Communication method and related equipment

By obtaining the identification information of the first network element and determining the data to be analyzed based on its token, the problem of being unable to perform fine-grained authorization management of the service network element data in the prior art is solved, and data security and management efficiency are improved.

CN120075801APending Publication Date: 2025-05-30HUAWEI TECH CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202311622819.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-29
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The prior art cannot perform fine-grained authorization management on data used to evaluate service network elements, resulting in inadequate data security and management efficiency.

Method used

By acquiring the identification information of the first network element, determining the data to be analyzed from the second network element based on its token, fine-grained authorization management of the data is realized.

Benefits of technology

It realizes fine-grained authorization management of business network element evaluation data, improving data security and management efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120075801A_ABST
    Figure CN120075801A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a communication method and related equipment, and relates to the field of communication. In the method, a fourth network element acquires identification information of a first network element; and the fourth network element determines the to-be-analyzed data from the second network element based on the token of the first network element. The token corresponds to the identification information of the first network element, the token comprises first information, and the first information indicates the data type of the first network element having the reading authority. The to-be-analyzed data is used for evaluating the service network element. And the fourth network element sends the to-be-analyzed data to the first network element. Therefore, according to the scheme, fine-grained authorization management can be carried out on the data from the second network element by utilizing the token of the first network element, and different to-be-analyzed data are distributed for different first network elements.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present application relate to the field of communications, and in particular, to a communication method and related devices. Background Art

[0002] The identification of malicious behavior-related data may be related to various events, such as predefined service operation violations (e.g., malformed messages), unexpected configuration changes, message requests exceeding configuration limits, and current resource utilization information (if resource utilization limits are exceeded). Such information can be indirectly collected from the evaluation target in the form of security logs or reports as inference data through Operation Administration and Maintenance (OAM).

[0003] For new data related to malicious behavior, the collection scheme refers to Figure 1A , Figure 1A which is a schematic flow diagram of a multi-faceted NF data collection provided for the embodiments of the present application; Figure 1A It shows data collection and data opening for security evaluation, including the following steps:

[0004] 1. A Network Data Analytics Function (NWDAF) collects data based on the operator's local policy. The NWDAF can collect data and provide functions to external operators to enable (assist) security evaluation and monitoring.

[0005] 2a. The NWDAF collects load data of a Network Function (NF). Among them, the load data of the NF can be collected from a Network Repository Function (NRF).

[0006] 2b. The NWDAF collects NF resource utilization data from OAM. The NF resource utilization data is data such as CPU and memory.

[0007] 2c. The NWDAF collects NF exception event data from OAM. Specifically, the NWDAF subscribes to the management service of OAM and collects data on one or more evaluated events related to the target NF and events related to various specific malicious behaviors.

[0008] The NWDAF sends the collected data to enable security evaluation and obtains a response. Specifically, refer to step 3a and step 3b.

[0009] 3a. The NWDAF acts as a data collection agent and provides the collected data to operator functions outside the 3GPP domain through the NEF, such as the External Operator Managed Function (EOMF), which is a network element enabling security assessment and detection.

[0010] 3b. The external operator function sends a security assessment response to the NWADF.

[0011] Figure 1A In the shown process, the NEF can only send all data to the EOMF for analysis.

[0012] Therefore, how to solve the above problems is a hot topic being studied by those skilled in the art. Summary of the Invention

[0013] This application provides a communication method and related devices, which can perform fine-grained authorization on data for evaluating service network elements.

[0014] In a first aspect, a communication method is provided. This communication method can be executed by a communication device or by a chip in the communication device. Exemplarily, the communication device is the fourth network element.

[0015] The above communication method includes the following steps: obtaining the identification information of the first network element; determining the data to be analyzed from the second network element based on the token of the first network element. The above token corresponds to the identification information of the first network element, and the token includes a first piece of information, which indicates the data types that the first network element has the read permission for. The above data to be analyzed is used to evaluate the service network element; sending the data to be analyzed to the first network element.

[0016] Among them, the above service network element is a network element carrying terminal services.

[0017] It can be seen that in this solution, the identification information of the first network element is obtained first. Since the identification information of the first network element corresponds to the token, the token of the first network element can be determined based on the identification information of the first network element; then the data to be analyzed sent to the first network element is determined based on the token of the first network element, realizing fine-grained authorization management of the data from the second network element and allocating different data to be analyzed to different first network elements.

[0018] In a possible implementation manner of the first aspect, the determining the data to be analyzed from the second network element based on the token of the first network element specifically includes the following steps: determining the data to be analyzed based on the token and the collected data of the second network element, and the data type of the data to be analyzed is all or part of the data types of the collected data.

[0019] Among them, the second network element obtains data from the service network element to obtain the above collected data.

[0020] In this solution, the data to be analyzed can be determined based on the token and the collected data of the second network element. The data type of the data to be analyzed is the data type of all or part of the collected data, that is, the data to be analyzed can be all or part of the collected data.

[0021] In a possible implementation manner of the first aspect, the obtaining of the identification information of the first network element specifically includes the following steps: receiving a data analysis request from the second network element. The data analysis request includes the identification information of the first network element, and the data analysis request is used to trigger the first network element to perform data analysis.

[0022] In this solution, the identification information of the first network element can be obtained based on the data analysis request sent by the second network element.

[0023] In a possible implementation manner of the first aspect, the data analysis request further includes the collected data of the second network element and a second piece of information indicating the data type of the collected data. The determining of the data to be analyzed from the second network element based on the token of the first network element specifically includes the following steps: determining the data to be analyzed from the collected data based on the token and the second piece of information. The data type of the data to be analyzed is the intersection data type of the data type indicated by the token and the data type indicated by the second piece of information.

[0024] In this solution, by comparing the data types based on the second piece of information and the token carried in the data analysis request, the data to be analyzed can be determined; the intersection data type can be the data type indicated by the token or a part of the data types indicated by the token.

[0025] In a possible implementation manner of the first aspect, after receiving the data analysis request from the second network element, the communication method further includes the following steps: sending a token check request to the first network element. Receiving a token check response from the first network element, where the token check response includes the token of the first network element.

[0026] In this solution, the first network element responds to the token check request by sending a token check response to obtain the token of the first network element in the token check response.

[0027] In a possible implementation manner of the first aspect, after receiving the data analysis request from the second network element, the communication method further includes: sending a data analysis request to the first network element. Receiving a data analysis request response from the first network element. The determining of the data to be analyzed from the second network element based on the token of the first network element specifically includes the following steps: when the data analysis request response indicates that the first network element accepts the data analysis request, determining the data to be analyzed based on the token of the first network element.

[0028] In this solution, when it is determined based on the data analysis request response that the first network element has accepted the data analysis request, the data to be analyzed sent to the first network element is determined based on the token of the first network element, and the data reading permission of the first network element is verified according to the token to ensure data security.

[0029] In a possible implementation manner of the first aspect, the above data analysis request further includes the data type that the second network element expects to analyze. When the first network element does not support reading the data type that the second network element expects to analyze, the data analysis request response includes the data types that the first network element cannot read.

[0030] In this solution, the data types that the first network element cannot read are carried in the data analysis request response, so that the second network element can re-adjust the expected data types to be analyzed as needed.

[0031] In a possible implementation manner of the first aspect, the above determining the data to be analyzed from the second network element based on the token of the first network element specifically includes the following steps: verifying the token of the first network element. When the verification result of the token is passed, a data analysis request response is sent to the second network element. The above data analysis request response includes the identification information of the first network element and the first information. Receive the data to be analyzed of the second network element, and the data type of the data to be analyzed is the data type indicated by the first information.

[0032] In this solution, when the token of the first network element passes the verification, the first information of the first network element is carried in the data analysis request response to instruct the second network element to collect data corresponding to the data type indicated by the first information, realizing data-directed collection.

[0033] In a possible implementation manner of the first aspect, the above sending the data to be analyzed to the first network element specifically includes the following steps: verifying the token of the first network element again. When the verification result of the token is passed, the data to be analyzed is sent to the first network element.

[0034] In this solution, before sending the data to be analyzed to the first network element, the token of the first network element is verified again to ensure that the first network element has the data reading permission for the data to be analyzed.

[0035] In a possible implementation manner of the first aspect, the above obtaining the identification information of the first network element specifically includes the following steps: receiving a data subscription request sent by the first network element, the data subscription request includes the identification information of the first network element, and the data subscription request is used to trigger the second network element to collect data.

[0036] In this solution, the identification information of the first network element is obtained through the data subscription request sent by the first network element.

[0037] In a possible implementation manner of the first aspect, determining the data to be analyzed based on the token of the first network element specifically includes the following steps: verifying the token of the first network element. When the verification result of the token is passed, sending the identification information of the first network element and the first information to the second network element. Receiving the data analysis request from the second network element, where the data analysis request includes the data to be analyzed and the identification information of the first network element, and the data type of the data to be analyzed is the data type indicated by the first information.

[0038] In this solution, when the token of the first network element passes the verification, the first information is sent to the second network element to indicate the data that the second network element needs to collect. The second network element collects the data according to the first information to obtain the data to be analyzed, and then carries the data to be analyzed in the data analysis request.

[0039] In a possible implementation manner of the first aspect, sending the data to be analyzed to the first network element specifically includes the following steps: sending a data analysis request to the first network element.

[0040] In this solution, the data to be analyzed is sent to the first network element by carrying the data to be analyzed in the data analysis request.

[0041] In a possible implementation manner of the first aspect, verifying the token of the first network element specifically includes the following steps: sending a data subscription request to the second network element. Receiving the token query request sent by the second network element, where the token query request includes the identification information of the first network element. Responding to the token query request and verifying the token of the first network element.

[0042] In this solution, a data subscription request is sent to the second network element, and the data subscription request includes the identification information of the first network element. The second network element determines whether to check the token of the first network element according to the identification information of the first network element. When it is necessary to check the token of the first network element, the second network element sends a token query request. Responding to the token query request of the second network element, the token of the first network element is verified.

[0043] In a possible implementation manner of the first aspect, the above communication method further includes the following steps: receiving the token registration request of the first network element, where the token registration request includes the identification information of the first network element and the token of the first network element. Storing the identification information of the first network element and the token of the first network element.

[0044] In this solution, the first network element realizes token registration by initiating a token registration request.

[0045] In a possible implementation manner of the first aspect, storing the identification information of the first network element and the token of the first network element specifically includes the following steps: performing validity verification on the token of the first network element. When the verification result of the validity verification passes, storing the identification information of the first network element and the token of the first network element.

[0046] In this solution, before storing the identification information and the token of the first network element, the token of the first network element is subjected to validity verification. When the validity verification passes, the identification information of the first network element and the token of the first network element are stored to ensure the validity of the token required for registration.

[0047] In a possible implementation manner of the first aspect, the above data types include at least one of the following: load data of a service network element, resource utilization rate data of a service network element, abnormal event data of a service network element, or energy consumption data of a service network element.

[0048] In a possible implementation manner of the first aspect, the above load data comes from a network storage network element, or the above resource utilization rate data and / or abnormal event data come from an operation and maintenance management network element.

