A Method for Ensuring the Security and Transparency of Financial Transactions Based on Blockchain

By configuring multiple UDM network elements as distributed accounting nodes of blockchain in the network of financial transaction terminals, the problem of how to provide blockchain accounting services to trading terminals through the 3GPP network is solved, and the security and transparency of financial transactions are guaranteed.

CN118537003BActive Publication Date: 2025-06-24BEIJING JET-TECH ZHICHENG TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202410595006.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2024-02-29
Filing Date
2024-05-14
Publication Date
2025-06-24
Estimated Expiration
2044-05-14

AI Technical Summary

Technical Problem

In the financial scenario, how to provide blockchain accounting services to transaction terminals through the network defined by 3GPP to ensure the security and transparency of financial transactions.

Method used

By configuring N data management functions UDM network elements in the network connected to the transaction terminal as distributed accounting nodes in the blockchain, the application function AF receives the smart contract data of the transaction terminal and sends it to the source UDM network elements, and then synchronizes it to other N-1 UDM network elements to realize distributed accounting of smart contract data.

Benefits of technology

It has realized the blockchain accounting services for transaction terminals through the network defined by 3GPP, which ensures the security and transparency of financial transactions, and solves the problems of equipment management in financial scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118537003B_ABST
    Figure CN118537003B_ABST
Patent Text Reader

Abstract

The present application provides a method for ensuring the security and transparency of financial transactions based on blockchain, belonging to the field of communication technologies, and is used to provide blockchain accounting services for transaction terminals through the network defined by 3GPP, ensuring the security and transparency of financial transactions. The method includes: The AF receives an application message from a transaction terminal, where the application message includes the smart contract data of the transaction terminal; in response to the application message, the AF determines the source UDM network element of the transaction terminal from N UDM network elements of the blockchain, where N is an integer greater than 1, and both the AF and the N UDM network elements are network elements in the network accessed by the transaction terminal, and the N UDM network elements are also distributed accounting nodes in the blockchain that serve the transaction terminal; the AF sends the smart contract data of the transaction terminal to the source UDM network element, so that the source UDM network element synchronizes the smart contract data of the transaction terminal to all UDM network elements in the N UDM network elements except the source UDM network element.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communications, and in particular to a method for ensuring the security and transparency of financial transactions based on blockchain. Background Art

[0002] On the one hand, blockchain is a decentralized, distributed database technology consisting of multiple nodes, which uses a consensus mechanism to verify and store data to achieve data immutability and sharing. It provides a decentralized, trust-free credit establishment paradigm. The essence of blockchain technology is a decentralized and distributed data storage, transmission and certification method, which replaces the current Internet's reliance on central servers with data blocks, so that all data changes or transaction items are recorded on a cloud system. On the other hand, the network structure defined by the standard organization can be applied to more other scenarios, such as financial scenarios. For example, terminals used to implement transactions, or any other possible form of terminals can communicate with other data networks through the network, so that the control end in the data network can remotely control the transaction terminal in a low-latency and high-reliability manner.

[0003] In the future, the integration of blockchain and the network defined by 3GPP is a possible trend. Therefore, in this case, how to achieve device management in financial scenarios is a hot topic of current research. Summary of the invention

[0004] The embodiment of the present application provides a method for ensuring the security and transparency of financial transactions based on blockchain, so as to provide blockchain accounting services to transaction terminals through a network defined by 3GPP.

[0005] In order to achieve the above objectives, this application adopts the following technical solutions:

[0006] In a first aspect, a method for ensuring financial transaction security and transparency based on blockchain is provided, the method comprising: an application function AF receives an application message from a transaction terminal, wherein the application message includes smart contract data of the transaction terminal; in response to the application message, the AF determines a source UDM network element of the transaction terminal from N data management function UDM network elements of the blockchain, wherein N is an integer greater than 1, and the AF and the N UDM network elements are network elements in a network accessed by the transaction terminal, and the N UDM network elements are also distributed accounting nodes in the blockchain serving the transaction terminal; the AF sends the smart contract data of the transaction terminal to the source UDM network element, so that the source UDM network element synchronizes the smart contract data of the transaction terminal to all UDM network elements among the N UDM network elements except the source UDM network element.

[0007] Optionally, the source UDM network element is the network element among the N UDM network elements that stores the subscription data of the transaction terminal, and the UDM network elements other than the source UDM network element among the N UDM network elements do not store the subscription data of the transaction terminal.

[0008] Optionally, the AF determines the source UDM network element of the transaction terminal from the N UDM network elements of the blockchain, including: the AF determines that the AF is pre-configured with a first distributed ledger node list of the blockchain, where the first distributed ledger node list is used to indicate the N UDM network elements, and the first distributed ledger node list is also used to indicate the source UDM network element among the N UDM network elements; the AF traverses the first distributed ledger node list to determine the source UDM network element of the transaction terminal.

[0009] Optionally, the AF determines the source UDM network element of the transaction terminal from the N UDM network elements of the blockchain, including: the AF determines that the AF is not configured with a distributed ledger node list of the blockchain; the AF sends a network element discovery request to the network element discovery function NRF network element in the network, where the network element discovery request is used to request the NRF network element to provide the distributed ledger node list of the blockchain; the AF receives a network element discovery response from the NRF network element, where the network element discovery response includes a first distributed ledger node list of the blockchain, the first distributed ledger node list is used to indicate the N UDM network elements, and the first distributed ledger node list is also used to indicate the source UDM network element among the N UDM network elements; the AF traverses the first distributed ledger node list to determine the source UDM network element of the transaction terminal.

[0010] Optionally, before the AF determines the source UDM network element of the transaction terminal from the N UDM network elements of the blockchain, the method further includes: during the process of the transaction terminal registering to the network, the source UDM network element receives an authentication request from the AUSF network element in the network; in response to the authentication request, the source UDM network element determines the N UDM network elements serving the transaction terminal in the blockchain according to the subscription data of the transaction terminal; the source UDM network element triggers the N UDM network elements to complete N primary authentications of the transaction terminal; in the case that all N primary authentications are passed, the source UDM network element saves the first distributed ledger node list of the blockchain to the NRF network element, where the first distributed ledger node list is used to indicate the N UDM network elements, and the first distributed ledger node list is also used to indicate the source UDM network element among the N UDM network elements.

