAI.
[0098] Optionally, the device is configured such that the RAN equipment detects the availability of AMF network elements in the AMF set and determines the available AMF network elements in the AMF set as a subset of AMFs.
[0099] Optionally, the device is configured such that: the RAN device determines the AMF subset as a first blockchain providing access and mobility management services to the terminal, based on the AMF subset including at least two AMF network elements. Furthermore, the device is configured to: obtain the load of the first AMF network element from the first AMF network element (e.g., requesting the first AMF network element to provide its current load); obtain the load of the second AMF network element from the second AMF network element (e.g., requesting the second AMF network element to provide its current load); if the load of the first AMF network element is higher than the load of the second AMF network element, the RAN device determines the first AMF network element as the serving AMF network element of the terminal; based on the fact that the first AMF network element is the serving AMF network element of the terminal, the RAN device determines the first AMF network element as the master node in the first blockchain; and based on the fact that the master node in the first blockchain has been determined, the RAN device determines the second AMF network element as the secondary node in the first blockchain.
[0100] Optionally, the apparatus is configured such that: the RAN device sends first indication information to a first AMF network element, wherein the first indication information is used to instruct the first AMF network element to act as a master node in the first blockchain to provide access and mobility management services to the terminal. For example, the first indication information includes at least one of the following: an identifier of the first blockchain, an identifier of the terminal, an identifier for instructing the first AMF network element to act as a master node in the first blockchain, an identifier for instructing the first AMF network element to act as a serving AMF network element, or an identifier for instructing the second AMF network element to act as a secondary node in the first blockchain. Furthermore, the RAN device sends second indication information to the second AMF network element, wherein the second indication information is used to instruct the second AMF network element to act as a secondary node in the first blockchain to record master node records for providing access and mobility management services to the terminal. For example, the second indication information includes at least one of the following: an identifier of the first blockchain, an identifier of the terminal, an identifier for instructing the first AMF network element to act as a master node in the first blockchain, or an identifier for instructing the AMF network element to act as a secondary node in the first blockchain.
[0101] In one possible design, the device is also applied to a first AMF network element, which is configured to: when a terminal requests to establish a session, the first AMF network element requests an NRF network element to discover SMF network elements for the terminal; the first AMF network element receives an SMF set provided by the NRF network element according to the request of the first AMF network element; the first AMF network element selects a subset of SMFs from the SMF set; the first AMF network element determines the SMF subset as a second blockchain that provides session management services for the terminal, wherein the SMF subset includes at least the first SMF network element and the second SMF network element, the first SMF network element serving as the terminal's service SMF network element is the master node in the second blockchain, and the second SMF network element is a secondary node in the second blockchain, the secondary node being used to synchronously record the session management services provided by the master node to the terminal.
[0102] Optionally, the device is configured to: send an SMF discovery request message to an NRF network element, wherein the SMF discovery request message carries the terminal's DNN and S-NSSAI. The device is also configured to: receive an SMF discovery response message returned by the NRF network element. The SMF discovery response message includes a set of SMFs, and the first and second SMF network elements are SMF network elements selected by the NRF network element that match the terminal's DNN and S-NSSAI.
[0103] Furthermore, the device is configured such that the RAN equipment determines the SMF set as a subset of SMFs that support the access technology used by the terminal access, such as supporting 3GPP access or non-3GPP access, based on the access technology used by the terminal access.
[0104] Furthermore, the device is configured such that: a first AMF network element, based on the fact that the SMF subset includes at least two SMF network elements, identifies the SMF subset as a first blockchain providing session management services to the terminal. Based on this, the device is configured such that: the first AMF network element obtains the load of the first SMF network element from the first SMF network element (e.g., requests the first SMF network element to provide its current load); the first AMF network element obtains the load of the second SMF network element from the second SMF network element (e.g., requests the second SMF network element to provide its current load); if the load of the first SMF network element is higher than the load of the second SMF network element, the first SMF network element identifies the first SMF network element as the serving SMF network element for the terminal; based on the fact that the first SMF network element is the serving SMF network element for the terminal, the first AMF network element identifies the first SMF network element as the master node in the second blockchain; and based on the fact that the master node in the second blockchain has been identified, the first AMF network element identifies the second SMF network element as a secondary node in the second blockchain.
[0105] Optionally, the device is configured such that: a first AMF network element sends a third indication message to a first SMF network element. The third indication message indicates that the first SMF network element needs to act as a master node in the second blockchain to provide session management services to the terminal; for example, the third indication message includes at least one of the following: an identifier of the second blockchain, an identifier of the terminal, an identifier indicating that the first SMF network element acts as a master node in the second blockchain, an identifier indicating that the SMF network element acts as a serving SMF network element, or an identifier indicating that the second SMF network element acts as a master-slave node in the second blockchain. The first AMF network element sends a fourth indication message to the second SMF network element, wherein the fourth indication message indicates that the second SMF network element needs to act as a slave node in the second blockchain to record master node providing session management services to the terminal; for example, the fourth indication message includes at least one of the following: an identifier of the second blockchain, an identifier of the terminal, an identifier indicating that the first SMF network element acts as a master node in the second blockchain, or an identifier indicating that the second SMF network element acts as a slave node in the second blockchain.