[0049] In this solution, the load data of the service network element is obtained through the network storage network element, and the resource utilization rate data and / or abnormal event data of the service network element are obtained through the operation and maintenance management network element.

[0050] In a second aspect, the present application further provides a communication method, which can be executed by a communication device or by a chip in the communication device. Exemplarily, the communication device is a verification server.

[0051] The above communication method includes the following steps: receiving a token issuance request of a first network element, where the token issuance request includes the identification information of the first network element. Sending a token grant response to the first network element, where the token grant response includes the token of the first network element. The above token corresponds to the identification information of the first network element, and the token includes first information, and the first information indicates the data types that the first network element has read permissions for.

[0052] In this solution, in response to the token issuance request of the first network element, a token is granted to the first network element to indicate the data types that the first network element has read permissions for.

[0053] In a possible implementation manner of the second aspect, after receiving the token issuance request of the first network element, the above communication method further includes the following steps: sending a subscription information query request to a third network element, where the subscription information query request includes the identification information of the first network element. Receiving a subscription information response sent by the third network element, where the subscription information response includes the trust level and / or service type of the first network element. The token of the first network element is determined according to the identification information of the first network element and / or the subscription information response.

[0054] In this solution, a subscription information response is obtained from a third network element based on the identification information of a first network element. The subscription information response includes the trust level and / or service type of the first network element. Furthermore, a token for the first network element is determined based on the identification information of the first network element and the subscription information response.

[0055] In a possible implementation manner of the second aspect, the above token issuance request further includes third information, and the third information indicates the data type that the first network element prefers to read. The token of the first network element is determined based on at least one of the identification information of the first network element, the subscription information response, and the third information.

[0056] In a third aspect, the present application further provides a communication method, which is applied to a first network element. The communication method can be executed by the first network element or by a chip in the first network element.

[0057] The above communication method includes the following steps: sending a token issuance request to an authentication server, where the token issuance request includes the identification information of the first network element. Receiving a token grant response sent by the authentication server, where the token grant response includes the token of the first network element. The token corresponds to the identification information of the first network element, and the token includes first information, and the first information indicates the data type that the first network element has read permission for.

[0058] In this solution, the first network element sends a token issuance request to the authentication server and receives the token grant response sent by the authentication server to obtain the corresponding token.

[0059] In a possible implementation manner of the third aspect, the token of the first network element is determined based on the identification information of the first network element and / or the subscription information response from the third network element, and the subscription information response includes the trust level and / or service type of the first network element.

[0060] In a possible implementation manner of the third aspect, the above token issuance request further includes third information, and the third information indicates the data type that the first network element prefers to read. The token of the first network element is determined based on at least one of the identification information of the first network element, the subscription information response, and the third information.

[0061] In a fourth aspect, the present application further provides a communication method, which is applied to a first network element. The communication method can be executed by the first network element or by a chip in the first network element.

[0062] The above communication method includes the following steps: receiving data to be analyzed sent by a fourth network element. The data to be analyzed is determined by the fourth network element based on the token of the first network element, and the data to be analyzed comes from a second network element. The token corresponds to the identification information of the first network element, and the token includes first information, and the first information indicates the data type that the first network element has read permission for. The data to be analyzed is used to evaluate a service network element.

[0063] In this solution, the data to be analyzed sent by the fourth network element is received. The data to be analyzed is determined by the fourth network element based on the token of the first network element, enabling fine-grained authorization management for the data from the second network element and allocating different data to be analyzed to different first network elements.

[0064] In a possible implementation manner of the fourth aspect, the above communication method further includes the following steps: receiving a token check request sent by the fourth network element; sending a token check response to the fourth network element, where the token check response includes the token of the first network element.

[0065] In this solution, the first network element sends a token check response in response to the token check request of the fourth network element, and the token of the first network element is carried in the token check response, so that the fourth network element can obtain the token of the first network element.

[0066] In a possible implementation manner of the fourth aspect, the above communication method further includes the following steps: receiving a data analysis request sent by the fourth network element, where the data analysis request includes the identification information of the first network element, and the data analysis request is used to trigger the first network element to perform data analysis; sending a data analysis request response to the fourth network element.

[0067] In this solution, the fourth network element determines whether to accept the data analysis request according to the identification information of the first network element, and the information indicating whether to accept the data analysis request is carried in the data analysis request response.

[0068] In a possible implementation manner of the fourth aspect, the above data analysis request further includes the data type expected to be analyzed by the second network element. When the first network element does not support reading the expected data type, the data analysis request response includes the data types that the first network element cannot read.

[0069] In this solution, the data types that the first network element cannot read are carried in the data analysis request response, so that the second network element can re-adjust the expected data type according to the need.

[0070] In a possible implementation manner of the fourth aspect, the above communication method further includes the following steps: sending a data subscription request to the fourth network element, where the data subscription request includes the identification information of the first network element, and the data subscription request is used to trigger the second network element to collect data.

[0071] In this solution, through the data subscription request sent by the first network element, the fourth network element can obtain the identification information of the first network element.

[0072] In a possible implementation manner of the fourth aspect, receiving the data to be analyzed sent by the fourth network element specifically includes the following steps: receiving a data analysis request sent by the fourth network element, where the data analysis request includes the data to be analyzed and the identification information of the first network element, and the data type of the data to be analyzed is the data type indicated by the first piece of information.

[0073] In this solution, the data to be analyzed is carried in the data analysis request so that the first network element can obtain the data to be analyzed.

[0074] In a possible implementation manner of the fourth aspect, the above communication method further includes the following steps: sending a token registration request to the fourth network element, where the token registration request includes the identification information of the first network element and the token of the first network element.

[0075] In this solution, the first network element realizes token registration by initiating a token registration request, so that the fourth network element can determine the data to be analyzed according to the token of the first network element.

[0076] In a possible implementation manner of the fourth aspect, the above data type includes at least one of the following: load data of a service network element, resource utilization rate data of a service network element, abnormal event data of a service network element, or energy consumption data of a service network element.

[0077] In a possible implementation manner of the fourth aspect, the above load data comes from a network storage network element, or the above resource utilization rate data and / or abnormal event data come from an operation and maintenance management network element.

[0078] Fifth aspect, the present application further provides a communication method, which is applied to a communication system. The communication system includes a first network element and a fourth network element. The communication method includes the following steps: The fourth network element obtains the identification information of the first network element. The fourth network element determines the data to be analyzed from the second network element based on the token of the first network element. The token corresponds to the identification information of the first network element. The token includes a first piece of information, and the first piece of information indicates the data type that the first network element has the read permission for. The data to be analyzed is used to evaluate the service network element. The fourth network element sends the data to be analyzed to the first network element. The first network element receives the data to be analyzed.

[0079] In a possible implementation manner of the fifth aspect, the fourth network element determines the data to be analyzed from the second network element based on the token of the first network element, specifically including the following steps: The fourth network element determines the data to be analyzed based on the token and the collected data of the second network element, and the data type of the data to be analyzed is the data type of all or part of the collected data.

[0080] In a possible implementation manner of the fifth aspect, the above-mentioned fourth network element obtains the identification information of the first network element, which specifically includes the following steps: The fourth network element receives a data analysis request from the second network element. The data analysis request includes the identification information of the first network element, and the data analysis request is used to trigger the first network element to perform data analysis.

[0081] In a possible implementation manner of the fifth aspect, the above-mentioned data analysis request further includes the collected data of the second network element and a second piece of information, and the second piece of information indicates the data type of the collected data. The above-mentioned fourth network element determines the data to be analyzed from the second network element based on the token of the first network element, which specifically includes the following steps: The fourth network element determines the data to be analyzed from the collected data based on the token and the second piece of information. The data type of the data to be analyzed is the intersection data type of the data type indicated by the token and the data type indicated by the second piece of information.

[0082] In a possible implementation manner of the fifth aspect, after the fourth network element receives the data analysis request from the second network element, the above-mentioned communication method further includes the following steps: The fourth network element sends a token check request to the first network element. The first network element sends a token check response to the fourth network element, and the token check response includes the token of the first network element.

[0083] In a possible implementation manner of the fifth aspect, after the fourth network element receives the data analysis request from the second network element, the above-mentioned communication method further includes the following steps: The fourth network element sends a data analysis request to the first network element. The first network element sends a data analysis request response to the fourth network element. The fourth network element determines the data to be analyzed from the second network element based on the token of the first network element, which specifically includes the following steps: When the data analysis request response indicates that the first network element accepts the data analysis request, the fourth network element determines the data to be analyzed based on the token of the first network element.

[0084] In a possible implementation manner of the fifth aspect, the above-mentioned data analysis request further includes the data type that the second network element expects to analyze. When the first network element does not support reading the data type that is expected to be analyzed, the data analysis request response includes the data type that the first network element cannot read.

[0085] In a possible implementation manner of the fifth aspect, the above-mentioned fourth network element determines the data to be analyzed from the second network element based on the token of the first network element, which specifically includes the following steps: The fourth network element verifies the token of the first network element. When the verification result of the token is verification passed, the fourth network element sends a data analysis request response to the second network element, and the data analysis request response includes the identification information of the first network element and a first piece of information. The second network element sends the data to be analyzed to the fourth network element, and the data type of the data to be analyzed is the data type indicated by the first piece of information.

[0086] In a possible implementation of the fifth aspect, the above-mentioned fourth network element sends data to be analyzed to the first network element, including: the fourth network element re-verifies the token of the first network element. When the verification result of the token passes, the fourth network element sends the data to be analyzed to the first network element.

[0087] In a possible implementation of the fifth aspect, the above-mentioned fourth network element obtains the identification information of the first network element, specifically including the following steps: the first network element sends a data subscription request to the fourth network element. The data subscription request includes the identification information of the first network element, and the data subscription request is used to trigger the second network element to collect data. The fourth network element receives the data subscription request.

[0088] In a possible implementation of the fifth aspect, the above-mentioned fourth network element determines the data to be analyzed based on the token of the first network element, specifically including the following steps: the fourth network element verifies the token of the first network element. When the verification result of the token passes, the fourth network element sends the identification information of the first network element and the first information to the second network element. The fourth network element receives the data analysis request from the second network element, and the data analysis request includes the data to be analyzed and the identification information of the first network element, and the data type of the data to be analyzed is the data type indicated by the first information.

[0089] In a possible implementation of the fifth aspect, the above-mentioned fourth network element sends the data to be analyzed to the first network element, specifically including the following steps: the fourth network element sends a data analysis request to the first network element.

[0090] In a possible implementation of the fifth aspect, the above-mentioned fourth network element verifies the token of the first network element, specifically including the following steps: the fourth network element sends the data subscription request to the second network element. The second network element sends a token query request to the fourth network element, and the token query request includes the identification information of the first network element. In response to the token query request, the fourth network element verifies the token of the first network element.

[0091] In a possible implementation of the fifth aspect, the above-mentioned communication method further includes the following steps: the fourth network element receives a token registration request from the first network element, and the token registration request includes the identification information of the first network element and the token of the first network element. The fourth network element stores the identification information of the first network element and the token of the first network element.

