Communication method and device
By receiving operation requests and authorization information of application function network elements, and performing tag operations within the scope of authorization, combined with signature information verification, the problem of low security of tag operations is solved, and higher security and permission control is achieved.
Patent Information
- Application Number
- CN202311607727.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-27
- Publication Date
- 2025-05-27
AI Technical Summary
In the prior art, the security of operating tags is not high and there is a lack of an effective authority control mechanism.
By receiving operation requests and operation authorization information from application function network elements, it is determined that the operation is within the permission range indicated by the authorization information, and the security of operation authorization information is improved through signature information verification.
It realizes permission control over tag operations, improves the security of AF network element access tags, and reduces illegal or illegal access or operations.
Smart Images

Figure CN120050659A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communications, and in particular, to a communication method and apparatus. Background Art
[0002] A tag is a terminal device that can be deployed in specific application scenarios to assist in implementing certain application functions. For example, in logistics and warehousing application scenarios, tags can be deployed to achieve functions such as inventory and tracking of goods, monitoring of the environment during the goods transportation process, and the status of goods. Or, in industrial manufacturing application scenarios, tags can be deployed to achieve functions such as monitoring of the environment and equipment status.
[0003] Currently, the management function of tags can be implemented on the network side. The network side can communicate with a reader to perform operations such as reading data, writing data, inactivation, and locking on the tags through the reader. However, the security of operating tags is currently not high. Summary of the Invention
[0004] This application provides a communication method and apparatus, which can improve the security of operating tags.
[0005] In a first aspect, this application provides a communication method, and the method includes: receiving a first operation request and operation authorization information from an application function network element, where the first operation request is used to indicate to perform a first operation on a first tag, and the operation authorization information is used to indicate the operation authority of the application function network element; determining that the first operation is within the scope of the operation authority indicated by the operation authorization information, and performing the first operation on the first tag.
[0006] Exemplarily, the method described in the first aspect can be applied to a first network element. For example, the method is executed by a network device carrying the first network element, or by a device (such as a chip) built into the network device carrying the first network element. The network device carrying the first network element may be a first network device.
[0007] Optionally, the first network element may be a network element that independently implements the label management function, such as a tag management function (TMF) network element. Alternatively, the first network element may also be other network elements with the label management function. For example, the other network element may be an access and mobility management function (AMF) network element, or a unified data management (UDM) network element, or a network exposure function (NEF) network element, or a network repository function (NRF) network element, or a unified data repository (UDR) network element, etc.
[0008] Exemplarily, the first tag may be a passive tag, or a semi-passive tag or an active tag, which will not be elaborated here.
[0009] The first operation may be to inventory the first tag, or read data from the first tag, or write data to the first tag, or inactivate the first tag, or lock the first tag, etc. There is no limitation on the first operation.
[0010] Exemplarily, the process of the first network element performing the first operation on the first tag can be implemented by a card reader. The card reader may be a relay or a mobile phone, or a dedicated card reader device, or other terminal devices capable of implementing the card reader function, which is not limited here. Alternatively, the card reader, or rather the capabilities of the card reader, can also be implemented in an access network device (such as a base station).
[0011] The communication method can, according to the operation permission range indicated by the operation authorization information of the application function (AF) network element, when it is determined that the AF network element has the permission to perform the first operation on the first tag, in response to the first operation request of the AF network element, perform the first operation on the first tag. By controlling the permission of the first operation of the AF network element according to the operation permission range indicated by the operation authorization information of the AF network element, an authorization access mechanism can be added to the process of the AF network element operating on the tag, improving the security of the AF network element accessing the tag. For example, this method can reduce the access or operation of the tag by illegal or unauthorized AF network elements.
[0012] Optionally, when the first network element performs the first operation on the first label, it may be in a serial manner. After performing the first operation on one first label, it continues to perform the first operation on the next first label. It may also be in a parallel manner, performing the first operation on multiple first labels in batch. This application does not limit the specific implementation manner of the batch operation.
[0013] Optionally, the operation authorization information of the AF network element may be sent by the target network element to the AF network element, that is, the target network element is the network element that sends the operation authorization information to the application function network element. Or rather, before the AF network element sends the operation authorization information to the first network element, it may obtain the operation authorization information from the target network element.
[0014] In a possible design, the target network element may be the above-mentioned first network element. For example, the target network element is a NEF network element or an NRF network element with label management capabilities. The method further includes: receiving a first message from the application function network element, where the first message is used to indicate a request to obtain operation authorization information; in response to the first message, sending the operation authorization information to the application function network element.
[0015] In this design, the first network element may pre-send the operation authorization information to the AF network element.
[0016] Optionally, the AF network element may also not send a first message to the first network element to request operation authorization, and the first network element may actively send the operation authorization information to the AF network element, which is not limited here.
[0017] In another possible design, the target network element may also be a second network element without label management capabilities. For example, the first network element is a TMF network element, or an AMF network element with label management capabilities, and the second network element is an NRF network element, or a NEF network element, etc.
[0018] In this design, the second network element may pre-send the operation authorization information to the AF network element.
[0019] Optionally, the AF network element may also not send a first message to the second network element to request operation authorization, and the second network element may actively send the operation authorization information to the AF network element, which is not limited here.
[0020] In a possible design, the operation authorization information carries first signature information, and the first signature information is used to indicate the signature of the target network element, where the target network element is the network element that sends the operation authorization information to the application function network element. Before determining that the first operation is within the operation authority range indicated by the operation authorization information and performing the first operation on the first label, the method further includes: determining that the first signature information and the second signature information match, where the second signature information is used to indicate the signature of the target network element.
[0021] Exemplarily, in this design, after receiving the first operation request and operation authorization information, the first network element may first verify whether the first signature information carried in the operation authorization information matches the second signature information, and the second signature information is also used to indicate the signature of the target network element. When the first signature information matches the second signature information, the first network element may determine whether the first operation is within the scope of operation authority indicated by the operation authorization information, and when it is determined that the first operation is within the scope of operation authority indicated by the operation authorization information, perform the first operation on the first tag. When the first signature information does not match the second signature information, the first network element may consider the operation authorization information illegal and no longer perform subsequent operations. For example, regardless of whether the first operation is within the scope of operation authority indicated by the operation authorization information, the first operation is no longer performed on the first tag.
[0022] This design can reduce the possibility of the operation authorization information being tampered with or forged during transmission, and further improve the security of the AF network element accessing the tag.
[0023] In a possible design, before determining that the first signature information and the second signature information match, the method further includes: receiving the second signature information from the target network element.
[0024] For the implementation manner where the above target network element is a second network element without a tag management function, the first network element may obtain the second signature information from the second network element before determining that the first signature information and the second signature information match.
[0025] In a possible design, the operation authorization information is further used to indicate at least one of the following information corresponding to the operation authority of the application function network element: area range, tag range, permission period.
[0026] In this design, by combining at least one of the area range, tag range, and permission period information, the operation authority of the AF network element can be controlled with finer granularity through the operation authorization information, which can improve the flexibility of the AF network element authorization access mechanism.
[0027] Optionally, the above operation authorization information is further used to indicate the identification information of the AF network element, such as it may include the ID of the AF network element. Combining the identification information of the AF network element can distinguish the operation authorization information of different AF network elements.
[0028] In a possible design, the operation authorization information is used to indicate the operation authority for the application function network element to perform the first operation and the second operation.
[0029] In this design, the operation authorization information sent by the target network element to the AF network element can be referred to as the first operation authorization information, and the operation authorization information sent by the AF network element to the first network element can be referred to as the second operation authorization information. The first operation and the second operation can be understood as two different operations, or the first operation and the second operation can be understood as two different types of operations. For example, the first operation is the first type of operation and the second operation is the second type of operation. The first operation authorization information and the second operation authorization information can be the same. After receiving the second operation authorization information, the first network element can determine whether to perform the first operation according to the operation authority of the AF network element to perform the first operation indicated in the second operation authorization information.
[0030] In this design, when the AF network element obtains the operation authorization information from the target network element and sends it to the first network element, it does not need to consider the first operation to be performed on the first label. The first network element determines the part of the operation authorization information that indicates the operation authority of the AF network element to perform the first operation according to the first operation.
[0031] In the design where both the above-mentioned first operation authorization information and the second operation authorization information indicate the operation authorities of the AF network element to perform the first operation and the second operation, the method further includes: receiving a second operation request from the application function network element, where the second operation request is used to indicate performing a second operation on the first label; determining that the second operation is within the scope of the operation authorities indicated in the operation authorization information, and performing the second operation on the first label.
[0032] In this design, when the first network element receives the second operation request from the AF network element, it can determine whether to perform the second operation according to the operation authorization information (the second operation authorization information) that has been received when performing the first operation before.
[0033] Optionally, in some other possible designs, the operation authorization information (that is, the operation authorization information sent by the AF network element to the first network element) is used to indicate the operation authority of the application function network element to perform the first operation.
[0034] In this design, the operation authorization information sent by the target network element to the AF network element can be referred to as the first operation authorization information, and the operation authorization information sent by the AF network element to the first network element can be referred to as the second operation authorization information.
[0035] In one implementation, the first operation authorization information is used to indicate the operation authorities of the AF network element to perform the first operation and the second operation. The second operation authorization information is a part of the first operation authorization information and is used to indicate the operation authority of the AF network element to perform the first operation. After receiving the second operation authorization information, the first network element can determine whether to perform the first operation according to the operation authority of the AF network element to perform the first operation indicated by the second operation authorization information.
[0036] In this implementation manner, the AF network element can, according to the requirement of performing the first operation, only send operation authorization information indicating the operation authority for the AF network element to perform the first operation to the first network element, saving communication costs.
[0037] In another implementation manner, the first operation authorization information is used to indicate the operation authority for the AF network element to perform the first operation. The second operation authorization information is the same as the first operation authorization information. After receiving the second operation authorization information, the first network element can determine whether to perform the first operation according to the operation authority for the AF network element to perform the first operation indicated by the second operation authorization information.
[0038] In this implementation manner, the AF network element can, according to the requirement of performing the first operation, only obtain from the target network element and send to the first network element the operation authorization information indicating the operation authority for the AF network element to perform the first operation, saving communication costs.
[0039] In a possible design, the method further includes: sending an operation confirmation request message to the application function network element, where the operation confirmation request message is used to indicate whether to perform the first operation on the first label; receiving an operation confirmation response message from the application function network element, where the operation confirmation response message is used to indicate confirmation of performing the first operation on the first label. The performing of the first operation includes: in response to the operation confirmation response message, performing the first operation on the first label.
[0040] This design enables the steps for the first network element to perform the first operation to be reconfirmed by the AF network element, reducing the possibility of misoperation and further improving the security of operating on the label. Additionally, when the first operation is a specific one or a type of operation, it is also possible to implement differentiated processing for this type of operation (such as special operations). For example, a special operation that has a great impact on the label can have an additional confirmation mechanism.
[0041] In a possible design, the operation confirmation response message includes operation authorization information; before performing the first operation on the first label in response to the operation confirmation response message, the method further includes: determining that the first operation is within the operation authority range indicated by the operation authorization information in the operation confirmation response message.
[0042] In this design, the operation confirmation response message includes operation authorization information. The first network element can again determine whether the first operation is within the operation authority range indicated by the operation authorization information in the operation confirmation response message, and when it is confirmed that the first operation is within the operation authority range indicated by the operation authorization information, perform the first operation, which can reduce the possibility that the first operation is illegal due to changes in the operation authorization information or the legal status of the AF network element, further improving the security of operating on the label.
[0043] In a possible design, the method further includes: receiving a first password from an application function network element, where the first password is the password corresponding to a first tag; the performing a first operation on the first tag includes: sending indication information and the first password to the first tag, where the indication information is used to indicate the first tag to perform the first operation, and the first password is used to indicate that when the first password is consistent with the local password of the first tag, the first operation is performed.
[0044] Exemplarily, the first tag and the AF network element respectively store the password corresponding to the first tag. The password stored in the first tag can be referred to as the local password of the first tag, and the password stored in the AF network element can be referred to as the first password, that is, the first password is the password corresponding to the first tag. When the AF network element needs to perform a first operation on the first tag, it can also send the first password to the first tag through the first network element, and the first tag can perform the first operation when it determines that the first password is consistent with the local password.
[0045] In this design, the first network element performs verification of operation authorization information and the first tag performs verification of the password, forming a dual authorization verification mechanism, which can further improve the security of the AF network element operating on the tag.
[0046] Optionally, in this design, when the first operation is for a specific one or a type of operations, it is also possible to implement differentiated processing for this type of operations. For example, the first operation can be an inactivation operation or the above special operation, so as to implement dual verification authorization for special operations that have a great impact on the tag.
[0047] In a possible design, the method further includes: receiving a password printing request from an application function network element, where the password printing request is used to indicate writing a second password to the first tag; determining that the application function network element has the write permission for the first tag, and writing the second password to the first tag, where the second password is the local password of the first tag.
[0048] Exemplarily, when the first network element receives the password printing request, it can first verify or query whether the AF network element has the write permission for the first tag, and when it determines that the AF network element has the write permission for the first tag, it responds to the password printing request and writes the second password to the first tag. When the AF network element does not have the write permission for the first tag, it can not respond to the password printing request.
[0049] In a possible design, a permission query request message is sent to a second network element, where the permission query request message is used to indicate a request to obtain the operation permission of an application function network element; a permission query response message is received from the second network element, where the permission query response message is used to indicate the operation permission of the application function network element.
[0050] In this design, the first network element can communicate with a second network element that does not have a label management function to query whether the AF network element has the write permission for the first label. The AF network element can write a local password into the first label through the first network element, and the first network element can write the local password into the first label when it determines that the AF network element has the write permission for the first label.
[0051] In a second aspect, the present application provides a communication device, and the device has the function of implementing the method described in the first aspect above. The function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more units or modules corresponding to the functions of the method described in the first aspect above. For example, a receiving unit, a processing unit, etc.
[0052] Among them, the receiving unit is used to receive a first operation request and operation authorization information from an application function network element. The first operation request is used to indicate performing a first operation on a first label, and the operation authorization information is used to indicate the operation permission of the application function network element; the processing unit is used to determine that the first operation is within the operation permission range indicated by the operation authorization information and perform the first operation on the first label.
[0053] In a possible design, the device further includes: a sending unit; the receiving unit is further used to receive a first message from the application function network element, and the first message is used to indicate a request to obtain operation authorization information; the sending unit is used to send operation authorization information to the application function network element in response to the first message.
[0054] In a possible design, the operation authorization information carries first signature information, and the first signature information is used to indicate the signature of the target network element, and the target network element is the network element that sends the operation authorization information to the application function network element; the processing unit is further used to determine that the first signature information and the second signature information match before performing the first operation on the first label when it determines that the first operation is within the operation permission range indicated by the operation authorization information, and the second signature information is used to indicate the signature of the target network element.
[0055] In a possible design, the receiving unit is further used to receive second signature information from the target network element.
[0056] In a possible design, the operation authorization information is further used to indicate at least one of the following information corresponding to the operation permission of the application function network element: area range, label range, permission period.
[0057] In a possible design, the operation authorization information is used to indicate the operation permissions for the application function network element to perform the first operation and the second operation.
[0058] In a possible design, the receiving unit is further configured to receive a second operation request from an application function network element, where the second operation request is used to indicate to perform a second operation on a first tag; the processing unit is further configured to determine that the second operation is within the scope of the operation authority indicated by the operation authorization information, and perform the second operation on the first tag.
[0059] In a possible design, the operation authorization information is used to indicate the operation authority for the application function network element to perform a first operation.
[0060] In a possible design, the apparatus further includes: a sending unit; the sending unit is configured to send an operation confirmation request message to the application function network element, where the operation confirmation request message is used to indicate whether to confirm performing a first operation on a first tag; the receiving unit is further configured to receive an operation confirmation response message from the application function network element, where the operation confirmation response message is used to indicate confirmation of performing a first operation on the first tag; the processing unit is specifically configured to, in response to the operation confirmation response message, perform the first operation on the first tag.
[0061] In a possible design, the operation confirmation response message includes operation authorization information; the processing unit is further configured to, before performing the first operation on the first tag in response to the operation confirmation response message, determine that the first operation is within the scope of the operation authority indicated by the operation authorization information in the operation confirmation response message.
[0062] In a possible design, the apparatus further includes: a sending unit; the receiving unit is further configured to receive a first password from the application function network element, where the first password is the password corresponding to the first tag; the processing unit is specifically configured to send indication information and the first password to the first tag through the sending unit, where the indication information is used to indicate the first tag to perform a first operation, and the first password is used to indicate that when the first password is consistent with the local password of the first tag, perform the first operation.
[0063] In a possible design, the receiving unit is further configured to receive a password printing request from the application function network element, where the password printing request is used to indicate writing a second password to the first tag; the processing unit is further configured to determine that the application function network element has the write permission for the first tag, and write the second password to the first tag, where the second password is the local password of the first tag.
[0064] In a third aspect, the present application further provides a communication apparatus, including: a processor configured to execute computer instructions stored in a memory, and when the computer instructions are executed, cause the apparatus to perform the method described in the first aspect or any possible design of the first aspect.
[0065] In a fourth aspect, the present application further provides a communication apparatus, including: a processor and an interface circuit, where the processor is configured to communicate with other devices through the interface circuit and perform the method described in the first aspect or any possible design of the first aspect.
[0066] Exemplarily, in the third aspect and the fourth aspect, the processor is configured to execute the method described in the first aspect or any possible design of the first aspect.
[0067] The communication device described in the second aspect to the fourth aspect above may be a first network device or a device (e.g., a chip) built into the first network device. The first network device may be a network device carrying a first network element.
[0068] In a fifth aspect, the present application further provides a computer-readable storage medium, including: computer software instructions; when the computer software instructions are run, the method described in the first aspect or any possible design of the first aspect is implemented. For example, when the computer software instructions run in the first network device or a device (e.g., a chip) built into the first network device, the first network device implements the method described in the first aspect or any possible design of the first aspect. The first network device may be a network device carrying a first network element.
[0069] It can be understood that for the beneficial effects that can be achieved by the second aspect to the fifth aspect provided above, reference may be made to the beneficial effects in the first aspect and any possible design thereof, which will not be elaborated herein.
[0070] In a sixth aspect, the present application provides a communication method, the method including: sending a first operation request and operation authorization information to a first network element, the first operation request being used to indicate performing a first operation on a first label, and the operation authorization information being used to indicate the operation permission of an application function network element; receiving a first operation response message from the first network element, the first operation response message being used to indicate the execution result of the first operation.
[0071] Exemplarily, the method described in the sixth aspect may be applied to an application function network element, i.e., an AF network element. For example, the method is executed by a network device carrying the application function network element, or by a device (e.g., a chip) built into the network device carrying the application function network element. The network device carrying the application function network element may be a second network device.
[0072] Optionally, the first network element may be a network element that independently implements the label management function, such as a TMF network element, or the first network element may also be other network elements with the label management function. For example, the other network elements may be an AMF network element, or a UDM network element, or a NEF network element, or an NRF network element, or a UDR network element, etc.
[0073] Exemplarily, the first label may be a passive label, or a semi-passive label or an active label, which will not be elaborated herein.
[0074] The first operation may be to take inventory of the first tag, or read data from the first tag, or write data to the first tag, or inactivate the first tag, or lock the first tag, etc. There is no limitation on the first operation.
[0075] According to the operation permission range indicated by the operation authorization information of the AF network element, when it is determined that the AF network element has the permission to perform the first operation on the first tag, in response to the first operation request of the AF network element, the first operation is performed on the first tag. By controlling the permission of the first operation of the AF network element according to the operation permission range indicated by the operation authorization information of the AF network element, an authorization access mechanism can be added to the process of the AF network element operating on the tag, improving the security of the AF network element accessing the tag. For example, this method can reduce the access or operation of the tag by illegal or unauthorized AF network elements.
[0076] Optionally, the operation authorization information of the AF network element may be sent to the AF network element by the target network element, that is, the target network element is the network element that sends the operation authorization information to the application function network element. Or rather, before sending the operation authorization information to the first network element, the AF network element may obtain the operation authorization information from the target network element.
[0077] For example, the method further includes: sending a first message to the target network element, the first message being used to indicate a request to obtain operation authorization information, and the target network element being the first network element or the second network element; receiving the operation authorization information from the target network element.
[0078] Exemplarily, in a possible design, the target network element may be the above-mentioned first network element. For example, the target network element is an NRF network element or a NEF network element with tag management functions. The first network element may pre-send the operation authorization information to the AF network element.
[0079] In another possible design, the target network element may also be a second network element without tag management functions. For example, the first network element is a TMF network element, or an AMF network element with tag management functions, and the second network element is an NRF network element, or a NEF network element, etc. The second network element may pre-send the operation authorization information to the AF network element.
[0080] In a possible design, the operation authorization information carries first signature information, and the first signature information is used to indicate the signature of the target network element, where the target network element is the network element that sends the operation authorization information to the application function network element.