[0011] Optionally, the source UDM network element determines N UDM network elements in the blockchain that serve the transaction terminal according to the subscription data of the transaction terminal, including: the source UDM network element obtains the blockchain information in the subscription data of the transaction terminal indicating that the transaction terminal has subscribed to the services of the blockchain; the source UDM network element requests the NRF network element to discover N-1 UDM network elements within the service scope according to the service scope of the blockchain in the blockchain information, where the N-1 UDM network elements and the source UDM network element constitute N UDM network elements in the blockchain that serve the transaction terminal.

[0012] Optionally, the source UDM network element triggers the N UDM network elements to complete N primary authentications of the transaction terminal, including: the source UDM network element generates the source 5G HE AV of the transaction terminal and triggers the AUSF network element to complete 1 primary authentication of the transaction terminal using the source 5G HE AV; the source UDM network element triggers the N-1 UDM network elements other than the source UDM network element among the N UDM network elements to complete N-1 primary authentications of the transaction terminal through the AUSF network element.

[0013] Optionally, the source UDM network element generates the source 5G HE AV of the transaction terminal and triggers the AUSF network element to complete 1 primary authentication of the transaction terminal using the source 5G HE AV, including: the source UDM network element generates the source RAND and AUTN; the source UDM network element generates the source XRES* according to the source RAND; the source UDM network element generates KAUSF according to the secret keys IK and CK of the transaction terminal; the source UDM network element encapsulates the source RAND, the source XRES*, the source secret key KAUSF, and the AUTN as the source 5G HE AV; the source UDM network element sends the source 5G HE AV to the AUSF network element; the source UDM network element learns from the AUSF network element that the 1 primary authentication of the transaction terminal is passed.

[0014] Optionally, the source UDM network element triggers the N-1 UDM network elements other than the source UDM network element among the N UDM network elements to complete N-1 primary authentications of the transaction terminal through the AUSF network element, including: the source UDM network element sends the information of the AUSF network element and the information for generating the 5G HE AV required to complete N-1 primary authentications of the transaction terminal to the N-1 UDM network elements; the source UDM network element learns from the N-1 UDM network elements that the N-1 primary authentications of the transaction terminal are passed.

[0015] Second aspect, a financial transaction security and transparency guarantee system based on blockchain is provided. The system is configured as follows: The application function AF receives an application message from a transaction terminal. The application message includes smart contract data of the transaction terminal. In response to the application message, AF determines the source UDM network element of the transaction terminal from N data management function UDM network elements of the blockchain. Here, N is an integer greater than 1. AF and the N UDM network elements are all network elements in the network accessed by the transaction terminal. The N UDM network elements are also distributed ledger nodes in the blockchain that serve the transaction terminal. AF sends the smart contract data of the transaction terminal to the source UDM network element, so that the source UDM network element synchronizes the smart contract data of the transaction terminal to all UDM network elements in the N UDM network elements except the source UDM network element.

[0016] Optionally, the source UDM network element is the network element among the N UDM network elements that stores the signing data of the transaction terminal. The UDM network elements among the N UDM network elements except the source UDM network element do not store the signing data of the transaction terminal.

[0017] Optionally, the system is configured as follows: AF determines that AF is pre-configured with a first distributed ledger node list of the blockchain. The first distributed ledger node list is used to indicate the N UDM network elements, and the first distributed ledger node list is also used to indicate the source UDM network element among the N UDM network elements. AF traverses the first distributed ledger node list to determine the source UDM network element of the transaction terminal.

[0018] Optionally, the system is configured as follows: AF determines that AF is not configured with a distributed ledger node list of the blockchain. AF sends a network element discovery request to the network element discovery function NRF network element. The network element discovery request is used to request the NRF network element to provide a distributed ledger node list of the blockchain. AF receives a network element discovery response from the NRF network element. The network element discovery response includes a first distributed ledger node list of the blockchain. The first distributed ledger node list is used to indicate the N UDM network elements, and the first distributed ledger node list is also used to indicate the source UDM network element among the N UDM network elements. AF traverses the first distributed ledger node list to determine the source UDM network element of the transaction terminal.

[0019] Optionally, the system is configured to: before the AF determines the source UDM network element of the transaction terminal from the N UDM network elements of the blockchain, during the process of the transaction terminal registering to the network, the source UDM network element receives an authentication request from the AUSF network element in the network; in response to the authentication request, the source UDM network element determines the N UDM network elements serving the transaction terminal in the blockchain according to the subscription data of the transaction terminal; the source UDM network element triggers the N UDM network elements to complete N primary authentications of the transaction terminal; in the case that all N primary authentications are passed, the source UDM network element saves the first distributed ledger node list of the blockchain to the NRF network element, where the first distributed ledger node list is used to indicate the N UDM network elements, and the first distributed ledger node list is also used to indicate the source UDM network element among the N UDM network elements.

[0020] Optionally, the system is configured to: the source UDM network element obtains the blockchain information in the subscription data of the transaction terminal that the transaction terminal subscribes to the services of the blockchain; the source UDM network element requests the NRF network element to discover N - 1 UDM network elements located within the service range according to the service range of the blockchain in the blockchain information, where the N - 1 UDM network elements and the source UDM network element constitute the N UDM network elements serving the transaction terminal in the blockchain.

[0021] Optionally, the system is configured to: the source UDM network element generates the source 5G HE AV of the transaction terminal and triggers the AUSF network element to complete 1 primary authentication of the transaction terminal using the source 5G HE AV; the source UDM network element triggers the N - 1 UDM network elements other than the source UDM network element among the N UDM network elements to complete N - 1 primary authentications of the transaction terminal through the AUSF network element.

[0022] Optionally, the system is configured to: the source UDM network element generates the source RAND and AUTN; the source UDM network element generates the source XRES* according to the source RAND; the source UDM network element generates KAUSF according to the secret keys IK and CK of the transaction terminal; the source UDM network element encapsulates the source RAND, the source XRES*, the source secret key KAUSF and the AUTN into the source 5G HE AV; the source UDM network element sends the source 5G HE AV to the AUSF network element; the source UDM network element learns from the AUSF network element that the 1 primary authentication of the transaction terminal is passed.