[0092] In a possible implementation of the fifth aspect, the above-mentioned fourth network element stores the identification information of the first network element and the token of the first network element, specifically including the following steps: the fourth network element performs a validity check on the token of the first network element. When the check result of the validity check passes, the fourth network element stores the identification information of the first network element and the token of the first network element.

[0093] In a possible implementation of the fifth aspect, the above data types include at least one of the following: load-related data of a service network element, resource utilization data of a service network element, abnormal event data of a service network element, or energy consumption data of a service network element.

[0094] In a possible implementation of the fifth aspect, the above load data comes from a network storage network element, or the above resource utilization data and / or abnormal event data come from an operation and maintenance management network element.

[0095] In a sixth aspect, the present application further provides a communication method, which is applied to a communication system. The communication system includes an authentication server and a first network element. The above communication method includes the following steps: The authentication server receives a token issuance request from the first network element. The token issuance request includes the identification information of the first network element. The first network element receives a token grant response sent by the authentication server. The token grant response includes a token of the first network element. The token corresponds to the identification information of the first network element. The token includes a first piece of information, and the first piece of information indicates the data types that the first network element has read permissions for.

[0096] In this solution, the authentication server responds to the token issuance request of the first network element and grants a token to the first network element to indicate the data types that the first network element has read permissions for.

[0097] In a possible implementation of the sixth aspect, after the authentication server receives the token issuance request of the first network element, the above communication method further includes the following steps: The authentication server sends a subscription information query request to a third network element. The subscription information query request includes the identification information of the first network element. The authentication server receives a subscription information response sent by the third network element. The subscription information response includes the trust level and / or service type of the first network element. The token of the first network element is determined based on the identification information of the first network element and / or the subscription information response.

[0098] In a possible implementation of the sixth aspect, the above token issuance request further includes a third piece of information, and the third piece of information indicates the data types that the first network element prefers to read. The token of the first network element is determined based on at least one of the identification information of the first network element, the subscription information response, and the third piece of information.

[0099] In a seventh aspect, the present application further provides a communication device, including a module for executing the communication method according to any one of the first aspect to the sixth aspect.

[0100] In an eighth aspect, the present application further provides a communication device, including a processor and an interface circuit. The interface circuit is configured to receive signals from other communication devices outside the communication device and transmit them to the processor, or send signals from the processor to other communication devices outside the communication device. The processor is configured to implement the communication method according to any one of the first aspect to the sixth aspect through logic circuits or by executing code instructions.

[0101] In a ninth aspect, the present application further provides a computer-readable storage medium, in which a computer program or instructions are stored. When the computer program or instructions are executed by a communication device, the communication method according to any one of the first aspect to the sixth aspect is implemented.

[0102] In a tenth aspect, the present application further provides a computer program product containing instructions. When the computer program product runs on a computer, the computer is caused to execute the communication method according to any one of the first aspect to the sixth aspect.

[0103] In an eleventh aspect, the present application further provides a chip, which includes a processor and a data interface. The processor reads instructions stored on a memory through the data interface and executes the communication method according to any one of the first aspect to the sixth aspect.

[0104] Optionally, as an implementation manner, the chip may further include a memory, in which instructions are stored. The processor is configured to execute the instructions stored on the memory. When the instructions are executed, the processor is configured to execute the communication method according to any one of the first aspect to the sixth aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0105] The following introduces the drawings used in the embodiments of the present application.

[0106] Figure 1A It is a schematic flow chart of a method for collecting NF data in multiple aspects provided by an embodiment of the present application;

[0107] Figure 1B It is a schematic diagram of a network architecture provided by an embodiment of the present application;

[0108] Figure 1C It is a schematic diagram of token generation and use provided by an embodiment of the present application;

[0109] Figure 2 It is a schematic flow chart of a communication method provided by an embodiment of the present application;

[0110] Figure 3 It is a schematic flow chart of another communication method provided by an embodiment of the present application;

[0111] Figure 4Flow diagram of another communication method provided by an embodiment of the present application;

[0112] Figure 5 Flow diagram of another communication method provided by an embodiment of the present application;

[0113] Figure 6 Flow diagram of another communication method provided by an embodiment of the present application;

[0114] Figure 7 Structural diagram of a communication device provided by an embodiment of the present application;

[0115] Figure 8 Structural diagram of another communication device provided by an embodiment of the present application;

[0116] Figure 9 Structural diagram of another communication device provided by an embodiment of the present application. Detailed implementation manners

[0117] The technical solutions in the present application will be described below with reference to the accompanying drawings.

[0118] In the embodiments of the present application, words such as "exemplary" or "for example" are used to represent examples, illustrations or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Exactly speaking, using words such as "exemplary" or "for example" aims to present relevant concepts in a specific manner.

[0119] "At least one" mentioned in the embodiments of the present application means one or more, and "a plurality" means two or more. "At least one of the following items" or its similar expressions refer to any combination of these items, including any combination of single item or plural items. For example, at least one of a, b, or c can represent: a, b, c, (a and b), (a and c), (b and c), or (a and b and c), where a, b, c can be single or multiple. "And / or" describes the association relationship of associated objects and indicates that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B can be singular or plural. The character " / " generally represents an "or" relationship between the associated objects before and after. And the sequence numbers of the steps in the embodiments of the present application (such as step S1, step S21, etc.) are only used to distinguish different steps, and the magnitudes of the sequence numbers of each step do not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0120] Also, unless otherwise stated, the ordinal numbers such as "first" and "second" are used in the embodiments of the present application to distinguish multiple objects, and are not used to limit the order, time sequence, priority or importance of multiple objects. For example, the first device and the second device are only for the convenience of description, and do not indicate differences in the structures, importance, etc. of the first device and the second device. In some embodiments, the first device and the second device may also be the same device.

[0121] As used in the above embodiments, depending on the context, the term "when..." can be interpreted to mean "if...", or "after...", or "in response to determining...", or "in response to detecting...". The above are only optional embodiments of the present application, and are not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the concept and principle of the present application shall be included in the protection scope of the present application.

[0122] The method of the embodiments of the present application can be applied to future communication networks such as Long Term Evolution (LTE) systems, Long Term Evolution-Advanced (LTE-A) systems, Enhanced Long Term Evolution-Advanced (eLTE), the New Radio (NR) system of the 5th Generation (5G) mobile communication system, and the 6th Generation (6G) mobile communication system, and can also be extended to similar wireless communication systems such as Wireless-Fidelity (WiFi), Worldwide Interoperability for Microwave Access (WIMAX), and cellular systems related to the 3rd Generation Partnership Project (3GPP).

[0123] Figure 1B It is the network architecture applied to the embodiments of the present application, and each network element that may be involved in this network architecture will be described separately.

[0124] 1. Terminal device: Abbreviated as terminal, also known as User Equipment (UE), which can include various handheld devices, vehicle-mounted devices, wearable devices, Internet of Things terminal devices, computing devices, or other processing devices connected to a wireless modem, as well as various forms of terminals, such as Mobile Station (MS), Terminal, soft terminal, access terminal, Subscriber Unit, terminal device station, mobile station, Mobile Station (MS), remote station, remote terminal, mobile device, terminal device agent, terminal device apparatus, etc. For example, water meters, electricity meters, sensors, etc.

[0125] 2. Radio Access Network ((R)AN): It is a device that provides wireless access for terminal devices. Exemplarily, it is a network composed of multiple (R)AN nodes, which can implement wireless physical layer functions, resource scheduling and wireless resource management, wireless access control, and mobility management functions. The (R)AN is connected to the user plane network element through the user plane interface N3 for transmitting the data of the terminal device; the (R)AN establishes a control plane signaling connection with the access and mobility management network element through the control plane interface N2 for realizing functions such as wireless access bearer control.

[0126] Specifically, it can be used to provide network access functions for authorized terminal devices in a specific area and can use transmission tunnels of different qualities according to the level of the terminal device, service requirements, etc.

[0127] (R)AN can manage wireless resources, provide access services for terminal devices, and then complete the forwarding of control signals and terminal device data between the terminal device and the core network.

[0128] The radio access network can have any of the following alternative terms: access network device, access network (Access Network, AN), where the access network device can be a base station, a further evolved node B (gNB), an evolved node B (Evolved Node B, eNB), a transmission reception point (Transmission Reception Point, TRP), a centralized unit (Centralized Unit, CU) node, a distributed unit (Distributed Unit, DU) node, a transmission point (Transmission Point, TP), a receiving point (Receiving Point, RP), a wireless access point (Access Point, AP), or a Worldwide Interoperability for Microwave Access (WiMAX) base station, etc., and there is no limitation in this regard. In this application, the radio access network is described by taking the base station as an example, and the functions performed by the base station are also applicable to other alternative terms of the radio access network.

[0129] 3. User plane network element: mainly responsible for processing user packets, such as forwarding, charging, etc.

[0130] In a 5G communication system, this user plane network element can be a user plane function (User Plane Function, UPF) network element. In future communication systems, the user plane network element can still be a UPF network element, or it can also have other names, which are not limited in this application.

[0131] Among them, the UPF mainly provides service processing functions for the user plane. As the anchor point of the protocol data unit (Protocol Data Units, PDU) session connection, the UPF is responsible for functions including filtering user equipment data packets, service routing, packet forwarding, anchoring function, rate control, generating charging information, quality of service (Quality of Service, QoS) mapping and execution, identifying and routing the uplink identifier to the data network, downlink packet caching, and triggering the notification of the arrival of downlink data, connecting to an external data network, etc.

[0132] 4. Data network: used to provide a network for transmitting data.

[0133] In a 5G communication system, this data network can be a data network (Data Network, DN). In future communication systems, the data network can still be a DN, or it can also have other names, which are not limited in this application.

[0134] Exemplarily, the UE accesses the data network by establishing a session between the UE, the RAN, the UPF, and the DN.

[0135] 5. Network Slice Authentication and Authorization Function: It is mainly responsible for the authentication and authorization of network slices and can interact with the Authentication, Authorization, and Accounting Server (AAA-S) through the Authentication, Authorization, and Accounting Proxy (AAA-P).

[0136] In the 5G communication system, the Network Slice Authentication and Authorization Function can be the Network Slice Specific Authentication and Authorization Function (NSSAAF). In future communication systems, the Network Slice Authentication and Authorization Function can still be the NSSAAF, or it can have other names, which are not limited in this application.

[0137] 6. Authentication Service Function: It is used to perform security authentication on the UE when the UE accesses the network.

[0138] In the 5G communication system, the Authentication Service Function can be the Authentication Server Function (AUSF). In future communication systems, the Authentication Service Function can still be the AUSF, or it can have other names, which are not limited in this application.

[0139] Taking the 5G communication system as an example, exemplarily, the AUSF receives a request from the AMF to authenticate the UE, requests a key from the UDM, and then forwards the key sent by the UDM to the AMF for authentication processing.

[0140] 7. Access and Mobility Management Function: It is mainly used for mobility management and access management, etc., and can be used to implement other functions of the Mobility Management Entity (MME) function except session management, such as user location update, user registration to the network, user handover, etc.

[0141] In a 5G communication system, the access and mobility management function network element may be an Access and Mobility Management Function (AMF) network element. In future communication systems, the access and mobility management function network element may still be an AMF network element, or it may have other names, which are not limited in this application.