[0081] Exemplarily, in this design, after receiving the first operation request and operation authorization information, the first network element can first verify whether the first signature information carried in the operation authorization information matches the second signature information, and the second signature information is also used to indicate the signature of the target network element. When the first signature information matches the second signature information, the first network element can determine whether the first operation is within the scope of the operation authority indicated by the operation authorization information, and when it is determined that the first operation is within the scope of the operation authority indicated by the operation authorization information, perform the first operation on the first label. When the first signature information does not match the second signature information, the first network element can consider the operation authorization information illegal and no longer perform subsequent operations. For example, regardless of whether the first operation is within the scope of the operation authority indicated by the operation authorization information, the first operation is no longer performed on the first label.
[0082] This design can reduce the possibility of the operation authorization information being tampered with or forged during transmission, and further improve the security of the AF network element accessing the label.
[0083] In a possible design, the operation authorization information is also used to indicate at least one of the following information corresponding to the operation authority of the application function network element: area range, label range, permission period.
[0084] In this design, at least one of the information of the area range, label range, and permission period can be combined, and the operation authority of the AF network element can be controlled with finer granularity through the operation authorization information, which can improve the flexibility of the AF network element authorization access mechanism.
[0085] Optionally, the above operation authorization information is also used to indicate the identification information of the AF network element, such as it can include the ID of the AF network element. Combining the identification information of the AF network element can distinguish the operation authorization information of different AF network elements.
[0086] In a possible design, the operation authorization information is used to indicate the operation authority for the application function network element to perform the first operation and the second operation.
[0087] In this design, the operation authorization information sent by the target network element to the AF network element can be called the first operation authorization information, and the operation authorization information sent by the AF network element to the first network element can be called the second operation authorization information. The first operation and the second operation can be understood as two different operations, or the first operation and the second operation can be understood as two different types of operations. For example, the first operation is the first type of operation and the second operation is the second type of operation. The first operation authorization information and the second operation authorization information can be the same. After receiving the second operation authorization information, the first network element can determine whether to perform the first operation according to the operation authority of the AF network element to perform the first operation indicated in the second operation authorization information.
[0088] In this design, when the AF network element obtains the operation authorization information from the target network element and sends it to the first network element, it does not need to consider the first operation to be performed on the first label. Instead, the first network element determines, according to the first operation, the part of the operation authorization information that indicates the operation permission for the AF network element to perform the first operation.
[0089] In the design where both the above-mentioned first operation authorization information and the second operation authorization information indicate the operation permissions for the AF network element to perform the first operation and the second operation, the method further includes: sending a second operation request to the first network element, where the second operation request is used to indicate performing a second operation on the first label; receiving a second operation response message from the first network element, where the second operation response message is used to indicate the execution result of the second operation.
[0090] In this design, when the first network element receives the second operation request from the AF network element, it can determine whether to perform the second operation according to the operation authorization information (second operation authorization information) that it has received when performing the first operation previously.
[0091] Optionally, in some other possible designs, the operation authorization information (i.e., the operation authorization information sent by the AF network element to the first network element) is used to indicate the operation permission for the application function network element to perform the first operation.
[0092] In this design, the operation authorization information sent by the target network element to the AF network element can be referred to as the first operation authorization information, and the operation authorization information sent by the AF network element to the first network element can be referred to as the second operation authorization information.
[0093] In one implementation, the first operation authorization information is used to indicate the operation permissions for the AF network element to perform the first operation and the second operation. The second operation authorization information is a part of the first operation authorization information and is used to indicate the operation permission for the AF network element to perform the first operation. After receiving the second operation authorization information, the first network element can determine whether to perform the first operation according to the operation permission for the AF network element to perform the first operation indicated by the second operation authorization information.
[0094] In this implementation, the AF network element can, according to the requirement of performing the first operation, only send the operation authorization information indicating the operation permission for the AF network element to perform the first operation to the first network element, saving communication costs.
[0095] In another implementation, the first operation authorization information is used to indicate the operation permission for the AF network element to perform the first operation. The second operation authorization information is the same as the first operation authorization information. After receiving the second operation authorization information, the first network element can determine whether to perform the first operation according to the operation permission for the AF network element to perform the first operation indicated by the second operation authorization information.
[0096] In this implementation manner, the AF network element can obtain from the target network element and send to the first network element only the operation authorization information indicating the operation authority for the AF network element to perform the first operation according to the requirement of performing the first operation, saving communication costs.
[0097] In a possible design, the method further includes: receiving an operation confirmation request message from the first network element, where the operation confirmation request message is used to indicate whether to confirm performing the first operation on the first label; sending an operation confirmation response message to the first network element, where the operation confirmation response message is used to indicate confirming performing the first operation on the first label.
[0098] This design enables the step of the first network element performing the first operation to be reconfirmed by the AF network element, reducing the possibility of misoperation and further improving the security of operating on the label. Additionally, when the first operation is a specific one or a type of operation, it is also possible to implement differentiated processing for this type of operation (such as a special operation). For example, a special operation that has a greater impact on the label can have an additional confirmation mechanism.
[0099] In a possible design, the operation confirmation response message includes operation authorization information.
[0100] In this design, since the operation confirmation response message includes operation authorization information, the first network element can determine again whether the first operation is within the operation authority range indicated by the operation authorization information in the operation confirmation response message, and when it is confirmed that the first operation is within the operation authority range indicated by the operation authorization information, perform the first operation, which can reduce the possibility that the first operation is illegal due to changes in the operation authorization information or changes in the legal status of the AF network element, further improving the security of operating on the label.
[0101] In a possible design, the method further includes: sending a first password to the first network element, where the first password is the password corresponding to the first label, and the first password is used to indicate performing the first operation when the first password is consistent with the local password of the first label.
[0102] Exemplarily, the first label and the AF network element respectively store the password corresponding to the first label. The password stored in the first label can be called the local password of the first label, and the password stored in the AF network element can be called the first password, that is, the first password is the password corresponding to the first label. When the AF network element needs to perform the first operation on the first label, it can also send the first password to the first label through the first network element, and the first label can perform the first operation when it determines that the first password is consistent with the local password.
[0103] In this design, the first network element verifies the operation authorization information and the first tag verifies the password, forming a dual authorization verification mechanism, which can further improve the security of the AF network element's operation on the tag.
[0104] Optionally, in this design, when the first operation is for a specific one or a type of operations, it is also possible to implement differentiated processing for this type of operation. For example, the first operation can be an inactivation operation or the above-mentioned special operation, so as to implement dual verification authorization for special operations that have a great impact on the tag.
[0105] In a possible design, the method further includes: sending a password printing request to the first network element, where the password printing request is used to instruct writing a second password to the first tag, and the second password is the local password of the first tag.
[0106] Exemplarily, when the first network element receives the password printing request, it can first verify or query whether the AF network element has the write permission for the first tag, and when it is determined that the AF network element has the write permission for the first tag, it responds to the password printing request and writes the second password to the first tag. When the AF network element does not have the write permission for the first tag, it may not respond to the password printing request.
[0107] In a seventh aspect, the present application provides a communication device, which has the function of implementing the method described in the sixth aspect above. The function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more units or modules corresponding to the functions of the method described in the sixth aspect above. For example, a sending unit, a receiving unit, etc.
[0108] Among them, the sending unit is used to send a first operation request and operation authorization information to the first network element. The first operation request is used to instruct performing a first operation on the first tag, and the operation authorization information is used to indicate the operation permission of the application function network element; the receiving unit is used to receive a first operation response message from the first network element, and the first operation response message is used to indicate the execution result of the first operation.
[0109] In a possible design, the sending unit is further used to send a first message to the target network element, where the first message is used to indicate a request to obtain operation authorization information, and the target network element is the first network element or the second network element; the receiving unit is further used to receive the operation authorization information from the target network element.
[0110] In a possible design, the operation authorization information carries first signature information, and the first signature information is used to indicate the signature of the target network element, where the target network element is the network element that sends the operation authorization information to the application function network element.
[0111] In a possible design, the operation authorization information is further used to indicate at least one of the following information corresponding to the operation permissions of the application function network element: area range, label range, and permission period.
[0112] In a possible design, the operation authorization information is used to indicate the operation permissions for the application function network element to perform a first operation and a second operation.
[0113] In a possible design, the sending unit is further configured to send a second operation request to the first network element, where the second operation request is used to indicate performing a second operation on a first label; the receiving unit is further configured to receive a second operation response message from the first network element, where the second operation response message is used to indicate the execution result of the second operation.
[0114] In a possible design, the operation authorization information is used to indicate the operation permission for the application function network element to perform a first operation.
[0115] In a possible design, the receiving unit is further configured to receive an operation confirmation request message from the first network element, where the operation confirmation request message is used to indicate confirming whether to perform a first operation on a first label; the sending unit is further configured to send an operation confirmation response message to the first network element, where the operation confirmation response message is used to indicate confirming performing a first operation on the first label.
[0116] In a possible design, the operation confirmation response message includes the operation authorization information.
[0117] In a possible design, the sending unit is further configured to send a first password to the first network element, where the first password is the password corresponding to the first label, and the first password is used to indicate that when the first password is consistent with the local password of the first label, the first operation is performed.
[0118] In a possible design, the sending unit is further configured to send a password printing request to the first network element, where the password printing request is used to indicate writing a second password to the first label, and the second password is the local password of the first label.
[0119] In an eighth aspect, the present application further provides a communication device, including: a processor configured to execute computer instructions stored in a memory, and when the computer instructions are executed, the device is caused to perform the method described in the sixth aspect or any possible design of the sixth aspect.
[0120] In a ninth aspect, the present application further provides a communication device, including: a processor and an interface circuit, where the processor is configured to communicate with other devices through the interface circuit and perform the method described in the sixth aspect or any possible design of the sixth aspect.
[0121] Exemplarily, in the eighth aspect and the ninth aspect, the processor is configured to perform the method described in the sixth aspect or any possible design of the sixth aspect.
[0122] The communication device described in the above seventh to ninth aspects can be a second network device or a device (e.g., a chip) built into the second network device. The second network device can be a network device carrying application function network elements.
[0123] In a tenth aspect, the present application further provides a computer-readable storage medium, including: computer software instructions; when the computer software instructions are run, the method described in the sixth aspect or any possible design of the sixth aspect is implemented. For example, when the computer software instructions run in the second network device or a device (e.g., a chip) built into the second network device, the second network device implements the method described in the sixth aspect or any possible design of the sixth aspect. The second network device can be a network device carrying application function network elements.
[0124] It can be understood that for the beneficial effects that can be achieved by the above-provided seventh to tenth aspects, reference can be made to the beneficial effects in the sixth aspect and any of its possible designs, which will not be elaborated here.
[0125] In an eleventh aspect, the present application provides a communication method, the method including: receiving indication information and a first password from a first network element, the indication information being used to indicate the execution of a first operation; determining that the first password is consistent with the local password, and executing the first operation.
[0126] Exemplarily, the method described in the eleventh aspect can be applied to a tag, such as a first tag, e.g.: the method is executed by the first tag or by a device (e.g., a chip) built into the first tag.
[0127] Optionally, the first network element can be a network element that independently implements the tag management function, such as a TMF network element, or the first network element can also be other network elements with the tag management function. For example, the other network elements can be an AMF network element, or a UDM network element, or a NEF network element, or an NRF network element, or a UDR network element, etc.
[0128] Exemplarily, the first tag can be a passive tag, or a semi-passive tag or an active tag, which will not be elaborated here.
[0129] The first operation can be to inventory the first tag, or read data from the first tag, or write data to the first tag, or inactivate the first tag, or lock the first tag, etc. There is no limitation on the first operation.
[0130] For this communication method, the first tag can perform password verification, improving the security of the AF network element's operation on the tag. For example, the first network element performs verification of operation authorization information and the first tag performs password verification, forming a dual authorization verification mechanism.
[0131] Optionally, in this design, when the first operation is an operation for a specific one or a type of operations, it is also possible to implement differentiated processing for this type of operation. For example, the first operation can be an inactivation operation or the above-mentioned special operation, so as to implement double verification authorization for special operations that have a great impact on the label.
[0132] In a possible design, the method further includes: receiving a second password from a first network element; writing the second password as the local password.
[0133] Exemplarily, the local password of the first label can be written by the first network element.
[0134] In a twelfth aspect, the present application provides a communication device, and the device has the function of implementing the method described in the eleventh aspect above. The function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more units or modules corresponding to the functions of the method described in the eleventh aspect above. For example, a receiving unit, a processing unit, etc.
[0135] Among them, the receiving unit is used to receive indication information and a first password from the first network element, and the indication information is used to indicate the execution of the first operation; the processing unit is used to determine that the first password is consistent with the local password and execute the first operation.
[0136] In a possible design, the receiving unit is further used to receive a second password from the first network element; the processing unit is further used to write the second password as the local password.
[0137] In a thirteenth aspect, the present application further provides a communication device, including: a processor, configured to execute computer instructions stored in a memory, and when the computer instructions are executed, cause the device to execute the method described in the eleventh aspect or any possible design of the eleventh aspect.
[0138] In a fourteenth aspect, the present application further provides a communication device, including: a processor and an interface circuit, and the processor is used to communicate with other devices through the interface circuit and execute the method described in the eleventh aspect or any possible design of the eleventh aspect.
[0139] Exemplarily, in the thirteenth aspect and the fourteenth aspect, the processor is configured to execute the method described in the eleventh aspect or any possible design of the eleventh aspect.
[0140] The communication devices described in the above twelfth aspect to fourteenth aspect can be the first label or a device (such as a chip) built into the first label.
[0141] In a fifteenth aspect, the present application further provides a computer-readable storage medium, including: computer software instructions; when the computer software instructions are run, the method described in the eleventh aspect or any possible design of the eleventh aspect is implemented. For example, when the computer software instructions are run in the first tag or a device (such as a chip) built into the first tag, the first tag implements the method described in the eleventh aspect or any possible design of the eleventh aspect.
[0142] It can be understood that for the beneficial effects that can be achieved by the above-provided twelfth aspect to fifteenth aspect, reference can be made to the beneficial effects in the eleventh aspect and any of its possible designs, which will not be elaborated here.
[0143] In a sixteenth aspect, the present application provides a communication method, the method including: receiving a first message from an application function network element, the first message being used to indicate a request for obtaining operation authorization information, and the operation authorization information being used to indicate the operation authority of the application function network element; in response to the first message, sending the operation authorization information to the application function network element.
[0144] Exemplarily, the method described in the sixteenth aspect can be applied to a second network element, such as: the method is executed by a network device carrying the second network element, or by a device (such as a chip) built into the network device carrying the second network element. The network device carrying the second network element can be a third network device.
[0145] Optionally, the second network element can be an NRF network element, or a NEF network element, etc., and the second network element does not have a tag management function.
[0146] In this communication method, the second network element can pre-send the operation authorization information to the AF network element.
[0147] Optionally, the AF network element can also not send the first message to the second network element to request operation authorization, and the second network element can actively send the operation authorization information to the AF network element, which is not limited here.
[0148] In a possible design, the method is applied to the second network element, and the operation authorization information carries first signature information, and the first signature information is used to indicate the signature of the second network element.
[0149] Exemplarily, in this design, after the first network element receives the first operation request and operation authorization information, it can first verify whether the first signature information carried in the operation authorization information matches the second signature information, and the second signature information is also used to indicate the signature of the target network element. When the first signature information matches the second signature information, the first network element can determine whether the first operation is within the scope of the operation authority indicated by the operation authorization information, and when it is determined that the first operation is within the scope of the operation authority indicated by the operation authorization information, perform the first operation on the first label. When the first signature information does not match the second signature information, the first network element can consider the operation authorization information illegal and no longer perform subsequent operations. For example, regardless of whether the first operation is within the scope of the operation authority indicated by the operation authorization information, the first operation is no longer performed on the first label.
[0150] This design can reduce the possibility of the operation authorization information being tampered with or forged during transmission, and further improve the security of the AF network element accessing the label.
[0151] In a possible design, the method further includes: sending the second signature information to the first network element, and the second signature information is used to indicate the signature of the second network element.
[0152] In this design, before determining that the first signature information and the second signature information match, the first network element can obtain the second signature information from the second network element.
[0153] In a possible design, the operation authorization information is further used to indicate at least one of the following information corresponding to the operation authority of the application function network element: area range, label range, permission period.
[0154] In this design, at least one of the area range, label range, and permission period can be combined, and the operation authority of the AF network element can be controlled with finer granularity through the operation authorization information, which can improve the flexibility of the AF network element authorization access mechanism.
[0155] Optionally, the above operation authorization information is further used to indicate the identification information of the AF network element, such as it can include the ID of the AF network element. Combining the identification information of the AF network element can distinguish the operation authorization information of different AF network elements.
[0156] In a possible design, the operation authorization information is used to indicate the operation authority of the application function network element to perform the first operation and the second operation.
[0157] In this design, the operation authorization information sent by the second network element to the AF network element can be referred to as the first operation authorization information, and the operation authorization information sent by the AF network element to the first network element can be referred to as the second operation authorization information. The first operation and the second operation can be understood as two different operations, or the first operation and the second operation can be understood as two different types of operations. For example, the first operation is an operation of the first type, and the second operation is an operation of the second type. The first operation authorization information and the second operation authorization information can be the same. After receiving the second operation authorization information, the first network element can determine whether to perform the first operation according to the operation authority regarding the AF network element's execution of the first operation indicated in the second operation authorization information.
[0158] In this design, when the AF network element obtains the operation authorization information from the second network element and sends it to the first network element, it may not need to consider the first operation to be performed on the first label. The first network element determines the part of the operation authorization information that indicates the operation authority for the AF network element to perform the first operation according to the first operation.
[0159] In a possible design, the operation authorization information is used to indicate the operation authority for the application function network element to perform the first operation.
[0160] In this design, the operation authorization information sent by the second network element to the AF network element can be referred to as the first operation authorization information, and the operation authorization information sent by the AF network element to the first network element can be referred to as the second operation authorization information. The first operation authorization information is used to indicate the operation authority for the AF network element to perform the first operation. The second operation authorization information is the same as the first operation authorization information. After receiving the second operation authorization information, the first network element can determine whether to perform the first operation according to the operation authority of the AF network element to perform the first operation indicated by the second operation authorization information.
[0161] In this design, the AF network element can obtain and send to the first network element only the operation authorization information indicating the operation authority for the AF network element to perform the first operation according to the requirement of performing the first operation, saving communication costs.
[0162] In a possible design, receive a permission query request message from the first network element, where the permission query request message is used to indicate a request to obtain the operation permission of the application function network element; send a permission query response message to the first network element, where the permission query response message is used to indicate the operation permission of the application function network element.
[0163] Exemplarily, in this design, the first network element can be a TMF network element or an AMF network element with label management functions.
[0164] In this design, the first network element can communicate with the second network element that does not have the label management function to query whether the AF network element has the write permission for the first label. The AF network element can write the local password into the first label through the first network element, and the first network element can write the local password into the first label when it is determined that the AF network element has the write permission for the first label.
[0165] In a seventeenth aspect, the present application provides a communication device, and the device has the function of implementing the method described in the above sixteenth aspect. The function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more units or modules corresponding to the functions of the method described in the above sixteenth aspect. For example, a receiving unit, a sending unit, etc.
[0166] Among them, the receiving unit is used to receive a first message from the application function network element, and the first message is used to indicate a request to obtain operation authorization information, and the operation authorization information is used to indicate the operation permission of the application function network element; the sending unit is used to respond to the first message and send the operation authorization information to the application function network element.
[0167] In a possible design, the device is applied to the second network element, and the operation authorization information carries first signature information, and the first signature information is used to indicate the signature of the second network element.
[0168] In a possible design, the sending unit is further used to send second signature information to the first network element, and the second signature information is used to indicate the signature of the second network element.
[0169] In a possible design, the operation authorization information is further used to indicate at least one of the following information corresponding to the operation permission of the application function network element: area range, label range, permission period.
[0170] In a possible design, the operation authorization information is used to indicate the operation permissions for the application function network element to perform the first operation and the second operation.
[0171] In a possible design, the operation authorization information is used to indicate the operation permission for the application function network element to perform the first operation.
[0172] In a possible design, the receiving unit is further used to receive a permission query request message from the first network element, and the permission query request message is used to indicate a request to obtain the operation permission of the application function network element; the sending unit is further used to send a permission query response message to the first network element, and the permission query response message is used to indicate the operation permission of the application function network element.
[0173] In an eighteenth aspect, the present application further provides a communication device, including: a processor configured to execute computer instructions stored in a memory, and when the computer instructions are executed, causing the device to perform the method described in the sixteenth aspect or any possible design of the sixteenth aspect.
[0174] In a nineteenth aspect, the present application further provides a communication device, including: a processor and an interface circuit, where the processor is configured to communicate with other devices through the interface circuit and perform the method described in the sixteenth aspect or any possible design of the sixteenth aspect.
[0175] Exemplarily, in the eighteenth aspect and the nineteenth aspect, the processor is configured to perform the method described in the sixteenth aspect or any possible design of the sixteenth aspect.
