Communication method and communication device
By verifying the effectiveness of ID routing relationship information, the accuracy problem of user ID service discovery in 5G mobile communication system is solved, and a higher service success rate is achieved.
Patent Information
- Application Number
- CN202311787291.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-22
- Publication Date
- 2025-06-24
AI Technical Summary
In the service-oriented architecture of the 5G mobile communication system, when the network storage function entity performs service discovery based on the user ID, the wrong NF entity may be found, resulting in service failure.
A communication method and a communication device are provided to ensure the accurate relationship between the user ID and the NF entity by verifying the validity of the ID routing relationship information. The specific steps include receiving information from the second functional entity, indicating the first routing relationship, and determining its validity.
Improve the accuracy of NRF entities when service discovery is based on user ID, avoid NF entities conflicts caused by user ID errors, and ensure business success.
Smart Images

Figure CN120201507A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of wireless communications, and in particular, to a communication method and a communication device. Background Art
[0002] In the service-based architecture (SBA) of the 5th generation (5G) mobile communication system, a registration and discovery model is adopted. For example, when a network function (NF) entity registers with a network repository function (NRF) entity, it can report the user identity (ID) of its own service. The NRF entity can determine the ID routing relationship information based on the user ID reported by the NF entity, so that the NRF entity can perform service discovery based on the user ID to determine the NF entity that meets the service requirements. The ID routing relationship information can be understood as the relationship between the user ID and the NF entity.
[0003] However, there are the following problems with this registration and discovery method: When the NRF entity performs service discovery based on the user ID, it may find the wrong NF entity, resulting in service failure. Summary of the Invention
[0004] This application provides a communication method and a communication device. This application provides a verification mechanism for determining the validity of identity (ID) routing relationship information to improve the accuracy when a network repository function (NRF) entity performs service discovery based on the user ID.
[0005] In a first aspect, this application provides a communication method, which is applied to a first functional entity. The method includes: receiving first information from a second functional entity, where the first information indicates a first routing relationship, and the first routing relationship is the relationship between the identity information of the second functional entity and the first user identity information; determining the validity of the first routing relationship.
[0006] As an example, this method can be executed by the first functional entity, or can be executed by a chip system, a hardware circuit, and / or a software module applied in the first functional entity.
[0007] As an example, the first functional entity may be an ID access gateway, and the second functional entity may be an ID home server directly connected to the first functional entity.
[0008] In this technical solution, when the second functional entity completes configuration and the device accesses the network, it can register with the first functional entity and report its own capabilities and attributes. For example, the second functional entity can send a first message to the first functional entity, and the first message is used to indicate a first routing relationship, where the first routing relationship is the relationship between the identification information of the second functional entity and the first user identification information.
[0009] As an example, the identification information of the second functional entity can be the host ID of the second functional entity, and the host ID of the second functional entity can be represented by a common network entity identifier such as the fully qualified domain name (FQDN) of the second functional entity or other domain names; the first routing relationship can be understood as ID routing relationship information, and the first user identification information can be understood as the user ID reported by the second functional entity during registration. The user ID can be represented by the segment of the user ID, the prefix of the user ID, or the value of the user ID. The segment of the user ID can also be referred to as the range or range of the user ID. Among them, the segment of the user ID is, for example, from 4600310000 to 4600320000, the prefix of the user ID is, for example, 4600 or 46003, and the value of the user ID can be any specific value between 4600310000 and 4600320000.
[0010] In this technical solution, after receiving the first message sent by the second functional entity, the first functional entity can determine the validity of the first routing relationship indicated by the first message, avoiding the problem of conflicts in the user IDs reported by different second functional entities caused by incorrect user IDs reported by the second functional entity, so that the accuracy of the second functional entity found by the first functional entity based on the user ID is relatively high. Among them, determining the validity of the first routing relationship can also be referred to as determining the legality of the first routing relationship, or verifying / validating / authenticating the validity of the first routing relationship, which is not specifically limited here.
[0011] Combined with the first aspect, in some implementation manners of the first aspect, determining the validity of the first routing relationship includes: sending a second message to a third functional entity, where the second message is used to request to determine the validity of the first routing relationship; receiving a third message from the third functional entity, and the third message indicates the validity of the first routing relationship.
[0012] In this implementation manner, the first functional entity can request the third functional entity to determine the validity of the first routing relationship. As an example, the third functional entity can be an ID routing authentication service directly connected to the first functional entity, or in other words, the third functional entity can be an ID routing authentication service located in the same routing domain as the first functional entity.
[0013] As an example, the second information may include the first routing relationship.
[0014] As an example, the third information may include a determination result of the validity of the first routing relationship, and the determination result may be any one of the following: valid, invalid, or unknown. It should be understood that when the determination result is valid, it can be considered that the authentication of the first routing relationship is successful; when the determination result is invalid, it can be considered that the authentication of the first routing relationship fails; when the determination result is unknown, it can be considered that the authentication function for determining the validity of the first routing relationship of the third functional entity is not enabled.
[0015] As an example, when the determination result is valid, the first functional entity may save the first routing relationship to the local database; when the determination result is invalid, the first functional entity does not save the first routing relationship; when the determination result is unknown, the first functional entity may process the first routing relationship based on the local configuration policy. As an example, the local configuration policy may be that when the determination result of the validity of the first routing relationship is unknown, the first functional entity may save or not save the first routing relationship. If the first routing relationship is saved, it is necessary to indicate that the determination result of the validity of the saved first routing relationship is unknown. Optionally, the local configuration policy may be pre-configured in the first functional entity in advance.
[0016] Combined with the first aspect, in some implementation manners of the first aspect, when the first routing relationship is valid, the third information further includes the routing valid domain of the first routing relationship.
[0017] In this implementation manner, when it is determined that the first routing relationship is valid, the third information may further include the routing valid domain of the first routing relationship. The routing valid domain of the first routing relationship can be understood as the publishing range or transmission range of the first routing relationship in the ID routing network.
[0018] Therefore, when the third information indicates that the determination result of the validity of the first routing relationship is valid, the first functional entity also needs to determine whether the third information includes the routing valid domain of the first routing relationship. As an example, if the third information does not include the routing valid domain of the first routing relationship, the first functional entity may consider that the routing valid domain of the first routing relationship is the entire ID routing network.
[0019] In this implementation manner, by carrying the routing valid domain of the first routing relationship in the third information, the first functional entity can determine the publishing range of the first routing relationship, so that the first functional entity can implement the functions of hiding or publishing routing information according to the routing valid domain, and realizes the security isolation and hiding of routing information.
[0020] In combination with the first aspect, in some implementations of the first aspect, determining the validity of the first routing relationship includes: obtaining fourth information, where the fourth information includes information obtained by signing a second routing relationship with a key pair of a first certificate, the first certificate being a certificate of the second functional entity, and the second routing relationship being a relationship between the identification information of the second functional entity and the user identification information belonging to the second functional entity; determining the validity of the first routing relationship based on the fourth information.
[0021] In this implementation, the first functional entity can independently determine the validity of the first routing relationship. As an example, the first functional entity can periodically obtain the signed second routing relationship from the ID resource management center. The signed second routing relationship is obtained by signing the second routing relationship with a key pair of the certificate of the second functional entity, and the key can include a public key and a private key.
[0022] As an example, the second routing relationship is a relationship between the identification information of the second functional entity and the second user identification information. The second user identification information can be understood as the user ID resource assigned by the ID resource management center to the second functional entity. As an example, the second routing relationship can include one or more key values (key), and the key value can be expressed as <second user identification information, identification information of the second functional entity>. It should be understood that the number of key values is consistent with the number of second user identification information.
[0023] Therefore, the first functional entity can determine the validity of the first routing relationship based on the second routing relationship. As an example, when there is a key value in the second routing relationship that matches the first routing relationship, the first routing relationship can be considered valid. For example, if the first routing relationship matches the first key value in the second routing relationship, then the identification information of the second functional entity in the first routing relationship is the same as the identification information of the second functional entity in the first key value, and the first user identification information in the first routing relationship is a subset of the second user identification information in the first key value.
[0024] In this implementation, the second routing relationship can be signed by using certificate signing, so that the first functional entity can determine the validity of the first routing relationship based on the signed second routing relationship.