[0142] Among them, the AMF is mainly responsible for functions such as UE authentication, UE mobility management, network slice selection, and session management network element selection; serving as the anchor point for N1 and N2 signaling connections and providing routing for N1 / N2 session management (Session Management, SM) messages to the session management network element; maintaining and managing the status information of the UE.

[0143] 8. Session management network element: mainly used for session management (such as session establishment, modification, release, etc.), Internet Protocol (IP) address allocation and management of terminal devices, selection of manageable user plane functions, termination of policy control and charging function interfaces, and downlink data notification, etc. Specific functions include allocating IP addresses for users, selecting UPFs that provide packet forwarding functions, etc.

[0144] In a 5G communication system, the session management network element may be a Session Management Function (SMF) network element. In future communication systems, the session management network element may still be an SMF network element, or it may have other names, which are not limited in this application.

[0145] Among them, the SMF is mainly responsible for all control plane functions of UE session management, including user plane network element selection, IP address allocation, QoS management of sessions, obtaining policy and charging control (PCC) information (from the policy control network element), etc.

[0146] 9. Network slice selection network element: used to select a set of slice instances for the UE, determine the AMF set and the allowed NSSAI for the UE. (NSSAI is the abbreviation of Network Slice Selection Assistance Information, that is, network slice selection assistance information / network slice selection auxiliary information. A network slice is uniquely identified by a single S-NSSAI, and a set of one or more S-NSSAIs is called an NSSAI.)

[0147] In a 5G communication system, the network slice selection network element may be a Network Slice Selection Function (NSSF) network element. In future communication systems, the network slice selection network element may still be the NSSF network element, or it may have other names, which are not limited in this application.

[0148] 10. Network capability open network element: It is used to connect the interaction between other internal network elements of the core network and external application servers of the core network, so as to provide network capability information to external application servers, or provide information of external application servers to core network network elements.

[0149] In a 5G communication system, the network capability open network element may be a NEF network element. In future communication systems, the network capability open network element may still be the NEF, or it may have other names, which are not limited in this application.

[0150] 11. Network storage network element: It is responsible for registering and monitoring the network function services, etc., to realize the automated management, selection and scalability of network function services, and allows each network function to discover the services provided by other network functions. It is used for registering, managing and detecting the status of Network Functions (NFs), to realize the automated management of all NFs. When each NF starts, it must register with the NRF to provide services, and the registration information includes NF type, address, service list, etc.

[0151] In a 5G communication system, the network storage network element may be an NRF network element. In future communication systems, the network storage network element may still be the NRF, or it may have other names, which are not limited in this application.

[0152] 12. Policy control network element: It is used for the unified policy framework to guide network behavior, provides configuration policy information for UEs, and provides policy rule information for control plane function network elements (such as AMF, SMF network elements, etc.).

[0153] In a 5G communication system, the policy control network element may be a Policy Control Function (PCF) network element. In future communication systems, the policy control network element may still be the PCF network element, or it may have other names, which are not limited in this application.

[0154] 13. Data management network element: It is used to process terminal device identification, access authentication, registration and mobility management, etc.

[0155] In a 5G communication system, the data management network element may be a Unified Data Management (UDM) network element. In future communication systems, the data management network element may still be a UDM network element, or it may have other names, which are not limited in this application.

[0156] The UDM network element mainly manages user data, such as subscription information, authentication / authorization information. This includes obtaining subscription information from the data repository and providing it to other network elements (such as the AMF); generating 3GPP authentication credentials for the UE; registering and maintaining the network elements currently serving the UE.

[0157] 14. Application service network element: Interacts with core network elements to provide some services. For example, it interacts with the policy control network element for service policy control, interacts with the network capability open network element to obtain some network capability information or provide some application information to the network, and provides some data network access point information to the policy control network element to generate corresponding data service routing information.

[0158] In a 5G communication system, the application service network element may be an Application Function (AF) network element. In future communication systems, the application service network element may still be an AF network element, or it may have other names, which are not limited in this application. For example, the application service network element may have any of the following replacement words: Application server (AS), AF, third party, third-party application, Application (APP), etc.

[0159] It should be noted that the above "network element" may also be referred to as an entity, device, apparatus, or module, etc., which is not particularly limited in this application. And in this application, for the convenience of understanding and description, the description of "network element" is omitted in some parts. For example, the AMF network element is abbreviated as AMF. In this case, the "AMF" should be understood as the AMF network element or the AMF entity. Hereinafter, the description of the same or similar situations is omitted.

[0160] In this network architecture, a network data analysis network element may also be included, which is used for the analysis of various network data, including network operation data collected from the NF, terminal and network-related statistical data obtained from the OAM network element, and application data obtained from a third-party AF. The analysis results generated by the NWDAF will also be output to the NF, OAM, or third-party AF. The specific working steps of the network data analysis network element can be classified into several categories, including request analysis, subscription analysis, data collection, etc.

[0161] In a 5G communication system, the network data analysis network element may be a Network Data Analytics Function (NWDAF) network element. In future communication systems, the network data analysis network element may still be NWDAF, or it may have other names, which are not limited in this application.

[0162] In this network architecture, an Operation Administration and Maintenance (OAM) network element may also be included. According to the actual needs of the operator's network operation, the OAM network element divides the network management work into three categories: Operation, Administration, and Maintenance. Operation mainly completes the analysis, prediction, planning, and configuration work for the daily network and services; Maintenance mainly refers to the daily operation activities such as testing and fault management of the network and its services.

[0163] In a 5G communication system, the operation and maintenance management network element may be an OAM network element, or generally refers to network management devices. In future communication systems, the operation and maintenance management network element may still be OAM, or it may have other names, which are not limited in this application.

[0164] In this network architecture, an external operator management network element may also be included, which is used to evaluate whether a service network element is abnormal based on data.

[0165] In a 5G communication system, the external operator management network element may be an External Operator Managed Function (EOMF) network element. In future communication systems, the external operator management network element may still be an EOMF network element, or it may have other names, which are not limited in this application.

[0166] In this network architecture, an Authentication Server may also be included. The authentication server may be a service function located inside the core network, such as an AUSF network element, an NRF network element, or a third-party authentication server; it may also be a network element outside the operator, such as an external AF.

[0167] It should be understood that the network architecture applied to the embodiments of this application is only an example described from the perspective of a service-oriented architecture, and the network architecture applicable to the embodiments of this application is not limited to this. Any network architecture that can implement the functions of the above-mentioned network elements is applicable to the embodiments of this application.

[0168] For example, in some network architectures, network function entities such as AMF, SMF, PCF, and UDM are all called NF network elements; or, in some other network architectures, the set of network elements such as AMF, SMF, PCF, and UDM can be called a Control Plane Function (CPF) network element.

[0169] Next, take the network elements in the 5G system as an example to introduce the specific solution details. It can be understood that when this solution is used in the LTE system or future communication systems, the network elements in the solution can be replaced by other network elements with corresponding functions, and this application does not make any limitations in this regard.

[0170] It should be understood that Figure 1B is only an exemplary network architecture, and the network architectures applicable to the embodiments of this application are not limited thereto. Any network architecture that can implement the functions of the above-mentioned network elements is applicable to the embodiments of this application.

[0171] The following introduces the specific process of token generation and use.

[0172] Referring to Figure 1C , Figure 1C is a schematic diagram of token generation and use provided for the embodiments of this application; specifically, it includes the following steps:

[0173] (A) The client requests authorization from the resource owner. The authorization request can be sent directly to the resource owner (as shown in Figure 1C ), or indirectly sent through an authentication server acting as an intermediary.

[0174] (B) The client receives the authorization grant, which is a credential indicating that the resource owner authorizes. Exemplarily, it is represented by using one of the four grant types defined in the specifications of the Internet Engineering Task Force (IETF) or an extended grant type. The authorization grant type depends on the method used by the client to request authorization and the types supported by the authentication server.

[0175] (C) The client requests an access token by authenticating with the authentication server and providing the authorization grant.

[0176] (D) The authentication server authenticates the client and verifies the authorization grant. If it is valid, it issues an access token.

[0177] (E) The client requests a protected resource from the resource server and authenticates by providing the access token.

[0178] (F) The resource server verifies the access token. If it is valid, it provides services for the request.

[0179] Reference Figure 1A In the process shown, NWDAF acts as a data collection agent and provides the collected data to operator functions outside the 3GPP domain through the NEF. However, the NEF can only send all the data to the EOMF for analysis and cannot perform fine-grained analysis and authorization checks on the data that the EOMF can read. Therefore, the embodiments of the present application provide a communication method that can perform fine-grained authorization on the data used to evaluate service network elements.

[0180] The following specifically describes the communication method of the embodiments of the present application.

[0181] Reference Figure 2 , Figure 2 is a schematic flowchart of a communication method provided by an embodiment of the present application; the communication method of the embodiment of the present application includes the following steps:

[0182] 201. The fourth network element obtains the identification information of the first network element.

[0183] Specifically, in the embodiments of the present application, the fourth network element is an intermediary or gateway device between the first network element and the second network element. For example, the fourth network element is a NEF network element, a Security Edge Protection Proxy (SEPP), or a Service Communication Proxy (SCP), etc. In the embodiments of the present application, the fourth network element is described by taking the NEF network element as an example.

[0184] The first network element is used to evaluate the service network element. For example, the first network element is an external operator management network element. In the embodiments of the present application, the first network element is described by taking the external operator management network element as an example. The above service network element is a network element that bears terminal services. For example, the service network element is an SMF network element or a (R)AN, etc. The first network element can evaluate the security status of the SMF network element or the energy consumption of the (R)AN, etc.

[0185] The second network element is used to collect data of the service network element. For example, the second network element is a network data analysis network element. In the embodiments of the present application, the second network element is described by taking the network data analysis network element as an example.

[0186] Exemplarily, the identification information of the first network element may be at least one of the following: the name of the first network element, the identification of the network function instance of the first network element, the device number of the first network element, or the IP address of the first network element.

[0187] 202. The fourth network element determines the data to be analyzed from the second network element based on the token of the first network element.

[0188] Specifically, the above token corresponds to the identification information of the first network element. Since the identification information of the first network element corresponds to the token, the fourth network element can determine the token of the first network element based on the identification information of the first network element. For the specific process of determining the token, refer to the relevant descriptions in Embodiments 1 to 4 below, which will not be elaborated here.

[0189] The token of the first network element includes first information, and the first information indicates the data type for which the first network element has read permission. Therefore, the data to be analyzed sent to the first network element can be determined based on the token of the first network element.

[0190] Exemplarily, the first information can directly or indirectly indicate the data type for which the first network element has read permission, and the first information can be at least one of the following: data type indication, data type description, or data type tag. The above data types include at least one of the following: load data of a service network element, resource utilization rate data of a service network element, abnormal event data of a service network element, or energy consumption data of a service network element.

[0191] For example, the data type indication "0" corresponds to the load data of the service network element, the data type indication "1" corresponds to the resource utilization rate data of the service network element, the data type indication "2" corresponds to the abnormal event data of the service network element, and the data type indication "3" corresponds to the energy consumption data of the service network element.