[0176] The communication device described in the above seventeenth aspect to nineteenth aspect may be a third network device or a device (such as a chip) built in the third network device. The third network device may be a network device carrying the second network element.
[0177] In a twentieth aspect, the present application further provides a computer-readable storage medium, including: computer software instructions; when the computer software instructions are run, causing the method described in the sixteenth aspect or any possible design of the sixteenth aspect to be implemented. For example, when the computer software instructions are run in a third network device or a device (such as a chip) built in the third network device, causing the third network device to implement the method described in the sixteenth aspect or any possible design of the sixteenth aspect. The third network device may be a network device carrying the second network element.
[0178] It can be understood that the beneficial effects that can be achieved by the above seventeenth aspect to twentieth aspect can refer to the beneficial effects in the sixteenth aspect and any of its possible designs, which will not be elaborated here.
[0179] In a twenty-first aspect, the present application further provides a communication device, including: a transceiver unit and a processing unit. The transceiver unit may be configured to transmit and receive information or communicate with other network elements. The processing unit may be configured to process data. The device may implement the method described in the first aspect and any of its possible designs, or the method described in the sixth aspect and any of its possible designs, or the method described in the eleventh aspect and any of its possible designs, or the method described in the sixteenth aspect and any of its possible designs through the transceiver unit and the processing unit.
[0180] In a twenty-second aspect, the present application further provides a computer program product, which when executed can implement the methods described in the first aspect and any possible design thereof, or the methods described in the sixth aspect and any possible design thereof, or the methods described in the eleventh aspect and any possible design thereof, or the methods described in the sixteenth aspect and any possible design thereof.
[0181] In a twenty-third aspect, the present application further provides a chip system, which includes one or more interface circuits and one or more processors; the interface circuits and the processors are interconnected by lines; the processors receive and execute computer instructions from the memory of the electronic device through the interface circuits to implement the methods described in the first aspect and any possible design thereof, or the methods described in the sixth aspect and any possible design thereof, or the methods described in the eleventh aspect and any possible design thereof, or the methods described in the sixteenth aspect and any possible design thereof.
[0182] In a twenty-fourth aspect, the present application further provides a communication system, including: an application function network element, a first network element, and a first tag. The first network element executes the methods described in the first aspect and any possible design thereof, and the application function network element executes the steps corresponding to the interaction with the first network element in the methods described in the sixth aspect and any possible design thereof. The first tag executes the steps corresponding to the interaction with the first network element in the methods described in the eleventh aspect and any possible design thereof.
[0183] Exemplarily, the communication system further includes a second network element, and the second network element executes the steps corresponding to the interaction with the first network element and the application function network element in the methods described in the sixteenth aspect and any possible design thereof.
[0184] In a twenty-fifth aspect, the present application further provides a network element or network device, which can be used to implement the methods described in the first aspect and any possible design thereof, or the methods described in the sixth aspect and any possible design thereof, or the methods described in the sixteenth aspect and any possible design thereof.
[0185] In a twenty-sixth aspect, the present application further provides a tag or terminal device, which can be used to implement the methods described in the eleventh aspect and any possible design thereof.
[0186] It can be understood that for the beneficial effects that can be achieved by the above-provided twenty-first aspect to twenty-sixth aspect, reference can be made to the beneficial effects described in the first aspect, sixth aspect, eleventh aspect, sixteenth aspect, etc., which will not be elaborated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0187] Figure 1Shows a schematic diagram of the composition of a communication system provided by an embodiment of the present application;
[0188] Figure 2 Shows a schematic diagram of the composition of a network device provided by an embodiment of the present application;
[0189] Figure 3 Shows a schematic flowchart of a communication method provided by an embodiment of the present application;
[0190] Figure 4 Shows a schematic flowchart of performing a first operation;
[0191] Figure 5 Shows a schematic flowchart of the implementation of random access;
[0192] Figure 6 Shows another schematic flowchart of a communication method provided by an embodiment of the present application;
[0193] Figure 7 Shows yet another schematic flowchart of a communication method provided by an embodiment of the present application;
[0194] Figure 8 Shows yet another schematic flowchart of a communication method provided by an embodiment of the present application;
[0195] Figure 9 Shows yet another schematic flowchart of a communication method provided by an embodiment of the present application;
[0196] Figure 10 Shows yet another schematic flowchart of a communication method provided by an embodiment of the present application;
[0197] Figure 11 Shows yet another schematic flowchart of a communication method provided by an embodiment of the present application;
[0198] Figure 12 Shows yet another schematic flowchart of a communication method provided by an embodiment of the present application;
[0199] Figure 13 Shows yet another schematic flowchart of a communication method provided by an embodiment of the present application;
[0200] Figure 14 Shows yet another schematic flowchart of a communication method provided by an embodiment of the present application;
[0201] Figure 15 Shows yet another schematic flowchart of a communication method provided by an embodiment of the present application;
[0202] Figure 16 Shows a schematic diagram of the structure of a communication device provided by an embodiment of the present application;
[0203] Figure 17 Another structural schematic diagram of the communication device provided by the embodiment of the present application is shown;
[0204] Figure 18 Yet another structural schematic diagram of the communication device provided by the embodiment of the present application is shown;
[0205] Figure 19 Yet another structural schematic diagram of the communication device provided by the embodiment of the present application is shown. Detailed implementation manners
[0206] A tag is a terminal device that can be deployed in a specific application scenario to assist in implementing certain application functions. For example, in the logistics and warehousing application scenario, inventory and tracking of goods, monitoring of the environment during the goods transportation process and the status of goods, etc. can be achieved by deploying tags. Or, in the industrial manufacturing application scenario, monitoring of the environment and equipment status, etc. can be achieved by deploying tags.
[0207] Currently, the management function of tags can be implemented on the network side. For example, the management function of tags can be implemented in a tag management function (TMF) network element. The network side can communicate with a reader to perform operations such as inventorying, reading data, writing data, inactivating, and locking tags through the reader. However, the security of performing the foregoing operations on tags is currently not high.
[0208] For this reason, the embodiment of the present application provides a communication method, which can be applicable to the scenario where the network side (such as a TMF network element) operates on tags, and can provide a secure access mechanism for the process of the network side operating on tags, improving the security of operating on tags.
[0209] The method may include: receiving a first operation request and operation authorization information from an application function (AF) network element, where the first operation request is used to indicate performing a first operation on a first tag, and the operation authorization information is used to indicate the operation authority of the application function network element; determining that the first operation is within the scope of the operation authority indicated by the operation authorization information, and performing the first operation on the first tag.
[0210] Exemplarily, Figure 1 A schematic diagram of the composition of a communication system provided by the embodiment of the present application is shown. The communication method provided by the embodiment of the present application can be applied to Figure 1 the shown communication system. As Figure 1 shown, the communication system may include: a first network element 110, an access network device 120, a first tag 130, and an AF network element 140.
[0211] The method described above can be applied to the first network element 110. For example, the method is executed by a network device that hosts the first network element 110, or by a device (such as a chip) built into the network device that hosts the first network element 110. The network device that hosts the first network element 110 may be a first network device.
[0212] Optionally, the first network element 110 may be a network element that independently implements the label management function, such as a tag management function (TMF) network element. Or the first network element 110 may also be other network elements capable of implementing the label management function. For example, the other network elements may be access and mobility management function (AMF) network elements with TMF, or unified data management (UDM) network elements, or network exposure function (NEF) network elements, or network repository function (NRF) network elements, or unified data repository (UDR) network elements, etc. The present application does not limit the specific implementation of the first network element. The foregoing first network element may be a core network element.
[0213] Among them, the AMF network element can be used to implement mobility management and access control. For example, the AMF network element can be responsible for processing the access and handover of user equipment, and managing the movement of user equipment between different base stations. The AMF network element can also be responsible for processing functions such as authentication, security, and session management of user equipment to ensure that user equipment can access and use the network safely and efficiently.
[0214] The UDM network element can be used to generate 3GPP AKA authentication certificates, process user identifiers (User IDs), perform access authorization based on subscription information, manage the registration of network function (NF) services, and uniformly manage function-related data such as subscription information management.
[0215] The NEF network element can be used to expose the services and capabilities of 3GPP network functions to the AF network element, and can also allow the AF to provide information to 3GPP network functions.
[0216] The NRF network element can be used to support the service discovery function of network functions, maintain the NF configuration files of available NF instances and the services they support, notify subscribers (NF service consumers or SCPs) of newly registered / updated / deregistered NFs and service communication proxy (SCP) instances and their potential NF services, and maintain the health status of NF and SCP service control points, etc.
[0217] The UDR network element can be used for the UDM to store and obtain subscription data, the terminal and the policy control function (PCF) to store and obtain policy data, store structured data for capability exposure, and store application data for application detection.
[0218] The access network device 120 can also be referred to as a radio access network (RAN) device or a next-generation radio access network device, such as a base station. Different access network devices 120 can communicate with each other through the Xn interface.
[0219] Optionally, in the embodiments of the present application, the access network device 120 may include various forms of macro base stations, micro base stations (also known as small stations), etc. For example, the access network device 120 may include: a base station in wideband code division multiple access (WCDMA) or LTE, a next generation node B (gNB), a next generation evolved node B (Ng-eNB), a transmission reception point (TRP), an evolved Node B (eNB), a radio network controller (RNC), a Node B (NB), a base station controller (BSC), a base transceiver station (BTS), a home base station (e.g., home evolved NodeB, or home Node B, HNB), a base band unit (BBU), or a wireless fidelity (Wifi) access point (AP), a wireless relay node, a wireless backhaul node, a transmission point (TP), or a transmission and reception point (TRP), etc.
[0220] In some deployments, the gNB may include a centralized unit (CU) and a distributed unit (DU). The gNB may also include an active antenna unit (AAU). The CU implements some functions of the gNB, and the DU implements some functions of the gNB. For example, the CU is responsible for processing non-real-time protocols and services, implementing the functions of the radio resource control (RRC) and packet data convergence protocol (PDCP) layers. The DU is responsible for processing physical layer protocols and real-time services, implementing the functions of the radio link control (RLC) layer, media access control (MAC) layer, and physical (PHY) layer. The AAU implements some physical layer processing functions, radio frequency processing, and related functions of the active antenna. The information of the RRC layer is generated by the CU and will ultimately be encapsulated into PHY layer information by the PHY layer of the DU, or vice versa. Therefore, in this architecture, high-layer signaling such as RRC layer signaling can also be considered to be sent by the DU, or by the DU + AAU. It can be understood that the access network device 120 may be a device including one or more of the CU node, DU node, and AAU node. In addition, the CU may be classified as an access network device 120 in the access network, or the CU may be classified as an access network device 120 in the core network (CN). This application does not make any limitations in this regard.
[0221] The access network device 120 can manage radio resources, provide access services for user equipment, and forward user equipment data between the user equipment (such as the first tag 130) and the core network (such as the first network element 110). The first tag 130 and the access network device 120 can communicate through the Uu interface. The Uu interface is a device-to-network interface that utilizes the core network and base station equipment of the communication system, enables communication between the device and the network, and transmits and manages data through the network.
[0222] For example, the first network element 110 can communicate with the first tag 130 through the access network device 120, receive data from the first tag 130, or send data to the first tag 130. The core network device (such as the first network element 110) and the access network device 120 can communicate through the next generation (NG) interface.
[0223] The first tag 130 may be a user equipment or a terminal device, or an access terminal, a subscriber unit, a subscriber station, a mobile station (MS), a remote station, a remote terminal, a mobile terminal (MT), a user terminal, a wireless communication device, a user agent, a user device, a target terminal, etc., without limitation herein.
[0224] In some embodiments, the first tag 130 may be a passive IoT terminal or a passive tag, or a passive device, or a terminal for passive communication. For example, the first tag 130 may include, but is not limited to, power-free terminal tags such as radio frequency identification (RFID), Bluetooth, Zigbee, etc. Such passive tags can collect energy through backscatter technology to send and receive messages.
[0225] In some other embodiments, the first tag 130 may be a semi-passive device, or an active device, or a terminal for active communication or non-passive communication. Among them, a semi-passive device refers to a device with a battery or a power supply device, which can be activated by the battery or the power supply, but the device itself does not send signals. They will only be activated and reply with data when receiving signals from the reader. An active device may be a device with wireless transceiver functions, such as a mobile phone, a pad, a computer with wireless transceiver functions, a virtual reality (VR) terminal, an augmented reality (AR) terminal, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, a cellular phone, a cordless phone, a session initiation protocol (SIP) phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), a handheld device with wireless communication functions, a computing device or other processing devices connected to a wireless modem, a vehicle-mounted device, a wearable device, a terminal in a 5G mobile communication system or a terminal in a future evolved network, etc.
[0226] This application does not limit the specific product form of the first tag 130.
[0227] The AF network element 140 can represent the application functions of a third party or an operator. It is an interface for the communication system to obtain external application data and can be used to transfer the requirements of the application side to the network side.
[0228] For example, in the embodiments of this application, the application side can initiate a process for performing an operation on the first tag 130. The AF network element can send a first operation request and operation authorization information to the first network element 110. The first operation request is used to indicate performing a first operation on the first tag 130, and the operation authorization information is used to indicate the operation permission of the application function network element. When the first network element 110 determines that the first operation is within the scope of the operation permission indicated by the operation authorization information, it can perform the first operation on the first tag 130. For example, the first network element 110 can communicate with the first tag 130 through the access network device 120 to perform the first operation on the first tag 130.
[0229] Exemplarily, Figure 1 The shown communication system may further include a user plane function (UPF) network element, a data network (DN), a terminal, and a policy control function (PCF) network element, etc.
[0230] In the embodiments of this application, Figure 1 The shown communication system may be a WCDMA system, an LTE system, an advanced long-term evolution LTE-A (LTE advanced) system, an LTE frequency division duplex (FDD) system, a universal mobile telecommunication system (UMTS), a 5G NR system, and other wireless communication systems applying OFDM technology, etc. Or, it may also be a future sixth-generation mobile information technology (6G) network communication system. This application does not limit the specific type of this communication system.
[0231] It can be understood that in the above communication system, when the first network element 110 is a TMF network element that independently implements the label management function, the communication system may further include other network elements such as an AMF network element, a NEF network element, a UDM network element, a UDR network element, and an NRF network element. When the first network element 110 is another network element with the label management function, the communication system may further include network elements that do not have the label management function among the foregoing other network elements. For example, when the first network element 110 is an AMF network element with the label management function, the communication system may further include other network elements such as a UDM network element, a UDR network element, an NRF network element, and a NEF network element.
[0232] In addition, the foregoing communication system is merely for more clearly illustrating the technical solutions of the embodiments of the present application and does not constitute a limitation on the technical solutions provided by the embodiments of the present application. For example, the communication system may further include other devices, such as a network control device. The network control device may be an operation administration and maintenance (OAM) system, also referred to as a network management system.
[0233] Exemplarily, Figure 2 shows a schematic diagram of the composition of a network device provided by an embodiment of the present application. The network device may be a network device carrying the foregoing first network element 110, or an access network device 120, or a network device carrying an AF network element 140, etc. As Figure 2 shown, the network device may include: at least one processor 21, a memory 22, a communication interface 23, and a bus 24.
[0234] The processor 21 is the control center of the network device and may be a single processor or a collective term for multiple processing elements. For example, the processor 21 may be a central processing unit (CPU), or an application specific integrated circuit (ASIC), or may also be one or more integrated circuits configured to implement the embodiments of the present application, such as: one or more digital signal processors (DSPs), or one or more field programmable gate arrays (FPGAs), etc.
[0235] Among them, the processor 21 can execute various functions of the network device by running or executing software programs stored in the memory 22 and calling data stored in the memory 22. For example, it can execute the steps performed by the first network element 110 in the communication method provided in the embodiments of the present application, or the steps performed by the AF network element 140, or the steps performed by the second network element in the following embodiments.
[0236] In a specific implementation, as an embodiment, the processor 21 may include one or more CPUs. For example, Figure 2 the CPU0 and CPU1 shown in
[0237] In a specific implementation, as an embodiment, the network device may include multiple processors. For example, Figure 2 the processor 21 and the processor 25 shown in
[0238] Each of these processors can be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). Here, the processor can refer to one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions).
[0239] The memory 22 can store software programs of the method steps executed by the network device and be controlled by the processor 21 for execution. The memory 22 can be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic storage media or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto.
[0239] The memory 22 can exist independently and be connected to the processor 21 through the bus 24. Alternatively, the memory 22 can also be integrated with the processor 21, which is not limited herein.
[0240] The communication interface 23 uses any device such as a transceiver for communicating with other devices or communication networks. The communication interface 23 can be an Ethernet interface, a radio access network (RAN) interface, a wireless local area networks (WLAN) interface, etc. The communication interface 23 can include a receiving unit to implement the receiving function and a transmitting unit to implement the transmitting function.
[0241] The bus 24 can be an industry standard architecture (ISA) bus, a peripheral component interconnect (PCI) bus, an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 2 only a thick line is used in the figure, but it does not mean that there is only one bus or one type of bus.
[0242] Although the bus 24 is used in the figure, it can be understood that the bus can also be replaced by other forms of connection relationships, not limited to the bus itself. Figure 2 In the embodiments of the present application, the network device carrying other network elements (such as the second network element) and the composition of the first tag 130 can also be referred to
[0243] as shown in the figure. Or, the network device carrying other network elements (such as the second network element), and / or the first tag 130 may further include more or fewer components than Figure 2 shown in the figure, which is not limited herein. Figure 2
[0244] The communication method provided in the embodiments of the present application will be described below by way of example. The processing described below as being performed by a single execution entity can also be divided into being performed by multiple execution entities, and these execution entities can be logically and / or physically separated. It should also be understood that with the evolution of the network architecture and the emergence of new service scenarios, the technical solutions provided in the embodiments of the present application are equally applicable to similar technical problems.
[0245] It should be noted that in the description of the embodiments of the present application, words such as "first" and "second" are only used for distinguishing descriptions and are not used for specifically limiting a certain feature. That is, the first or the second may include more content, rather than being limited to a specific concept. "And / or" describes the association relationship of associated objects and indicates that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally represents an "or" relationship between the associated objects before and after. At least one means one or more; multiple means two or more. The embodiments of the present application may only execute fewer steps than all the steps, or execute more steps, without limitation. "At least one of the following" or its similar expressions are used to represent any combination of the items listed; for example, at least one of A, B, and (or) C can represent the following situations: A exists alone, B exists alone, C exists alone, A and B exist simultaneously, B and C exist simultaneously, A and C exist simultaneously, and A, B, and C exist simultaneously, where A, B, and C can be single or multiple.
[0246] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which this application belongs. The terms used in the description of this application are only for the purpose of describing specific embodiments and are not intended to limit the present invention application.
[0247] Figure 3 The flowchart of the communication method provided by the embodiments of the present application is shown. As Figure 3 shown, the communication method may include S301 - S303.
[0248] Exemplarily, Figure 3 In the shown process, the steps executed by the first network element may be specifically executed by the network device carrying the first network element, or by a device (such as a chip) built into the network device carrying the first network element. The network device carrying the first network element may be the first network device. As described in the foregoing embodiments, in Figure 3 the shown process, the first network element may be a TMF network element, or an AMF network element with label management functions, or a NEF network element, or a UDM network element, or a UDR network element, or other network elements such as an NRF network element. The steps executed by the AF network element may be specifically executed by the network device carrying the AF network element, or by a device (such as a chip) built into the network device carrying the AF network element. The network device carrying the AF network element may be the second network device.
[0249] S301. The AF network element sends a first operation request and operation authorization information to the first network element.
[0250] Among them, the first operation request is used to indicate to perform a first operation on a first tag, and the operation authorization information is used to indicate the operation permission of the application function network element.
[0251] Correspondingly, the first network element receives the first operation request and the operation authorization information from the AF network element.
[0252] Exemplarily, as described in the foregoing embodiments, the first tag may be a passive tag, or a semi-passive tag or an active tag, which will not be elaborated here.
[0253] When the application side needs to perform a first operation on the first tag, the AF network element may send a first operation request to the first network element. The first operation request is used to indicate to perform a first operation on the first tag. For example, the AF network element may send a message capable of indicating to perform a first operation on the first tag to the first network element, such as a first operation request message. Among them, the first operation may be to take inventory of the first tag, or read data from the first tag, or write data to the first tag, or inactivate the first tag, or lock the first tag, etc. Among them, inactivating a tag generally means stopping or disabling its signal transmission, and inactivation can also be called destruction. Figure 3 In the shown process, the first operation may be any of the foregoing operations, and the specific type of the first operation is not limited here.
[0254] In addition, the AF network element may also send operation authorization information to the first network element. The operation authorization information may be used to indicate the operation permission of the AF network element. For example, the operation authorization information may specify whether the AF network element has the permission to take inventory of the first tag, the permission to read data from the first tag, the permission to write data to the first tag, the permission to inactivate the first tag, the permission to lock the first tag, etc.
[0255] Exemplarily, the operation authorization information may be a statement file, or a part of the terms or content in the statement file, or other forms of text and other information. The implementation manner of the operation authorization information is not limited here.