[0025] In combination with the first aspect, in some implementations of the first aspect, the fourth information further includes the first certificate, and determining the validity of the first routing relationship based on the fourth information includes: determining the validity of the first certificate; when the first certificate is valid, determining the validity of the first routing relationship based on the first certificate.
[0026] In this implementation manner, if the validity of the first routing relationship is determined based on the second routing relationship, the signed second routing relationship needs to be decrypted. Therefore, the first functional entity also needs to obtain the certificate of the second functional entity from the ID resource management center, and when it is determined that the certificate of the second functional entity is valid, use the key of the certificate of the second functional entity to decrypt the signed second routing relationship, so as to determine the validity of the first routing relationship.
[0027] Combined with the first aspect, in some implementation manners of the first aspect, the fourth information further includes a second certificate, and the second certificate is a certificate of the routing domain to which the second functional entity belongs; wherein, determining the validity of the first certificate includes: determining the validity of the second certificate; when the second certificate is valid, determining the validity of the first certificate based on the second certificate.
[0028] As an example, the certificate of the second functional entity can be signed by the second certificate, and the second certificate can also be called a trust domain certificate, and the trust domain certificate can be a certificate of the ID routing domain to which the second functional entity belongs. Therefore, the first functional entity also needs to obtain the second certificate from the ID resource management center, and decrypt the signer information in the certificate of the second functional entity based on the key of the second certificate, so as to determine the validity of the certificate of the second functional entity.
[0029] Combined with the first aspect, in some implementation manners of the first aspect, determining the validity of the second certificate includes: determining the validity of the second certificate based on the root certificate, and the second certificate is signed by the root certificate.
[0030] As an example, the second certificate can be signed by the root certificate. Therefore, the first functional entity can decrypt the signer information in the second certificate based on the key of the root certificate, so as to determine the validity of the second certificate.
[0031] As an example, the first functional entity can obtain the root certificate from the ID resource management center.
[0032] As an example, the root certificate can be pre-configured in the first functional entity.
[0033] Combined with the first aspect, in some implementation manners of the first aspect, the second routing relationship further includes a routing valid domain of the second routing relationship.
[0034] As an example, the routing valid domain of the second routing relationship can be understood as the routing publication range of each key value in the second routing relationship.
[0035] As an example, the routing valid domain can be represented by a common network domain identifier such as the FQDN format.
[0036] As an example, the routing valid domain of the first routing relationship can be determined based on the routing valid domain of the second routing relationship. For example, when the first key value in the first routing relationship matches the first key value in the second routing relationship, the routing valid domain of the first routing relationship is consistent with the routing valid domain of the first key value.
[0037] In combination with the first aspect, in some implementation manners of the first aspect, when the first routing relationship is valid, the method further includes: sending fifth information to a fourth functional entity, where the fifth information includes the first user identification information and the identification information of the first functional entity.
[0038] As an example, the fourth functional entity can be understood as an ID router or an ID access gateway directly connected to the first functional entity.
[0039] In this implementation manner, when determining that the first routing relationship is valid, the first functional entity can also send fifth information to the fourth functional entity, and the fifth information can include the first user identification information and the identification information of the first functional entity. It should be understood that the first user identification information included in the fifth information is the first user identification information included in the determined valid first routing relationship.
[0040] In combination with the first aspect, in some implementation manners of the first aspect, the sending the fifth information to the fourth functional entity includes: when the routing valid domain of the first routing relationship is greater than the service domain of the first functional entity, sending the fifth information to the fourth functional entity.
[0041] In this implementation manner, when determining that the first routing relationship is valid, the first functional entity can determine whether to send the fifth information based on the routing valid domain of the first routing relationship. As an example, the first functional entity can determine the routing valid domain of the first routing relationship based on the third information or the routing valid domain of the second routing relationship.
[0042] As an example, if the routing valid domain of the first routing relationship is not greater than the service domain of the first functional entity, there is no need to send the fifth information to the fourth functional entity. If the routing valid domain of the first routing relationship is greater than the service domain of the first functional entity, the first functional entity can send the fifth information to the fourth functional entity. Among them, the service domain of the fourth functional entity is smaller than the routing valid domain of the first routing relationship, or in other words, the service domain of the fourth functional entity is included in the routing valid domain of the first routing relationship. Optionally, the service domain of the first functional entity or the fourth functional entity can be represented by common network domain identifiers such as the FQDN or domain name of the first functional entity or the fourth functional entity.
[0043] In combination with the first aspect, in some implementation manners of the first aspect, the fifth information further includes the identification information of the second functional entity, and / or, the routing valid domain of the first routing relationship.
[0044] In this implementation manner, the fifth piece of information may further include the identification information of the second functional entity, so that the fourth functional entity can determine the validity of the first routing relationship included in the fifth piece of information, and when the fourth functional entity determines that the first routing relationship is invalid, it can trace the device of the second functional entity that reports the invalid first routing relationship based on the identification information of the second functional entity.
[0045] In this implementation manner, the fifth piece of information may further include the routing valid domain of the first routing relationship, so that the fourth functional entity can determine whether to continue forwarding the routing information including the first user identification information according to the routing valid domain, so that the fourth functional entity realizes the function of publishing or hiding the routing information, and realizes the security isolation and hiding of the routing information.
[0046] In a second aspect, the present application provides a communication method, which is applied to a second functional entity, and the method includes: determining first information, where the first information indicates a first routing relationship, and the first routing relationship is a relationship between the identification information of the second functional entity and the first user identification information; sending the first information to a first functional entity.
[0047] As an example, this method may be executed by the second functional entity, or may be executed by a chip system, a hardware circuit, and / or a software module applied in the second functional entity.
[0048] As an example, the second functional entity may be an ID attribution server, and the first functional entity may be an ID access gateway directly connected to the second functional entity.
[0049] In this technical solution, when the second functional entity completes configuration and the device accesses the network, it can register and report its own capabilities and attributes to the first functional entity. For example, the second functional entity may send first information to the first functional entity, and the first information is used to indicate a first routing relationship, and the first routing relationship is a relationship between the identification information of the second functional entity and the first user identification information.
[0050] As an example, the identification information of the second functional entity may be the host ID of the second functional entity, and the host ID of the second functional entity may be represented by common network entity identifications such as the FQDN of the second functional entity or other domain names; the first routing relationship may be understood as ID routing relationship information, and the first user identification information may be understood as the user ID registered and reported by the second functional entity. The user ID may be represented by the segment of the user ID, the prefix of the user ID, and the value of the user ID. The segment of the user ID may also be referred to as the range or range segment of the user ID. Among them, the segment of the user ID is, for example, from 4600310000 to 4600320000, the prefix of the user ID is, for example, 4600 or 46003, and the value of the user ID may be any specific value from 4600310000 to 4600320000.
[0051] In a third aspect, the present application provides a communication method, which is applied to a third functional entity. The method includes: receiving second information from a first functional entity, where the second information is used to request to determine the validity of a first routing relationship, and the first routing relationship is the relationship between the identification information of a second functional entity and first user identification information; sending third information to the first functional entity, where the third information indicates the validity of the first routing relationship.
[0052] As an example, this method may be executed by the third functional entity, or may be executed by a chip system, a hardware circuit, and / or a software module applied to the third functional entity.
[0053] As an example, the third functional entity may be an ID routing authentication service, the first functional entity may be an ID access gateway directly connected to the third functional entity, or in other words, the first functional entity may be an ID access gateway located in the same routing domain as the third functional entity, and the second functional entity may be an ID home server directly connected to the first functional entity.
[0054] As an example, the identification information of the second functional entity may be the host ID of the second functional entity, and the host ID of the second functional entity may be represented by common network entity identifications such as the FQDN of the second functional entity or other domain names; the first routing relationship may be understood as ID routing relationship information, and the first user identification information may be understood as the user ID registered and reported by the second functional entity to the first functional entity. The user ID may be represented by the segment of the user ID, the prefix of the user ID, and the value of the user ID. The segment of the user ID may also be referred to as the range or range segment of the user ID. Among them, the segment of the user ID is, for example, from 4600310000 to 4600320000, the prefix of the user ID is, for example, 4600 or 46003, and the value of the user ID may be any specific value from 4600310000 to 4600320000.
[0055] As an example, the second information may include a first routing relationship.