[0192] The data type description is the description content of the data type. For example, the load data of the service network element can be described as "service load", the "resource utilization rate data of the service network element" can be described as "resource utilization rate", the "abnormal event data of the service network element" can be described as "abnormal event", and the "energy consumption data of the service network element" can be described as "energy consumption".

[0193] The data type tag is used to directly or indirectly indicate what data type the data is. Indirect indication means that it is only known what kind of data it is by reading the data itself. Exemplarily, the data type tag can be an event identifier (Event ID), and the event identifier is a specific collection task indication. For example, if NWDAF collects data in the form of event subscription, then the result data of one or more events can be aggregated, and in this way, the event identifier is carried on the data.

[0194] For example, Event ID 10001 corresponds to the collection of the central processing unit (CPU) data of the network element, and Event ID 10003 corresponds to the collection of the graphics processing unit (GPU) data of the network element. The CPU data and the GPU data belong to the resource utilization rate data. The collection task using the Event ID can implicitly correspond to a data type.

[0195] For another example, when the EventID is 10001, the user plane payload data is collected; when the EventID is 10003, the signaling plane payload data is collected. They can implicitly correspond to the data type indicator 0 and the data type description "service payload".

[0196] For another example, when the EventID is 10004, the user plane energy consumption data is collected; when the EventID is 10005, the signaling plane energy consumption data is collected. They can implicitly correspond to the data type indicator 3 and the data type description "energy consumption".

[0197] For another example, when the EventID is 10004, the energy consumption data of the Data Radio Bearer (DRB) is collected; when the EventID is 10005, the energy consumption data of the Signaling Radio Bearer (SRB) is collected. They can implicitly correspond to the data type indicator 3 and the data type description "energy consumption".

[0198] The data to be analyzed is used to evaluate the service network element. The data to be analyzed is collected by the second network element.

[0199] In a possible implementation manner, the above-mentioned payload data comes from the network storage network element, or the above-mentioned resource utilization rate data and / or abnormal event data come from the operation and maintenance management network element. Exemplarily, the second network element collects the payload data of the service network element from the network storage network element, or the second network element collects the resource utilization rate data and / or abnormal event data of the service network element from the operation and maintenance management network element.

[0200] 203. The fourth network element sends the data to be analyzed to the first network element.

[0201] Correspondingly, the first network element receives the data to be analyzed.

[0202] In the embodiments of the present application, the fourth network element first obtains the identification information of the first network element. Since the identification information of the first network element corresponds to the token, the token of the first network element can be determined based on the identification information of the first network element; then the data to be analyzed sent to the first network element is determined based on the token of the first network element, realizing fine-grained authorization management of the data from the second network element and allocating different data to be analyzed to different first network elements.

[0203] The following uses Embodiment 1 to Embodiment 4 to specifically describe the possible communication methods in the embodiments of the present application.

[0204] Embodiment 1

[0205] Refer to Figure 3 , Figure 3Schematic flowchart of another communication method provided by an embodiment of this application; the communication method includes the following steps:

[0206] 0a. The second network element collects data.

[0207] Specifically, the target for the second network element to collect data can be a service network element (such as an AMF network element instance), or multiple service network elements, such as multiple network elements of the same type (such as multiple AMF network elements), or all types of network elements within a region, and this is not limited.

[0208] In addition, the second network element can obtain the collected data from an NF (i.e., a service network element), an NRF network element, an OAM network element, etc.

[0209] 0b. The second network element sends a data analysis request to the fourth network element.

[0210] Among them, in a possible implementation manner, the data analysis request includes the identification information of the first network element, and the data analysis request is used to trigger the first network element to perform data analysis.

[0211] Correspondingly, the fourth network element receives the data analysis request. The fourth network element can obtain the identification information of the first network element based on the above data analysis request.

[0212] In another possible implementation manner, the above data analysis request further includes the collected data of the second network element and second information. The second information indicates the data type of the collected data.

[0213] Specifically, the collected data is carried in the data analysis request. In this way, the fourth network element can open the collected data to external network elements, such as the first network element. The data types indicated by the second information include at least one of the following: load data of the service network element, resource utilization rate data of the service network element, abnormal event data of the service network element, or energy consumption data of the service network element. Exemplarily, the second information can be a data type and / or a data type label. The specific ways for the first information and the second information to indicate the data type are the same, such as both being data type labels, etc.

[0214] 0c. The fourth network element pre-configures verification information with the verification server.

[0215] Specifically, the verification information includes a certificate or a key, etc. The verification server is used to issue a token to the first network element. The fourth network element has the ability to verify the token of the first network element, and verifying the token requires the use of verification information. Therefore, it is necessary to pre-configure the verification information in advance.

[0216] Step 0c has no sequence relationship with the previous steps and can be executed before, between, or after steps 0a and 0b. Other steps can also be inserted between step 0c and steps 0a and 0b.

[0217] 1. The first network element sends a token issuance request to the authentication server.

[0218] Specifically, in a possible implementation, the above token issuance request includes the identification information of the first network element. Correspondingly, the authentication server receives the token issuance request from the first network element.

[0219] In another possible implementation, the above token issuance request further includes third information, and the third information indicates the data type that the first network element prefers to read. The third information can directly or indirectly indicate the data type that the first network element prefers to read. For example, the third information can be in at least one of the following forms: data type indication, description of the data type that the first network element prefers to read, or data type label (such as EventID), etc. The specific form of the third information is the same as the specific form of the second information in 0b. Taking Table 1 below as an example:

[0220] Table 1 Schematic Table of Data Type Indications

[0221] EventID Data type indication Data type description 10001、10003 1 Resource utilization 10002 2 Exception event 10004 0 Business load 10005 3 Energy consumption … … …

[0222] For example, referring to Table 1, when the EventID is 10001, the corresponding data collected is CPU data, and when the Event ID is 10003, the corresponding data collected is GPU data. Then, it can implicitly correspond to the data type indication 1 and the data type description "resource utilization rate". 2. The authentication server sends a subscription information query request to the third network element.

[0223] Correspondingly, the third network element receives the subscription information query request. The third network element can be a data management network element.

[0224] Specifically, the subscription information query request includes the identification information of the first network element, and the query content is, for example: the working scope subscribed by the first network element, or the trust level. The authentication server can determine the type of token to be issued to the first network element based on this content.

[0225] Step 2 is optional. If the authentication server itself does not need subscription information to assist in judgment, or has a cache of the subscription information of the first network element, it can not send the subscription information query request.

[0226] 3. The third network element sends a subscription information response to the authentication server.

[0227] Corresponding to Step 2, Step 3 is optional. The subscription information response includes the trust level and / or service type of the first network element.

[0228] 4. The authentication server determines the token of the first network element.

[0229] Specifically, the authentication server determines the token of the first network element based on at least one of the identification information of the first network element, the subscription information response, and the third information. The authentication server determines the type and scope of the token issued to the first network element. The token contains a first information field that can directly or indirectly indicate the data types that the first network element has read permissions for.

[0230] In a possible implementation, the authentication server can determine the token of the first network element based on the identification information of the first network element. Additionally, the authentication server can determine the name of the first network element based on the identification information of the first network element, and the authentication server can determine the token of the first network element based on the name of the first network element. The authentication server can determine the token of the first network element based on the subscription information response. The authentication server can also determine the token of the first network element based on the third information. For example, the authentication server issues a token directly according to the data types of the preferred reads indicated by the third information for the first network element. The authentication server can also determine the token of the first network element based on the identification information of the first network element and the subscription information response. The authentication server can also determine the token of the first network element based on the identification information of the first network element and the third information. The authentication server can also determine the token of the first network element based on the subscription information response and the third information. The authentication server can also determine the token of the first network element based on the identification information of the first network element, the subscription information response, and the third information.

[0231] In another possible implementation, the authentication server can also determine the token of the first network element according to pre-configured rules. For example, as long as there is a token issuance request, a token is issued. The data types indicated by the token for which there are read permissions can be preset. The preset data types of the token are, for example, the load-related data of the service network element.

[0232] In another possible implementation, the authentication server determines the token of the first network element based on at least one of the identification information of the first network element, the subscription information response, and the third information and the pre-configured rules. For example, the authentication server determines the token of the first network element according to the third information and the pre-configured rules. The third information indicates that the data types preferred by the first network element for reading are the load-related data of the service network element, the resource utilization-related data of the service network element, and the exception event-related data of the service network element. The pre-configured rule is not to issue a token with read permissions for the data type of the exception event-related data of the service network element. Then the authentication server issues a token to the first network element indicating that there are read permissions for the load-related data of the service network element and the resource utilization-related data of the service network element.

[0233] 5. The authentication server sends a token grant response to the first network element.

[0234] Correspondingly, the first network element receives the token grant response sent by the authentication server.

[0235] The token grant response includes the token of the first network element. The token corresponds to the identification information of the first network element, and the token includes first information indicating the data types that the first network element has read permissions for.

[0236] Exemplarily, the token can be one or more of the following: an Open Authentication (Oauth) token (such as an Oauth2.0 token), a certificate, or a one-time code, etc. The token can also be in other forms, and the present application does not make a unique limitation thereon.

[0237] The tokens in different embodiments can be in different forms. For example, the token in Embodiment 1 is an Oauth token, the token in Embodiment 2 is a certificate, and the tokens in Embodiments 3 and 4 are one-time codes, etc., without making a unique limitation.

[0238] 6. The fourth network element determines whether to check the token.

[0239] Specifically, the fourth network element determines whether there is a token check record of the first network element locally according to the identification information of the first network element in the data analysis request. In one possible implementation manner, if there is a historical token check record of the first network element, the token of the first network element is not checked, and step 10b is executed. In another possible implementation manner, if there is a historical token check record of the first network element and the token has not expired, the token of the first network element is not checked, and step 10b is executed. In another possible implementation manner, if there is no token check record of the first network element, step 7 is triggered to be executed.

[0240] 7. The fourth network element sends a token check request to the first network element.

[0241] Optionally, the token check request includes second information.

[0242] 8. The first network element checks the token.

[0243] Specifically, in one possible implementation manner, if step 7 does not carry the second information, the first network element determines whether to report the token in the token check response according to its own configuration rules. For example, the first network element only needs to check whether there is a token locally and does not need to consider the type correspondence. If the first network element has a token locally, the token of the first network element is carried in the token check response.

[0244] In another possible implementation manner, if step 7 carries the second information, the first network element determines whether it has a token of the data type indicated by the second information. If so, the corresponding token is carried in the token check response. If not, the first network element is triggered to execute steps 1 to 5 and then execute step 8. It can be seen that the above token issuance process (i.e., steps 1 to 5) can be executed before step 8 or triggered to be executed by step 8.

[0245] In another implementation, the token check response may carry first information in addition to the token.

[0246] 9. The first network element sends a token check response to the fourth network element.

[0247] Correspondingly, the fourth network element receives the token check response.

[0248] In a possible implementation, the fourth network element may obtain the token of the first network element in the token check response. In another possible implementation, the fourth network element may obtain the first information in the token check response.

[0249] 10a. The fourth network element checks the validity of the token.