[0256] Optionally, the operation authorization information and the first operation request may be carried in the same message, or may be carried in different messages, which is not limited here. The AF network element and the first network element may communicate directly through an interface, or may communicate indirectly through other network elements.
[0257] After receiving the first operation request and the operation authorization information, the first network element may respond to the first operation request and execute S302.
[0258] S302. The first network element determines that the first operation is within the scope of the operation permission indicated by the operation authorization information, and performs the first operation on the first tag.
[0259] Exemplarily, the first network element may determine whether to perform the first operation based on whether the first operation is within the scope of operation authority indicated by the operation authorization information. For example, when the first operation is within the scope of operation authority indicated by the operation authorization information, the first network element may perform the first operation on the first tag. Alternatively, when the first operation is not within the scope of operation authority indicated by the operation authorization information, the first network element may not perform the first operation.
[0260] In other words, the first network element may verify whether the first operation is legal according to the operation authorization information and perform the first operation when the first operation is legal. That is, when the first operation is within the scope of operation authority indicated by the operation authorization information, the first operation is a legal operation; when the first operation is not within the scope of operation authority indicated by the operation authorization information, the first operation is an illegal operation or an unlawful operation.
[0261] For example, assume that the operation authorization information indicates that the AF network element only has the authority to take inventory of the first tag and the authority to read data from the first tag. Or, it indicates that the AF network element does not have the authority to write data to the first tag and the authority to inactivate the first tag. When the first operation is to write data to the first tag or inactivate the first tag, the first operation is an illegal operation, and the first network element may not perform the first operation. Or, when the first operation is to take inventory of the first tag or read data from the first tag, the first operation is a legal operation, and the first network element may perform the first operation.
[0262] Exemplarily, the process for the first network element to perform the first operation on the first tag may be implemented by a card reader. The card reader may be a relay or a mobile phone, or a dedicated card reader device, or other terminal devices capable of implementing the card reader function, which is not limited herein. The first network element may communicate with the card reader to implement the first operation on the first tag. For example, the first network element may send indication information to the card reader through a base station, and the indication information is used to instruct the first tag to perform the first operation. The card reader may send (transparent transmission or forwarding) the indication information to the first tag. After receiving the indication information, the first tag may perform the first operation in response to the indication information. For example, the first tag may perform the first operation and return the execution result of the first operation, such as returning the execution result of the first operation to the first network element through the card reader and the base station.
[0263] For example, taking the first operation as reading data from the first tag as an example, after receiving the indication information, the first tag may read the tag data and return the tag data to the card reader, and the card reader may forward the tag data to the first network element through the base station. The tag data is the execution result of the first operation.
[0264] In some implementation manners, the card reader, or the capabilities of the card reader, can also be implemented in an access network device (such as a base station). For example, by integrating the new air interface radio technology of the card reader with the resources of the radio access network, the capabilities of the card reader can be implemented. The passive tag is excited through the air interface radio technology, and the card reader function is implemented on the base station, so as to increase the communication distance between the passive terminal and the card reader and combine the unified management of the operator's base station. For example, the first network element can send indication information to the base station, and the indication information is used to instruct the first tag to perform a first operation. The base station can send (transparent transmission or forwarding) the indication information to the first tag, and the first tag can, in response to the indication information, perform the first operation and return the execution result of the first operation.
[0265] Optionally, the above-mentioned indication information can also be referred to as operation information, or other names. Its function is to instruct the first tag to perform the first operation, and the present application does not limit the name of this information.
[0266] Taking the implementation of the card reader function in the base station as an example, Figure 4 FIG. shows a schematic flowchart of performing a first operation. The process of the first network element performing the first operation on the first tag can be referred to Figure 4 as shown. It should be understood that when the card reader function is not implemented in the base station, the base station can interact with the first tag through a separate card reader, and its process is similar to Figure 4 that shown. As Figure 4 shown, the process of the first network element performing the first operation on the first tag may include S401-S404.
[0267] S401. The first network element sends indication information to the base station, and the indication information is used to instruct the first tag to perform the first operation.
[0268] Exemplarily, the indication information may be a request message for instructing the first tag to perform the first operation, or a field in the request message. The implementation manner of the indication information is not limited herein. The first operation can be specifically referred to the foregoing embodiments and will not be elaborated herein.
[0269] Correspondingly, the base station receives the indication information.
[0270] S402. The base station sends the indication information to the first tag.
[0271] Correspondingly, the first tag receives the indication information.
[0272] It should be understood that S401-S402 implement the first network element sending the indication information to the first tag through the base station. In this process, the base station can transparently transmit (or forward) the indication information to the first tag. For the first tag, the received indication information is used to instruct the first tag to perform the first operation.
[0273] S403. The first tag sends the execution result of the first operation to the base station in response to the indication information.
[0274] Correspondingly, the base station receives the execution result of the first operation.
[0275] S404. The base station sends the execution result of the first operation to the first network element.
[0276] Correspondingly, the first network element receives the execution result of the first operation.
[0277] Exemplarily, after receiving the indication information, the first tag can execute the first operation and return the execution result of the first operation to the first network element through the base station. The base station can transparently transmit (or forward) the execution result of the first operation to the first network element.
[0278] Exemplarily, when the first operation is to read data from the first tag, the execution result of the first operation can be the tag data returned by the first tag. Or, when the first operation is to write data to the first tag, the execution result of the first operation can be a message indicating successful data writing or a message received for writing data. Or, when the first operation is to inactivate the first tag, the execution result of the first operation can be a message indicating successful or failed tag inactivation. Or, when the first operation is to inventory the first tag, the execution result of the first operation can be the identification information or tag information of the first tag, etc.
[0279] Optionally, in the above Figure 4 shown process, when the first tag is a passive tag, the first network element can first initiate a random access process through the base station, determine the identity of the first tag in the random access manner, and then execute the processes described in S401 - S404 above. For example, the first network element can instruct the base station or the reader to send an excitation signal to all the first tags to which the first operation is to be performed, so that the first tags are powered on and perform random access. The first tags that succeed in random access will be selected, and the first operation will be performed on the first tags according to the above process. Exemplarily, Figure 5 shows a schematic diagram of an implementation process of random access. As Figure 5 shown, the process of determining the identity of the first tag in the random access manner can include S501 - S507.
[0280] S501. The first network element sends an access request message to the base station. The access request message can be used to indicate random access to the first tags within a preset range.
[0281] Among them, the preset range refers to the tag range for which the first network element is to perform the first operation. The first tags within the preset range refer to all the tags within this preset range.
[0282] Correspondingly, the base station receives the access request message.
[0283] S502. The base station selects the first tag to be inventoried through a Select command. For example, the base station sends a Select command to the first tag within a preset range.
[0284] Correspondingly, the first tag receives the Select command.
[0285] Among them, the first tag to be inventoried can be the first tag within a preset range.
[0286] S503. The base station starts an inventory cycle through a Query command. For example, the base station sends a Query command to the first tag within a preset range.
[0287] Exemplarily, an inventory cycle can inventory all the first tags selected by the Select command. The first command of the inventory cycle is Query, and the subsequent commands can be QueryRep or QueryAdjust. The Query-related commands will carry a Q value. The tag that receives the corresponding Q value can select a random value from the range (0, 2^Q – 1) and place it into the time slot counter. 2^Q represents 2 to the power of Q. When the random value is 0, the tag can respond with a random number RN16, and the base station with the function of a reader uses this RN16 to confirm the response to the tag. The confirmed tag can carry its own tag ID EPC information and reply. Through QueryAdjust and QueryRep, the Q value can be changed and decreased. It can be understood that the Q value is set according to the number of tags to be inventoried and the maximum number of tags that can be inventoried within the inventory cycle by this reader. When multiple tags reply with RN at the same time, a collision problem will occur, and the collision can be reduced through the Q value setting. That is, the inventory command can carry the Q value for the tag to randomly generate a random number. The tag can determine whether to respond to Query / QueryRep / QueryAdjust according to the random value.
[0288] For example, for the first tag to respond to the Query command and the base station to perform response confirmation, the process of the first tag completing random access can refer to S504 - S507. It should be understood that the following S504 - S507 describe the process of each first tag responding to the Query command to complete random access. Or rather, S501 - S503 can be understood as the base station interacting with all the first tags within a preset range, and S504 - S507 can be understood as the base station interacting with a certain first tag that performs random access.
[0289] S504. The first tag responds to the Query command and sends a Q-bit random number RN to the base station.
[0290] For example, Q can be 16. When the first tag gets a random value of 0 with a probability of 1 / (2^Q – 1), it can reply with a random number RN.
[0291] Accordingly, the base station receives a random number RN.
[0292] S505. The base station sends an acknowledgment response message to the first tag, and the acknowledgment response message includes or carries the random number RN.
[0293] Accordingly, the first tag receives the acknowledgment response message.
[0294] The first tag can match the RN in the acknowledgment response message with the previously sent RN. If they are the same, the random access process is successful, a connection is successfully established between the first tag and the base station (reader), and the first tag can execute S506.
[0295] S506. The first tag sends a registration request message to the base station, and the registration request message includes the electronic product code (EPC) of the first tag, such as the tag ID.
[0296] Accordingly, the base station receives the registration request message.
[0297] In other words, the first tag that has successfully performed random access can send its EPC to the base station.
[0298] S507. The base station sends a registration request message to the first network element.
[0299] Accordingly, the first network element receives the registration request message.
[0300] After receiving the registration request message from the first tag, the first network element can execute the first operation on the first tag according to the Figure 4 process shown for the first tag.
[0301] It can be understood that when the first network element can first initiate a random access process through the base station, determine the identity of the first tag in the random access manner, and then execute the process of the first network element performing the first operation on the first tag as described in S401 - S404 above, the process of the first network element performing the first operation on the first tag is generally for one first tag. After performing the first operation on one first tag, it can continue to perform the first operation on the next first tag.
[0302] In some other embodiments of the present application, the first network element can also batch - execute the first operation on multiple (such as at least two) first tags. The batch - executed first operation can be an inactivation operation, an inventory operation, a locking operation, etc., which are not limited herein.
[0303] Taking the batch - executed first operation as an inactivation operation as an example, the first network element can, through the base station, in the above - mentioned Figure 5In the random access process shown, indication information is sent to multiple first tags in batches to instruct the first tags to perform inactivation operations. For example, the indication information can be implemented through reserved fields in the Select command. In S502, the Select command can be used to instruct multiple first tags selected by the Select command to perform inactivation operations. Alternatively, the indication information can be implemented through reserved fields in the Query command. In S503, the Query command can be used to instruct multiple first tags selected by the Select command to perform inactivation operations. Or, independent messages can also be used in S502 or S503 to send indication information to the first tags to instruct the first tags to perform inactivation operations.
[0304] That is, in the embodiments of the present application, when the first network element performs a first operation on the first tag, it can be in a serial manner. After performing the first operation on one first tag, it continues to perform the first operation on the next first tag. It can also be in a parallel manner to perform the first operation on multiple first tags in batches. The present application does not limit the specific implementation manner of the operations performed in batches.
[0305] Optionally, before the first network element performs the first operation on the first tag, it can also perform security authentication on the first tag. For example, the first network element can perform security authentication such as encryption negotiation, identity authentication, security parameter negotiation, secure connection establishment, and secure data exchange with the first tag to improve communication security.
[0306] Optionally, after the first network element performs the first operation on the first tag and obtains the execution result of the first operation, it can execute S303.
[0307] S303. The first network element sends a first operation response message to the AF network element.
[0308] Among them, the first operation response message is used to indicate the execution result of the first operation. The execution result of the first operation can be referred to as described above. For example, when the first operation is to read data from the first tag, the execution result of the first operation can be the tag data returned by the first tag, and the first operation response message can include the tag data, which will not be elaborated here.
[0309] Correspondingly, the AF network element receives the first operation response message from the first network element.
[0310] Optionally, when the first network element determines that the first operation is not within the operation authority range indicated by the operation authorization information, it can either not send the first operation response message to the AF network element, or it can also send the first operation response message, but the execution result of the first operation indicated by the first operation response message is empty or information related to indicating operation failure.
[0311] As described above, in the communication method provided by the embodiments of the present application, the first network element may, according to the operation permission range indicated by the operation authorization information of the AF network element, when determining that the AF network element has the permission to perform the first operation on the first label, in response to the first operation request of the AF network element, perform the first operation on the first label. By controlling the permission of the first operation of the AF network element according to the operation permission range indicated by the operation authorization information of the AF network element, an authorization access mechanism can be implemented for the process of the AF network element operating on the label, improving the security of the AF network element accessing the label. For example, this method can reduce the access or operation of the label by illegal or unqualified AF network elements, or can reduce the possibility of the operation of the AF network element on the label being tampered with.
[0312] Optionally, in the embodiments of the present application, the operation authorization information of the AF network element may be sent by the target network element to the AF network element, that is, the target network element is the network element that sends the operation authorization information to the AF network element. Or rather, before the AF network element sends the operation authorization information to the first network element, it may obtain the operation authorization information from the target network element. Among them, the target network element may be a NEF network element, an NRF network element, etc. For example, in this communication method, the AF network element may send a first message to the target network element and receive the operation authorization information from the target network element, and the first message is used to indicate a request to obtain the operation authorization information.
[0313] In some implementation manners, the target network element may be the above-mentioned first network element. For example, the target network element is an NRF network element or a NEF network element with a label management function. In this implementation manner, the first network element may pre-send the operation authorization information to the AF network element. Exemplarily, Figure 6 shows another schematic flowchart of the communication method provided by the embodiments of the present application. As Figure 6 shown, in this implementation manner, this communication method may include S601 - S605.
[0314] S601. The AF network element sends a first message to the first network element, and the first message is used to indicate a request to obtain the operation authorization information.
[0315] Correspondingly, the first network element receives the first message.
[0316] Exemplarily, the first message may be a token acquisition request message, or an authorization acquisition request message.
[0317] S602. In response to the first message, the first network element sends the operation authorization information to the AF network element.
[0318] Correspondingly, the AF network element receives the operation authorization information.
[0319] Optionally, after the AF network element obtains permission, the first network element may send operation authorization information to the AF network element. For example, the first network element may authenticate the AF network element. For instance, based on the geographical location information and IP information of the AF network element, and / or its subscription information, it determines whether the AF network element has access attacks or is legal. When the AF network element is a network element with secure access or a legal network element, it indicates that the authentication is passed and the first network element's authorization permission can be obtained.
[0320] S603. The AF network element sends a first operation request and operation authorization information to the first network element.
[0321] S604. The first network element determines that the first operation is within the scope of operation permissions indicated by the operation authorization information, and performs the first operation on the first label.
[0322] S605. The first network element sends a first operation response message to the AF network element.
[0323] S603 - S605 can be referred to the above S301 - S303, and will not be elaborated here.
[0324] Optionally, the AF network element may also not send a first message to the first network element to request operation authorization. The first network element may actively send operation authorization information to the AF network element, and there is no restriction here.
[0325] In some other implementation manners, the target network element may also be a second network element that does not have a label management function. For example, the first network element is a TMF network element, or an AMF network element with a label management function, and the second network element is a NEF network element, or an NRF network element, etc. Exemplarily, Figure 1 The communication system shown may further include a second network element. The second network element communicates with the first network element and the AF network element, and new drawings are not used here to represent it. In this implementation manner, the second network element may pre - send operation authorization information to the AF network element. Exemplarily, taking the first network element as a TMF network element and the second network element as an NRF network element as an example, Figure 7 shows another flowchart of the communication method provided by the embodiment of the present application. As Figure 7 shown, in this implementation manner, the communication method may include S701 - S705.
[0326] S701. The AF network element sends a first message to the NRF network element. The first message is used to indicate a request to obtain operation authorization information.
[0327] Correspondingly, the NRF network element receives the first message.
[0328] Exemplarily, the first message may be a token acquisition request message, or an authorization acquisition request message.
[0329] The NRF network element sends operation authorization information to the AF network element in response to the first message.
[0330] Correspondingly, the AF network element receives the operation authorization information.
[0331] Optionally, the NRF network element may send operation authorization information to the AF network element after the AF network element obtains permission. For example, the NRF network element may authenticate the AF network element. For instance, based on the geographical location information and IP information of the AF network element, and / or its subscription information, it determines whether the AF network element has access attacks or is legal. When the AF network element is a network element with secure access or a legal network element, it indicates that the authentication is passed and the AF network element can obtain the authorization permission of the NRF network element.
[0332] S703. The AF network element sends a first operation request and operation authorization information to the TMF network element.
[0333] S704. The TMF network element determines that the first operation is within the scope of operation authority indicated by the operation authorization information, and performs the first operation on the first label.
[0334] S705. The TMF network element sends a first operation response message to the AF network element.
[0335] S703 - S705 can be referred to the above S301 - S303 and will not be elaborated here.
[0336] Optionally, the AF network element may also not send the first message to the second network element to request operation authorization. The second network element may actively send operation authorization information to the AF network element, and there is no restriction here.
[0337] In a possible design, the operation authorization information described in the above embodiments carries first signature information, and the first signature information is used to indicate the signature of the above target network element.
[0338] In this design, after receiving the first operation request and operation authorization information, the first network element may first verify whether the first signature information carried in the operation authorization information matches the second signature information, and the second signature information is also used to indicate the signature of the target network element. When the first signature information matches the second signature information, the first network element may determine whether the first operation is within the scope of operation authority indicated by the operation authorization information, and when it is determined that the first operation is within the scope of operation authority indicated by the operation authorization information, perform the first operation on the first label. When the first signature information does not match the second signature information, the first network element may consider the operation authorization information illegal and no longer perform subsequent operations. For example, regardless of whether the first operation is within the scope of operation authority indicated by the operation authorization information, it no longer performs the first operation on the first label.
[0339] In other words, in this design, before the first network element performs a first operation on the first tag when it determines that the first operation is within the scope of the operation authority indicated by the operation authorization information, the method may further include: the first network element determines that the first signature information and the second signature information match.
[0340] For the implementation manner where the target network element is the first network element, the first network element may locally store its own signature, and the second signature information may be used to indicate the signature locally stored by the first network element.
[0341] For the implementation manner where the target network element is a second network element without a tag management function, the first network element may communicate with the second network element to obtain the second signature information, and the second signature information may be used to indicate the signature of the second network element. Optionally, after the first network element obtains the second signature information, it may also be stored locally.
[0342] Exemplarily, the signature of the target network element may be a signature field or text, or other signature data. Verifying whether the first signature information carried in the operation authorization information matches the second signature information may include: verifying whether the signatures of the target network element indicated by the first signature information and the second signature information are the same or identical, or verifying whether the hash values of the signatures of the target network element indicated by the first signature information and the second signature information are the same or identical. If they are the same or identical, it means that the first signature information and the second signature information match.
[0343] Alternatively, the signature of the target network element may also include the private key and public key of the target network element. The signature of the target network element indicated by the first signature information may be the private key, which is used to encrypt the operation authorization information. The signature of the target network element indicated by the second signature information may be the public key, which is used to decrypt the operation authorization information. Verifying whether the first signature information carried in the operation authorization information matches the second signature information may include: verifying whether the public key indicated by the second signature information can decrypt the private key indicated by the first signature information. If it can be decrypted, it means that the first signature information and the second signature information match.
[0344] This application does not limit the implementation manner of the signature of the target network element, nor the manner of verifying whether the first signature information carried in the operation authorization information matches the second signature information.
[0345] This design can reduce the possibility of the operation authorization information being tampered with or forged during transmission, and further improve the security of the AF network element accessing the tag.
[0346] It can be understood that for the implementation method of the second network element that does not have the label management function among the above target network elements, the first network element can obtain the second signature information before determining that the first signature information and the second signature information match. For example, before the step of determining that the first signature information and the second signature information match, the method further includes: the first network element receives the second signature information from the target network element (the second network element).
[0347] Exemplarily, taking the first network element as a TMF network element and the second network element as an NRF network element as an example, after the TMF network element successfully registers to the NRF network element, the NRF network element can share the signature with the TMF network element, and the TMF network element can receive the second signature information of the NRF network element. For example, Figure 8 shows another schematic flowchart of the communication method provided by the embodiment of the present application. As Figure 8 shown, the communication method may include S801 - S807.
[0348] S801. The TMF network element successfully registers to the NRF network element, and the NRF network element shares the signature with the TMF network element. For example, the NRF network element sends the second signature information to the TMF network element.
[0349] Correspondingly, the TMF network element receives the second signature information.
[0350] Exemplarily, the TMF network element can also send its own signature information to the NRF network element. The second signature information can be referred to as above and will not be elaborated here.
[0351] S802. The AF network element sends a first message to the NRF network element, and the first message is used to indicate a request for obtaining operation authorization information.
[0352] Correspondingly, the NRF network element receives the first message.
[0353] Exemplarily, the first message can be a token acquisition request message, or an authorization acquisition request message.
[0354] S803. In response to the first message, the NRF network element sends operation authorization information to the AF network element, and the operation authorization information carries the first signature information.