[0056] As an example, the third information may include a determination result of the validity of the first routing relationship, and the determination result may be any one of the following: valid, invalid, or unknown. It should be understood that when the determination result is valid, it can be considered that the authentication of the first routing relationship is successful; when the determination result is invalid, it can be considered that the authentication of the first routing relationship fails; when the determination result is unknown, it can be considered that the authentication function for determining the validity of the first routing relationship of the third functional entity is not enabled.
[0057] In this technical solution, when the second functional entity completes configuration and the device accesses the network, it can register and report its own capabilities and attributes to the first functional entity. For example, the second functional entity may send a first information to the first functional entity, and the first information is used to indicate a first routing relationship, and the first routing relationship is the relationship between the identification information of the second functional entity and the first user identification information; after receiving the first information sent by the second functional entity, the first functional entity may determine the validity of the first routing relationship indicated by the first information. Therefore, the first functional entity may send a second information to the third functional entity to request the third functional entity to determine the validity of the first routing relationship. Correspondingly, the third functional entity may receive the second information, and after determining whether the first routing relationship is valid, send a third information to the first functional entity to indicate the validity of the first routing relationship.
[0058] Combined with the third aspect, in some implementation manners of the third aspect, when the first routing relationship is valid, the third information further includes a routing valid domain of the first routing relationship.
[0059] In this implementation manner, when it is determined that the first routing relationship is valid, the third information may further include a routing valid domain of the first routing relationship. The routing valid domain of the first routing relationship may be understood as the publishing range or transmission range of the first routing relationship in the ID routing network.
[0060] As an example, when the determination result of the validity of the first routing relationship is valid, but the third information does not include the routing valid domain of the first routing relationship, it can be considered that the routing valid domain of the first routing relationship is the entire ID routing network.
[0061] In this implementation manner, by carrying the routing valid domain of the first routing relationship in the third information, the first functional entity can determine the publishing range of the first routing relationship, so that the first functional entity can implement the functions of hiding or publishing routing information according to the routing valid domain, and realizes the security isolation and hiding of routing information.
[0062] In combination with the third aspect, in some implementation manners of the third aspect, the method further includes: determining the validity of the first routing relationship.
[0063] In this implementation manner, after receiving the second information, the third functional entity may determine the validity of the first routing relationship included in the second information.
[0064] In combination with the third aspect, in some implementation manners of the third aspect, the determining the validity of the first routing relationship includes: obtaining sixth information, where the sixth information includes information obtained by signing a second routing relationship with a key pair of a first certificate, the first certificate being a certificate of the second functional entity, and the second routing relationship being a relationship between the identification information of the second functional entity and the user identification information belonging to the second functional entity; determining the validity of the first routing relationship based on the sixth information.
[0065] As an example, the third functional entity may periodically obtain the signed second routing relationship from the ID resource management center. The signed second routing relationship is obtained by signing the second routing relationship with a key pair of a certificate of the second functional entity, and the key may include a public key and a private key.
[0066] As an example, the second routing relationship is a relationship between the identification information of the second functional entity and the second user identification information. The second user identification information may be understood as the user ID resource allocated by the ID resource management center to the second functional entity. As an example, the second routing relationship may include one or more key values (key). The key value may be expressed as <the second user identification information, the identification information of the second functional entity>. It should be understood that the number of key values is consistent with the number of the second user identification information.
[0067] Therefore, the third functional entity may determine the validity of the first routing relationship based on the second routing relationship. As an example, when there is a key value in the second routing relationship that matches the first routing relationship, the first routing relationship may be considered valid. For example, if the first routing relationship matches the first key value in the second routing relationship, then the identification information of the second functional entity in the first routing relationship is the same as the identification information of the second functional entity in the first key value, and the first user identification information in the first routing relationship is a subset of the second user identification information in the first key value.
[0068] In this implementation manner, the second routing relationship may be signed by using a certificate signature, so that the third functional entity may determine the validity of the first routing relationship based on the signed second routing relationship.
[0069] In combination with the third aspect, in some implementation manners of the third aspect, the sixth information further includes the first certificate, and determining the validity of the first routing relationship based on the sixth information includes: determining the validity of the first certificate; when the first certificate is valid, determining the validity of the first routing relationship based on the first certificate.
[0070] In this implementation manner, if determining the validity of the first routing relationship based on the second routing relationship, the signed second routing relationship needs to be decrypted. Therefore, the third functional entity also needs to obtain the certificate of the second functional entity from the ID resource management center, and when determining that the certificate of the second functional entity is valid, use the private key of the certificate of the second functional entity to decrypt the signed second routing relationship, so as to determine the validity of the first routing relationship.
[0071] In combination with the third aspect, in some implementation manners of the third aspect, the sixth information further includes a second certificate, and the second certificate is the certificate of the routing domain to which the second functional entity belongs; wherein, determining the validity of the first certificate includes: determining the validity of the second certificate; when the second certificate is valid, determining the validity of the first certificate based on the second certificate.
[0072] As an example, the certificate of the second functional entity can be signed by the second certificate, and the second certificate can also be referred to as a trust domain certificate. The trust domain certificate can be the certificate of the ID routing domain to which the second functional entity belongs. Therefore, the third functional entity also needs to obtain the second certificate from the ID resource management center, and based on the private key of the second certificate, decrypt the signer information in the certificate of the second functional entity, so as to determine the validity of the certificate of the second functional entity.
[0073] In combination with the third aspect, in some implementation manners of the third aspect, determining the validity of the second certificate includes: determining the validity of the second certificate based on the root certificate, and the second certificate is signed by the root certificate.
[0074] As an example, the second certificate can be signed by the root certificate. Therefore, the third functional entity can decrypt the signer information in the second certificate based on the private key of the root certificate, so as to determine the validity of the second certificate.
[0075] As an example, the third functional entity can obtain the root certificate from the ID resource management center.
[0076] As an example, the root certificate can be pre-configured in the third functional entity.
[0077] In combination with the third aspect, in some implementation manners of the third aspect, the second routing relationship further includes the routing valid domain of the second routing relationship.
[0078] As an example, the routing valid domain of the second routing relationship can be understood as the routing publication scope of each key value in the second routing relationship.
[0079] As an example, the routing valid domain can be represented by common network domain identifiers such as the FQDN format.
[0080] As an example, the routing valid domain of the first routing relationship can be determined based on the routing valid domain of the second routing relationship. For example, when the first key value in the first routing relationship matches the first key value in the second routing relationship, the routing valid domain of the first routing relationship is the same as the routing valid domain of the first key value.
[0081] In this implementation manner, by carrying the routing valid domain in the second routing relationship, each functional entity (such as the first functional entity, the fourth functional entity, etc.) in the ID routing network can determine the publication scope of the routing information, so that each functional entity can implement the functions of hiding or publishing the routing information according to the routing valid domain, realizing the security isolation and hiding of the routing information.
[0082] In a fourth aspect, the present application provides a communication method, which is applied to a fourth functional entity, and the method includes: receiving fifth information from a first functional entity, where the fifth information indicates a first routing relationship, and the first routing relationship is a relationship between the identification information of a second functional entity and the first user identification information; determining the validity of the first routing relationship.
[0083] As an example, this method can be executed by the fourth functional entity, or can be executed by a chip system, a hardware circuit, and / or a software module applied to the fourth functional entity.
[0084] As an example, the fourth functional entity can be an ID router or an ID access gateway, the first functional entity can be understood as an ID access gateway directly connected to the fourth functional entity, and the second functional entity can be an ID home server directly connected to the first functional entity.
[0085] In this technical solution, after the first functional entity receives the first routing relationship reported by the second functional entity during registration, it can determine the validity of the first routing relationship, and in the case of determining that the first routing relationship is valid, send the fifth information to the fourth functional entity.
[0086] As an example, the identification information of the second functional entity may be the host ID of the second functional entity, and the host ID of the second functional entity may be represented by common network entity identifications such as the FQDN of the second functional entity or other domain names; the first routing relationship may be understood as ID routing relationship information, and the first user identification information may be understood as the user ID registered and reported by the second functional entity. The user ID may be represented by the number segment of the user ID, the prefix of the user ID, or the value of the user ID. The number segment of the user ID may also be referred to as the range or range of the user ID. Among them, the number segment of the user ID is, for example, from 4600310000 to 4600320000, the user ID prefix is, for example, 4600 or 46003, and the value of the user ID may be any specific value from 4600310000 to 4600320000.