[0023] Optionally, the system is configured to: the source UDM network element sends the information of the AUSF network element and the information for generating the 5G HE AV required to complete the N - 1 primary authentications of the transaction terminal to the N - 1 UDM network elements; the source UDM network element learns from the N - 1 UDM network elements that the N - 1 primary authentications of the transaction terminal are passed.

[0024] In summary, by configuring N UDM network elements in the network as distributed accounting nodes in the blockchain for the transaction terminal, after the transaction terminal sends the smart contract data to the AF, the AF can send the smart contract data to the source UDM network element among the N UDM network elements, so that the source UDM network element synchronizes the smart contract data of the transaction terminal to all UDM network elements except the source UDM network element among the N UDM network elements, that is, to achieve distributed accounting of the smart contract data, thereby realizing providing blockchain accounting services for the transaction terminal through the network defined by 3GPP to ensure the security and transparency of financial transactions. Description of the Drawings

[0025] Figure 1 It is a schematic diagram of the 5G network architecture;

[0026] Figure 2 It is a schematic diagram of the architecture of the communication system provided by the embodiment of the present application;

[0027] Figure 3 It is a schematic flowchart of the method for ensuring the security and transparency of financial transactions based on blockchain provided by the embodiment of the present application;

[0028] Figure 4 It is a schematic diagram of the structure of the communication device provided by the embodiment of the present application. Detailed Embodiment

[0029] For easy understanding, the technical terms involved in the embodiments of the present application will be introduced first below.

[0030] 1. Fifth-generation (5G) mobile communication system (abbreviated as 5G system (5GS)):

[0031] Figure 1 It is a schematic diagram of the 5GS architecture. As Figure 1 shown, 5GS includes: access network (AN) and core network (CN), and may also include: terminal.

[0032] The terminal(s) can be one or more, such as the first terminal, the second terminal, the third terminal, etc. The terminal can be a terminal with transceiver functions, or it can also be a chip or chip system disposed in the terminal. The terminal can also be referred to as user equipment (UE), access terminal, subscriber unit, user station, mobile station (MS), mobile phone, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent, or user device. The terminal in the embodiments of this application can be a mobile phone, cellular phone, smartphone, tablet (Pad), wireless data card, personal digital assistant (PDA), wireless modem, handset, laptop computer, machine type communication (MTC) terminal, computer with wireless transceiver functions, virtual reality (VR) terminal, augmented reality (AR) terminal, smart home device (such as refrigerator, TV, air conditioner, electricity meter, etc.), smart robot, robotic arm, workshop equipment, wireless terminal in industrial control, wireless terminal in self-driving, wireless terminal in remote medical, wireless terminal in smart grid, wireless terminal in transportation safety, wireless terminal in smart city, wireless terminal in smart home, in-vehicle terminal, roadside unit (RSU) with terminal functions, flight equipment (such as smart robot, hot air balloon, drone, airplane), etc. The terminal in this application can also be an in-vehicle module, in-vehicle module group, in-vehicle component, in-vehicle chip, or in-vehicle unit built into a vehicle as one or more components or units. The terminal device can also be other devices with terminal functions. For example, the terminal device can also be a device that serves as a terminal in D2D communication.

[0033] Embodiments of this application do not limit the device form of the terminal. The device for implementing the functions of the terminal device may be the terminal device; it may also be a device capable of supporting the terminal device to implement this function, such as a chip system. This device may be installed in the terminal device or used in matching with the terminal device. In the embodiments of this application, the chip system may be composed of chips or may include chips and other discrete devices.

[0034] The above-mentioned AN is used to implement functions related to access, can provide network access functions for authorized users in a specific area, and can determine transmission links of different qualities according to the user level, service requirements, etc. to transmit user data. The AN forwards control signals and user data between the terminal and the CN. The AN may include: access network devices, which may also be referred to as radio access network (RAN) devices. The CN is mainly responsible for maintaining the subscription data of the mobile network and providing functions such as session management, mobility management, policy management, and security authentication for the terminal. The CN mainly includes the following network elements: user plane function (UPF) network element, authentication server function (AUSF) network element, AMF network element, SMF network element, network slice selection function (NSSF) network element, network exposure function (NEF) network element, network function repository function (NRF) network element, policy control function (PCF) network element, unified data management (UDM) network element, unified data repository (UDR), and application function network element (AF).

[0035] The RAN device, that is, the access network device can be one or more. The access network device can be a device with wireless transceiver functions, or can also be a chip or chip system disposed in the device, located in the access network (AN) of the communication system, and used to provide access services for terminals. For example, the access network device can be referred to as a radio access network (RAN) device. Specifically, it can be an access network device of the next-generation mobile communication system, such as a 6G base station. Or, in the next-generation mobile communication system, the access network device can also have other naming methods, all of which are covered by the protection scope of the embodiments of the present application, and the present application does not make any limitation thereto. Or, the access network device can also include 5G, such as the gNB in the new radio (NR) system, or one or a group (including multiple antenna panels) of antenna panels of the base station in 5G. Or, it can also be a network node constituting the gNB, transmission and reception point (TRP or transmission point, TP), or transmission measurement function (TMF), such as a central unit (CU), a distributed unit (DU), a CU-control plane (CP), a CU-user plane (UP), or a radio unit (RU), an RSU with base station functions, or a wired access gateway, or a core network element of 5G, etc. Or, the access network device can also include: an access point (AP) in a wireless fidelity (WiFi) system, a wireless relay node, a wireless backhaul node, various forms of macro base stations, micro base stations (also called small stations), relay stations, access points, wearable devices, vehicle-mounted devices, and so on.

[0036] Among them, the CU and DU can be set separately, or can also be included in the same network element, such as in the baseband unit (BBU). The RU can be included in a radio frequency device or a radio frequency unit, such as included in a remote radio unit (RRU), an active antenna unit (AAU), or a remote radio head (RRH). It can be understood that the network device can be a CU node, or a DU node, or a device including a CU node and a DU node. In addition, the CU can be classified as a network device in the radio access network (RAN), or the CU can be classified as a network device in the core network (CN), which is not limited here.