[0355] Correspondingly, the AF network element receives the operation authorization information.
[0356] S804. The AF network element sends a first operation request and operation authorization information to the TMF network element, and the operation authorization information carries the first signature information.
[0357] Correspondingly, the TMF network element receives the first operation request and operation authorization information.
[0358] S805. The TMF network element determines that the first signature information and the second signature information match.
[0359] S805 can refer to the matching method of the first signature information and the second signature information described above, which will not be elaborated here.
[0360] S806. The TMF network element determines that the first operation is within the scope of the operation authority indicated by the operation authorization information, and performs the first operation on the first label.
[0361] S807. The TMF network element sends a first operation response message to the AF network element.
[0362] Correspondingly, the AF network element receives the first operation response message.
[0363] S802 - S804, and S806 - S807 can refer to what is described in S701 - S705, which will not be elaborated here. The difference is that in S804, the operation authorization information carries the first signature information.
[0364] In a possible design, the above operation authorization information is further used to indicate at least one of the following information corresponding to the operation authority of the AF network element: area range, label range, permission period.
[0365] Among them, the area range is used to indicate for which specific area or areas the operation authority of the AF network element is for the labels within. For example, the area range may include area A, area B, area C, etc., and the area can be understood as the actual geographical area.
[0366] The label range is used to indicate for which specific label or labels within the label range the operation authority of the AF network element is for. For example, the label range may be the labels within the corresponding range of service 1, the labels within the corresponding range of service 2, or alternatively, the label range may be the labels within the corresponding range of a certain or certain service types, etc. The label range can be understood as a set of a class of labels classified according to services or functions, or other methods, and the classification method is not limited here.
[0367] The permission period can be understood as the validity period of the operation authority (operation authorization information) of the AF network element, and can be used to indicate within what time range the operation authority of the AF network element is valid, or at which time point it will be invalid or expire. When the time exceeds the permission period, it means that the operation authorization information is invalid, and the operation authority of the AF network element indicated by the operation authorization information is untrustworthy or incorrect.
[0368] Exemplarily, taking the area range corresponding to the operation authority of the AF network element indicated by the above operation authorization information as area A as an example, after receiving the operation authorization information, the first network element can, according to the indication of the operation authorization information, only perform the steps described in the foregoing embodiments on the first label within area A.
[0369] Alternatively, taking the example where the operation authorization information indicates that the area scope corresponding to the operation permission of the AF network element is Area A and the label scope is the scope corresponding to Service 1, after receiving the operation authorization information, the first network element can, according to the indication of the operation authorization information, perform the steps described in the foregoing embodiments only for the first label that belongs to Area A and within the scope corresponding to Service 1.
[0370] Or, taking the example where the operation authorization information indicates that the area scope corresponding to the operation permission of the AF network element is Area A, the label scope is the scope corresponding to Service 1, and the permission period is from May 1st to December 1st of the current year, the first network element can perform the steps described in the foregoing embodiments only for the first label that belongs to Area A and within the scope corresponding to Service 1 after receiving the operation authorization information during the period from May 1st to December 1st of the current year according to the indication of the operation authorization information.
[0371] In this design, at least one of the information such as the area scope, label scope, and permission period can be combined, and the operation permission of the AF network element can be controlled with a finer granularity through the operation authorization information, which can improve the flexibility of the authorization access mechanism of the AF network element.
[0372] Optionally, the above operation authorization information is further used to indicate the identification information of the AF network element, such as it may include the ID of the AF network element. Combining the identification information of the AF network element can distinguish the operation authorization information of different AF network elements.
[0373] In a possible design, the first message sent by the AF network element to the target network element can also be used to indicate the target scope. The target scope is used to indicate that the AF network element expects to obtain the operation permission for the labels within the target scope. The operation authorization information received by the AF network element can be used to indicate or include the operation permission of the AF network element for the labels within the target scope.
[0374] Optionally, the above target scope may include an area scope and / or a label scope.
[0375] For example, when the AF network element expects to obtain the operation permission for the labels within the scope corresponding to Service 1 in Area A, the target scope is the scope corresponding to Service 1 in Area A. The first message can also be used to indicate the scope corresponding to Service 1 in Area A. The operation authorization information received by the AF network element can be used to indicate or include the operation permission of the AF network element for the labels within the scope corresponding to Service 1 in Area A.
[0376] Exemplarily, in this design, before the AF network element sends the first message to the target network element, it may know that the network element managing the labels within the target scope is the above first network element, or it may not know which network element manages the labels within the target scope.
[0377] When the AF network element knows that the network element managing the labels within the target range is the first network element as described above, the first message may be an authorization acquisition request message as described in the foregoing embodiments. The authorization acquisition request message may carry the identification information of the first network element (such as the TMF network element) as described above.
[0378] Alternatively, when the AF network element does not know which network element is managing the labels within the target range, the first message may be a service discovery message. The service discovery message may be used to indicate a request to obtain the operation authority of the AF network element for the labels within the target range. The target network element knows that the network element managing the labels within the target range is the first network element as described above. The target network element may send a response message to the service discovery message to the AF network element. Correspondingly, the AF network element receives the response message to the service discovery message. The response message to the service discovery message may include operation authorization information and carry the identification information of the first network element (such as the TMF network element) as described above. The operation authorization information is used to indicate the operation authority of the AF network element for the labels within the target range. The AF network element may send the first operation request and the operation authorization information as described in the foregoing embodiments to the first network element according to the identification information of the first network element (such as the TMF network element) carried in the response message to the service discovery message.
[0379] Or, when the AF network element does not know which network element is managing the labels within the target range, the AF network element may first send a service discovery message to the target network element. The service discovery message may be used to indicate a request to query which network element is managing the labels within the target range, or a request to obtain the identification information of the network element managing the labels within the target range. The target network element may send a response message to the service discovery message to the AF network element. The response message to the service discovery message may carry the identification information of the first network element (such as the TMF network element) as described above. After receiving the response message to the service discovery message, the AF network element may send a first message to the target network element. The first message may be an authorization acquisition request message. The authorization acquisition request message may carry the identification information of the first network element (such as the TMF network element) as described above. That is, when the AF network element does not know which network element is managing the labels within the target range, the first message may also be an authorization acquisition request message.
[0380] In this design, the AF network element may obtain the operation authorization information for the operation authority of the labels within the target range from the target network element through an authorization acquisition request message or a service discovery message, and there is no limitation here.
[0381] In a possible design, the AF network element may send the above first message to the target network element when it needs to perform a first operation on a first label to obtain operation authorization information. Then, send a first operation request and operation authorization information to the first network element.
[0382] In another possible design, the AF network element may also send the above first message to the target network element in advance, obtain the operation authorization information, and store it locally. When it is necessary to perform the first operation on the first tag, the operation authorization information can be directly obtained from the local storage to send the first operation request and the operation authorization information to the first network element.
[0383] This application does not limit the timing of the AF network element sending the first message to the target network element.
[0384] In a possible design, the operation authorization information sent by the target network element to the AF network element in the above embodiments can be used to indicate the operation permissions for the AF network element to perform the first operation and the second operation. Or rather, the operation permissions of the AF network element indicated by the operation authorization information may include the operation permissions for the AF network element to perform the first operation and the second operation. The operation authorization information sent by the AF network element to the first network element can be the operation authorization information received from the target network element.
[0385] For example, the operation authorization information sent by the target network element to the AF network element can be called the first operation authorization information, and the operation authorization information sent by the AF network element to the first network element can be called the second operation authorization information. The first operation authorization information and the second operation authorization information can be the same. After receiving the second operation authorization information, the first network element can determine whether to perform the first operation according to the operation permissions of the AF network element indicated in the second operation authorization information.
[0386] Exemplarily, taking the first operation authorization information as a statement document, the statement document may include the first information recording the operation permissions of the AF network element to perform the first operation and the second information recording the operation permissions of the AF network element to perform the second operation. The second operation authorization information sent by the AF network element to the first network element can be this statement document. After receiving this statement document, the first network element can determine whether to perform the first operation according to the first information in this statement document. It should be understood that the first information is used to indicate or record the operation permissions of the AF network element to perform the first operation.
[0387] In some implementation manners of this design, the first operation and the second operation can be understood as two different operations. For example, the first operation is a random access operation, and the second operation is an operation to inactivate the first tag. Another example is that the first operation is an operation to read data from the first tag, and the second operation is an operation to write data to the first tag, etc.
[0388] In some other implementation manners of this design, the first operation and the second operation can be understood as two different types of operations. For example, the first operation is the first type of operation, and the second operation is the second type of operation.
[0389] Exemplarily, the operations of the first type may be operations that inactivate the first tag, write data to the first tag, etc., which have a greater impact on or make greater changes to the first tag, or operations that have an impact. Such operations may also be referred to as special operations. The operations of the second type may be operations such as random access operations, reading data from the first tag, etc., which have little impact on or make little changes to the first tag. Such operations may also be referred to as ordinary operations. Alternatively, it may also be that the operations of the first type are ordinary operations and the operations of the second type are special operations, which is not restricted here.
[0390] Optionally, in this implementation, the operations of the first type and the operations of the second type may be predefined according to service requirements or manually configured. For example, it may be preconfigured or predefined in the first network element through a protocol which operations belong to the operations of the first type and which operations belong to the operations of the second type. For the AF network element and the first network element, the first operation request indicating the first operation to be performed on the first tag may generally refer to any operation of the first type, such as operation 1. Similarly, the second operation may generally refer to any operation of the second type, such as operation 2. After receiving the operation authorization information (such as the above-mentioned second operation authorization information) from the AF network element and the first operation request, the first network element may determine that operation 1 belongs to the operations of the first type according to the predefined or preconfigured operation types, and determine whether to perform operation 1 according to the operation permission of the AF network element to perform the first operation.
[0391] Alternatively, in this implementation, the operations of the first type and the operations of the second type may also not need to be preconfigured or defined in advance. For the AF network element and the first network element, the first operation request indicating the first operation to be performed on the first tag may generally refer to any operation of the first type, such as operation 1. Similarly, the second operation may generally refer to any operation of the second type, such as operation 2. After receiving the operation authorization information (such as the above-mentioned second operation authorization information) from the AF network element and the first operation request, the first network element may also dynamically determine that operation 1 is an operation of the first type according to the preset rules, and determine whether to perform operation 1 according to the operation permission of the AF network element to perform the first operation. Exemplarily, the preset rules may include: if the operation has an impact on the first tag or changes the tag data or status, then determine that the operation is an operation of the first type; if the operation has no impact on the first tag or does not change the tag data or status, then determine that the operation is an operation of the second type. The preset rules are not restricted here.
[0392] In this design, the operation authorization information (such as the first operation authorization information) received by the AF network element from the target network element, and the operation authorization information (such as the second operation authorization information) sent by the AF network element to the first network element both indicate the operation permissions for the AF network element to perform the first operation and the second operation. The first network element can determine whether to perform the first operation based on the operation permission of the AF network element to perform the first operation. In other words, in this design, when the AF network element obtains and sends operation authorization information to the first network element from the target network element, it does not need to consider the first operation to be performed on the first label. Instead, the first network element determines the part of the operation authorization information that indicates the operation permission for the AF network element to perform the first operation according to the first operation.
[0393] Optionally, in the design where both the above-mentioned first operation authorization information and the second operation authorization information indicate the operation permissions for the AF network element to perform the first operation and the second operation, the method may further include: The first network element receives a second operation request from the AF network element, and the second operation request is used to indicate to perform a second operation on the first label; The first network element determines that the second operation is within the scope of the operation permissions indicated by the operation authorization information (i.e., the second operation authorization information), and performs the second operation on the first label. The first network element sends a second operation response message to the AF network element, and the second operation response message is used to indicate the execution result of the second operation.
[0394] For example, based on the above Figure 8 shown process as an example, Figure 9 shows another schematic flowchart of the communication method provided by the embodiment of the present application. As Figure 9 shown, this communication method may include S901 - S911. Among them, the first network element is a TMF network element, and the second network element (target network element) is an NRF network element.
[0395] S901. The TMF network element successfully registers to the NRF network element, and the NRF network element shares a signature with the TMF network element, such as the NRF network element sending the second signature information to the TMF network element.
[0396] Correspondingly, the TMF network element receives the second signature information.
[0397] S902. The AF network element sends a first message to the NRF network element, and the first message is used to indicate a request to obtain the first operation authorization information.
[0398] Correspondingly, the NRF network element receives the first message.
[0399] S903. In response to the first message, the NRF network element sends the first operation authorization information to the AF network element. The first operation authorization information carries the first signature information and is used to indicate the operation permissions for the AF network element to perform the first operation and the second operation.
[0400] Accordingly, the AF network element receives the first operation authorization information.
[0401] That is, the operation authorization information sent by the NRF network element to the AF network element is called the first operation authorization information.
[0402] S904. The AF network element sends a first operation request and a second operation authorization information to the TMF network element. The second operation authorization information carries a first signature information and is used to indicate the operation permissions for the AF network element to perform the first operation and the second operation.
[0403] For example, the first operation authorization information and the second operation authorization information are the same.
[0404] That is, the operation authorization information sent by the AF network element to the TMF network element (the first network element) is called the second operation authorization information.
[0405] Accordingly, the TMF network element receives the first operation request and the second operation authorization information.
[0406] S905. The TMF network element determines that the first signature information and the second signature information match.
[0407] S906. The TMF network element determines that the first operation is within the operation permission range for the AF network element to perform the first operation indicated by the second operation authorization information, and performs the first operation on the first label.
[0408] For example, the first information in the second operation authorization information indicates the operation permission for the AF network element to perform the first operation.
[0409] S907. The TMF network element sends a first operation response message to the AF network element.
[0410] Accordingly, the AF network element receives the first operation response message.
[0411] S908. The AF network element sends a second operation request to the TMF network element. The second operation request is used to indicate to perform a second operation on the first label.
[0412] Accordingly, the TMF network element receives the second operation request.
[0413] S909. The TMF network element determines that the first signature information and the second signature information match.
[0414] Optionally, S909 may also not be executed or skipped. It should be understood that in both S909 and S905, it is determined that the first signature information carried by the second operation authorization information and the second signature information match.
[0415] S910. The TMF network element determines that the second operation is within the operation permission range for the AF network element to perform the second operation indicated by the second operation authorization information, and performs the second operation on the first label.
[0416] For example, the second information in the second operation authorization information indicates the operation permission for the AF network element to perform the second operation.
[0417] S911. The TMF network element sends a second operation response message to the AF network element.
[0418] Correspondingly, the AF network element receives the second operation response message.
[0419] Among them, for S901 - S907, reference can be made to S801 - S807 and will not be elaborated here. The processes described in S908 - S911 are similar to the processes described in S904 - S907, the difference being that there is no need to repeatedly send the second operation authorization information, and the second operation and the first operation are different operations, which will not be elaborated here. Of course, it should be understood that when the AF network element sends a second operation request to the TMF network element, the second operation authorization information can also be repeatedly sent. For example, S908 can include the AF network element sending a second operation request and the second operation authorization information, which is not limited here.
[0420] Exemplarily, in this embodiment, the first operation authorization information can be referred to as a token, and the token can include token1 and token2. The second operation authorization information can include token1 and token2.
[0421] In this embodiment, when the first network element receives the second operation request from the AF network element, it can determine whether to perform the second operation according to the operation authorization information (the second operation authorization information) that has been received when performing the first operation before.
[0422] In another possible design, the operation authorization information sent by the target network element to the AF network element in the above embodiments can be used to indicate the operation permissions for the AF network element to perform the first operation and the second operation. When it is necessary to perform the first operation on the first label, the operation authorization information sent by the AF network element to the first network element can be the part of the operation authorization information received from the target network element that is used to indicate the operation permission for the AF network element to perform the first operation.
[0423] For example, the operation authorization information sent by the target network element to the AF network element can be referred to as the first operation authorization information, and the operation authorization information sent by the AF network element to the first network element can be referred to as the second operation authorization information. The first operation authorization information is used to indicate the operation permissions for the AF network element to perform the first operation and the second operation. The second operation authorization information is a part of the first operation authorization information and is used to indicate the operation permission for the AF network element to perform the first operation. After receiving the second operation authorization information, the first network element can determine whether to perform the first operation according to the operation permission for the AF network element to perform the first operation indicated by the second operation authorization information.
[0424] Exemplarily, taking the first operation authorization information as a statement document as an example, the statement document may include first information recording the operation authority for the AF network element to perform the first operation, and second information recording the operation authority for the AF network element to perform the second operation. The second operation authorization information sent by the AF network element to the first network element may be the first information in the statement document. After receiving the first information, the first network element may determine whether to perform the first operation according to the first information. It should be understood that the first information is used to indicate or record the operation authority for the AF network element to perform the first operation.
[0425] Similar to the design described in the foregoing embodiments, in this design, the first operation and the second operation can be understood as two different operations, or two different types of operations, which will not be elaborated here.
[0426] Optionally, in this design, the first type of operation and the second type of operation can be predefined or manually configured according to service requirements as described in the foregoing embodiments. For the AF network element and the first network element, the first operation request indicating the first operation performed on the first label can generally refer to any first type of operation, such as operation 1. Similarly, the second operation can generally refer to any second type of operation, such as operation 2. The difference from the foregoing embodiments is that in this design, which operations belong to the first type of operation and which operations belong to the second type of operation can be preconfigured or predefined in the AF network element through a protocol. When the AF network element needs to perform operation 1 on the first label, it can determine that operation 1 belongs to the first type of operation according to the predefined or preconfigured operation type, and send the second operation authorization information indicating the operation authority for the AF network element to perform the first operation to the first network element. After receiving the second operation authorization information and the first operation request from the AF network element, the first network element can determine whether to perform operation 1 according to the operation authority for the AF network element to perform the first operation.
[0427] Alternatively, in this design, the first type of operation and the second type of operation can also be as described in the foregoing embodiments without prior configuration or definition. For the AF network element and the first network element, the first operation request indicating the first operation performed on the first label can generally refer to any first type of operation, such as operation 1. Similarly, the second operation can generally refer to any second type of operation, such as operation 2. The difference from the foregoing embodiments is that in this design, the AF network element can dynamically determine that operation 1 is the first type of operation according to a preset rule, and send the second operation authorization information indicating the operation authority for the AF network element to perform the first operation to the first network element. After receiving the second operation authorization information and the first operation request from the AF network element, the first network element can determine whether to perform operation 1 according to the operation authority for the AF network element to perform the first operation. For the preset rule, please refer to the description in the foregoing embodiments and will not be elaborated here.
[0428] In this design, the operation authorization information (such as the first operation authorization information) received by the AF network element from the target network element indicates the operation permissions for the AF network element to perform the first operation and the second operation. The operation authorization information (such as the second operation authorization information) sent by the AF network element to the first network element indicates the operation permission for the AF network element to perform the first operation. The first network element can determine whether to perform the first operation based on the operation permission for the AF network element to perform the first operation. In other words, in this design, the AF network element can, according to the requirement of performing the first operation, only send the operation authorization information indicating the operation permission for the AF network element to perform the first operation to the first network element, thus saving communication costs.
[0429] It should be understood that in the above design where the first operation authorization information indicates the operation permissions for the AF network element to perform the first operation and the second operation, and the second operation authorization information indicates the operation permission for the AF network element to perform the first operation, when the AF network element needs to perform the second operation on the first label, it needs to re - send the operation authorization information indicating the operation permission for the AF network element to perform the second operation to the first network element, which can be referred to as the third operation authorization information. For example, optionally, in this design, the method may further include: The first network element receives a second operation request and the third operation authorization information from the AF network element. The second operation request is used to indicate performing the second operation on the first label, and the third operation authorization information is used to indicate the operation permission for the AF network element to perform the second operation. For example, the third operation authorization information may be the part of the above - mentioned first operation authorization information that indicates the operation permission for the AF network element to perform the second operation. The first network element determines that the second operation is within the operation permission range for the AF network element to perform the second operation indicated by the third operation authorization information, and performs the second operation on the first label. The first network element sends a second operation response message to the AF network element, and the second operation response message is used to indicate the execution result of the second operation.
[0430] Exemplarily, also based on the above Figure 8 shown process as an example, Figure 10 shows another schematic flowchart of the communication method provided by the embodiment of the present application. As Figure 10 shown, the communication method may include S1001 - S1011. Among them, the first network element is a TMF network element, and the second network element (target network element) is an NRF network element.
[0431] S1001. The TMF network element successfully registers with the NRF network element, and the NRF network element shares a signature with the TMF network element. For example, the NRF network element sends the second signature information to the TMF network element.
[0432] Correspondingly, the TMF network element receives the second signature information.
[0433] S1002. The AF network element sends a first message to the NRF network element, and the first message is used to indicate a request to obtain the first operation authorization information.
[0434] Accordingly, the NRF network element receives the first message.
[0435] S1003. In response to the first message, the NRF network element sends first operation authorization information to the AF network element. The first operation authorization information carries first signature information and is used to indicate the operation permissions for the AF network element to perform the first operation and the second operation.
[0436] Accordingly, the AF network element receives the first operation authorization information.