[0087] As an example, the fifth information indicates the first routing relationship, which may be understood as the fifth information includes the first routing relationship. It should be understood that the first user identification information included in the fifth information is the first user identification information included in the determined valid first routing relationship.
[0088] As an example, the fifth information may further include the identification information of the first functional entity.
[0089] In this technical solution, after receiving the fifth information, the fourth functional entity can determine the validity of the first routing relationship included in the fifth information, so as to avoid receiving an invalid first routing relationship from the first functional entity, making the accuracy of the first routing relationship published / transmitted in the ID routing network relatively high. Among them, determining the validity of the first routing relationship may also be referred to as determining the legality of the first routing relationship, or verifying / checking / authenticating the validity of the first routing relationship, which is not specifically limited here.
[0090] Combined with the fourth aspect, in some implementation manners of the fourth aspect, the fifth information further includes the routing valid domain of the first routing relationship.
[0091] In this implementation manner, the fifth information may further include the routing valid domain of the first routing relationship, so that the fourth functional entity can determine whether to continue forwarding the routing information including the first user identification information according to the routing valid domain, so that the fourth functional entity realizes the functions of publishing or hiding the routing information, and realizes the security isolation and hiding of the routing information.
[0092] Combined with the fourth aspect, in some implementation manners of the fourth aspect, determining the validity of the first routing relationship includes: sending the seventh information to the fifth functional entity, where the seventh information is used to request determining the validity of the first routing relationship; receiving the eighth information from the fifth functional entity, where the eighth information indicates the validity of the first routing relationship.
[0093] In this implementation manner, the fourth functional entity may request the fifth functional entity to determine the validity of the first routing relationship. As an example, the fifth functional entity may be an ID routing authentication service directly connected to the fourth functional entity, or the fifth functional entity may be an ID routing authentication service located in the same routing domain as the fourth functional entity.
[0094] As an example, the seventh information may include the first routing relationship, and the first routing relationship included in the seventh information is valid.
[0095] As an example, the eighth information may include the determination result of the validity of the first routing relationship, and the determination result may be any one of the following: valid, invalid, or unknown. It should be understood that when the determination result is valid, it can be considered that the authentication of the first routing relationship is successful; when the determination result is invalid, it can be considered that the authentication of the first routing relationship fails; when the determination result is unknown, it can be considered that the authentication function for determining the validity of the first routing relationship of the fifth functional entity is not enabled.
[0096] As an example, when the determination result is valid, the fourth functional entity may save the first routing relationship to the local database; when the determination result is invalid, the fourth functional entity does not save the first routing relationship; when the determination result is unknown, the fourth functional entity may process the first routing relationship based on the local configuration policy. As an example, the local configuration policy may be that when the determination result of the validity of the first routing relationship is unknown, the fourth functional entity may save or not save the first routing relationship. If the first routing relationship is saved, it is necessary to indicate that the determination result of the validity of the saved first routing relationship is unknown. Optionally, the local configuration policy may be pre-configured in the fourth functional entity in advance.
[0097] Combined with the fourth aspect, in some implementation manners of the fourth aspect, when the first routing relationship is valid, the eighth information further includes the routing valid domain of the first routing relationship.
[0098] In this implementation manner, when it is determined that the first routing relationship is valid, the eighth information may further include the routing valid domain of the first routing relationship. The routing valid domain of the first routing relationship can be understood as the publishing range or transmission range of the first routing relationship in the ID routing network.
[0099] Therefore, when the eighth information indicates that the determination result of the validity of the first routing relationship is valid, the fourth functional entity also needs to determine whether the eighth information includes the routing valid domain of the first routing relationship. As an example, if the eighth information does not include the routing valid domain of the first routing relationship, the fourth functional entity may consider the routing valid domain of the first routing relationship to be the entire ID routing network.
[0100] In this implementation manner, by carrying the routing valid domain of the first routing relationship in the eighth piece of information, the fourth functional entity can determine the publishing scope of the first routing relationship, so that the fourth functional entity can implement the functions of hiding or publishing routing information according to the routing valid domain, achieving the security isolation and hiding of routing information.
[0101] Combined with the fourth aspect, in some implementation manners of the fourth aspect, determining the validity of the first routing relationship includes: obtaining ninth information, where the ninth information includes the information obtained by signing the second routing relationship with the key pair of the first certificate, the first certificate is the certificate of the second functional entity, and the second routing relationship is the relationship between the identification information of the second functional entity and the user identification information belonging to the second functional entity; determining the validity of the first routing relationship based on the ninth information.
[0102] In this implementation manner, the fourth functional entity can independently determine the validity of the first routing relationship. As an example, the fourth functional entity can periodically obtain the signed second routing relationship from the ID resource management center. The signed second routing relationship is obtained by signing the second routing relationship with the key pair of the certificate of the second functional entity, and the key can include a public key and a private key.
[0103] As an example, the second routing relationship is the relationship between the identification information of the second functional entity and the second user identification information. The second user identification information can be understood as the user ID resource allocated by the ID resource management center for the second functional entity. As an example, the second routing relationship can include one or more key values (key), and the key value can be expressed as <second user identification information, identification information of the second functional entity>. It should be understood that the number of key values is consistent with the number of second user identification information.
[0104] Therefore, the fourth functional entity can determine the validity of the first routing relationship based on the second routing relationship. As an example, when there is a key value in the second routing relationship that matches the first routing relationship, it can be considered that the first routing relationship is valid. For example, if the first routing relationship matches the first key value in the second routing relationship, then the identification information of the second functional entity in the first routing relationship is the same as the identification information of the second functional entity in the first key value, and the first user identification information in the first routing relationship is a subset of the second user identification information in the first key value.
[0105] In this implementation manner, the second routing relationship can be signed by using the certificate signature method, so that the fourth functional entity can determine the validity of the first routing relationship based on the signed second routing relationship.
[0106] In combination with the fourth aspect, in some implementations of the fourth aspect, the ninth information further includes the first certificate. Determining the validity of the first routing relationship based on the ninth information includes: determining the validity of the first certificate; when the first certificate is valid, determining the validity of the first routing relationship based on the first certificate.
[0107] In this implementation, if the validity of the first routing relationship is determined based on the second routing relationship, the signed second routing relationship needs to be decrypted. Therefore, the fourth functional entity also needs to obtain the certificate of the second functional entity from the ID resource management center, and when it is determined that the certificate of the second functional entity is valid, use the key of the certificate of the second functional entity to decrypt the signed second routing relationship, so as to determine the validity of the first routing relationship.
[0108] In combination with the fourth aspect, in some implementations of the fourth aspect, the ninth information further includes a second certificate, and the second certificate is the certificate of the routing domain to which the second functional entity belongs; wherein, determining the validity of the first certificate includes: determining the validity of the second certificate; when the second certificate is valid, determining the validity of the first certificate based on the second certificate.
[0109] As an example, the certificate of the second functional entity can be signed by the second certificate, and the second certificate can also be called the trust domain certificate, and the trust domain certificate can be the certificate of the ID routing domain to which the second functional entity belongs. Therefore, the fourth functional entity also needs to obtain the second certificate from the ID resource management center, and decrypt the signer information in the certificate of the second functional entity based on the key of the second certificate, so as to determine the validity of the certificate of the second functional entity.
[0110] In combination with the fourth aspect, in some implementations of the fourth aspect, determining the validity of the second certificate includes: determining the validity of the second certificate based on the root certificate, and the second certificate is signed by the root certificate.
[0111] As an example, the second certificate can be signed by the root certificate. Therefore, the fourth functional entity can decrypt the signer information in the second certificate based on the key of the root certificate, so as to determine the validity of the second certificate.
[0112] As an example, the fourth functional entity can obtain the root certificate from the ID resource management center.
[0113] As an example, the root certificate can be pre-configured in the fourth functional entity.
[0114] In combination with the fourth aspect, in some implementations of the fourth aspect, the second routing relationship further includes the routing valid domain of the second routing relationship.
[0115] As an example, the routing valid domain of the second routing relationship can be understood as the routing distribution range of each key value in the second routing relationship.
[0116] As an example, the routing valid domain can be represented by common network domain identifiers such as the FQDN format.
[0117] As an example, the routing valid domain of the first routing relationship can be determined based on the routing valid domain of the second routing relationship. For example, when the first key value in the first routing relationship matches the second routing relationship, the routing valid domain of the first routing relationship is the same as the routing valid domain of the first key value.