[0037] In different systems, the CU (or CU-CP and CU-UP), DU, or RU may also have different names, but those skilled in the art can understand their meanings. For example, in the ORAN system, the CU can also be called O-CU (Open CU), the DU can also be called O-DU, the CU-CP can also be called O-CU-CP, the CU-UP can also be called O-CU-UP, and the RU can also be called O-RU. For the convenience of description, the CU, CU-CP, CU-UP, DU, and RU are used as examples in this application. Any unit among the CU (or CU-CP, CU-UP), DU, and RU in this application can be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.

[0038] The UPF network element is mainly responsible for user data processing (forwarding, receiving, charging, etc.). For example, the UPF network element can receive user data from a data network (DN) and forward the user data to the terminal through the access network device. The UPF network element can also receive user data from the terminal through the access network device and forward the user data to the DN. The DN network element refers to the operator network that provides data transmission services for users. For example, Internet Protocol (IP) multimedia service (IMS), Internet, etc.

[0039] The DN can be an operator external network or an operator-controlled network, and is used to provide service to the terminal device.

[0040] The AUSF network element is mainly used to perform security authentication of the terminal.

[0041] The AMF network element is mainly used for mobility management in the mobile network. For example, user location update, user registration to the network, user handover, etc.

[0042] The SMF network element is mainly used for session management in a mobile network. For example, session establishment, modification, and release. Specific functions include, for example, allocating Internet Protocol (IP) addresses for users and selecting UPF network elements that provide packet forwarding functions, etc.

[0043] The PCF network element mainly supports providing a unified policy framework to control network behavior, providing policy rules to control layer network functions, and is also responsible for obtaining user subscription information related to policy decisions. The PCF network element can provide policies to the AMF network element and the SMF network element, such as Quality of Service (QoS) policies, slice selection policies, etc.

[0044] The NSSF network element is mainly used for selecting network slices for terminals.

[0045] The NEF network element is mainly used to support the opening of capabilities and events.

[0046] The UDM network element is mainly used to store user data, such as subscription data, authentication / authorization data, etc.

[0047] The UDR network element is mainly used to store structured data, including subscription data, policy data, exposed structured data, and application-related data.

[0048] The AF mainly supports interacting with the CN to provide services, such as influencing data routing decisions, policy control functions, or providing some third-party services to the network side.

[0049] The technical solution of the embodiment of the present application can be applied to various communication systems, such as wireless network systems, vehicle-to-everything (V2X) communication systems, device-to-device (D2D) communication systems, vehicle networking communication systems, 4G mobile communication systems, such as Long Term Evolution (LTE) systems, Worldwide Interoperability for Microwave Access (WiMAX) communication systems, 5G mobile communication systems, such as NR systems, and future communication systems, etc.

[0050] In the embodiments of the present application, "indication" may include direct indication and indirect indication, and may also include explicit indication and implicit indication. If the information indicated by a certain piece of information (such as the first indication information, the second indication information, or the third indication information below) is called the information to be indicated, then in the specific implementation process, there are many ways to indicate the information to be indicated. For example, but not limited to, the information to be indicated can be directly indicated, such as the information to be indicated itself or the index of the information to be indicated, etc. It is also possible to indirectly indicate the information to be indicated by indicating other information, where there is an association relationship between the other information and the information to be indicated. It is also possible to only indicate a part of the information to be indicated, while the other parts of the information to be indicated are known or pre-agreed. For example, it is also possible to use the arrangement order of each piece of information pre-agreed (such as stipulated in the protocol) to achieve the indication of specific information, thereby reducing the indication overhead to a certain extent. At the same time, the common parts of each piece of information can be identified and indicated uniformly to reduce the indication overhead caused by indicating the same information separately.

[0051] In addition, the specific indication method can also be various existing indication methods. For example, but not limited to, the above indication methods and their various combinations, etc. The specific details of various indication methods can refer to the prior art and will not be elaborated herein. As can be seen from the above, for example, when it is necessary to indicate multiple pieces of information of the same type, there may be a situation where the indication methods of different pieces of information are different. In the specific implementation process, the required indication method can be selected according to specific needs. The embodiments of the present application do not limit the selected indication method. In this way, the indication methods involved in the embodiments of the present application should be understood to cover various methods that can enable the party to be indicated to obtain the information to be indicated.

[0052] "Pre-definition" or "pre-configuration" can be achieved by pre-saving corresponding codes, tables, or other ways that can be used to indicate relevant information in the device. The embodiments of the present application do not limit its specific implementation method. Among them, "saving" can mean saving in one or more memories. The one or more memories can be separately provided, or can be integrated in an encoder, a decoder, a processor, or a communication device. The one or more memories can also be partially separately provided and partially integrated in a decoder, a processor, or a communication device. The type of memory can be any form of storage medium, and the embodiments of the present application do not limit this.

[0053] The "protocol" involved in the embodiments of the present application can refer to a protocol family in the communication field, a standard protocol similar to the frame structure of a protocol family, or a related protocol applied to a future communication system. The embodiments of the present application do not make specific limitations on this.

[0054] In the embodiments of the present application, descriptions such as "when...", "in the case of...", "if", and "when" all refer to the situation where the device will perform corresponding processing under certain objective circumstances, which do not limit time, and do not require the device to have a judgment action when implemented, nor does it mean there are other limitations.

[0055] In the description of the embodiments of the present application, unless otherwise specified, " / " means that the objects associated before and after are in an "or" relationship. For example, A / B can represent A or B. The "and / or" in the embodiments of the present application is only an association relationship describing the associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B can be singular or plural. Also, in the description of the embodiments of the present application, unless otherwise specified, "a plurality of" means two or more than two. "At least one (item)" or its similar expression refers to any combination of these items, including any combination of single item (item) or plural items (items). For example, at least one (item) of a, b, or c can represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, c can be single or multiple. Additionally, in order to clearly describe the technical solutions of the embodiments of the present application, in the embodiments of the present application, terms such as "first" and "second" are used to distinguish identical or similar items with basically the same functions and roles. Those skilled in the art can understand that terms such as "first" and "second" do not limit the quantity and execution order, and "first", "second", etc. do not necessarily mean different. At the same time, in the embodiments of the present application, words such as "exemplary" or "for example" are used to represent examples, illustrations, or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the embodiments of the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Exactly speaking, using words such as "exemplary" or "for example" aims to present relevant concepts in a specific way for easy understanding.