[0437] That is, the operation authorization information sent by the NRF network element to the AF network element is called the first operation authorization information.
[0438] S1004. The AF network element sends a first operation request and second operation authorization information to the TMF network element. The second operation authorization information carries first signature information and is used to indicate the operation permission for the AF network element to perform the first operation.
[0439] For example, the first operation authorization information includes first information indicating the operation permission for the AF network element to perform the first operation and second information indicating the operation permission for the AF network element to perform the second operation. The second operation authorization information may be the first information in the first operation authorization information.
[0440] That is, when performing the first operation, the operation authorization information sent by the AF network element to the TMF network element (the first network element) is called the second operation authorization information.
[0441] Accordingly, the TMF network element receives the first operation request and the second operation authorization information.
[0442] S1005. The TMF network element determines that the first signature information and the second signature information match.
[0443] It should be understood that in S1005, it is determined that the first signature information carried in the second operation authorization information and the second signature information match.
[0444] S1006. The TMF network element determines that the first operation is within the operation permission range for the AF network element to perform the first operation indicated by the second operation authorization information, and performs the first operation on the first label.
[0445] S1007. The TMF network element sends a first operation response message to the AF network element.
[0446] Accordingly, the AF network element receives the first operation response message.
[0447] S1008. The AF network element sends a second operation request and third operation authorization information to the TMF network element. The third operation authorization information carries first signature information and is used to indicate the operation permission for the AF network element to perform the second operation.
[0448] For example, the third operation authorization information may be the second information in the first operation authorization information.
[0449] Accordingly, the TMF network element receives the second operation request and the third operation authorization information.
[0450] S1009. The TMF network element determines that the first signature information and the second signature information match.
[0451] It should be understood that in S1009, it is determined that the first signature information and the second signature information carried in the third operation authorization information match.
[0452] S1010. The TMF network element determines that the second operation is within the operation permission range of the AF network element indicated by the third operation authorization information to perform the second operation, and performs the second operation on the first label.
[0453] S1011. The TMF network element sends a second operation response message to the AF network element.
[0454] Accordingly, the AF network element receives the second operation response message.
[0455] Among them, S1001 - S1007 can refer to S801 - S807 or S901 - S907. The difference is that when performing the first operation, the operation authorization information sent by the AF network element to the TMF network element (the first network element) is the second operation authorization information, and the second operation authorization information is the part of the first operation authorization information received by the AF network element that is used to indicate the operation permission for the AF network element to perform the first operation.
[0456] The process described in S1008 - S1011 is similar to the process described in S1004 - S1007. The difference is that when performing the second operation, the operation authorization information sent by the AF network element to the TMF network element (the first network element) is the third operation authorization information, and the third operation authorization information is the part of the first operation authorization information received by the AF network element that is used to indicate the operation permission for the AF network element to perform the second operation.
[0457] Exemplarily, in this embodiment, the first operation authorization information may be referred to as a token, and the token may include token1 and token2. The second operation authorization information may be token1, and the third operation authorization information may be token2.
[0458] In this embodiment, the AF network element can perform the first operation or the second operation as needed, select the operation authorization information for indicating the operation permission for the AF network element to perform the first operation or the second operation and send it to the first network element. When the first network element receives the first operation request or the second operation request, it can determine whether to perform the first operation or the second operation according to the corresponding received operation authorization information.
[0459] In yet another possible design, the operation authorization information sent by the target network element to the AF network element in the above embodiments may be related to which operation the AF network element needs to perform on the first label. That is, when the AF network element needs to perform a first operation on the first label, the operation authorization information sent by the target network element to the AF network element can be used or only used to indicate the operation permission for the AF network element to perform the first operation.
[0460] For example, when the AF network element needs to perform a first operation on the first label, the operation authorization information sent by the target network element to the AF network element can be referred to as the first operation authorization information, and the operation authorization information sent by the AF network element to the first network element can be referred to as the second operation authorization information. The first operation authorization information is used to indicate the operation permission for the AF network element to perform the first operation. The second operation authorization information is the same as the first operation authorization information. After receiving the second operation authorization information, the first network element can determine whether to perform the first operation according to the operation permission for the AF network element to perform the first operation indicated by the second operation authorization information.
[0461] Exemplarily, taking the first operation authorization information as a statement document as an example, the operation permission for the AF network element to perform the first operation can be recorded in the statement document. The second operation authorization information sent by the AF network element to the first network element can be this statement document. After receiving this statement document, the first network element can determine whether to perform the first operation according to this statement document.
[0462] In some implementation manners of this design, the first operation can be understood as a single operation or one-time operation. For example, the first operation is a random access operation, or an operation to inactivate the first label, or an operation to read data from the first label, etc.
[0463] In some other implementation manners of this design, the first operation can also be understood as a type of operation. For example, it can be the first type of operation or the second type of operation described in the foregoing embodiments (for the convenience of description, in this application, the first operation is taken as an example of the first type of operation), and the operation type will not be elaborated here.
[0464] Optionally, in this design, the first type of operation and the second type of operation can be predefined or manually configured according to business requirements as described in the foregoing embodiments. For the AF network element and the first network element, the first operation request indicating the first operation performed on the first label can generally refer to any first type of operation, such as Operation 1. Similarly, the second operation can generally refer to any second type of operation, such as Operation 2. The difference from the foregoing embodiments is that in this design, it is possible to pre-configure or pre-define through a protocol in the AF network element and / or the target network element which operations belong to the first type of operation and which operations belong to the second type of operation. When the AF network element needs to perform Operation 1 on the first label, it can determine, according to the predefined or pre-configured operation type, that Operation 1 belongs to the first type of operation, and request from the target network element the first operation authorization information for indicating the operation permission for the AF network element to perform the first operation, such as the first message for indicating the request for obtaining the first operation authorization information for indicating the operation permission for the AF network element to perform the first operation. Alternatively, the first message can indicate the request for obtaining the operation authorization information and the need to perform Operation 1 (such as including the name or identifier of Operation 1), or for indicating the request for obtaining the operation authorization information corresponding to Operation 1. The target network element can determine, according to the predefined or pre-configured operation type, that Operation 1 belongs to the first type of operation, and send to the AF network element the first operation authorization information for indicating the operation permission for the AF network element to perform the first operation. After receiving the first operation authorization information, the AF network element can send to the first network element the second operation authorization information for indicating the operation permission for the AF network element to perform the first operation. After receiving the second operation authorization information and the first operation request from the AF network element, the first network element can determine whether to perform Operation 1 according to the operation permission for the AF network element to perform the first operation.
[0465] Alternatively, in this design, the first type of operation and the second type of operation can also be as described in the foregoing embodiments without prior configuration or definition. For the AF network element and the first network element, the first operation request indicating the first operation performed on the first label can generally refer to any first type of operation, such as Operation 1. Similarly, the second operation can generally refer to any second type of operation, such as Operation 2. The difference from the foregoing embodiments is that in this design, the AF network element can dynamically determine that Operation 1 is a first type of operation according to a preset rule, and request the target network element to obtain the first operation authorization information for indicating the operation authority for the AF network element to perform the first operation. For example, the first message is used to indicate a request to obtain the first operation authorization information for indicating the operation authority for the AF network element to perform the first operation. Alternatively, the first message can indicate a request to obtain the operation authorization information, and the need to perform Operation 1 (such as including the name or identifier of Operation 1), or is used to indicate a request to obtain the operation authorization information corresponding to Operation 1. The target network element can dynamically determine that Operation 1 is a first type of operation according to a preset rule, and send the first operation authorization information for indicating the operation authority for the AF network element to perform the first operation to the AF network element. After receiving the first operation authorization information, the AF network element can send the second operation authorization information for indicating the operation authority for the AF network element to perform the first operation to the first network element. After receiving the second operation authorization information and the first operation request from the AF network element, the first network element can determine whether to perform Operation 1 according to the operation authority for the AF network element to perform the first operation. The preset rule can be referred to the description in the foregoing embodiments and will not be elaborated here.
[0466] In this design, when the AF network element needs to perform the first operation on the first label, the operation authorization information (such as the first operation authorization information) received by the AF network element from the target network element indicates the operation authority for the AF network element to perform the first operation, and the operation authorization information (such as the second operation authorization information) sent by the AF network element to the first network element indicates the operation authority for the AF network element to perform the first operation. The first network element can determine whether to perform the first operation according to the operation authority for the AF network element to perform the first operation. In other words, in this design, the AF network element can, according to the requirement of performing the first operation, only obtain from the target network element and send to the first network element the operation authorization information indicating the operation authority for the AF network element to perform the first operation, saving communication costs.
[0467] It should be understood that in the design where the above first operation authorization information instructs the AF network element to perform the first operation and the second operation authorization information instructs the operation permission of the AF network element to perform the first operation, when the AF network element needs to perform the second operation on the first tag, it needs to re-obtain the operation authorization information (such as the third operation authorization information) indicating the operation permission of the AF network element to perform the second operation from the target network element, and send the operation authorization information (such as the fourth operation authorization information) indicating the operation permission of the AF network element to perform the second operation to the first network element. For example, optionally, in this design, the method may further include: The target network element receives a second message from the AF network element, and the second message is used to indicate a request to obtain the third operation authorization information. The target network element sends the third operation authorization information to the AF network element. The first network element receives a second operation request and the fourth operation authorization information from the AF network element. The second operation request is used to indicate performing the second operation on the first tag, and the fourth operation authorization information is used to indicate the operation permission of the AF network element to perform the second operation. For example, the fourth operation authorization information may be the same as the third operation authorization information. The first network element determines that the second operation is within the operation permission range of the AF network element to perform the second operation indicated by the fourth operation authorization information, and performs the second operation on the first tag. The first network element sends a second operation response message to the AF network element, and the second operation response message is used to indicate the execution result of the second operation.
[0468] Exemplarily, also based on the above Figure 8 shown process as an example, Figure 11 shows another schematic flowchart of the communication method provided by the embodiment of the present application. As Figure 11 shown, the communication method may include S1101 - S1113. Among them, the first network element is the TMF network element, and the second network element (target network element) is the NRF network element.
[0469] S1101. The TMF network element successfully registers to the NRF network element, and the NRF network element shares the signature with the TMF network element. For example, the NRF network element sends the second signature information to the TMF network element.
[0470] Correspondingly, the TMF network element receives the second signature information.
[0471] S1102. The AF network element sends a first message to the NRF network element, and the first message is used to indicate a request to obtain the first operation authorization information.
[0472] Correspondingly, the NRF network element receives the first message.
[0473] S1103. In response to the first message, the NRF network element sends the first operation authorization information to the AF network element. The first operation authorization information carries the first signature information and is used to indicate the operation permission of the AF network element to perform the first operation.
[0474] Accordingly, the AF network element receives the first operation authorization information.
[0475] S1104. The AF network element sends a first operation request and a second operation authorization information to the TMF network element. The second operation authorization information carries the first signature information and is used to indicate the operation authority for the AF network element to execute the first operation.
[0476] For example, the first operation authorization information and the second operation authorization information are the same.
[0477] Accordingly, the TMF network element receives the first operation request and the second operation authorization information.
[0478] S1105. The TMF network element determines that the first signature information and the second signature information match.
[0479] It should be understood that in S1105, it is to determine that the first signature information carried in the second operation authorization information and the second signature information match.
[0480] S1106. The TMF network element determines that the first operation is within the scope of the operation authority for the AF network element to execute the first operation indicated by the second operation authorization information, and performs the first operation on the first label.
[0481] S1107. The TMF network element sends a first operation response message to the AF network element.
[0482] Accordingly, the AF network element receives the first operation response message.
[0483] S1108. The AF network element sends a second message to the NRF network element. The second message is used to indicate a request to obtain the third operation authorization information.
[0484] Accordingly, the NRF network element receives the first message.
[0485] For the implementation manner of the second message, reference may be made to the implementation manner of the first message in the foregoing embodiments, which will not be elaborated here.
[0486] S1109. In response to the second message, the NRF network element sends the third operation authorization information to the AF network element. The third operation authorization information carries the first signature information and is used to indicate the operation authority for the AF network element to execute the second operation.
[0487] Accordingly, the AF network element receives the third operation authorization information.
[0488] S1110. The AF network element sends a second operation request and a fourth operation authorization information to the TMF network element. The fourth operation authorization information carries the first signature information and is used to indicate the operation authority for the AF network element to execute the second operation.
[0489] For example, the third operation authorization information and the fourth operation authorization information are the same.
[0490] Accordingly, the TMF network element receives a second operation request and fourth operation authorization information.
[0491] S1111. The TMF network element determines that the first signature information and the second signature information match.
[0492] It should be understood that in S1111, it is determined that the first signature information carried in the fourth operation authorization information and the second signature information match.
[0493] S1112. The TMF network element determines that the second operation is within the operation permission range of the AF network element indicated by the fourth operation authorization information to perform the second operation, and performs the second operation on the first label.
[0494] S1113. The TMF network element sends a second operation response message to the AF network element.
[0495] Accordingly, the AF network element receives the second operation response message.
[0496] Among them, for S1101 - S1107, reference can be made to S801 - S807 or S901 - S907. The difference is that when performing the first operation, the operation authorization information sent by the AF network element to the TMF network element (the first network element) is the second operation authorization information, and the second operation authorization information is the same as the first operation authorization information received by the AF network element, and is used to indicate the operation permission of the AF network element to perform the first operation.
[0497] The processes described in S1108 - S1109 are similar to the processes described in S1102 - S1103. The difference is that S1102 - S1103 are for obtaining the operation permission of the AF network element to perform the first operation, and S1108 - S1109 are for obtaining the operation permission of the AF network element to perform the second operation.
[0498] The processes described in S1110 - S1113 are similar to the processes described in S1104 - S1107. The difference is that when performing the second operation, the operation authorization information sent by the AF network element to the TMF network element (the first network element) is the fourth operation authorization information, and the fourth operation authorization information is the same as the third operation authorization information received by the AF network element, and is used to indicate the operation permission of the AF network element to perform the second operation.
[0499] Exemplarily, in this embodiment, the first operation authorization information may be referred to as token1, and the second operation authorization information may be token1. The third operation authorization information may be referred to as token2, and the fourth operation authorization information may be token2.
[0500] In this embodiment, the AF network element can perform a first operation or a second operation as needed, obtain operation authorization information for the operation permission of performing the first operation or the second operation from the target network element, and send it to the first network element. When the first network element receives a first operation request or a second operation request, it can determine whether to perform the first operation or the second operation according to the received operation authorization information.
[0501] In a possible design, the method described in any of the above embodiments may further include: the first network element sends an operation confirmation request message to the AF network element, and the operation confirmation request message is used to indicate whether to confirm performing the first operation on the first tag; correspondingly, the AF network element receives the operation confirmation request message. The AF network element sends an operation confirmation response message to the first network element, and the operation confirmation response message is used to indicate confirming performing the first operation on the first tag; correspondingly, the first network element receives the operation confirmation response message. In this method, the first network element performing the first operation may specifically include: the first network element performs the first operation on the first tag in response to the operation confirmation response message. That is, before performing the first operation, the first network element can use the operation confirmation request message to confirm with the AF network element again whether to perform the first operation, and perform the first operation after obtaining the confirmation from the AF network element.
[0502] For example, based on the above Figure 8 shown process as an example, Figure 12 Fig. shows another schematic flowchart of the communication method provided by the embodiment of the present application. As Figure 12 shown, this communication method may include S1201 - S1210. Among them, the first network element is a TMF network element, and the second network element (target network element) is an NRF network element.
[0503] S1201. The TMF network element successfully registers to the NRF network element, and the NRF network element shares a signature with the TMF network element, such as the NRF network element sending second signature information to the TMF network element.
[0504] Correspondingly, the TMF network element receives the second signature information.
[0505] S1202. The AF network element sends a first message to the NRF network element, and the first message is used to indicate a request to obtain operation authorization information.
[0506] Correspondingly, the NRF network element receives the first message.
[0507] S1203. In response to the first message, the NRF network element sends operation authorization information to the AF network element, and the operation authorization information carries first signature information.
[0508] Correspondingly, the AF network element receives the operation authorization information.
[0509] The AF network element sends a first operation request and operation authorization information to the TMF network element, and the operation authorization information carries first signature information.
[0510] Correspondingly, the TMF network element receives the first operation request and operation authorization information.
[0511] S1205. The TMF network element determines that the first signature information and the second signature information match.
[0512] S1206. The TMF network element determines that the first operation is within the scope of the operation authority indicated by the operation authorization information.
[0513] S1207. The TMF network element sends an operation confirmation request message to the AF network element, and the operation confirmation request message is used to indicate whether to confirm the execution of the first operation on the first label.
[0514] Correspondingly, the AF network element receives the operation confirmation request message.
[0515] Optionally, the operation confirmation request message can also indicate the label range for which the first operation needs to be executed, such as which first labels.
[0516] S1208. The AF network element sends an operation confirmation response message to the TMF network element, and the operation confirmation response message is used to indicate the confirmation of the execution of the first operation on the first label.
[0517] Correspondingly, the TMF network element receives the operation confirmation response message.
[0518] S1209. In response to the operation confirmation response message, the TMF network element performs the first operation on the first label.
[0519] Optionally, when the TMF network element does not receive the operation confirmation response message, for example, within a preset duration (such as 1 second, 2 seconds, etc., without limitation) it does not receive the operation confirmation response message, or when the operation confirmation response message indicates not to perform the first operation on the first label (such as a misoperation), the first operation may not be performed.
[0520] S1210. The TMF network element sends a first operation response message to the AF network element.
[0521] Correspondingly, the AF network element receives the first operation response message.
[0522] S1201 - S1206, and S1209 - S1210 can be referred to as described in S801 - S807 and will not be elaborated further. The difference is that in S1209, after receiving the operation confirmation response message, the TMF network element performs the first operation on the first label.
[0523] Exemplarily, in some implementations, the first operation described in this design may be any one or any type of operation described in the foregoing embodiments. For example, if the first type of operation is a special operation and the second type of operation is a normal operation, the first operation may be the first type of operation or the second type of operation.
[0524] In some other implementations, the first operation described in this design may also be a specific one or a specific type of operation. For example, the first operation may be an inactivation operation, an operation of writing data to the first tag, or an operation of locking the first tag. Also, for example, if the first type of operation is a special operation and the second type of operation is a normal operation, the first operation may be the first type of operation.
[0525] This design enables the first network element to perform the step of the first operation, which requires reconfirmation by the AF network element, reducing the possibility of misoperation and further improving the security of operating on the tag. Additionally, when the first operation is a specific one or a specific type of operation, it is also possible to implement differentiated processing for this type of operation (such as a special operation). For example, a special operation that has a greater impact on the tag can have an additional confirmation mechanism.
[0526] In a possible design, the above operation confirmation response message may further include operation authorization information. The content of the operation authorization information can be found in the foregoing embodiments. Before the first network element performs the step of the first operation in response to the operation confirmation response message, the method may further include: the first network element determines that the first operation is within the operation authority range indicated by the operation authorization information in the operation confirmation response message. That is, after receiving the operation confirmation response message, the first network element can again determine whether the first operation is within the operation authority range indicated by the operation authorization information in the operation confirmation response message, and when it is confirmed that the first operation is within the operation authority range indicated by the operation authorization information, perform the first operation.
[0527] For example, based on the above Figure 12 shown process as an example, Figure 13 Figure 13 shows another schematic flowchart of the communication method provided by the embodiments of the present application. As Figure 13 shown, the communication method may include S1301 - S1311. Among them, the first network element is a TMF network element, and the second network element (target network element) is an NRF network element.
[0528] S1301. The TMF network element successfully registers with the NRF network element, and the NRF network element shares a signature with the TMF network element, such as the NRF network element sending the second signature information to the TMF network element.
[0529] Correspondingly, the TMF network element receives the second signature information.
[0530] In S1302, the AF network element sends a first message to the NRF network element, and the first message is used to indicate a request for obtaining operation authorization information.
[0531] Correspondingly, the NRF network element receives the first message.
[0532] In S1303, in response to the first message, the NRF network element sends operation authorization information to the AF network element, and the operation authorization information carries first signature information.
[0533] Correspondingly, the AF network element receives the operation authorization information.
[0534] In S1304, the AF network element sends a first operation request and operation authorization information to the TMF network element, and the operation authorization information carries first signature information.
[0535] Correspondingly, the TMF network element receives the first operation request and operation authorization information.
[0536] In S1305, the TMF network element determines that the first signature information and the second signature information match.
[0537] In S1306, the TMF network element determines that the first operation is within the scope of operation permissions indicated by the operation authorization information.
[0538] In S1307, the TMF network element sends an operation confirmation request message to the AF network element, and the operation confirmation request message is used to indicate whether to confirm the execution of the first operation on the first label.
[0539] Correspondingly, the AF network element receives the operation confirmation request message.
[0540] Optionally, the operation confirmation request message may also indicate the label range for which the first operation needs to be executed, such as which first labels.