[0118] In a fifth aspect, the present application provides a communication method. The method is applied to a fifth functional entity and includes: receiving seventh information from a fourth functional entity, where the seventh information is used to request determination of the validity of a first routing relationship, and the first routing relationship is a relationship between the identification information of a second functional entity and first user identification information; and sending eighth information to the fourth functional entity, where the eighth information indicates the validity of the first routing relationship.
[0119] As an example, this method can be executed by the fifth functional entity, or can be executed by a chip system, a hardware circuit, and / or a software module applied to the fifth functional entity.
[0120] As an example, the fifth functional entity can be an ID routing authentication service, the fourth functional entity can be an ID access gateway directly connected to the fifth functional entity, or in other words, the fourth functional entity can be an ID access gateway located in the same routing domain as the fifth functional entity, and the second functional entity can be an ID home server directly connected to the fourth functional entity.
[0121] As an example, the identification information of the second functional entity can be the host ID of the second functional entity, and the host ID of the second functional entity can be represented by common network entity identifiers such as the FQDN of the second functional entity or other domain names; the first routing relationship can be understood as ID routing relationship information, and the first user identification information can be understood as the user ID registered and reported by the second functional entity to the first functional entity. The user ID can be represented by the segment of the user ID, the prefix of the user ID, and the value of the user ID. The segment of the user ID can also be referred to as the range or segment range of the user ID. Among them, the segment of the user ID is, for example, from 4600310000 to 4600320000, the prefix of the user ID is, for example, 4600 or 46003, and the value of the user ID can be any specific value from 4600310000 to 4600320000.
[0122] As an example, the seventh information can include the first routing relationship.
[0123] As an example, the eighth piece of information may include the determination result of the validity of the first routing relationship, and the determination result may be any one of the following: valid, invalid, or unknown. It should be understood that when the determination result is valid, it can be considered that the authentication of the first routing relationship is successful; when the determination result is invalid, it can be considered that the authentication of the first routing relationship fails; when the determination result is unknown, it can be considered that the authentication function of the fifth functional entity for determining the validity of the first routing relationship is not enabled.
[0124] In this technical solution, after receiving the fifth piece of information, the fourth functional entity can verify the validity of the first routing relationship included in the fifth piece of information. Therefore, the fourth functional entity can send the seventh piece of information to the fifth functional entity to request the fifth functional entity to determine the validity of the first routing relationship. Correspondingly, the fifth functional entity can receive the seventh piece of information, and after determining whether the first routing relationship is valid, send the eighth piece of information to the fourth functional entity to indicate the validity of the first routing relationship.
[0125] Combined with the fifth aspect, in some implementation manners of the fifth aspect, when the first routing relationship is valid, the eighth piece of information further includes the routing valid domain of the first routing relationship.
[0126] In this implementation manner, when it is determined that the first routing relationship is valid, the eighth piece of information may further include the routing valid domain of the first routing relationship. The routing valid domain of the first routing relationship can be understood as the publishing range or transmission range of the first routing relationship in the ID routing network.
[0127] As an example, when the determination result of the validity of the first routing relationship is valid, but the eighth piece of information does not include the routing valid domain of the first routing relationship, it can be considered that the routing valid domain of the first routing relationship is the entire ID routing network.
[0128] In this implementation manner, by carrying the routing valid domain of the first routing relationship in the eighth piece of information, the fourth functional entity can determine the publishing range of the first routing relationship, so that the fourth functional entity can implement the functions of hiding or publishing routing information according to the routing valid domain, realizing the security isolation and hiding of routing information.
[0129] Combined with the fifth aspect, in some implementation manners of the fifth aspect, the method further includes: determining the validity of the first routing relationship.
[0130] In this implementation manner, after receiving the seventh piece of information, the fifth functional entity can determine the validity of the first routing relationship included in the seventh piece of information.
[0131] In combination with the fifth aspect, in some implementations of the fifth aspect, determining the validity of the first routing relationship includes: obtaining tenth information, where the tenth information includes information obtained by signing a second routing relationship with a key pair of a first certificate, the first certificate being a certificate of the second functional entity, and the second routing relationship being a relationship between the identification information of the second functional entity and the user identification information belonging to the second functional entity; determining the validity of the first routing relationship based on the tenth information.
[0132] As an example, the fifth functional entity can periodically obtain the signed second routing relationship from the ID resource management center. The signed second routing relationship is obtained by signing the second routing relationship with a key pair of the certificate of the second functional entity, and the key can include a public key and a private key.
[0133] As an example, the second routing relationship is a relationship between the identification information of the second functional entity and the second user identification information. The second user identification information can be understood as the user ID resource allocated by the ID resource management center to the second functional entity. As an example, the second routing relationship can include one or more key values (keys), and the key value can be represented as <second user identification information, identification information of the second functional entity>. It should be understood that the number of key values is consistent with the number of second user identification information.
[0134] Therefore, the fifth functional entity can determine the validity of the first routing relationship based on the second routing relationship. As an example, when there is a key value in the second routing relationship that matches the first routing relationship, the first routing relationship can be considered valid. For example, if the first routing relationship matches the first key value in the second routing relationship, then the identification information of the second functional entity in the first routing relationship is consistent with the identification information of the second functional entity in the first key value, and the first user identification information in the first routing relationship is a subset of the second user identification information in the first key value.
[0135] In this implementation, the second routing relationship can be signed by using certificate signing, so that the fifth functional entity can determine the validity of the first routing relationship based on the signed second routing relationship.
[0136] In combination with the fifth aspect, in some implementations of the fifth aspect, the tenth information further includes the first certificate, and determining the validity of the first routing relationship based on the tenth information includes: determining the validity of the first certificate; when the first certificate is valid, determining the validity of the first routing relationship based on the first certificate.
[0137] In this implementation method, if the validity of the first routing relationship is determined based on the second routing relationship, the signed second routing relationship needs to be decrypted. Therefore, the fifth functional entity also needs to obtain the certificate of the second functional entity from the ID resource management center, and when it is determined that the certificate of the second functional entity is valid, use the key of the certificate of the second functional entity to decrypt the signed second routing relationship, so as to determine the validity of the first routing relationship.
[0138] Combined with the fifth aspect, in some implementation methods of the fifth aspect, the tenth information further includes a second certificate, and the second certificate is the certificate of the routing domain to which the second functional entity belongs; wherein, determining the validity of the first certificate includes: determining the validity of the second certificate; when the second certificate is valid, determining the validity of the first certificate based on the second certificate.
[0139] As an example, the certificate of the second functional entity can be signed by the second certificate, and the second certificate can also be called the trust domain certificate, and the trust domain certificate can be the certificate of the ID routing domain to which the second functional entity belongs. Therefore, the fifth functional entity also needs to obtain the second certificate from the ID resource management center, and decrypt the signer information in the certificate of the second functional entity based on the key of the second certificate, so as to determine the validity of the certificate of the second functional entity.
[0140] Combined with the fifth aspect, in some implementation methods of the fifth aspect, determining the validity of the second certificate includes: determining the validity of the second certificate based on the root certificate, and the second certificate is signed by the root certificate.
[0141] As an example, the second certificate can be signed by the root certificate. Therefore, the fifth functional entity can decrypt the signer information in the second certificate based on the key of the root certificate, so as to determine the validity of the second certificate.
[0142] As an example, the fifth functional entity can obtain the root certificate from the ID resource management center.
[0143] As an example, the root certificate can be pre-configured in the fifth functional entity.
[0144] Combined with the fifth aspect, in some implementation methods of the fifth aspect, the second routing relationship further includes the routing valid domain of the second routing relationship.
[0145] As an example, the routing valid domain of the second routing relationship can be understood as the routing publication range of each key value in the second routing relationship.
[0146] As an example, the routing valid domain can be represented by common network domain identifiers such as the FQDN format.
[0147] As an example, the routing valid domain of the first routing relationship can be determined based on the routing valid domain of the second routing relationship. For example, when the first key value in the first routing relationship matches the first key value in the second routing relationship, the routing valid domain of the first routing relationship is consistent with the routing valid domain of the first key value.