[0250] Specifically, the way for the fourth network element to check the validity of the token of the first network element is through the verification information preconfigured in step 0c. In a possible implementation, if the validity check passes, step 10b is executed. In another possible implementation, if the validity check result fails, the fourth network element sends a failure response to the first network element, and the failure response includes the reason for the failure.

[0251] Exemplarily, if the token of the first network element uses the signature protection of the verification server, the fourth network element performs an integrity check on the token, such as by using a certificate again to check the signature. If the signature check passes, the token is considered to be complete and valid. Another example is that the fourth network element decrypts the token using a key, and if the decryption is successful, the token is regarded as complete and valid.

[0252] 10b. The fourth network element checks the content of the token.

[0253] Specifically, the fourth network element checks the content of the token, determines the data to be analyzed based on the token and the collected data of the second network element, and the data type of the data to be analyzed is the data type of all or part of the collected data. That is, the data to be analyzed can be all or part of the collected data.

[0254] In a possible implementation, the fourth network element determines the data to be analyzed sent to the first network element according to the token of the first network element, the second information, and the preconfigured rules. According to the preconfigured rules, if there is an intersection between the data types indicated by the token and the second information, the first network element trims the collected data and only sends the part of the data corresponding to the intersection data type; or if the data types indicated by the token and the second information do not completely match, it is considered that the content check fails.

[0255] Among them, the fourth network element determines the data to be analyzed from the collected data based on the token and the second information. The data type of the data to be analyzed is the intersection data type of the data types indicated by the token and the second information. By comparing the data types based on the second information and the token carried in the data analysis request, the data to be analyzed can be determined; the intersection data type can be the data type indicated by the token or some of the data types indicated by the token. If there is no intersection data type, the content verification result is failed. For example, if it is determined according to Table 1 and the token that the data types that the first network element has read permission for are data type indicators 0, 1, and 2, but the second information in step 0b indicates that the collected data contains data type indicators 1, 2, and 3, then the fourth network element retains the data with data type indicators 1 and 2, and trims the other data in the collected data to obtain the data to be analyzed.

[0256] For another example, if it is determined according to Table 1 and the token that the data types that the first network element has read permission for are data type indicators 0, 1, and 2, but the second information in step 0b indicates that the collected data contains data type indicators 1, 2, and 3, then the fourth network element determines that the verification result of the content of the token is failed.

[0257] In another possible implementation, when step 6 determines that the token does not need to be checked, the fourth network element determines the data to be analyzed based on the token in the historical check result and the collected data. For the method of determining the data to be analyzed based on the token and the collected data, refer to the above relevant description.

[0258] 11. Send data or a failure response according to the check result.

[0259] Specifically, when step 6 determines that the token needs to be checked, according to the check results of step 10a and step 10b, it is determined whether to send the data to be analyzed or a failure response to the first network element. In a possible implementation, when the check results of step 10a and step 10b are both passed, the fourth network element sends the data to be analyzed to the first network element. In another possible implementation, when the check result of step 10a or step 10b is not passed, the fourth network element sends a failure response to the first network element, and the failure response includes the reason for the failure.

[0260] When step 6 does not require checking the token, according to the check result of step 10b, it is determined whether to send the data to be analyzed or a failure response to the first network element. In a possible implementation, when the check result of step 10b is passed, the fourth network element sends the data to be analyzed to the first network element. In another possible implementation, when the check result of step 10b is not passed, the fourth network element sends a failure response to the first network element, and the failure response includes the reason for the failure.

[0261] In the first embodiment, for the first network element with different trust levels, the fourth network element clips the collected data of the second network element based on the token of the first network element, and only opens part of the data for the first network element to process. For different first network elements, the fourth network element can perform fine-grained authorization control to ensure the security of the communication network.

[0262] Second Embodiment

[0263] Reference Figure 4 , Figure 4 FIG. is a schematic flow chart of another communication method provided by the embodiment of the present application; the communication method includes the following steps:

[0264] 0. The first network element obtains a token.

[0265] Specifically, before step 1, the first network element obtains its own token, and the method for specifically obtaining the token is not limited. For example, the token of the first network element can be obtained according to steps 0c to 5 in the first embodiment.

[0266] 1. The first network element sends a token registration request to the fourth network element.

[0267] Correspondingly, the fourth network element receives the token registration request from the first network element.

[0268] In one implementation manner, the above token registration request includes the identification information of the first network element and the token of the first network element.

[0269] In another implementation manner, the above token registration request includes the identification information of the first network element and the token information of the first network element. The above token information is the relevant information of the token of the first network element, such as the identification information of the token, etc.

[0270] 2a. The fourth network element checks the validity of the token.

[0271] Specifically, in a possible implementation manner, refer to step 10a in the first embodiment to check the validity of the token. The fourth network element performs a validity check on the token of the first network element. When the check result of the validity check passes, step 2b is executed. In another possible implementation manner, when the check result of the validity check fails, the token registration result is a failure, and the fourth network element sends a registration request response to the first network element, and the registration request response includes the reason for the registration failure.

[0272] In one implementation manner, the fourth network element can obtain the token of the first network element according to the token information of the first network element, and then check the validity of the token. For example, the first network element obtains the token from the verification server, and the first network element sends the identification information of the token to the fourth network element for registration. After receiving the identification information of the token, the fourth network element can obtain the token of the first network element from the verification server through the identification information.

[0273] 2b. The fourth network element stores the identification information of the first network element and the token of the first network element.

[0274] Specifically, in one implementation, the fourth network element records the identification information of the first network element and the token of the first network element (such as Figure 4 2b). In another implementation, the fourth network element records the identification information of the first network element and the token information of the first network element.

[0275] Before storing the identification information and the token (or token information) of the first network element in the embodiments of the present application, the token of the first network element is subjected to validity verification. When the validity verification passes, the identification information of the first network element and the token (or token information) of the first network element are stored to ensure the validity of the token (or token information) required for registration.

[0276] 3. The fourth network element sends a registration request response to the first network element.

[0277] Correspondingly, the first network element receives the registration request response.

[0278] Specifically, the registration request response indicates the token registration result. When the registration fails, the registration request response includes the reason for the registration failure.

[0279] 4. The second network element sends a data analysis request to the fourth network element.

[0280] Correspondingly, the fourth network element receives the data analysis request from the second network element.

[0281] In a possible implementation, the above data analysis request includes the identification information of the first network element, and the data analysis request is used to trigger the first network element to perform data analysis. The fourth network element can obtain the identification information of the first network element through the data analysis request.

[0282] Among them, the above data analysis request can be sent once or periodically. When the data analysis request is sent periodically, the data analysis request is an analysis subscription request.

[0283] In another possible implementation, the above data analysis request further includes the data type that the second network element expects to analyze.

[0284] Furthermore, the fourth network element sends a data analysis request to the first network element. Correspondingly, the first network element receives the data analysis request sent by the fourth network element.

[0285] Among them, steps 1 to 3 and step 4 are not necessarily connected. Steps 1 to 3 can be before or after sending the data analysis request, and there is no limitation on this. For example, steps 1 to 3 can be executed before step 5, and steps 1 to 3 are triggered by step 4.

[0286] 5. The first network element sends a data analysis request response to the fourth network element.

[0287] Correspondingly, the fourth network element receives the data analysis request response.

[0288] Specifically, in a possible implementation manner, when the first network element determines that it cannot respond to the data analysis request of the second network element according to the pre-configured rules and / or the data type expected to be analyzed by the second network element, the reason for the inability to respond is carried in the data analysis request response. For example, the pre-configured rules determine whether to respond to the data analysis request of the second network element according to the identification information and / or name of the first network element. The fourth network element forwards the data analysis request response to the second network element.

[0289] In another possible implementation manner, when the data type expected to be analyzed by the second network element is carried in the data analysis request and the first network element determines that it does not support reading the expected data type, the data analysis request response includes the data type that the first network element cannot read. At this time, the fourth network element forwards the data analysis request response to the second network element to indicate that the second network element can re-adjust the expected data type carried in the data analysis request as needed.

[0290] In another possible implementation manner, when the first network element determines that it can respond to the data analysis request of the second network element according to the pre-configured rules and / or the data type expected to be analyzed by the second network element, the identification information of the first network element is carried in the data analysis request response; step 6a is executed.

[0291] 6a. The fourth network element checks the validity period of the token.

[0292] When the data analysis request response indicates that the first network element accepts the data analysis request, the fourth network element determines the data to be analyzed based on the token of the first network element; verifies the data reading permission of the first network element according to the token to ensure data security.

[0293] Specifically, first check the token registration record according to the identification information of the first network element. In a possible implementation manner, if there is a token registration record of the first network element and the token of the first network element has not expired, step 6b is triggered for execution. In another possible implementation manner, if there is no token registration record of the first network element and / or the token of the first network element has expired, step 0 is triggered for execution, and then step 6a is executed.

[0294] In a possible embodiment, when the fourth network element determines that there is a token registration record of the first network element, it can obtain the token of the first network element according to the token information of the first network element, and then determine whether the token of the first network element has expired.

[0295] 6b. The fourth network element verifies the token.

[0296] Specifically, the fourth network element first checks the validity of the token, and the checking method is the same as step 10a in the first embodiment. In a possible implementation, when the validity check result of the token passes, the fourth network element checks the content of the token to determine the fourth information, and the fourth information indicates the data type of the data that needs to be collected by the second network element. In another possible implementation, when the validity check result of the token fails, the fourth network element sends a data analysis request response to the second network element, and the data analysis request response includes the reason for failure.

[0297] In a possible implementation, the fourth information may be the same as the first information. For example, referring to Table 1, when the fourth network element checks the content of the token and determines that the data types with read permissions indicated by the first network element are 1, 2, and 3, it is determined that the data types indicated by the fourth information are 1, 2, and 3.

[0298] In another possible implementation, the fourth network element generates the fourth information based on the first information, and the fourth information may be the same as or different from the first information. Exemplarily, the fourth network element generates the fourth information according to preconfigured rules and the first information. For example, when the preconfigured rule is not to allow collection of information of the first data type, and the data types indicated by the first information include this first data type, the fourth network element modifies the first information and removes the first data type from the first information to obtain the fourth information.

[0299] In another possible implementation, when the fourth information generated by the fourth network element based on the first information is empty, the fourth network element sends a data analysis request response to the first network element, and the response includes the reason for failure.

[0300] 7. The fourth network element sends the identification information of the first network element and the fourth information to the second network element.

[0301] In a possible implementation, when the check results of both step 6a and step 6b pass, the fourth network element sends the identification information of the first network element and the fourth information to the second network element. There is no limitation on the specific manner in which the fourth network element sends the identification information of the first network element and the fourth information. For example, the identification information of the first network element and the fourth information may be carried in the data analysis request response, and the data analysis request response is sent to the second network element to instruct the second network element to collect data corresponding to the data type indicated by the fourth information, thereby realizing data-directed collection.

[0302] 8. The second network element sends the data to be analyzed to the fourth network element.

[0303] Specifically, the second network element collects data according to the indication of the fourth information to obtain the data to be analyzed. The second network element sends the data to be analyzed to the fourth network element, and the specific manner of sending the data to be analyzed by the second network element is not limited. Exemplarily, the second network element may send a data analysis request to the fourth network element, and the data analysis request includes the identification information of the second network element and the data to be analyzed. Optionally, the data analysis request further includes information indicating the data type of the data to be analyzed (such as data type indication and / or data type label, etc.).