[0541] In S1308, the AF network element sends an operation confirmation response message to the TMF network element, and the operation confirmation response message is used to indicate the confirmation of the execution of the first operation on the first label and includes the operation authorization information.
[0542] Correspondingly, the TMF network element receives the operation confirmation response message.
[0543] In S1309, the TMF network element determines that the first operation is within the scope of operation permissions indicated by the operation authorization information.
[0544] It should be understood that the operation authorization information described in S1309 is the operation authorization information included in the operation confirmation response message. Or S1309 can also be replaced by the TMF network element verifying whether the operation authorization information included in the operation confirmation response message is consistent with the operation authorization information received in S1304, and there is no limitation here.
[0545] S1310. The TMF network element performs a first operation on the first label in response to the operation confirmation response message.
[0546] S1311. The TMF network element sends a first operation response message to the AF network element.
[0547] Correspondingly, the AF network element receives the first operation response message.
[0548] S1301 - S1311 can be referred to as described in S1201 - S1210 and will not be elaborated here. The difference is that there is an additional step described in S1309, where the TMF network element performs an additional verification on the operation authorization information.
[0549] In this design, the operation confirmation response message includes operation authorization information. The first network element determines again whether the first operation is within the scope of the operation authority indicated by the operation authorization information in the operation confirmation response message, and when it is confirmed that the first operation is within the scope of the operation authority indicated by the operation authorization information, the first operation is performed, which can reduce the possibility that the first operation is illegal due to changes in the operation authorization information or changes in the legal status of the AF network element, and further improve the security of operating on the label.
[0550] In a possible design, based on any of the above embodiments, the first label and the AF network element respectively store the password corresponding to the first label. The password stored in the first label can be called the local password of the first label, and the password stored in the AF network element can be called the first password, that is, the first password is the password corresponding to the first label. When the AF network element needs to perform a first operation on the first label, it can also send the first password to the first label through the first network element. The first label can perform the first operation when it determines that the first password and the local password are the same. For example, the method further includes: the AF network element sends the first password to the first network element. Correspondingly, the first network element receives the first password. The first network element performing the first operation on the first label includes: the first network element sends indication information and the first password to the first label, and the indication information is used to instruct the first label to perform the first operation. Correspondingly, the first label receives the indication information and the first password from the first network element. The first label determines that the first password and the local password are the same and performs the first operation. That is, the first password can be used to instruct the first operation to be performed when the first password and the local password of the first label are the same.
[0551] Exemplarily, Figure 14 shows another schematic flowchart of the communication method provided by the embodiment of the present application. As Figure 14 shown, the communication method may include S1401 - S1405.
[0552] S1401. The AF network element sends a first operation request, operation authorization information, and the first password to the first network element.
[0553] Accordingly, the first network element receives a first operation request, operation authorization information, and a first password.
[0554] Optionally, the first password may be sent in the same or different messages as the first operation request and the operation authorization information, and there is no limitation here.
[0555] The password corresponding to the first tag may refer to the signature information described in the foregoing embodiments, such as a secret key, a public key, etc. Information, and there is no limitation on the implementation manner of the password and the rule for verifying whether the passwords are consistent here.
[0556] S1402. The first network element determines that the first operation is within the scope of operation authority indicated by the operation authorization information.
[0557] S1401 - S1402 may refer to that described in S301 - S302 and will not be elaborated here.
[0558] S1403. The first network element sends indication information and the first password to the first tag, and the indication information is used to instruct the first tag to perform the first operation.
[0559] The indication information can be seen in the Figure 4 process described above and will not be elaborated here either.
[0560] Accordingly, the first tag receives the indication information and the first password.
[0561] S1404. The first tag determines that the first password is consistent with the local password and performs the first operation.
[0562] For example, when the first tag determines that the first password is consistent with the local password, it may return the execution result of the first operation to the first network element. The execution result of the first operation can be seen in that described in the foregoing embodiments.
[0563] Optionally, when the first password is inconsistent with the local password, the first tag may not perform the first operation.
[0564] S1405. The first network element sends a first operation response message to the AF network element.
[0565] Accordingly, the AF network element receives the first operation response message. The first operation response message may indicate the execution result of the first operation.
[0566] In this design, the first network element verifies the operation authorization information and the first tag verifies the password, forming a dual authorization verification mechanism, which can further improve the security of the AF network element's operation on the tag. Optionally, in this design, when the first operation is for a specific one or a type of operations, it is also possible to implement differentiated processing for this type of operation. For example, the first operation can be an inactivation operation or the above-mentioned special operation, so as to implement dual verification authorization for special operations that have a great impact on the tag.
[0567] Optionally, the local password in the first tag can be written by the AF network element to the first tag through the first network element. For example, the method further includes: the AF network element sends a password printing request to the first network element, and the password printing request is used to instruct to write a second password to the first tag. Correspondingly, the first network element receives the password printing request. The first network element determines that the AF network element has the write permission for the first tag, and writes the second password to the first tag. Correspondingly, the first tag receives the second password from the first network element and writes the second password as the local password. That is, the second password is the local password of the first tag.
[0568] In a possible design, when the first network element receives the password printing request, it can first verify or query whether the AF network element has the write permission for the first tag, and when it is determined that the AF network element has the write permission for the first tag, it responds to the password printing request and writes the second password to the first tag. When the AF network element does not have the write permission for the first tag, it can not respond to the password printing request.
[0569] As described in the foregoing embodiments, the target network element may maintain or store the operation authorization information of the AF network element. In some implementation manners, the target network element may be the above-mentioned first network element. In some other implementation manners, the target network element may also be a second network element that does not have the tag management function.
[0570] For the scenario where the target network element is the first network element, in this design, the first network element can query the operation authorization information of the AF network element stored by itself from the local storage to determine whether the AF network element has the write permission for the first tag.
[0571] For the scenario where the target network element is a second network element that does not have the tag management function, in this design, the first network element can communicate with the second network element to query whether the AF network element has the write permission for the first tag. For example, the first network element can send a permission query request message to the second network element, and the permission query request message is used to instruct to request to obtain the operation permission of the application function network element; correspondingly, the second network element receives the permission query request message. The second network element can send a permission query response message to the first network element, and the permission query response message is used to instruct the operation permission of the application function network element; correspondingly, the first network element receives the permission query response message.
[0572] Exemplarily, taking the first network element as an independent TMF network element and the second network element as a UDM network element as an example (or the second network element can also be an NRF network element or an NEF network element), Figure 15 Another schematic flowchart of the communication method provided by the embodiment of the present application is shown. As Figure 15 shown, the communication method may include S1501 - S1511.
[0573] S1501. The AF network element sends a password printing request to the TMF network element, and the password printing request is used to indicate writing a second password to the first tag.
[0574] Correspondingly, the TMF network element receives the password printing request.
[0575] S1502. The TMF network element sends a permission query request message to the UDM network element, and the permission query request message is used to indicate a request to obtain the operation permission of the AF network element.
[0576] Correspondingly, the UDM network element receives the permission query request message.
[0577] S1503. The UDM network element sends a permission query response message to the TMF network element, and the permission query response message is used to indicate the operation permission of the AF network element.
[0578] Correspondingly, the TMF network element receives the permission query response message. For example, the permission query response message may include the above - mentioned operation authorization information.
[0579] S1504. The TMF network element determines that the AF network element has the write permission for the first tag.
[0580] S1505. The TMF network element writes the second password to the first tag.
[0581] Correspondingly, the first tag receives the second password from the TMF network element and writes the second password as the local password.
[0582] S1506. The TMF network element sends the password writing result to the AF network element.
[0583] The password writing result may indicate that the second password is successfully written.
[0584] S1507. The AF network element sends a first operation request, operation authorization information, and a first password to the TMF network element.
[0585] Correspondingly, the TMF network element receives the first operation request, operation authorization information, and the first password.
[0586] S1508. The TMF network element determines that the first operation is within the operation permission range indicated by the operation authorization information.
[0587] S1509. The TMF network element sends indication information and a first password to the first tag, and the indication information is used to instruct the first tag to perform a first operation.
[0588] Correspondingly, the first tag receives the indication information and the first password.
[0589] S1510. The first tag determines that the first password is consistent with the local password and performs the first operation.
[0590] S1511. The TMF network element sends a first operation response message to the AF network element.
[0591] Correspondingly, the AF network element receives the first operation response message.
[0592] S1507 - S1511 can be referred to as described in S1401 - S1405 and will not be elaborated here.
[0593] In this design, the AF network element can write the local password into the first tag through the first network element. The first network element can write the local password into the first tag when determining that the AF network element has the write permission for the first tag.
[0594] Optionally, the local password in the first tag can be written into the first tag by other network elements through the first network element, such as the second network element, such as the UDM network element, the NRF network element, the NEF network element, etc., and there is no limitation here.
[0595] Optionally, in some other possible designs, the operation authorization information can also be carried in the password printing request, and the first network element can determine whether the AF network element has the write permission for the first tag in the same way as performing the first operation or the second operation described in the foregoing embodiments.
[0596] Based on the foregoing embodiments, the embodiments of the present application actually provide methods that can be applied to the foregoing first network element, methods that can be applied to the foregoing AF network element, methods that can be applied to the foregoing second network element, and methods that can be applied to the foregoing first tag. Among them, the method applied to the foregoing first network element can refer to the steps performed by the first network element in the foregoing embodiments. The method applied to the foregoing AF network element can refer to the steps performed by the AF network element in the foregoing embodiments. The method applied to the foregoing second network element can refer to the steps performed by the second network element in the foregoing embodiments. The method applied to the foregoing first tag can refer to the steps performed by the first tag in the foregoing embodiments.
[0597] Exemplarily, in the above method embodiments, the steps performed by the first network element may be executed by a network device carrying the first network element, or by a device (such as a chip) built into the network device carrying the first network element. The network device carrying the first network element may be the first network device. The steps performed by the AF network element may be executed by a network device carrying the AF network element, or by a device (such as a chip) built into the network device carrying the AF network element. The network device carrying the AF network element may be the second network device. The steps performed by the second network element may be executed by a network device carrying the second network element, or by a device (such as a chip) built into the network device carrying the second network element. The network device carrying the second network element may be the first network device. The steps performed by the first tag may be executed by the first tag, or by a device (such as a chip) built into the first tag.
[0598] The above mainly introduces the solution provided in the embodiments of the present application from the perspective of the interaction between each network element. It can be understood that each network element, such as the first network element, the second network element, the AF network element, the first tag, etc., includes corresponding hardware structures and / or software modules for implementing the above functions.
[0599] For example, the embodiments of the present application may provide a communication device for implementing the functions of the above first network element. The communication device may be the first network device or a device (such as a chip) built into the first network device. Figure 16 The structural schematic diagram of the communication device provided in the embodiments of the present application is shown. As Figure 16 shown, the communication device may include: a receiving unit 1601, a processing unit 1602, and a transmitting unit 1603.
[0600] Among them, the receiving unit 1601 is used to receive a first operation request and operation authorization information from the application function network element. The first operation request is used to indicate to perform a first operation on the first tag, and the operation authorization information is used to indicate the operation authority of the application function network element. The processing unit 1602 is used to determine that the first operation is within the operation authority range indicated by the operation authorization information, and perform the first operation on the first tag.
[0601] In a possible design, the receiving unit 1601 is further used to receive a first message from the application function network element. The first message is used to indicate a request to obtain operation authorization information. The transmitting unit 1603 is used to send operation authorization information to the application function network element in response to the first message.
[0602] In a possible design, the operation authorization information carries first signature information, and the first signature information is used to indicate the signature of the target network element, where the target network element is the network element that sends the operation authorization information to the application function network element; the processing unit 1602 is further configured to determine that the first signature information and the second signature information match before performing the first operation on the first tag when it is determined that the first operation is within the scope of the operation authority indicated by the operation authorization information, and the second signature information is used to indicate the signature of the target network element.
[0603] In a possible design, the receiving unit 1601 is further configured to receive second signature information from the target network element.
[0604] In a possible design, the operation authorization information is further used to indicate at least one of the following information corresponding to the operation authority of the application function network element: area range, tag range, permission period.
[0605] In a possible design, the operation authorization information is used to indicate the operation authority for the application function network element to perform the first operation and the second operation.
[0606] In a possible design, the receiving unit 1601 is further configured to receive a second operation request from the application function network element, where the second operation request is used to indicate performing a second operation on the first tag; the processing unit 1602 is further configured to determine that the second operation is within the scope of the operation authority indicated by the operation authorization information and perform the second operation on the first tag.
[0607] In a possible design, the operation authorization information is used to indicate the operation authority for the application function network element to perform the first operation.
[0608] In a possible design, the sending unit 1603 is configured to send an operation confirmation request message to the application function network element, where the operation confirmation request message is used to indicate confirming whether to perform the first operation on the first tag; the receiving unit 1601 is further configured to receive an operation confirmation response message from the application function network element, where the operation confirmation response message is used to indicate confirming performing the first operation on the first tag; the processing unit 1602 is specifically configured to perform the first operation on the first tag in response to the operation confirmation response message.
[0609] In a possible design, the operation confirmation response message includes the operation authorization information; the processing unit 1602 is further configured to determine that the first operation is within the scope of the operation authority indicated by the operation authorization information in the operation confirmation response message before performing the first operation on the first tag in response to the operation confirmation response message.
[0610] In a possible design, the receiving unit 1601 is further configured to receive a first password from the application function network element, where the first password is the password corresponding to the first tag; the processing unit 1602 is specifically configured to send, via the sending unit, indication information and the first password to the first tag, where the indication information is used to instruct the first tag to perform a first operation, and the first password is used to instruct the first operation to be performed when the first password is consistent with the local password of the first tag.
[0611] In a possible design, the receiving unit 1601 is further configured to receive a password printing request from the application function network element, where the password printing request is used to instruct writing a second password to the first tag; the processing unit 1602 is further configured to determine that the application function network element has the write permission for the first tag, and write the second password to the first tag, where the second password is the local password of the first tag.
[0612] For another example, an embodiment of the present application may provide a communication device for implementing the functions of the above AF network element. The communication device may be a second network device or a device (for example, a chip) built in the second network device. Figure 17 Another structural schematic diagram of the communication device provided by the embodiment of the present application is shown. As Figure 17 shown, the communication device may include: a sending unit 1701 and a receiving unit 1702.
[0613] Among them, the sending unit 1701 is configured to send a first operation request and operation authorization information to the first network element, where the first operation request is used to instruct performing a first operation on the first tag, and the operation authorization information is used to indicate the operation permission of the application function network element; the receiving unit 1702 is configured to receive a first operation response message from the first network element, where the first operation response message is used to indicate the execution result of the first operation.
[0614] In a possible design, the sending unit 1701 is further configured to send a first message to the target network element, where the first message is used to indicate a request for obtaining operation authorization information, and the target network element is the first network element or the second network element; the receiving unit 1702 is further configured to receive the operation authorization information from the target network element.
[0615] In a possible design, the operation authorization information carries first signature information, where the first signature information is used to indicate the signature of the target network element, and the target network element is the network element that sends the operation authorization information to the application function network element.
[0616] In a possible design, the operation authorization information is further used to indicate at least one of the following information corresponding to the operation permission of the application function network element: area range, tag range, and permission period.
[0617] In a possible design, the operation authorization information is used to indicate the operation permissions for the application function network element to perform the first operation and the second operation.
[0618] In a possible design, the sending unit 1701 is further configured to send a second operation request to the first network element, where the second operation request is used to indicate to perform a second operation on the first tag; the receiving unit 1702 is further configured to receive a second operation response message from the first network element, where the second operation response message is used to indicate the execution result of the second operation.
[0619] In a possible design, the operation authorization information is used to indicate the operation permission for the application function network element to perform the first operation.
[0620] In a possible design, the receiving unit 1702 is further configured to receive an operation confirmation request message from the first network element, where the operation confirmation request message is used to indicate whether to confirm performing the first operation on the first tag; the sending unit 1701 is further configured to send an operation confirmation response message to the first network element, where the operation confirmation response message is used to indicate the confirmation of performing the first operation on the first tag.
[0621] In a possible design, the operation confirmation response message includes operation authorization information.
[0622] In a possible design, the sending unit 1701 is further configured to send a first password to the first network element, where the first password is the password corresponding to the first tag, and the first password is used to indicate that when the first password is consistent with the local password of the first tag, the first operation is performed.
[0623] In a possible design, the sending unit 1701 is further configured to send a password printing request to the first network element, where the password printing request is used to indicate writing a second password to the first tag, and the second password is the local password of the first tag.
[0624] Optionally, the above Figure 17 The communication device shown may further include a processing unit, configured to implement the function of processing data.
[0625] For another example, an embodiment of the present application may provide a communication device for implementing the function of the above first tag. The communication device may be the first tag or a device (such as a chip) built into the first tag. Figure 18 Another structural schematic diagram of the communication device provided by the embodiment of the present application is shown. As Figure 18 shown, the communication device may include: a receiving unit 1801, a processing unit 1802.
[0626] Among them, the receiving unit 1801 is configured to receive indication information and a first password from the first network element, where the indication information is used to indicate performing the first operation; the processing unit 1802 is configured to determine that the first password is consistent with the local password and perform the first operation.
[0627] In a possible design, the receiving unit 1801 is further configured to receive a second password from a first network element; the processing unit 1802 is further configured to write the second password as the local password.
[0628] Optionally, the above Figure 18 The communication device shown may further include a sending unit for implementing the function of sending data.
[0629] For another example, an embodiment of the present application may provide a communication device for implementing the functions of the above-mentioned second network element. The communication device may be a third network device or a device (such as a chip) built into the third network device. Figure 19 Another schematic structural diagram of the communication device provided by the embodiment of the present application is shown. As Figure 19 shown, the communication device may include: a receiving unit 1901, a sending unit 1902.
[0630] Among them, the receiving unit 1901 is configured to receive a first message from an application function network element. The first message is used to indicate a request to obtain operation authorization information, and the operation authorization information is used to indicate the operation permissions of the application function network element; the sending unit 1902 is configured to send the operation authorization information to the application function network element in response to the first message.
[0631] In a possible design, the operation authorization information carries first signature information, and the first signature information is used to indicate the signature of the second network element.
[0632] In a possible design, the sending unit 1902 is further configured to send second signature information to the first network element, and the second signature information is used to indicate the signature of the second network element.
[0633] In a possible design, the operation authorization information is further used to indicate at least one of the following information corresponding to the operation permissions of the application function network element: area range, label range, permission period.
[0634] In a possible design, the operation authorization information is used to indicate the operation permissions for the application function network element to perform a first operation and a second operation.
[0635] In a possible design, the operation authorization information is used to indicate the operation permissions for the application function network element to perform a first operation.
[0636] In a possible design, the receiving unit 1901 is further configured to receive a permission query request message from the first network element. The permission query request message is used to indicate a request to obtain the operation permissions of the application function network element; the sending unit 1902 is further configured to send a permission query response message to the first network element, and the permission query response message is used to indicate the operation permissions of the application function network element.
[0637] Optionally, the aboveFigure 19 The communication device shown may further include a processing unit for implementing the function of processing data.
[0638] It should be understood that the division of units in the above device is only a division of logical functions. In actual implementation, they can be fully or partially integrated into a physical entity, or physically separated. And the units in the device can all be implemented in the form of software called by processing elements; they can also all be implemented in hardware form; or some units can be implemented in the form of software called by processing elements, and some units can be implemented in hardware form.
[0639] For example, each unit can be a separately established processing element, or can be integrated in a certain chip of the device. In addition, it can also be stored in the memory in the form of a program and called and executed by a certain processing element of the device to implement the function of the unit. In addition, all or part of these units can be integrated together or can be independently implemented. The processing element mentioned here can also be called a processor, which can be an integrated circuit with signal processing capabilities. In the implementation process, each step of the above method or each of the above units can be implemented through the integrated logic circuit of the hardware in the processor element or in the form of software called by the processing element.
[0640] In one example, the units in any of the above devices can be one or more integrated circuits configured to implement the above method. For example: one or more application specific integrated circuits (ASICs), or one or more digital signal processing (DSP) circuits, or one or more field programmable gate arrays (FPGAs), or a combination of at least two of these integrated circuit forms.
[0641] Again, when the units in the device can be implemented in the form of a processing element scheduler, the processing element can be a general-purpose processor, such as a CPU or other processors that can call programs. Again, these units can be integrated together and implemented in the form of a system-on-a-chip (SOC).
[0642] The above-mentioned unit for reception is an interface circuit or an input circuit of the device, which is used to receive signals from other devices. For example, when the device is implemented in the form of a chip, the receiving unit is an interface circuit or an input circuit of the chip for receiving signals from other chips or devices. When the communication device includes a unit for transmission, the unit for transmission is an interface circuit or an output circuit of the device, which is used to send signals to other devices. For example, when the device is implemented in the form of a chip, the transmitting unit is an interface circuit or an output circuit of the chip for sending signals to other chips or devices.
[0643] For example, an embodiment of the present application may further provide a communication device, which may include: a processor and an interface circuit. The processor may include one or more.
[0644] When the communication device is applied to the first network element, the processor is used to communicate with other devices through the interface circuit and execute each step performed by the first network element in the above method.