[0148] In this implementation manner, by carrying the routing valid domain in the second routing relationship, each functional entity (such as the first functional entity, the fourth functional entity, etc.) in the ID routing network can determine the publishing scope of the routing information, so that each functional entity can implement the functions of hiding or publishing the routing information according to the routing valid domain, realizing the security isolation and hiding of the routing information.
[0149] In a sixth aspect, the present application provides a communication device, which includes each module for implementing the method in the first aspect or any one of its implementation manners, and each module can be implemented in the form of hardware and / or software.
[0150] For example, the device may include: a receiving module and a processing module. The receiving module is used to receive the first information from the second functional entity, and the first information indicates the first routing relationship, where the first routing relationship is the relationship between the identification information of the second functional entity and the first user identification information; the processing module is used to determine the validity of the first routing relationship.
[0151] In combination with the sixth aspect, in some implementation manners of the sixth aspect, the device may further include a sending module. The sending module is used to send the second information to the third functional entity, and the second information is used to request to determine the validity of the first routing relationship; the receiving module is further used to receive the third information from the third functional entity, and the third information indicates the validity of the first routing relationship.
[0152] In combination with the sixth aspect, in some implementation manners of the sixth aspect, when the first routing relationship is valid, the third information further includes the routing valid domain of the first routing relationship.
[0153] In combination with the sixth aspect, in some implementation manners of the sixth aspect, the processing module is further used to obtain the fourth information, where the fourth information includes the information obtained by signing the second routing relationship with the key pair of the first certificate, the first certificate is the certificate of the second functional entity, and the second routing relationship is the relationship between the identification information of the second functional entity and the user identification information belonging to the second functional entity; the processing module is further used to determine the validity of the first routing relationship based on the fourth information.
[0154] In combination with the sixth aspect, in certain implementations of the sixth aspect, the fourth information further includes the first certificate, and the processing module is further configured to determine the validity of the first certificate; the processing module is further configured to, when the first certificate is valid, determine the validity of the first routing relationship based on the first certificate.
[0155] In combination with the sixth aspect, in certain implementations of the sixth aspect, the fourth information further includes a second certificate, and the second certificate is a certificate of the routing domain to which the second functional entity belongs; the processing module is further configured to determine the validity of the second certificate; the processing module is further configured to, when the second certificate is valid, determine the validity of the first certificate based on the second certificate.
[0156] In combination with the sixth aspect, in certain implementations of the sixth aspect, the processing module is further configured to determine the validity of the second certificate based on a root certificate, and the second certificate is signed by the root certificate.
[0157] In combination with the sixth aspect, in certain implementations of the sixth aspect, the second routing relationship further includes a routing valid domain of the second routing relationship.
[0158] In combination with the sixth aspect, in certain implementations of the sixth aspect, when the first routing relationship is valid, the sending module is further configured to send fifth information, and the fifth information includes the first user identification information and the identification information of the first functional entity.
[0159] In combination with the sixth aspect, in certain implementations of the sixth aspect, the sending module is further configured to send the fifth information to the fourth functional entity when the routing valid domain of the first routing relationship is larger than the service domain of the first functional entity.
[0160] In combination with the sixth aspect, in certain implementations of the sixth aspect, the fifth information further includes the identification information of the second functional entity, and / or, the routing valid domain of the first routing relationship.
[0161] In a seventh aspect, the present application provides a communication device, and the device includes each module for implementing the method in the second aspect or any one of its implementations, and each module can be implemented in the form of hardware and / or software.
[0162] For example, the device may include: a processing module and a sending module. The processing module is configured to determine first information, and the first information indicates a first routing relationship, and the first routing relationship is a relationship between the identification information of the second functional entity and the first user identification information; the sending module is configured to send the first information to the first functional entity.
[0163] In an eighth aspect, the present application provides a communication device, which includes various modules for implementing the methods in the third aspect or any one of its implementation manners, and each module can be implemented in the form of hardware and / or software.
[0164] For example, the device may include: a receiving module and a sending module. The receiving module is configured to receive second information from a first functional entity, where the second information is used to request to determine the validity of a first routing relationship, and the first routing relationship is the relationship between the identification information of a second functional entity and the first user identification information; the sending module is configured to send third information to the first functional entity, and the third information indicates the validity of the first routing relationship.
[0165] In combination with the eighth aspect, in some implementation manners of the eighth aspect, when the first routing relationship is valid, the third information further includes the routing valid domain of the first routing relationship.
[0166] In combination with the eighth aspect, in some implementation manners of the eighth aspect, the device may further include: a processing module. The processing module is configured to determine the validity of the first routing relationship.
[0167] In combination with the eighth aspect, in some implementation manners of the eighth aspect, the processing module is further configured to obtain sixth information, where the sixth information includes the information obtained by signing a second routing relationship with a key pair of a first certificate, the first certificate is the certificate of the second functional entity, and the second routing relationship is the relationship between the identification information of the second functional entity and the user identification information belonging to the second functional entity; the processing module is further configured to determine the validity of the first routing relationship based on the sixth information.
[0168] In combination with the eighth aspect, in some implementation manners of the eighth aspect, the sixth information further includes the first certificate, and the processing module is further configured to determine the validity of the first certificate; the processing module is further configured to determine the validity of the first routing relationship based on the first certificate when the first certificate is valid.
[0169] In combination with the eighth aspect, in some implementation manners of the eighth aspect, the sixth information further includes a second certificate, and the second certificate is the certificate of the routing domain to which the second functional entity belongs; the processing module is further configured to determine the validity of the second certificate; the processing module is further configured to determine the validity of the first certificate based on the second certificate when the second certificate is valid.
[0170] In combination with the eighth aspect, in some implementation manners of the eighth aspect, the processing module is further configured to determine the validity of the second certificate based on a root certificate, and the second certificate is signed by the root certificate.
[0171] In combination with the eighth aspect, in some implementations of the eighth aspect, the second routing relationship further includes a routing valid domain of the second routing relationship.
[0172] A ninth aspect of the present application provides a communication device, which includes various modules for implementing the method in the fourth aspect or any one of its implementations, and each module can be implemented in the form of hardware and / or software.
[0173] For example, the device may include: a receiving module and a processing module. The receiving module is configured to receive fifth information from a first functional entity, where the fifth information indicates a first routing relationship, and the first routing relationship is a relationship between the identification information of a second functional entity and the first user identification information; the processing module is configured to determine the validity of the first routing relationship.
[0174] In combination with the ninth aspect, in some implementations of the ninth aspect, the fifth information further includes a routing valid domain of the first routing relationship. In combination with the ninth aspect, in some implementations of the ninth aspect, the device may further include a sending module. The sending module is configured to send seventh information to a fifth functional entity, where the seventh information is used to request determination of the validity of the first routing relationship; the receiving module is further configured to receive eighth information from the fifth functional entity, where the eighth information indicates the validity of the first routing relationship.
[0175] In combination with the ninth aspect, in some implementations of the ninth aspect, when the first routing relationship is valid, the eighth information further includes a routing valid domain of the first routing relationship.
[0176] In combination with the ninth aspect, in some implementations of the ninth aspect, the processing module is further configured to obtain ninth information, where the ninth information includes information obtained by signing a second routing relationship with a key pair of a first certificate, the first certificate is a certificate of the second functional entity, and the second routing relationship is a relationship between the identification information of the second functional entity and the user identification information belonging to the second functional entity; the processing module is further configured to determine the validity of the first routing relationship based on the ninth information.
[0177] In combination with the ninth aspect, in some implementations of the ninth aspect, the ninth information further includes the first certificate, and the processing module is further configured to determine the validity of the first certificate; the processing module is further configured to determine the validity of the first routing relationship based on the first certificate when the first certificate is valid.
[0178] In combination with the ninth aspect, in some implementations of the ninth aspect, the ninth information further includes a second certificate, where the second certificate is a certificate of the routing domain to which the second functional entity belongs; the processing module is further configured to determine the validity of the second certificate; the processing module is further configured to, when the second certificate is valid, determine the validity of the first certificate based on the second certificate.
[0179] In combination with the ninth aspect, in some implementations of the ninth aspect, the processing module is further configured to determine the validity of the second certificate based on a root certificate, where the second certificate is signed by the root certificate.
[0180] In combination with the ninth aspect, in some implementations of the ninth aspect, the second routing relationship further includes a routing valid domain of the second routing relationship.