[0304] 9a. The fourth network element checks the validity of the token.

[0305] 9b. The fourth network element checks the content of the token.

[0306] Before sending the data to be analyzed to the first network element, the fourth network element checks the token of the first network element again.

[0307] Specifically, steps 9a and 9b are optional. For details, reference can be made to steps 10a and 10b in Embodiment 1. Exemplarily, before steps 9a and 9b, if it is found that the token of the first network element has expired or does not exist, step 0 can be triggered again; if it has not expired, steps 9a and 9b can be directly executed.

[0308] 10. According to the inspection result, send data or a failure response.

[0309] Specifically, according to the inspection results of steps 9a and 9b, it is determined whether to send the data to be analyzed or a failure response to the first network element. In a possible implementation manner, when the inspection results of steps 9a and 9b are both passed, the fourth network element sends the data to be analyzed to the first network element to ensure that the first network element has the data reading permission for the data to be analyzed.

[0310] In another possible implementation manner, when the inspection result of step 9a or step 9b is not passed, the fourth network element sends a failure response to the first network element, and the failure response includes the reason for failure.

[0311] If steps 9a and 9b are not executed, the fourth network element directly forwards the data to be analyzed (or the data analysis request in step 8) to the first network element.

[0312] In Embodiment 2, the second network element actively sends a data analysis request to the first network element. The fourth network element does not need to check the data type indication in the token of the first network element. The fourth network element determines the fourth information according to the token of the first network element to instruct the second network element to collect the corresponding data, so as to solve the problem from the source.

[0313] Embodiment 3

[0314] Reference Figure 5 , Figure 5Schematic flowchart of another communication method provided by an embodiment of the present application; the communication method includes the following steps:

[0315] 0. The same as steps 0 to 3 in Embodiment 2.

[0316] The first network element registers a token or token information in the fourth network element.

[0317] 1a. The first network element sends a data subscription request to the fourth network element.

[0318] Among them, the data subscription request includes the identification information of the first network element, and the data subscription request is used to trigger the second network element to collect data.

[0319] Correspondingly, the fourth network element receives the data subscription request. The fourth network element obtains the identification information of the first network element through the data subscription request sent by the first network element.

[0320] 1b. The fourth network element forwards the data subscription request to the second network element.

[0321] 2. The second network element determines whether to check the token.

[0322] Specifically, in a possible implementation manner, if the second network element determines that it does not need to check the token of the first network element, the second network element collects data according to the data subscription request and / or pre-configured rules to obtain the data to be analyzed, and executes step 5.

[0323] The above pre-configured rules can be set according to the actual situation without limitation. For example, the pre-configured rules stipulate to collect data with data type indicators 2 and 3. When the second network element determines the data to be collected only according to the pre-configured rules, the second network element needs to collect data with data type indicators 2 and 3.

[0324] When the second network element determines the data to be collected only according to the data subscription request, for example, the second network element determines the data to be collected according to the name of the data subscription request. For example, if the name of the data subscription request is "load data subscription request", the data to be collected by the second network element is the load data of the service network element.

[0325] Exemplarily, if the second network element locally caches the token or token information of the first network element, there is no need to send a token query request. Or, if the second network element determines that the security of the first network element does not require token checking, there is no need to send a token query request. For example, if the first network element and the second network element are managed by the same operator, it is determined that the security of the first network element is high and token checking is not required.

[0326] In another possible implementation, if the second network element determines that it is necessary to check the token of the first network element, the second network element sends a token query request to the fourth network element and executes step 3a. The token query request includes the identification information of the first network element.

[0327] 3a. The fourth network element checks the validity period of the token.

[0328] In response to the token query request, the fourth network element verifies the token of the first network element. The fourth network element first checks the validity period of the token. Specifically, according to the identification information of the first network element, it checks the token registration record. In one possible implementation, if the token of the first network element has been registered and has not expired, the fourth network element executes step 3b. In another possible implementation, if the token of the first network element has not been registered and / or the token has expired, step 0 is triggered and then step 3a is executed.

[0329] 3b. The fourth network element verifies the token.

[0330] Specifically, the fourth network element first checks the validity of the token. The checking method is the same as step 10a in the first embodiment. In one possible implementation, when the validity check result of the token passes, the fourth network element checks the content of the token to determine the fourth information. Specifically, reference can be made to the description in step 6b and details are not repeated here. In another possible implementation, when the validity check result of the token fails, the fourth network element sends a data subscription request response to the first network element, and the response includes the reason for failure.

[0331] 4. The fourth network element sends the identification information of the first network element and the fourth information to the second network element.

[0332] Specifically, there is no limitation on the specific manner in which the fourth network element sends the identification information of the first network element and the fourth information to the second network element. In one possible implementation, when both step 3a and step 3b pass the check, the fourth network element returns the verification result information to the second network element. The verification result information includes the identification information of the first network element, the token verification result, and the fourth information.

[0333] 5. The second network element sends the data to be analyzed to the first network element.

[0334] Specifically, in one possible implementation, the second network element receives the identification information of the first network element and the fourth information, collects data according to the fourth information to obtain the data to be analyzed, and sends the data to be analyzed to the first network element.

[0335] There is no limitation on the specific manner in which the second network element sends the data to be analyzed. Exemplarily, similar to steps 8 to 10 of Embodiment 2, the second network element may send the data to be analyzed to the first network element through the fourth network element. The fourth network element may perform a secondary verification on the token of the first network element and then forward the data to be analyzed, or directly forward the data to be analyzed (or the data analysis request) to the first network element.

[0336] In Embodiment 3, the first network element actively requests data from the second network element. The second network element queries the token status through the fourth network element, and the fourth network element determines the fourth information based on the token to instruct the second network element to collect data.

[0337] Embodiment 4

[0338] Reference Figure 6 , Figure 6 is a schematic flowchart of another communication method provided by the embodiments of the present application; the communication method includes the following steps:

[0339] 0. The same as steps 0 to 3 in Embodiment 2.

[0340] 1. The first network element sends a data subscription request to the fourth network element.

[0341] The data subscription request includes the identification information of the first network element, and the data subscription request is used to trigger the second network element to collect data.

[0342] Correspondingly, the fourth network element receives the data subscription request. The fourth network element obtains the identification information of the first network element through the data subscription request sent by the first network element.

[0343] 2a. The fourth network element checks the validity period of the token.

[0344] In response to the data subscription request, the fourth network element verifies the token of the first network element. The fourth network element first checks the validity period of the token. Specifically, according to the identification information of the first network element, it checks the token registration record. In one possible implementation, if the token of the first network element is registered and not expired, step 2b is executed. In another possible implementation, if the token of the first network element is not registered and / or the token has expired, step 0 is triggered and then step 2a is executed.

[0345] 2b. The fourth network element verifies the token.

[0346] Specifically, the fourth network element first checks the validity of the token, and the checking method is the same as step 10a in Example 1. In one embodiment, when the validity check result of the token is passed, the fourth network element checks the content of the token to determine the fourth information. For details, please refer to the record of step 6b, which will not be repeated here. In another possible embodiment, when the validity check result of the token is not passed, the fourth network element sends a data subscription request response to the first network element, and the response includes the reason for the failure.

[0347] 3. The fourth network element sends the identification information of the first network element and the fourth information to the second network element.

[0348] Specifically, in a possible implementation, when both step 2a and step 2b are checked to be passed, the fourth network element sends the identification information and the fourth information of the first network element to the second network element. The specific manner in which the fourth network element sends the identification information and the fourth information of the first network element is not limited. For example, the fourth network element returns verification result information to the second network element, and the verification result information includes the identification information of the first network element, the token verification result, and the fourth information.

[0349] In another possible implementation, when the check result of step 2a and / or step 2b is failure, the fourth network element returns a subscription failure response to the first network element, where the subscription failure response includes a failure reason.

[0350] 4. The second network element sends the data to be analyzed to the first network element.

[0351] Specifically, the second network element receives the identification information and the fourth information of the first network element, collects data according to the fourth information to obtain the data to be analyzed, and sends the data to be analyzed to the first network element.

[0352] The specific method for the second network element to send the data to be analyzed is not limited. Similar to step 8 to step 10 of the second embodiment, the second network element can send the data to be analyzed to the first network element through the fourth network element, and the fourth network element can perform a secondary verification on the token of the first network element before forwarding the data to be analyzed, or directly forward the data to be analyzed (or data analysis request) to the first network element.

[0353] In the fourth embodiment, the first network element actively requests data, the fourth network element inquires about the token status and instructs the second network element to collect data according to the token.

[0354] Figure 7 , Figure 8 and Figure 9A schematic diagram of the structure of a possible communication device provided for an embodiment of the present application. These communication devices can be used to implement the functions of the first network element, the fourth network element, or the verification server in the above method embodiment, and thus can also achieve the beneficial effects possessed by the above method embodiment. In an embodiment of the present application, the communication device can be the first network element, the fourth network element, or the verification server, and can also be a module (such as a chip) applied to the first network element, the fourth network element, or the verification server.

[0355] like Figure 7 As shown, the communication device 700 includes a processing unit 710 and a transceiver unit 720. The communication device 700 is used to implement the above Figure 2 Alternatively, the communication device 700 may include a device for implementing the above Figure 2 A module for any function or operation of the fourth network element in the method embodiment shown in the figure may be implemented in whole or in part by software, hardware, firmware or any combination thereof.

[0356] When the communication device 700 is used to implement Figure 2 The function of the fourth network element in the method embodiment shown is: a processing unit 710, which is used to obtain the identification information of the first network element. The processing unit 710 is also used to determine the data to be analyzed from the second network element based on the token of the first network element. The above token corresponds to the identification information of the first network element, and the token includes first information, which indicates the type of data that the first network element has read permission. The above data to be analyzed is used to evaluate the service network element. The transceiver unit 720 is used to send the data to be analyzed to the first network element.

[0357] For more detailed description of the processing unit 710 and the transceiver unit 720, please refer to Figures 2 to 6 The relevant description in any method embodiment is directly obtained and will not be repeated here.

[0358] like Figure 8 As shown, the communication device 800 includes a transceiver unit 810. The communication device 800 is used to implement the above Figure 3 Alternatively, the communication device 800 may include a method for implementing the above Figure 3 In the method embodiment shown in the figure, a module for verifying any function or operation of the server or the first network element may be implemented in whole or in part by software, hardware, firmware or any combination thereof.

[0359] When the communication device 800 is used to implement Figure 3When verifying the function of the verification server in the method embodiment shown: The transceiver unit 810 is configured to receive a token issuance request from a first network element, where the token issuance request includes identification information of the first network element. The transceiver unit 810 is further configured to send a token grant response to the first network element, where the token grant response includes a token of the first network element. The token corresponds to the identification information of the first network element, and the token includes first information indicating the data types that the first network element has read permissions for.