[0056] The network architecture and service scenarios described in the embodiments of the present application are for more clearly explaining the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those of ordinary skill in the art know that with the evolution of the network architecture and the emergence of new service scenarios, the technical solutions provided by the embodiments of the present application are equally applicable to similar technical problems.

[0057] To facilitate the understanding of the embodiments of the present application, first, Figure 2 Taking the communication system shown in Figure 2 as an example, a communication system applicable to the embodiments of the present application is described in detail. Exemplarily, Figure 2 is a schematic diagram of the architecture of a communication system applicable to the method for ensuring the security and transparency of financial transactions based on blockchain provided by the embodiments of the present application.

[0058] As shown Figure 2 in the figure, the communication system mainly includes: a UDM network element and an AF.

[0059] The UDM network element can be the UDM network element in the above-mentioned 5GS. For specific details, please refer to the relevant introduction above. Or it can be a network element in a future communication system that realizes data management or storage functions, and there is no limitation on this.

[0060] The AF can be the AF in the above-mentioned 5GS. For specific details, please refer to the relevant introduction above. Or it can be a network element in a future communication system that realizes application functions, and there is no limitation on this.

[0061] Next, in combination with Figure 3 , the interaction process between each network element / device in the above communication system will be specifically introduced through method embodiments. The method for ensuring the security and transparency of financial transactions based on blockchain provided in the embodiments of the present application can be applied to the above communication system and specifically applied to various scenarios / processes mentioned in the above communication system. The following is a specific introduction.

[0062] Figure 3 It is a schematic flowchart of the method for ensuring the security and transparency of financial transactions based on blockchain provided in the embodiments of the present application. The process of the method for ensuring the security and transparency of financial transactions based on blockchain is as follows:

[0063] S301, the AF receives an application message from a transaction terminal.

[0064] Among them, the application message includes the smart contract data of the transaction terminal, that is, the data that needs to be distributed for accounting, specifically, it can be data related to financial transactions. The application message can also include the identifier of the blockchain, which is used to uniquely indicate the blockchain.

[0065] S302, in response to the application message, the AF determines the source UDM network element of the transaction terminal from N data management function UDM network elements of the blockchain.

[0066] N is an integer greater than 1, and AF and N UDM network elements are all network elements in the network accessed by the trading terminal. AF can be an application that provides the sludge treatment service executed by the trading terminal. The network can be an operator network, specifically a Public Land Mobile Network (PLMN). The N UDM network elements are also distributed ledger nodes in the blockchain that serve the trading terminal. The source UDM network element can be the network element among the N UDM network elements that stores the subscription data of the trading terminal. The UDM network elements other than the source UDM network element among the N UDM network elements do not store the subscription data of the trading terminal. That is, although all N UDM network elements have the ability to record accounts for the trading terminal, usually only the source UDM network element can store the subscription data of the trading terminal.

[0067] AF can determine that AF is pre-configured with a first distributed ledger node list of the blockchain. Among them, the first distributed ledger node list can be used to indicate the N UDM network elements, such as including the identifiers of each of the N UDM network elements, and the first distributed ledger node list is also used to indicate the source UDM network element among the N UDM network elements, such as including the address of the source UDM network element corresponding to the identifier of the source UDM network element. That is, the UDM network element with an address is the source UDM network element. AF can traverse the first distributed ledger node list to determine the source UDM network element of the trading terminal. Alternatively, AF determines that AF is not configured with a distributed ledger node list of the blockchain. AF can send a network element discovery request to a Network Repository Function (NRF) network element in the network. Among them, the network element discovery request can be used to request the NRF network element to provide a distributed ledger node list of the blockchain, such as including the identifier of the blockchain. The NRF network element can obtain the distributed ledger node list corresponding to the identifier of the blockchain locally in the NRF network element, that is, the first distributed ledger node list of the blockchain. AF can receive a network element discovery response from the NRF network element. Among them, the network element discovery response can include the first distributed ledger node list of the blockchain.

[0068] S303, AF sends the smart contract data of the trading terminal to the source UDM network element, so that the source UDM network element synchronizes the smart contract data of the trading terminal to all UDM network elements other than the source UDM network element among the N UDM network elements.

[0069] AF can send the smart contract data of the transaction terminal to the source UDM network element according to the address of the source UDM network element. The source UDM network element can locally save the smart contract data of the transaction terminal, copy the smart contract data of the transaction terminal N - 1 times, and then send them to the N - 1 UDM network elements other than the source UDM network element among the N UDM network elements respectively. Each of these N - 1 UDM network elements can save the received smart contract data of the transaction terminal, thus realizing the distributed ledger of the smart contract data of the transaction terminal.

[0070] In summary, by configuring the N UDM network elements in the network as distributed ledger nodes in the blockchain for the transaction terminal, after the transaction terminal sends the smart contract data to AF, AF can send the smart contract data to the source UDM network element among the N UDM network elements, so that the source UDM network element synchronizes the smart contract data of the transaction terminal to all UDM network elements other than the source UDM network element among the N UDM network elements, that is, realizes the distributed ledger of the smart contract data, thereby realizing providing the blockchain ledger service for the transaction terminal through the network defined by 3GPP to ensure the security and transparency of financial transactions.

[0071] Before S301, the method may further include:

[0072] Step 1: During the process of the transaction terminal registering to the network, the source UDM network element receives an authentication request from the AUSF network element in the network. That is, in the authentication process, the AUSF network element requests the source UDM network element to provide an authentication vector through the authentication request.