[0181] The tenth aspect provides a communication device, which includes respective modules for implementing the method in the fifth aspect or any one of its implementations, and each module can be implemented in the form of hardware and / or software.
[0182] For example, the device may include: a receiving module and a sending module. The receiving module is configured to receive seventh information from a fourth functional entity, where the seventh information is used to request determination of the validity of a first routing relationship, and the first routing relationship is a relationship between the identification information of a second functional entity and first user identification information; the sending module is configured to send eighth information to the fourth functional entity, where the eighth information indicates the validity of the first routing relationship.
[0183] In combination with the tenth aspect, in some implementations of the tenth aspect, when the first routing relationship is valid, the eighth information further includes a routing valid domain of the first routing relationship.
[0184] In combination with the tenth aspect, in some implementations of the tenth aspect, the device may further include a processing module. The processing module is configured to determine the validity of the first routing relationship.
[0185] In combination with the tenth aspect, in some implementations of the tenth aspect, the processing module is further configured to obtain tenth information, where the tenth information includes information obtained by signing a second routing relationship with a key pair of a first certificate, the first certificate is a certificate of the second functional entity, and the second routing relationship is a relationship between the identification information of the second functional entity and user identification information belonging to the second functional entity; the processing module is further configured to determine the validity of the first routing relationship based on the tenth information.
[0186] In combination with the tenth aspect, in certain implementations of the tenth aspect, the tenth information further includes the first certificate, and the processing module is further configured to determine the validity of the first certificate; the processing module is further configured to, when the first certificate is valid, determine the validity of the first routing relationship based on the first certificate.
[0187] In combination with the tenth aspect, in certain implementations of the tenth aspect, the tenth information further includes a second certificate, where the second certificate is a certificate of the routing domain to which the second functional entity belongs; the processing module is further configured to determine the validity of the second certificate; the processing module is further configured to, when the second certificate is valid, determine the validity of the first certificate based on the second certificate.
[0188] In combination with the tenth aspect, in certain implementations of the tenth aspect, the processing module is further configured to determine the validity of the second certificate based on a root certificate, where the second certificate is signed by the root certificate.
[0189] In combination with the tenth aspect, in certain implementations of the tenth aspect, the second routing relationship further includes a routing valid domain of the second routing relationship.
[0190] The eleventh aspect provides a communication device, including a processor, which can be coupled to a memory and is configured to call program code in the memory to execute the method as described in the first aspect or any one of its possible implementations. Optionally, the device further includes a memory. Optionally, the device further includes a communication interface, and the processor is coupled to the communication interface.
[0191] The twelfth aspect provides a communication device, including a processor, which can be coupled to a memory and is configured to call program code in the memory to execute the method as described in the second aspect or any one of its possible implementations. Optionally, the device further includes a memory. Optionally, the device further includes a communication interface, and the processor is coupled to the communication interface.
[0192] The thirteenth aspect provides a communication device, including a processor, which can be coupled to a memory and is configured to call program code in the memory to execute the method as described in the third aspect or any one of its possible implementations. Optionally, the device further includes a memory. Optionally, the device further includes a communication interface, and the processor is coupled to the communication interface.
[0193] The fourteenth aspect provides a communication device, including a processor, which can be coupled to a memory and is configured to call program code in the memory to execute the method as described in the fourth aspect or any one of its possible implementations. Optionally, the device further includes a memory. Optionally, the device further includes a communication interface, and the processor is coupled to the communication interface.
[0194] In a fifteenth aspect, the present application provides a communication device, including a processor which can be coupled to a memory and is used to call program code in the memory to execute the method described in the fifth aspect or any possible implementation manner thereof. Optionally, the device further includes a memory. Optionally, the device further includes a communication interface, and the processor is coupled to the communication interface.
[0195] In a sixteenth aspect, the present application provides a communication system, which includes the device in the sixth aspect or the eleventh aspect, includes the device in the seventh aspect or the twelfth aspect, includes the device in the eighth aspect or the thirteenth aspect, includes the device in the ninth aspect or the fourteenth aspect, and includes the device in the tenth aspect or the fifteenth aspect.
[0196] In a seventeenth aspect, the present application provides a computer program product containing instructions, which when running on a computer, causes the computer to execute the method described in the first aspect, the second aspect, the third aspect, the fourth aspect, the fifth aspect or any possible implementation manner thereof.
[0197] In an eighteenth aspect, the present application provides a computer-readable medium, which stores program code for a device to execute, and the program code includes the code for executing the method described in the first aspect, the second aspect, the third aspect, the fourth aspect, the fifth aspect or any possible implementation manner thereof.
[0198] For the technical effects that can be achieved by any one of the above sixth aspect to eighteenth aspect and any possible design in any one of them, please refer to the technical effects that can be brought by the above first aspect to fifth aspect for description, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0199] Figure 1 It is an exemplary illustration diagram of a communication system;
[0200] Figure 2 It is a schematic diagram of an application scenario provided by an embodiment of the present application;
[0201] Figure 3 It is a schematic illustration diagram of a communication method provided by an embodiment of the present application;
[0202] Figure 4 It is a schematic illustration diagram of a certificate management and signature rule provided by an embodiment of the present application;
[0203] Figure 5 It is a schematic illustration diagram of a communication method provided by another embodiment of the present application;
[0204] Figure 6Schematic illustration of a communication method provided by another embodiment of the present application;
[0205] Figure 7 Structural schematic diagram of a communication device provided by an embodiment of the present application;
[0206] Figure 8 Structural schematic diagram of a communication device provided by another embodiment of the present application. Detailed implementation manners
[0207] Here, the exemplary embodiments will be described in detail, and the examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with the present application. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.
[0208] To facilitate a clear description of the technical solutions of the embodiments of the present application, in the embodiments of the present application, terms such as "first" and "second" are used to distinguish identical or similar items with basically the same functions and roles. Those skilled in the art can understand that the terms "first" and "second" do not limit the quantity and execution order, and the terms "first" and "second" do not necessarily mean different.
[0209] It should be noted that in the embodiments of the present application, words such as "exemplary" or "for example" are used to represent examples, illustrations or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Exactly speaking, using words such as "exemplary" or "for example" aims to present relevant concepts in a specific manner.
[0210] In the embodiments of the present application, "at least one" means one or more, and "a plurality" means two or more. "And / or" describes the association relationship of associated objects and indicates that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone, where A and B can be singular or plural. The character " / " generally represents an "or" relationship between the associated objects before and after. "At least one (item)" or its similar expression below refers to any combination of these items, including any combination of single item (item) or plural items (items). For example, at least one (item) of a, b, or c can represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, c can be single or multiple.
[0211] The technical solutions provided by this application can be applied to various communication systems, including but not limited to: narrow band-internet of things (NB-IoT), global system for mobile communications (GSM), enhanced data rate for GSM evolution (EDGE), wideband code division multiple access (WCDMA), code division multiple access 2000 (CDMA2000), time division-synchronization code division multiple access (TD-SCDMA), wireless fidelity (WIFI), 3rd generation (3G) mobile communication systems, long term evolution (LTE) systems, LTE advanced (LTE-A) systems, LTE frequency division duplex (FDD) systems, LTE time division duplex (TDD), 4th generation (4G) mobile communication systems, 5th generation (5G) mobile communication systems, the three major application scenarios of 5G new radio (NR) communication systems: enhanced mobile broadband (eMBB), ultra-reliable and low latency communications (URLLC), and massive machine type communication (mMTC), as well as future 6th generation (6G) mobile communication systems, such as: high frequency, terahertz, optical communication, etc. This application does not make specific limitations on this.
[0212] The following will describe Figure 1 the technical problems solved by this application.
[0213] The service-based architecture (SBA) of the 5G mobile communication system adopts a registration and discovery model. As an example, when a network function (NF) entity accesses the network, the NF entity reports its own capabilities and attributes to the network repository function (NRF) entity. For example, the NF entity can provide services or service-based interfaces (SBIs) and the interface addresses of the SBIs for which user identities (IDs), tracking area identities (TAIs), and access point names (APNs). After receiving the information reported by the NF entity, the NRF entity can store the received information according to certain rules. For example, the NRF entity can internally organize and store the ID routing relationship information between the user ID and the NF entity, so that the NRF entity can perform service discovery based on the user ID to determine the NF entity that meets the service requirements. For example, in the session activation process of a terminal device, the session management function (SMF) entity can use the subscription permanent identifier (SUPI) of the terminal device to query the NRF entity for the unified data management (UDM) entity that serves the SUPI and the SBI interface address provided by the UDM entity. The NRF entity can determine the UDM entity and the SBI interface address of the UDM entity based on the SUPI and return them to the SMF entity. The SMF entity can call the SBI interface provided by the determined UDM entity to obtain the subscribed data of the terminal device. Among them, the user ID served by the NF entity can be allocated by the operator according to a certain area (such as province, city, district, etc.), that is, the operator can allocate the NF entity to which the user ID belongs.