[0106] The following is combined Figure 4 A detailed introduction to each component of the electronic device 500 is provided below:
[0107] The processor 501 is the control center of the electronic device 500. It can be a single processor or a collective term for multiple processing elements. For example, the processor 501 can be one or more central processing units (CPUs), application-specific integrated circuits (ASICs), or one or more integrated circuits configured to implement the embodiments of this application, such as one or more digital signal processors (DSPs), or one or more field-programmable gate arrays (FPGAs).
[0108] Optionally, the processor 501 can perform various functions of the electronic device 500, as described above, by running or executing software programs stored in the memory 502 and by calling data stored in the memory 502. Figure 3 The functions in the method shown.
[0109] In a specific implementation, as one example, the processor 501 may include one or more CPUs, for example... Figure 4 CPU0 and CPU1 are shown in the diagram.
[0110] In a specific implementation, as one example, the electronic device 500 may also include multiple processors. Each of these processors may be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). Here, a processor may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).
[0111] The memory 502 is used to store the software program that executes the solution of this application, and is controlled by the processor 501 to execute it. The specific implementation method can be referred to the above method embodiment, and will not be repeated here.
[0112] Optionally, memory 502 may be read-only memory (ROM) or other types of static storage devices capable of storing static information and instructions, such as random access memory (RAM) or...
[0113] Other types of dynamic storage devices capable of storing information and instructions may also be electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, universal optical discs, Blu-ray discs, etc.), magnetic disk storage media, or other magnetic storage devices, or any other medium capable of carrying or storing desired program code having an instruction or data structure form and accessible by a computer, but not limited thereto. Memory 502 may be integrated with processor 501 or exist independently, and may also be an interface circuit of electronic device 500. Figure 4 (Not shown in the image) is coupled to processor 501, and this embodiment does not specifically limit this.
[0114] Transceiver 503 is used for communication with other devices. For example, in a multi-beam positioning device as a terminal, transceiver 503 can be used to communicate with network devices or with another terminal.
[0115] Optionally, transceiver 503 may include a receiver and a transmitter. Figure 4 (Not shown separately). The receiver is used to implement the receiving function, and the transmitter is used to implement the sending function.
[0116] Optionally, the transceiver 503 can be integrated with the processor 501, or it can exist independently and be connected via the interface circuit of the electronic device 500. Figure 4 (Not shown in the image) is coupled to processor 501, and this embodiment does not specifically limit this.
[0117] It should be noted that, Figure 4 The structure of the electronic device 500 shown does not constitute a limitation on the device. The actual electronic device 500 may include more or fewer components than shown, or combine certain components, or have different component arrangements.
[0118] Furthermore, the technical effects of the electronic device 500 can be referred to the technical effects of the methods in the above method embodiments, and will not be repeated here.
[0119] It should be understood that the processor in the embodiments of this application can be a central processing unit (CPU), or it can be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor.
[0120] It should also be understood that the memory in the embodiments of this application can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate synchronous DRAM (DDR SDRAM), enhanced synchronous DRAM (ESDRAM), synchronous linked DRAM (SLDRAM), and direct rambus RAM (DR RAM).
[0121] The above embodiments can be implemented, in whole or in part, by software, hardware (such as circuits), firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented, in whole or in part, as a computer program product. A computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, all or part of the flow or function according to the embodiments of this application is generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. Computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., infrared, wireless, microwave, etc.) means. A computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more sets of available media. Available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media. Semiconductor media can be solid-state drives.
[0122] It should be understood that the term "and / or" in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. A and B can be singular or plural. Additionally, the character " / " in this article generally indicates an "or" relationship between the preceding and following related objects, but it can also represent an "and / or" relationship. Please refer to the context for a more accurate understanding.
[0123] In this application, "at least one" means one or more, and "more than one" means two or more. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single or multiple items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or multiple.
[0124] It should be understood that in the various embodiments of this application, the order of the above-mentioned processes does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0125] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0126] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0127] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some feature fields may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0128] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0129] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0130] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0131] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A blockchain-based trusted data storage method, characterized in that, The method is applied to a RAN device, and the method includes: When a terminal accesses the RAN device, the RAN device requests the NRF network element to discover the AMF network element for the terminal; The RAN device receives the AMF set provided by the NRF network element according to the request of the RAN device; The RAN device selects a subset of AMFs from the AMF set; The RAN device identifies the AMF subset as a first blockchain that provides access and mobility management services for the terminal. The AMF subset includes at least a first AMF network element and a second AMF network element. The first AMF network element, as the serving AMF network element of the terminal, is the master node in the first blockchain. The second AMF network element is a secondary node in the first blockchain. The secondary node is used to synchronously record the access and mobility management services provided by the master node to the terminal. The RAN device requests the NRF network element to discover the AMF network element for the terminal, including: The RAN device sends an AMF discovery request message to the NRF network element, wherein the AMF discovery request message carries the NSSAI of the terminal; The RAN device receives the AMF set provided by the NRF network element according to the request of the RAN device, including: The RAN device receives an AMF discovery response message returned by the NRF network element, wherein the AMF discovery response message includes the AMF set, and the first AMF network element and the second AMF network element are AMF network elements selected by the NRF network element that match the NSSAI of the terminal.