[0073] Step 2: In response to the authentication request, the source UDM network element determines the N UDM network elements serving the transaction terminal in the blockchain according to the subscription data of the transaction terminal. For example, the source UDM network element can obtain the blockchain information in the subscription data of the transaction terminal where the transaction terminal subscribes to the blockchain service. The source UDM network element requests the NRF network element to discover N - 1 UDM network elements within the service range according to the service range of the blockchain in the blockchain information. That is, the NRF network element can provide the identifiers and addresses of the N - 1 UDM network elements to the source UDM network element respectively. Among them, the N - 1 UDM network elements and the source UDM network element constitute the N UDM network elements serving the transaction terminal in the blockchain. That is, the source UDM network element can generate the above - mentioned first distributed ledger node list based on the identifiers of the above - mentioned N - 1 UDM network elements respectively.

[0074] Step 3: The source UDM network element triggers the N UDM network elements to complete N primary authentications of the transaction terminal.

[0075] The source UDM network element generates the source 5G HE AV of the transaction terminal and triggers the AUSF network element to use the source 5G HE AV to complete one primary authentication of the transaction terminal. For example, the source UDM network element generates the source RAND and AUTN. The source UDM network element generates the source XRES* according to the source RAND; the source UDM network element generates the key KAUSF according to the keys IK and CK of the transaction terminal. The source UDM network element encapsulates the source RAND, the source XRES*, the source key KAUSF, and the AUTN as the source 5G HE AV. The source UDM network element sends the source 5G HE AV to the AUSF network element; the source UDM network element learns from the AUSF network element that one primary authentication of the transaction terminal is passed. In response to receiving the source 5G HE AV, the AUSF network element can trigger one primary authentication of the transaction terminal. Specifically, the AUSF network element can generate the key KSEAF according to the key KAUSF. The AUSF network element can generate the source HXRES* according to the source XRES* and the key KSEAF; the AUSF network element can replace the source XRES* in the source 5G HEAV with the source HXRES*, and replace the key KSEAF with the key KSEAF to obtain the source 5G AV; the AUSF network element can send the source 5G AV to the security anchor function SEAF network element in the network. Correspondingly, the SEAF network element can use the source 5G AV to continue to complete one primary authentication. For specific details, please refer to the relevant introduction of 3GPP and will not be elaborated here. When the AUSF network element determines that this primary authentication is passed, it notifies the source UDM network element that this primary authentication is passed.

[0076] The source UDM network element can trigger the N - 1 UDM network elements among the N UDM network elements except the source UDM network element to complete N - 1 primary authentications of the transaction terminal through the AUSF network element. For example, the source UDM network element sends the information of the AUSF network element, such as the address of the AUSF network element, and the information for generating 5G HE AV required to complete N - 1 primary authentications of the transaction terminal, such as AUTN and the key KAUSF, to the N - 1 UDM network elements. For the i-th UDM network element among the N - 1 UDM network elements, where i ranges from 1 to N - 1, the i-th UDM network element can generate the i-th RAND. The i-th UDM network element can generate the i-th XRES* based on the i-th RAND; the UDM network element encapsulates the i-th RAND, the i-th XRES*, the key KAUSF, and AUTN as the i-th 5G HE AV. In response to receiving the i-th 5G HE AV, the AUSF network element can trigger the i-th primary authentication of the transaction terminal. In other words, compared with the existing AUSF network element, the AUSF network element can be an upgraded AUSF network element, which is used to trigger multiple primary authentications of the transaction terminal according to the received multiple 5G HE AV. For example, the AUSF network element can determine that the AUSF network element no longer derives and generates the key KSEAF based on receiving the key KAUSF again. The AUSF network element can use the i-th XRES* and the pre-generated key KSEAF to generate the i-th HXRES*; the AUSF network element can replace the i-th XRES* in the i-th 5G HE AV with HXRES*, and replace the i-th key KSEAF with the i-th key KSEAF to obtain the i-th 5G AV. When i ranges from 1 to N - 1, a total of N - 1 different 5G AVs are obtained; the AUSF network element can send the N - 1 5G AVs to the security anchor function SEAF network element in the network. Correspondingly, the SEAF network element can use the i-th 5GAV among the N - 1 5G AVs to continue to complete the i-th primary authentication among the N - 1 primary authentications. When i ranges from 1 to N, for specific details, reference can be made to the relevant introduction of 3GPP, which will not be elaborated here. In the case where the i-th primary authentication is passed, the AUSF network element can inform the source UDM network element that the i-th primary authentication is passed. In this way, the UDM network element can finally learn that all N primary authentications are passed.

[0077] Step 4: When all N primary authentications are passed, the source UDM network element saves the first distributed accounting node list of the blockchain to the NRF network element.

[0078] The above combination Figure 3 has elaborated in detail the method for ensuring the security and transparency of financial transactions based on blockchain provided by the embodiments of the present application. The following describes the system for ensuring the security and transparency of financial transactions based on blockchain for implementing the method for ensuring the security and transparency of financial transactions based on blockchain provided by the embodiments of the present application.

[0079] The system is configured such that: the application function AF receives an application message from a transaction terminal, where the application message includes the smart contract data of the transaction terminal; in response to the application message, AF determines the source UDM network element of the transaction terminal from N data management function UDM network elements of the blockchain, where N is an integer greater than 1, AF and the N UDM network elements are all network elements in the network accessed by the transaction terminal, and the N UDM network elements are also distributed ledger nodes in the blockchain that serve the transaction terminal; AF sends the smart contract data of the transaction terminal to the source UDM network element for the source UDM network element to synchronize the smart contract data of the transaction terminal to all UDM network elements in the N UDM network elements except the source UDM network element.

[0080] Optionally, the source UDM network element is the network element among the N UDM network elements that stores the subscription data of the transaction terminal, and the UDM network elements among the N UDM network elements except the source UDM network element do not store the subscription data of the transaction terminal.

[0081] Optionally, the system is configured such that: AF determines that AF is pre-configured with a first distributed ledger node list of the blockchain, where the first distributed ledger node list is used to indicate the N UDM network elements, and the first distributed ledger node list is also used to indicate the source UDM network element among the N UDM network elements; AF traverses the first distributed ledger node list to determine the source UDM network element of the transaction terminal.