[0645] When the communication device is applied to the AF network element, the processor is used to communicate with other devices through the interface circuit and execute each step performed by the AF network element in the above method.
[0646] When the communication device is applied to the first tag, the processor is used to communicate with other devices through the interface circuit and execute each step performed by the first tag in the above method.
[0647] When the communication device is applied to the second network element, the processor is used to communicate with other devices through the interface circuit and execute each step performed by the second network element in the above method.
[0648] In one implementation, the units that respectively implement each corresponding step in the above method for the first network element, or the AF network element, or the second network element, or the first tag may be implemented in the form of a processing element scheduler. For example, the device for the first network element, or the AF network element, or the second network element, or the first tag may include a processing element and a storage element. The processing element calls the program stored in the storage element to execute the method corresponding to the first network element, or the AF network element, or the second network element, or the first tag in the above method embodiment. The storage element may be a storage element on the same chip as the processing element, that is, an on-chip storage element.
[0649] In another implementation, the program for implementing the method executed by the first network element, or the AF network element, or the second network element, or the first label in the above method can be stored in a storage element on a different chip from the processing element, that is, an off-chip storage element. At this time, the processing element calls or loads the program from the off-chip storage element onto the on-chip storage element to call and execute the method corresponding to the first network element, or the AF network element, or the second network element, or the first label in the above method embodiments.
[0650] For example, an embodiment of the present application can further provide a communication device. The communication device may include a processor for executing computer instructions stored in a memory. When the computer instructions are executed, the device executes the method executed by the first network element, or the AF network element, or the second network element, or the first label above. The memory may be located inside or outside the communication device. And the processor includes one or more.
[0651] In yet another implementation, the units for implementing the respective steps in the above method by the first network element, or the AF network element, or the second network element, or the first label may be configured as one or more processing elements, and these processing elements may be correspondingly disposed on the first network element, or the AF network element, or the second network element, or the first label. Here, the processing element may be an integrated circuit, for example: one or more ASICs, or one or more DSPs, or one or more FPGAs, or a combination of these types of integrated circuits. These integrated circuits may be integrated together to form a chip.
[0652] The units for implementing the respective steps in the above method by the first network element, or the AF network element, or the second network element, or the first label may be integrated together and implemented in the form of an SOC. The SOC chip is used to implement the corresponding method. At least one processing element and a storage element may be integrated in the chip, and the corresponding method is implemented in the form of the processing element calling the program stored in the storage element; or, at least one integrated circuit may be integrated in the chip to implement the corresponding method; or, the above implementation methods may be combined, and the functions of some units are implemented in the form of the processing element calling the program, and the functions of some units are implemented in the form of the integrated circuit.
[0653] The processing element described above may be a general-purpose processor, such as a CPU, or may also be one or more integrated circuits configured to implement the above method, for example: one or more ASICs, or one or more microprocessor DSPs, or one or more FPGAs, etc., or a combination of at least two of these integrated circuit forms.
[0654] The storage element may be a memory or a collective term for multiple storage elements.
[0655] For example, the embodiments of the present application further provide a chip system, which can be applied to the above-mentioned first network element, or an AF network element, or a second network element, or a first tag. The chip system includes one or more interface circuits and one or more processors; the interface circuits and the processors are interconnected by lines; the processors receive and execute computer instructions from the memory of the electronic device through the interface circuits to implement the methods executed by the corresponding first network element, or AF network element, or second network element, or first tag in the above method embodiments. Among them, the electronic device can be the first network element, or an AF network element, or a second network element, or the first tag itself or the devices therein, or can also be other devices communicating with it.
[0656] Through the description of the above embodiments, those skilled in the art can clearly understand that for the convenience and simplicity of description, only the division of the above functional modules is used as an example. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above.
[0657] In several embodiments provided by the present application, it should be understood that the disclosed device and method can be implemented in other ways. For example, the device embodiments described above are only illustrative. For example, the division of the modules or units is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of the device or unit can be in an electrical, mechanical or other form.
[0658] The units described as separate components may or may not be physically separated. The components displayed as units may be one physical unit or multiple physical units, that is, they can be located in one place, or can also be distributed to multiple different places. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0659] In addition, each functional unit in the various embodiments of the present application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.
[0660] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on such an understanding, the technical solution of the embodiments of the present application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product, such as a program. This software product is stored in a program product, such as a computer-readable storage medium, and includes several instructions to enable a device (which can be a single-chip microcomputer, a chip, etc.) or a processor to execute all or part of the steps of the methods described in the embodiments of the present application. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, ROM, RAM, magnetic disks, or optical discs that can store program codes.
[0661] For example, the embodiments of the present application can also provide a computer-readable storage medium, including: computer software instructions; when the computer software instructions are run, the steps executed by the first network element, or the AF network element, or the second network element, or the first label in the method described in the foregoing embodiments are implemented.
[0662] Exemplarily, when the computer software instructions are run in the first network device or a device (such as a chip) built into the first network device, the first network device is enabled to implement the steps executed by the first network element in the foregoing embodiments. The first network device can be a network device carrying the first network element.
[0663] Or, when the computer software instructions are run in the second network device or a device (such as a chip) built into the second network device, the second network device is enabled to implement the steps executed by the AF network element in the foregoing embodiments. The second network device can be a network device carrying the AF network element.
[0664] Or, when the computer software instructions are run in the third network device or a device (such as a chip) built into the third network device, the third network device is enabled to implement the steps executed by the second network element in the foregoing embodiments. The third network device can be a network device carrying the second network element.
[0665] Or, when the computer software instructions are run in the first label or a device (such as a chip) built into the first label, the first label is enabled to implement the steps executed by the first label in the foregoing embodiments.
[0666] Optionally, an embodiment of the present application further provides a communication device. The communication device may include: a transceiver unit and a processing unit. The transceiver unit may be used to transmit and receive information, or to communicate with other network elements. The processing unit may be used to process data. For example, the device may implement the method performed by the first network element, or the AF network element, or the second network element, or the first tag through the transceiver unit and the processing unit.
[0667] Optionally, an embodiment of the present application further provides a computer program product, which when executed can implement the method performed by the first network element, or the AF network element, or the second network element, or the first tag as described above.
[0668] Based on the above embodiments, an embodiment of the present application further provides a communication system, including: an application function network element, a first network element, and a first tag. The first network element performs the steps performed by the first network element in the method described in the foregoing embodiments. The application function network element performs the steps corresponding to the interaction with the first network element in the method described in the foregoing embodiments. The first tag performs the steps corresponding to the interaction with the first network element in the method described in the foregoing embodiments.
[0669] Exemplarily, the communication system further includes a second network element, and the second network element performs the steps corresponding to the interaction with the first network element and the application function network element in the method described in the foregoing embodiments.
[0670] Exemplarily, an embodiment of the present application further provides a network element or a network device, which can be used to implement the method performed by the first network element, or the AF network element, or the second network element in the foregoing embodiments.
[0671] Exemplarily, an embodiment of the present application further provides a tag or a terminal device, which can be used to implement the method performed by the first tag in the foregoing embodiments.
[0672] It should be understood that the description of technical features, technical solutions, beneficial effects, or similar languages in the present application does not imply that all features and advantages can be achieved in any single embodiment. On the contrary, it can be understood that the description of features or beneficial effects means that specific technical features, technical solutions, or beneficial effects are included in at least one embodiment. Therefore, the description of technical features, technical solutions, or beneficial effects in this specification does not necessarily refer to the same embodiment. Furthermore, the technical features, technical solutions, and beneficial effects described in this embodiment can be combined in any appropriate manner. Those skilled in the art will understand that an embodiment can be implemented without one or more specific technical features, technical solutions, or beneficial effects of a specific embodiment. In other embodiments, additional technical features and beneficial effects can also be identified in specific embodiments that do not embody all embodiments.
[0673] As described above, it is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions within the technical scope disclosed in the present application should be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims described above.
Claims
1. A communication method, characterized in that, the method includes: receiving a first operation request and operation authorization information from an application function network element, the first operation request being used to indicate performing a first operation on a first tag, and the operation authorization information being used to indicate the operation authority of the application function network element; determining that the first operation is within the scope of the operation authority indicated by the operation authorization information, and performing the first operation on the first tag.
2. The method according to claim 1, characterized in that, the method further includes: receiving a first message from the application function network element, the first message being used to indicate a request to obtain the operation authorization information; in response to the first message, sending the operation authorization information to the application function network element.
3. The method according to claim 1 or 2, characterized in that, the operation authorization information carries first signature information, the first signature information being used to indicate the signature of a target network element, and the target network element being the network element that sends the operation authorization information to the application function network element; before determining that the first operation is within the scope of the operation authority indicated by the operation authorization information and performing the first operation on the first tag, the method further includes: determining that the first signature information and second signature information match, the second signature information being used to indicate the signature of the target network element.
4. The method according to claim 3, characterized in that, before determining that the first signature information and second signature information match, the method further includes: receiving the second signature information from the target network element.
5. The method according to any one of claims 1-4, characterized in that, the operation authorization information is further used to indicate at least one of the following information corresponding to the operation authority of the application function network element: area range, tag range, permission period.
6. The method according to any one of claims 1-5, characterized in that, the operation authorization information is used to indicate the operation authority of the application function network element to perform the first operation and the second operation.
7. The method according to claim 6, characterized in that, the method further includes: receiving a second operation request from the application function network element, the second operation request being used to indicate performing a second operation on the first tag; determining that the second operation is within the scope of the operation authority indicated by the operation authorization information, and performing the second operation on the first tag.
8. The method according to any one of claims 1-5, characterized in that, the operation authorization information is used to indicate the operation authority of the application function network element to perform the first operation.
9. The method according to any one of claims 1-8, characterized in that, the method further includes: sending an operation confirmation request message to the application function network element, the operation confirmation request message being used to indicate confirmation of whether to perform the first operation on the first tag; receiving an operation confirmation response message from the application function network element, the operation confirmation response message being used to indicate confirmation of performing the first operation on the first tag; performing the first operation includes: In response to the operation confirmation response message, perform the first operation on the first tag.
10. The method according to claim 9, wherein, the operation confirmation response message includes the operation authorization information; before performing the first operation on the first tag in response to the operation confirmation response message, the method further includes: determining that the first operation is within the operation authority range indicated by the operation authorization information in the operation confirmation response message.
11. The method according to any one of claims 1-10, wherein, the method further includes: receiving a first password from the application function network element, the first password being the password corresponding to the first tag; performing the first operation on the first tag includes: sending indication information and the first password to the first tag, the indication information being used to instruct the first tag to perform the first operation, and the first password being used to instruct the first operation to be performed when the first password is consistent with the local password of the first tag.
12. The method according to claim 11, wherein, the method further includes: receiving a password printing request from the application function network element, the password printing request being used to instruct writing a second password to the first tag; determining that the application function network element has the write permission for the first tag, and writing the second password to the first tag, the second password being the local password of the first tag.
13. A communication method, wherein, the method includes: sending a first operation request and operation authorization information to a first network element, the first operation request being used to instruct performing a first operation on a first tag, and the operation authorization information being used to indicate the operation authority of the application function network element; receiving a first operation response message from the first network element, the first operation response message being used to indicate the execution result of the first operation.
14. The method according to claim 13, wherein, the method further includes: sending a first message to a target network element, the first message being used to indicate a request to obtain the operation authorization information, the target network element being the first network element or a second network element; receiving the operation authorization information from the target network element.
15. The method according to claim 13 or 14, wherein, the operation authorization information carries first signature information, the first signature information being used to indicate the signature of the target network element, the target network element being the network element that sends the operation authorization information to the application function network element.
16. The method according to any one of claims 13-15, wherein, the operation authorization information is further used to indicate at least one of the following information corresponding to the operation authority of the application function network element: area range, tag range, permission period.
17. The method according to any one of claims 13-16, wherein, the operation authorization information is used to indicate the operation authority for the application function network element to perform the first operation and a second operation.
18. The method according to claim 17, wherein, the method further includes: Send a second operation request to the first network element, where the second operation request is used to indicate to perform a second operation on the first label; Receive a second operation response message from the first network element, where the second operation response message is used to indicate the execution result of the second operation.
19. The method according to any one of claims 13-16, characterized in that, The operation authorization information is used to indicate the operation permission for the application function network element to perform the first operation.
20. The method according to any one of claims 13-19, characterized in that, The method further includes: Receive an operation confirmation request message from the first network element, where the operation confirmation request message is used to indicate whether to confirm performing the first operation on the first label; Send an operation confirmation response message to the first network element, where the operation confirmation response message is used to indicate confirmation of performing the first operation on the first label.
21. The method according to claim 20, characterized in that, The operation confirmation response message includes the operation authorization information.
22. The method according to any one of claims 13-21, characterized in that, The method further includes: Send a first password to the first network element, where the first password is the password corresponding to the first label, and the first password is used to indicate that when the first password is the same as the local password of the first label, perform the first operation.
23. The method according to claim 22, characterized in that, The method further includes: Send a password printing request to the first network element, where the password printing request is used to indicate writing a second password to the first label, and the second password is the local password of the first label.
24. A communication method, characterized in that, The method includes: Receive indication information and a first password from a first network element, where the indication information is used to indicate performing a first operation; Determine that the first password is the same as the local password, and perform the first operation.
25. The method according to claim 24, characterized in that, The method further includes: Receive a second password from the first network element; Write the second password as the local password.
26. A communication device, characterized in that, The device includes: A receiving unit, configured to receive a first operation request and operation authorization information from an application function network element, where the first operation request is used to indicate performing a first operation on a first label, and the operation authorization information is used to indicate the operation permission of the application function network element; A processing unit, configured to determine that the first operation is within the operation permission range indicated by the operation authorization information, and perform the first operation on the first label.
27. The device according to claim 26, characterized in that, The device further includes: a sending unit; The receiving unit is further configured to receive a first message from the application function network element, where the first message is used to indicate a request to obtain the operation authorization information; The sending unit is configured to, in response to the first message, send the operation authorization information to the application function network element.
28. The device according to claim 26 or 27, characterized in that, The operation authorization information carries first signature information, and the first signature information is used to indicate the signature of the target network element, where the target network element is the network element that sends the operation authorization information to the application function network element; The processing unit is further configured to determine that the first signature information matches the second signature information before performing the first operation on the first tag when it is determined that the first operation is within the operation authority range indicated by the operation authorization information, where the second signature information is used to indicate the signature of the target network element.
29. The apparatus according to claim 28, wherein, The receiving unit is further configured to receive the second signature information from the target network element.
30. The apparatus according to any one of claims 26-29, wherein, The operation authorization information is further used to indicate at least one of the following information corresponding to the operation authority of the application function network element: area range, tag range, permission period.
31. The apparatus according to any one of claims 26-30, wherein, The operation authorization information is used to indicate the operation authority for the application function network element to perform the first operation and the second operation.
32. The apparatus according to claim 31, wherein, The receiving unit is further configured to receive a second operation request from the application function network element, where the second operation request is used to indicate to perform a second operation on the first tag; The processing unit is further configured to determine that the second operation is within the operation authority range indicated by the operation authorization information and perform the second operation on the first tag.
33. The apparatus according to any one of claims 26-30, wherein, The operation authorization information is used to indicate the operation authority for the application function network element to perform the first operation.
34. The apparatus according to any one of claims 26-33, wherein, The apparatus further includes: a sending unit; The sending unit is configured to send an operation confirmation request message to the application function network element, where the operation confirmation request message is used to indicate to confirm whether to perform the first operation on the first tag; The receiving unit is further configured to receive an operation confirmation response message from the application function network element, where the operation confirmation response message is used to indicate to confirm performing the first operation on the first tag; The processing unit is specifically configured to perform the first operation on the first tag in response to the operation confirmation response message.
35. The apparatus according to claim 34, wherein, The operation confirmation response message includes the operation authorization information; The processing unit is further configured to determine that the first operation is within the operation authority range indicated by the operation authorization information in the operation confirmation response message before performing the first operation on the first tag in response to the operation confirmation response message.
36. The apparatus according to any one of claims 26-35, wherein, The apparatus further includes: a sending unit; The receiving unit is further configured to receive a first password from the application function network element, where the first password is the password corresponding to the first tag. The processing unit is specifically configured to send indication information and the first password to the first tag through the sending unit, where the indication information is used to instruct the first tag to perform the first operation, and the first password is used to instruct to perform the first operation when the first password is consistent with the local password of the first tag.
37. The apparatus according to claim 36, wherein, the receiving unit is further configured to receive a password printing request from the application function network element, where the password printing request is used to instruct to write a second password to the first tag; the processing unit is further configured to determine that the application function network element has the write permission for the first tag, and write the second password to the first tag, where the second password is the local password of the first tag.
38. A communication apparatus, wherein, the apparatus includes: a sending unit, configured to send a first operation request and operation authorization information to a first network element, where the first operation request is used to instruct to perform a first operation on a first tag, and the operation authorization information is used to indicate the operation permission of the application function network element; a receiving unit, configured to receive a first operation response message from the first network element, where the first operation response message is used to indicate the execution result of the first operation.
39. The apparatus according to claim 38, wherein, the sending unit is further configured to send a first message to a target network element, where the first message is used to indicate a request to obtain the operation authorization information, and the target network element is the first network element or a second network element; the receiving unit is further configured to receive the operation authorization information from the target network element.
40. The apparatus according to claim 38 or 39, wherein, the operation authorization information carries first signature information, where the first signature information is used to indicate the signature of the target network element, and the target network element is the network element that sends the operation authorization information to the application function network element.
41. The apparatus according to any one of claims 38-40, wherein, the operation authorization information is further used to indicate at least one of the following information corresponding to the operation permission of the application function network element: area range, tag range, permission period.
42. The apparatus according to any one of claims 38-41, wherein, the operation authorization information is used to indicate the operation permission for the application function network element to perform the first operation and the second operation.
43. The apparatus according to claim 42, wherein, the sending unit is further configured to send a second operation request to the first network element, where the second operation request is used to instruct to perform a second operation on the first tag; the receiving unit is further configured to receive a second operation response message from the first network element, where the second operation response message is used to indicate the execution result of the second operation.
44. The apparatus according to any one of claims 38-41, wherein, the operation authorization information is used to indicate the operation permission for the application function network element to perform the first operation.
45. The apparatus according to any one of claims 38-44, wherein, The receiving unit is further configured to receive an operation confirmation request message from the first network element, where the operation confirmation request message is used to indicate whether to perform the first operation on the first tag; The sending unit is further configured to send an operation confirmation response message to the first network element, where the operation confirmation response message is used to indicate confirmation of performing the first operation on the first tag.
46. The apparatus according to claim 45, wherein, the operation confirmation response message includes the operation authorization information.
47. The apparatus according to any one of claims 38-46, wherein, the sending unit is further configured to send a first password to the first network element, where the first password is the password corresponding to the first tag, and the first password is used to indicate that when the first password is consistent with the local password of the first tag, the first operation is performed.
48. The apparatus according to claim 47, wherein, the sending unit is further configured to send a password printing request to the first network element, where the password printing request is used to indicate writing a second password to the first tag, and the second password is the local password of the first tag.
49. A communication apparatus, wherein, the apparatus includes: a receiving unit, configured to receive indication information and a first password from a first network element, where the indication information is used to indicate performing a first operation; a processing unit, configured to determine that the first password is consistent with the local password and perform the first operation.
50. The apparatus according to claim 49, wherein, the receiving unit is further configured to receive a second password from the first network element; the processing unit is further configured to write the second password as the local password.
51. A communication apparatus, wherein, the apparatus includes: a processor, configured to execute computer instructions stored in a memory, and when the computer instructions are executed, cause the apparatus to perform the method according to any one of claims 1-12, or perform the method according to any one of claims 13-23, or perform the method according to claim 24 or 25.
52. A communication apparatus, wherein, the apparatus includes: a processor and an interface circuit, where the processor is configured to communicate with other apparatuses through the interface circuit and perform the method according to any one of claims 1-12, or perform the method according to any one of claims 13-23, or perform the method according to claim 24 or 25.
53. A computer-readable storage medium, wherein, the computer-readable storage medium includes instructions, and when the instructions are run, cause the method according to any one of claims 1-12 to be implemented, or cause the method according to any one of claims 13-23 to be implemented, or cause the method according to claim 24 or 25 to be implemented.
54. A computer program product, wherein, When the computer program product is executed, the method according to any one of claims 1-12 is implemented, or the method according to any one of claims 13-23 is implemented, or the method according to claim 24 or 25 is implemented.
55. A chip system, characterized in that the chip system includes one or more interface circuits and one or more processors; the interface circuit and the processor are interconnected by a line; the processor receives and executes computer instructions from the memory of the electronic device through the interface circuit to implement the method according to any one of claims 1-12, or to implement the method according to any one of claims 13-23, or to implement the method according to claim 24 or 25.
56. A communication system, characterized in that it includes: an application function network element and a first network element; the first network element executes the method according to any one of claims 1-12; the application function network element correspondingly executes the method according to any one of claims 13-23.