2. The method according to claim 1, characterized in that, The RAN device selects a subset of AMFs from the AMF set, including: The RAN device detects the availability of AMF network elements in the AMF set and determines the available AMF network elements in the AMF set as the AMF subset.
3. The method according to claim 2, characterized in that, The RAN device identifies the AMF subset as the first blockchain providing access and mobility management services for the terminal, including: The RAN device determines the AMF subset as the first blockchain that provides access and mobility management services to the terminal, based on the fact that the AMF subset includes at least two AMF network elements. Based on this, the method further includes: The RAN device obtains the load of the first AMF network element from the first AMF network element; The RAN device obtains the load of the second AMF network element from the second AMF network element; When the load of the first AMF network element is higher than the load of the second AMF network element, the RAN device determines the first AMF network element as the serving AMF network element of the terminal. The RAN device determines the first AMF network element as the master node in the first blockchain based on the fact that the first AMF network element is the serving AMF network element of the terminal. The RAN device determines the second AMF network element as a secondary node in the first blockchain, based on the fact that the primary node in the first blockchain has been determined.
4. The method according to any one of claims 1-3, characterized in that, The method further includes: The RAN device sends a first indication message to the first AMF network element, wherein the first indication message is used to indicate that the first AMF network element needs to act as the master node in the first blockchain to provide access and mobility management services for the terminal. The RAN device sends a second instruction message to the second AMF network element, wherein the second instruction message is used to instruct the second AMF network element to act as a secondary node in the first blockchain to record the primary node providing access and mobility management services to the terminal.
5. The method according to claim 1, characterized in that, The method is also applied to the first AMF network element, and the method further includes: When the terminal requests to establish a session, the first AMF network element requests the NRF network element to discover the SMF network element for the terminal; The first AMF network element receives the SMF set provided by the NRF network element according to the request of the first AMF network element; The first AMF network element selects a subset of SMFs from the SMF set; The first AMF network element determines the SMF subset as a second blockchain that provides session management services for the terminal. The SMF subset includes at least the first SMF network element and the second SMF network element. The first SMF network element, as the service SMF network element of the terminal, is the master node in the second blockchain. The second SMF network element is the auxiliary node in the second blockchain. The auxiliary node in the second blockchain is used to synchronously record the session management services provided by the master node in the second blockchain to the terminal.
6. The method according to claim 5, characterized in that, The first AMF network element requests the NRF network element to discover the SMF network element for the terminal, including: The first AMF network element sends an SMF discovery request message to the NRF network element, wherein the SMF discovery request message carries the terminal's data network name DNN and S-NSSAI; The first AMF network element receives the SMF set provided by the NRF network element according to the request of the first AMF network element, including: The first AMF network element receives the SMF discovery response message returned by the NRF network element, wherein the SMF discovery response message includes the SMF set, and the first SMF network element and the second SMF network element are SMF network elements selected by the NRF network element that match the terminal's DNN and S-NSSAI.
7. The method according to claim 6, characterized in that, The first AMF network element selects a subset of SMFs from the SMF set, including: The first AMF network element determines the SMF network elements in the SMF set that support the access technology used by the terminal access as the SMF subset based on the access technology used by the terminal access.
8. The method according to claim 7, characterized in that, The first AMF network element identifies the SMF subset as a second blockchain that provides session management services for the terminal, including: The first AMF network element determines the SMF subset as the second blockchain that provides session management services for the terminal, based on the fact that the SMF subset includes at least two SMF network elements. Based on this, the method further includes: The first AMF network element obtains the load of the first SMF network element from the first SMF network element; The first AMF network element obtains the load of the second SMF network element from the second SMF network element; When the load of the first SMF network element is higher than the load of the second SMF network element, the first AMF network element determines the first SMF network element as the serving SMF network element of the terminal. The first AMF network element determines the first SMF network element as the master node in the second blockchain based on the fact that the first SMF network element is the serving SMF network element of the terminal; The first AMF network element determines the second SMF network element as a secondary node in the second blockchain based on the fact that the primary node in the second blockchain has been determined.
9. The method according to any one of claims 6-8, characterized in that, The method further includes: The first AMF network element sends a third indication message to the first SMF network element, wherein the third indication message is used to indicate that the first SMF network element needs to provide session management services for the terminal as the master node in the second blockchain; The first AMF network element sends a fourth indication message to the second SMF network element, wherein the fourth indication message is used to instruct the second SMF network element to act as a secondary node in the second blockchain to record the primary node in the second blockchain to provide session management services for the terminal.
Citation Information
Patent Citations
Communication method and communication device
CN110167195A
Block chain-based state data reconstruction method and device and storage medium
CN115168444A
Access to second network
CN116671183A
Method and system for blockchain-based information management among network devices
US20220141025A1