[0082] Optionally, the system is configured such that: AF determines that AF is not configured with a distributed ledger node list of the blockchain; AF sends a network element discovery request to the network element discovery function NRF network element in the network, where the network element discovery request is used to request the NRF network element to provide a distributed ledger node list of the blockchain; AF receives a network element discovery response from the NRF network element, where the network element discovery response includes a first distributed ledger node list of the blockchain, the first distributed ledger node list is used to indicate the N UDM network elements, and the first distributed ledger node list is also used to indicate the source UDM network element among the N UDM network elements; AF traverses the first distributed ledger node list to determine the source UDM network element of the transaction terminal.

[0083] Optionally, the system is configured to: before the AF determines the source UDM network element of the transaction terminal from the N UDM network elements of the blockchain, during the process of registering the transaction terminal to the network, the source UDM network element receives an authentication request from the AUSF network element in the network; in response to the authentication request, the source UDM network element determines, according to the subscription data of the transaction terminal, the N UDM network elements serving the transaction terminal in the blockchain; the source UDM network element triggers the N UDM network elements to complete N primary authentications for the transaction terminal; in the case that all N primary authentications are passed, the source UDM network element saves the first distributed ledger node list of the blockchain to the NRF network element, where the first distributed ledger node list is used to indicate the N UDM network elements, and the first distributed ledger node list is further used to indicate the source UDM network element among the N UDM network elements.

[0084] Optionally, the system is configured to: the source UDM network element obtains the blockchain information in the subscription data of the transaction terminal that the transaction terminal subscribes to the service of the blockchain; the source UDM network element requests the NRF network element to discover N-1 UDM network elements located within the service scope according to the service scope of the blockchain in the blockchain information, where the N-1 UDM network elements and the source UDM network element constitute the N UDM network elements serving the transaction terminal in the blockchain.

[0085] Optionally, the system is configured to: the source UDM network element generates the source 5G HE AV of the transaction terminal and triggers the AUSF network element to complete 1 primary authentication for the transaction terminal using the source 5G HE AV; the source UDM network element triggers the N-1 UDM network elements other than the source UDM network element among the N UDM network elements to complete N-1 primary authentications for the transaction terminal through the AUSF network element.

[0086] Optionally, the system is configured to: the source UDM network element generates the source RAND and AUTN; the source UDM network element generates the source XRES* according to the source RAND; the source UDM network element generates KAUSF according to the keys IK and CK of the transaction terminal; the source UDM network element encapsulates the source RAND, the source XRES*, the source key KAUSF and the AUTN into the source 5G HE AV; the source UDM network element sends the source 5G HE AV to the AUSF network element; the source UDM network element learns from the AUSF network element that the 1 primary authentication for the transaction terminal is passed.

[0087] Optionally, the system is configured to: the source UDM network element sends the information of the AUSF network element and the information for generating the 5G HE AV required to complete the N-1 primary authentications for the transaction terminal to the N-1 UDM network elements; the source UDM network element learns from the N-1 UDM network elements that the N-1 primary authentications for the transaction terminal are passed.

[0088] Figure 4The structural schematic diagram of the communication device provided by the embodiments of this application. Exemplarily, the communication device may be a terminal, or a chip (system) or other components or assemblies that can be set in the terminal. As Figure 4 shown, the communication device 400 may include a processor 401. Optionally, the communication device 400 may further include a memory 402 and / or a transceiver 403. Among them, the processor 401 is coupled to the memory 402 and the transceiver 403, and may be connected through a communication bus, for example.

[0089] The following Figure 4 will specifically introduce each component of the communication device 400:

[0090] Among them, the processor 401 is the control center of the communication device 400, and may be a single processor or a collective term for multiple processing elements. For example, the processor 401 is one or more central processing units (CPUs), or may be an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of this application. For example: one or more digital signal processors (DSPs), or one or more field programmable gate arrays (FPGAs).

[0091] Optionally, the processor 401 may execute various functions of the communication device 400 by running or executing software programs stored in the memory 402 and calling data stored in the memory 402. For example, execute the above Figure 3 shown method for ensuring the security and transparency of financial transactions based on blockchain.

[0092] In a specific implementation, as an embodiment, the processor 401 may include one or more CPUs, such as Figure 4 the CPU0 and CPU1 shown in

[0093] In a specific implementation, as an embodiment, the communication device 400 may also include multiple processors. Each of these processors may be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). Here, the processor may refer to one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions).

[0094] Among them, the memory 402 is used to store the software program for executing the solution of this application and is controlled by the processor 401 for execution. The specific implementation method can refer to the above method embodiment and will not be elaborated here.

[0095] Optionally, the memory 402 can be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 402 can be integrated with the processor 401 or exist independently and is coupled to the processor 401 through the interface circuit ( Figure 4 not shown) of the communication device 400. The embodiments of the present application do not make specific limitations on this.

[0096] The transceiver 403 is used for communication with other communication devices. For example, when the communication device 400 is a terminal, the transceiver 403 can be used for communication with a network device or with another terminal device. Another example is that when the communication device 400 is a network device, the transceiver 403 can be used for communication with a terminal or with another network device.

[0097] Optionally, the transceiver 403 can include a receiver and a transmitter ( Figure 4 not shown separately). Among them, the receiver is used to implement the receiving function, and the transmitter is used to implement the sending function.

[0098] Optionally, the transceiver 403 can be integrated with the processor 401 or exist independently and is coupled to the processor 401 through the interface circuit ( Figure 4 not shown) of the communication device 400. The embodiments of the present application do not make specific limitations on this.

[0099] It can be understood that Figure 4 the structure of the communication device 400 shown does not constitute a limitation on the communication device. The actual communication device may include more or fewer components than shown, or combine certain components, or have different component arrangements.

[0100] In addition, for the technical effects of the communication device 400, reference may be made to the technical effects of the method described in the foregoing method embodiments, which will not be elaborated herein.

[0101] It should be understood that the processor in the embodiments of the present application may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0102] It should also be understood that the memory in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable ROM (PROM), an erasable programmable ROM (EPROM), an electrically erasable programmable ROM (EEPROM) or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of random access memory (RAM) are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchlink DRAM (SLDRAM) and direct rambus RAM (DR RAM).

[0103] The above embodiments can be implemented in whole or in part by software, hardware (such as circuits), firmware, or any combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (such as infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more collections of available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, or magnetic tape), an optical medium (such as a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.