[0360] When the communication device 800 is used to implement Figure 3 the function of the first network element in the method embodiment shown: The transceiver unit 810 is configured to send a token issuance request to the verification server, where the token issuance request includes identification information of the first network element. The transceiver unit 810 is further configured to receive a token grant response sent by the verification server, where the token grant response includes a token of the first network element. The token corresponds to the identification information of the first network element, and the token includes first information indicating the data types that the first network element has read permissions for.

[0361] For a more detailed description of the above transceiver unit 810, reference can be directly made to Figure 3 the relevant description in the method embodiment shown, which will not be elaborated here.

[0362] As Figure 8 shown, the communication device 800 includes a transceiver unit 810. The communication device 800 is used to implement the function of the first network element in the method embodiment shown above. Figure 2 Alternatively, the communication device 800 may include a module for implementing any function or operation of the first network element in the method embodiment shown above, and the module may be implemented in whole or in part by software, hardware, firmware, or any combination thereof. Figure 2 shown above.

[0363] When the communication device 800 is used to implement Figure 2 the function of the first network element in the method embodiment shown: The transceiver unit 810 is configured to receive data to be analyzed sent by a fourth network element. The data to be analyzed is determined by the fourth network element based on the token of the first network element, and the data to be analyzed comes from a second network element. The token corresponds to the identification information of the first network element, and the token includes first information indicating the data types that the first network element has read permissions for. The data to be analyzed is used to evaluate the service network element.

[0364] For a more detailed description of the above transceiver unit 810, reference can be directly made to Figures 2 to 6 the relevant description in any method embodiment, which will not be elaborated here.

[0365] Exemplarily, an embodiment of the present application further provides a communication system, including Figure 2 the fourth network element and the first network element shown above.

[0366] Exemplarily, an embodiment of the present application further provides a communication system, including Figure 3 the first network element and the authentication server shown in the figure.

[0367] As Figure 9 shown, the communication device 900 includes a processor 910 and an interface circuit 920. The processor 910 and the interface circuit 920 are coupled to each other. It can be understood that the interface circuit 920 may be a transceiver or an input / output interface. Optionally, the communication device 900 may further include a memory 930 for storing instructions executed by the processor 910 or storing input data required for the processor 910 to run instructions or storing data generated after the processor 910 runs instructions. Among them, the memory 930 may be one or more, and the processor 910 may be one or more.

[0368] When the communication device 900 is used to implement Figure 2 the function of the fourth network element in the method shown in the figure, the processor 910 is used to implement the function of the above processing unit 710, and the interface circuit 920 is used to implement the function of the above transceiver unit 720. When the communication device 900 is used to implement Figure 2 the function of the first network element in the method shown in the figure, the interface circuit 920 is used to implement the function of the above transceiver unit 810. When the communication device 900 is used to implement Figure 3 the method shown in the figure, the interface circuit 920 is used to implement the function of the above transceiver unit 810.

[0369] When the above communication device is a chip applied to a network device, the network device chip implements the function of the network device in the above method embodiment. The network device chip receives information from other modules (such as a radio frequency module or an antenna) in the network device, and this information is sent by a terminal device to the network device; or, the network device chip sends information to other modules (such as a radio frequency module or an antenna) in the network device, and this information is sent by the network device to the terminal device.

[0370] Exemplarily, the communication device 900 may be a chip or a chip system.

[0371] It can be understood that the processor 910 in the embodiments of the present application may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.

[0372] The memory 930 may be a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 930 may store a program. When the program stored in the memory 930 is executed by the processor 910, the processor 910 is used to execute each step of the communication method described in any of the above embodiments.

[0373] The method steps in the embodiments of the present application may be implemented in a hardware manner or by a processor executing software instructions. The software instructions may be composed of corresponding software modules. The software modules may be stored in a random access memory, a flash memory, a read-only memory, a programmable read-only memory, an erasable programmable read-only memory, an electrically erasable programmable read-only memory, a register, a hard disk, a removable hard disk, a CD-ROM, or any other form of storage medium well known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium may also be a component of the processor. The processor and the storage medium may be located in an ASIC. Additionally, the ASIC may be located in a network device or a terminal device. Of course, the processor and the storage medium may also exist as discrete components in a network device or a terminal device.

[0374] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are executed in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, or other programmable devices. The computer program or instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer program or instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired or wireless manner. The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or a data center integrating one or more available media. The available medium may be a magnetic medium, such as a floppy disk, a hard disk, or a magnetic tape; it may also be an optical medium, such as a digital video disc; or it may be a semiconductor medium, such as a solid-state drive.

[0375] In various embodiments of the present application, if there is no special explanation and logical conflict, the terms and / or descriptions between different embodiments are consistent and can be cross-referenced. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.

Claims

1. A communication method, characterized in that, the method includes: obtaining identification information of a first network element; determining, based on a token of the first network element, data to be analyzed from a second network element, where the token corresponds to the identification information of the first network element, the token includes first information, and the first information indicates a data type for which the first network element has read permission; the data to be analyzed is used to evaluate a service network element; sending the data to be analyzed to the first network element.

2. The method according to claim 1, characterized in that, the determining, based on the token of the first network element, data to be analyzed from the second network element includes: determining the data to be analyzed based on the token and collected data of the second network element, where the data type of the data to be analyzed is all or part of the data type of the collected data.

3. The method according to claim 1 or 2, characterized in that, the obtaining identification information of the first network element includes: receiving a data analysis request from the second network element, where the data analysis request includes the identification information of the first network element, and the data analysis request is used to trigger the first network element to perform data analysis.

4. The method according to claim 3, characterized in that, the data analysis request further includes the collected data of the second network element, and second information, where the second information indicates the data type of the collected data; the determining, based on the token of the first network element, data to be analyzed from the second network element includes: determining the data to be analyzed from the collected data based on the token and the second information, where the data type of the data to be analyzed is an intersection data type of the data type indicated by the token and the data type indicated by the second information.

5. The method according to claim 3 or 4, characterized in that, after receiving the data analysis request from the second network element, the method further includes: sending a token check request to the first network element; receiving a token check response from the first network element, where the token check response includes the token of the first network element.

6. The method according to claim 3, characterized in that, after receiving the data analysis request from the second network element, the method further includes: sending the data analysis request to the first network element; receiving a data analysis request response from the first network element; the determining, based on the token of the first network element, data to be analyzed from the second network element includes: when the data analysis request response indicates that the first network element accepts the data analysis request, determining the data to be analyzed based on the token of the first network element.

7. The method according to claim 6, characterized in that, the data analysis request further includes a data type expected to be analyzed by the second network element; when the first network element does not support reading the expected data type to be analyzed, the data analysis request response includes the data types that the first network element cannot read.

8. The method according to claim 3, 6 or 7, characterized in that, the determining, based on the token of the first network element, data to be analyzed from the second network element includes: verifying the token of the first network element; When the verification result of the token is verified successfully, send the data analysis request response to the second network element, where the data analysis request response includes the identification information of the first network element and the first information; Receive the data to be analyzed from the second network element, where the data type of the data to be analyzed is the data type indicated by the first information.

9. The method according to claim 8, wherein, The sending the data to be analyzed to the first network element includes: Verifying the token of the first network element again; When the verification result of the token is verified successfully, send the data to be analyzed to the first network element.

10. The method according to claim 1, wherein, The obtaining the identification information of the first network element includes: Receive a data subscription request sent by the first network element, where the data subscription request includes the identification information of the first network element, and the data subscription request is used to trigger the second network element to collect data.

11. The method according to claim 10, wherein, The determining the data to be analyzed based on the token of the first network element includes: Verifying the token of the first network element; When the verification result of the token is verified successfully, send the identification information of the first network element and the first information to the second network element; Receive a data analysis request from the second network element, where the data analysis request includes the data to be analyzed and the identification information of the first network element, and the data type of the data to be analyzed is the data type indicated by the first information.

12. The method according to claim 11, wherein, The sending the data to be analyzed to the first network element includes: Send the data analysis request to the first network element.

13. The method according to claim 11 or 12, wherein, The verifying the token of the first network element includes: Send the data subscription request to the second network element; Receive a token query request sent by the second network element, where the token query request includes the identification information of the first network element; In response to the token query request, verify the token of the first network element.

14. The method according to any one of claims 1 to 13, wherein, The method further includes: Receive a token registration request from the first network element, where the token registration request includes the identification information of the first network element and the token of the first network element; Store the identification information of the first network element and the token of the first network element.

15. The method according to claim 14, wherein, The storing the identification information of the first network element and the token of the first network element includes: Performing a validity check on the token of the first network element; When the verification result of the validity check is verified successfully, store the identification information of the first network element and the token of the first network element.

16. The method according to any one of claims 1 to 15, wherein, The data type includes at least one of the following: The load data of the service network element, the resource utilization rate data of the service network element, the abnormal event data of the service network element, or the energy consumption data of the service network element.

17. The method according to claim 16, wherein, the load data comes from a network storage network element, or the resource utilization rate data and / or the abnormal event data come from an operation and maintenance management network element.

18. A communication method, wherein, the method includes: receiving a token issuance request from a first network element, the token issuance request including the identification information of the first network element; sending a token grant response to the first network element, the token grant response including the token of the first network element, the token corresponding to the identification information of the first network element, the token including first information, and the first information indicating the data types that the first network element has read permissions for.

19. The method according to claim 18, wherein, after receiving the token issuance request from the first network element, the method further includes: sending a subscription information query request to a third network element, the subscription information query request including the identification information of the first network element; receiving a subscription information response sent by the third network element, the subscription information response including the trust level and / or service type of the first network element; the token of the first network element is determined according to the identification information of the first network element and / or the subscription information response.

20. The method according to claim 19, wherein, the token issuance request further includes third information, and the third information indicates the data types that the first network element prefers to read; the token of the first network element is determined according to at least one of the identification information of the first network element, the subscription information response, and the third information.

21. A communication method, wherein, applied to a first network element, the method includes: sending a token issuance request to an authentication server, the token issuance request including the identification information of the first network element; receiving a token grant response sent by the authentication server, the token grant response including the token of the first network element, the token corresponding to the identification information of the first network element, the token including first information, and the first information indicating the data types that the first network element has read permissions for.

22. The method according to claim 21, wherein, the token of the first network element is determined according to the identification information of the first network element and / or a subscription information response from a third network element, and the subscription information response includes the trust level and / or service type of the first network element.

23. The method according to claim 22, wherein, the token issuance request further includes third information, and the third information indicates the data types that the first network element prefers to read; the token of the first network element is determined according to at least one of the identification information of the first network element, the subscription information response, and the third information.

24. A communication device, including a module for executing the method according to any one of claims 1 to 23.

25. A communication device, wherein, Comprising a processor and an interface circuit, the interface circuit being configured to receive signals from other communication devices outside the communication device and transmit them to the processor or send signals from the processor to other communication devices outside the communication device, the processor being configured to implement the method according to any one of claims 1 to 23 through logic circuits or by executing code instructions.

26. A computer-readable storage medium, characterized in that the storage medium stores a computer program or instructions, and when the computer program or instructions are executed by a communication device, the method according to any one of claims 1 to 23 is implemented.

Citation Information

Cited By

  • Communication method and related device

    EP4804585A1

  • Communication method and related device

    WO2025113338A1