[0104] It should be understood that the term "and / or" in this document is merely a description of the association relationship between associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B can be singular or plural. Additionally, the character " / " in this document generally represents an "or" relationship between the associated objects before and after, but it may also represent an "and / or" relationship, which can be understood specifically with reference to the context before and after.

[0105] In this application, "at least one" means one or more, and "a plurality" means two or more. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c can be single or multiple.

[0106] It should be understood that in various embodiments of the present application, the magnitudes of the sequence numbers of the above processes do not imply the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0107] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in connection with the embodiments disclosed herein can be implemented in electronic hardware, or in a combination of computer software and electronic hardware. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Skilled professionals may use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0108] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.

[0109] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.

[0110] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0111] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit.

[0112] When the above-mentioned functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art or a part of this technical solution can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs.

[0113] As described above, the above are only specific implementation manners of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed by this application can easily think of changes or substitutions, which should all be covered by the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.

Claims

1. A method for ensuring financial transaction security and transparency based on blockchain, characterized in that: The method comprises: The application function AF receives an application message from the transaction terminal, wherein the application message includes smart contract data of the transaction terminal; In response to the application message, the AF determines the source UDM network element of the transaction terminal from N data management function UDM network elements of the blockchain, wherein N is an integer greater than 1, the AF and the N UDM network elements are network elements in the network accessed by the transaction terminal, and the N UDM network elements are also distributed accounting nodes in the blockchain that serve the transaction terminal; The AF sends the smart contract data of the transaction terminal to the source UDM network element, so that the source UDM network element synchronizes the smart contract data of the transaction terminal to all UDM network elements among the N UDM network elements except the source UDM network element; The AF determines the source UDM network element of the transaction terminal from the N UDM network elements of the blockchain, including: The AF determines that the AF is not configured with a distributed accounting node list of the blockchain; The AF sends a network element discovery request to a network element discovery function NRF network element in the network, wherein the network element discovery request is used to request the NRF network element to provide a distributed accounting node list of the blockchain; The AF receives a network element discovery response from the NRF network element, wherein the network element discovery response includes a first distributed accounting node list of the blockchain, the first distributed accounting node list is used to indicate the N UDM network elements, and the first distributed accounting node list is also used to indicate the source UDM network element among the N UDM network elements; The AF traverses the first distributed accounting node list to determine the source UDM network element of the transaction terminal; Before the AF determines the source UDM network element of the transaction terminal from the N UDM network elements of the blockchain, the method further includes: During the process of registering the transaction terminal to the network, the source UDM network element receives an authentication request from an AUSF network element in the network; In response to the authentication request, the source UDM network element determines the N UDM network elements in the blockchain that serve the transaction terminal according to the contract data of the transaction terminal; The source UDM network element triggers the N UDM network elements to complete N primary authentications of the transaction terminal; When the N primary authentications are all passed, the source UDM network element saves the first distributed accounting node list of the blockchain to the NRF network element, wherein the first distributed accounting node list is used to indicate the N UDM network elements, and the first distributed accounting node list is also used to indicate the source UDM network element among the N UDM network elements.

2. The method according to claim 1, characterized in that The source UDM network element is a network element among the N UDM network elements that stores the subscription data of the transaction terminal, and the UDM network elements among the N UDM network elements other than the source UDM network element do not store the subscription data of the transaction terminal.

3. The method according to claim 2, characterized in that The AF determines the source UDM network element of the transaction terminal from the N UDM network elements of the blockchain, including: The AF determines that the AF is pre-configured with a first distributed accounting node list of the blockchain, wherein the first distributed accounting node list is used to indicate the N UDM network elements, and the first distributed accounting node list is also used to indicate the source UDM network element among the N UDM network elements; The AF traverses the first distributed accounting node list to determine the source UDM network element of the transaction terminal.

4. The method according to claim 1, characterized in that: The source UDM network element determines, according to the contract data of the transaction terminal, the N UDM network elements in the blockchain that serve the transaction terminal, including: The source UDM network element obtains, from the contract data of the transaction terminal, blockchain information indicating that the transaction terminal has signed a contract for a service of the blockchain; The source UDM network element requests the NRF network element to discover N-1 UDM network elements within the service scope of the blockchain in the blockchain information, wherein the N-1 UDM network elements and the source UDM network element constitute the N UDM network elements in the blockchain that serve the transaction terminal.

5. The method according to claim 1, characterized in that The source UDM network element triggers the N UDM network elements to complete N primary authentications of the transaction terminal, including: The source UDM network element generates a source 5G HE AV of the transaction terminal, and triggers the AUSF network element to complete a primary authentication of the transaction terminal using the source 5G HE AV; The source UDM network element triggers N-1 UDM network elements among the N UDM network elements except the source UDM network element to complete the N-1 primary authentication of the transaction terminal through the AUSF network element.

6. The method according to claim 5, characterized in that The source UDM network element generates a source 5G HE AV of the transaction terminal, and triggers the AUSF network element to use the source 5G HE AV to complete a primary authentication of the transaction terminal, including: The source UDM network element generates source RAND and AUTN; The source UDM network element generates a source XRES* according to the source RAND; The source UDM network element generates KAUSF according to the key IK,CK of the transaction terminal; The source UDM network element encapsulates the source RAND, the source XRES *, the KAUSF, and the AUTN into the source 5G HE AV; The source UDM network element sends the source 5G HE AV to the AUSF network element; The source UDM network element learns from the AUSF network element that the primary authentication of the transaction terminal has passed.

7. The method according to claim 5, characterized in that The source UDM network element triggers N-1 UDM network elements other than the source UDM network element among the N UDM network elements to complete N-1 primary authentication of the transaction terminal through the AUSF network element, including: The source UDM network element sends the information of the AUSF network element to the N-1 UDM network elements, as well as the information used to generate the 5G HE AV required to complete the N-1 primary authentication of the transaction terminal; The source UDM network element learns from the N-1 UDM network elements that the N-1 primary authentication of the transaction terminal is successful.

Citation Information

Patent Citations

  • Block chain-based trusted data storage method and device

    CN117560743A