[0214] Figure 1 It is an exemplary illustration diagram of a communication system. As Figure 1 shown, the communication system may include NRF entity 1, NRF entity 2, NF entity 1, NF entity 2, NF entity 3, and NF entity 4. It should be understood that the number of NF entities and NRF entities is only an example.
[0215] Among them, NRF entity 1, NF entity 1, and NF entity 2 are located in the same network, such as in Network 1, and NF entity 1 and NF entity 2 are within the management domain of NRF entity 1. NF entity 1 or NF entity 2 can register with NRF entity 1 to report the user IDs served by NF entity 1 or NF entity 2. After receiving the user IDs reported by NF entity 1 or NF entity 2, NRF entity 1 can internally organize and store the ID routing relationship information between the user IDs and NF entity 1 or NF entity 2.
[0216] NRF entity 2, NF entity 3, and NF entity 4 are located in the same network, such as in Network 2, and NF entity 3 and NF entity 4 are within the management domain of NRF entity 2. NF entity 3 or NF entity 4 can register with NRF entity 2 to report the user IDs served by NF entity 3 or NF entity 4. After receiving the user IDs reported by NF entity 3 or NF entity 4, NRF entity 2 can internally organize and store the ID routing relationship information between the user IDs and NF entity 3 or NF entity 4.
[0217] In this communication system, assuming that NF entity 4 needs to call the service interface provided by other NF entities, NF entity 4 uses the user ID to query NRF entity 2 for the NF entity serving this user ID. After receiving the user ID, NRF entity 2 can determine which NRF entity's management domain the NF entity to which this user ID belongs is located in. Assuming that the NF entity to which this user ID belongs is within the management domain of NRF entity 1, then NRF entity 2 can use this user ID to query NRF entity 1 for the NF entity serving this user ID. After receiving the user ID, NRF entity 1 can determine the NF entity serving this user ID and the interface information of the NF entity based on the user ID in the stored ID routing relationship information, and return it to NRF entity 2, so that NF entity 4 can call the required service interface. It should be noted that each NRF entity is pre-configured with the user IDs served by the NF entities within the management domain of other NRF entities.
[0218] However, there are the following problems with this registration and discovery method: When different NF entities independently report the user IDs they serve, it is possible that the user IDs reported by the NF entities are incorrect, which may lead to conflicts in the user IDs reported by different NF entities, and further lead to the possibility of finding the wrong NF entity when the NRF entity performs service discovery based on the user ID, resulting in business failure.
[0219] In view of this, the present application provides a communication method and a communication device. The present application provides a verification process or mechanism for signing ID routing relationship information using a certificate signature to determine the validity and legality of the ID routing relationship information. For example, the NRF entity can verify the ID routing relationship information stored in the organization, or the NRF entity can verify the ID routing relationship information received from other NRF entities, thereby improving the accuracy of service discovery by the NRF entity based on the user ID. In addition, the present application also provides a decision-making mechanism for determining whether the ID routing relationship information needs to be transmitted across networks or ID routing domains through the routing valid domain of the ID routing relationship information. It should be noted that the communication method and communication device provided in the present application are based on the same technical concept. Since the principles for solving problems by the method and the device are similar, the implementation of the method and the device can refer to each other, and the repeated parts will not be elaborated.
[0220] Figure 2 FIG. is a schematic diagram of an application scenario provided for an embodiment of the present application. Figure 2 The application scenario or system architecture shown can be referred to as an ID routing network architecture or an ID routing-based network architecture. This system architecture can be defined based on the 5G core network (5Gcore, 5GC) SBA architecture and future network evolution (such as ID routing network evolution) scenarios. As Figure 2 shown, this system architecture can include an ID resource management center 210, an ID routing domain 220, an ID routing domain 230, and an ID routing domain 240. Among them, the ID resource management center 210 mainly includes two functional modules, such as a certificate authority and an ID resource allocation and signature management functional module. The ID routing domain 220 can include an ID routing authentication service 221, an ID access gateway 222, and an ID home server 223. The ID routing domain 230 can include an ID routing authentication service 231, an ID access gateway 232, and an ID home server 233. The ID routing domain 240 can include an ID routing authentication service 241 and an ID router 242.
[0221] Among them, the ID resource management center 210 can be connected to the ID routing authentication service 221, the ID access gateway 222, the ID routing authentication service 231, the ID access gateway 232, the ID routing authentication service 241, and the ID router 242. The ID access gateway 222 can be respectively connected to the ID routing authentication service 221, the ID home server 223, the ID access gateway 232, and the ID router 242. The ID access gateway 232 can be respectively connected to the ID routing authentication service 231, the ID home server 233, and the ID router 242. The ID router 242 is connected to the ID routing authentication service 241. In the embodiments of the present application, the ID routing authentication service 221, the ID access gateway 222, the ID home server 223, the ID routing authentication service 231, the ID access gateway 232, the ID home server 233, the ID routing authentication service 241, and the ID router 242, etc. can be referred to as functional entities, network elements, functional modules, devices, network entities, etc. The present application does not make specific limitations thereto. It should be understood that the number of ID routing domains, each functional module, or each functional entity in this system architecture is only an example rather than a limitation.
[0222] In some embodiments, the ID routing authentication service 221 and the ID access gateway 222 can be combined into one functional entity, and the functions of the ID routing authentication service 221 and the ID access gateway 222 can be implemented by one functional entity at the same time; similarly, the ID routing authentication service 231 and the ID access gateway 232 can also be combined into one functional entity, and the ID routing authentication service 241 and the ID router 242 can also be combined into one functional entity.
[0223] It should be noted that each functional module or functional entity included in this system architecture can be provided by different manufacturers or by the same manufacturer. The present application does not make specific limitations thereto. It should be understood that the naming of the ID routing domain, functional module, or functional entity included in this system architecture is only an example rather than a limitation. As long as the functions are the same as those of the network element, device, module, or functional entity in the ID routing domain, functional module, or functional entity in this system architecture, they can be included in the scope of the ID routing domain, functional module, or functional entity in this system architecture.
[0224] As an example, the ID resource management center can be a first-level organization or a multi-level organization, and organizations at different levels manage ID resources within their own scopes.
[0225] The certificate issuing center can be used to complete the hierarchical issuance and signature of certificates. For example, the certificate issuing center can issue the same trust domain certificate for all ID routing domains in the system architecture, issue device certificates for each functional entity in the system architecture, and sign the certificates of each functional entity with the trust domain certificate; Another example is that the certificate issuing center can issue corresponding trust domain certificates for each ID routing domain in the system architecture, issue device certificates for each functional entity in each ID routing domain, and sign the certificates of each functional entity in each ID routing domain with the trust domain certificates of each ID routing domain, so as to achieve the hierarchical issuance of certificates. Therefore, each functional entity can communicate after mutually determining the validity of the certificates to improve the communication security between each functional entity. In the embodiments of the present application, if functional entity A can use the key of the trust domain certificate to decrypt the certificate of functional entity B, it can be considered that the certificate of functional entity B is valid. Determining the validity of the certificate can also be referred to as determining / verifying / checking / authenticating the legality of the certificate. The present application does not make specific limitations on this.
[0226] The ID resource allocation and signature management function module can be used to complete ID resource allocation. For example, allocate user IDs to each ID home server according to certain rules; It can also be used to sign and store the ID routing relationship information of each ID home server with the certificate of each ID home server; It can also be used to provide an interface for each functional entity connected to the ID resource management center. Each functional entity can obtain the signed ID routing relationship information and the notification information of the ID resource allocation and signature management function module to update the signed ID routing relationship information based on this interface. Among them, the signed ID routing relationship information can also be referred to as ID routing relationship information signature data. As an example, the ID routing relationship information can be the relationship between the user ID and the ID home server host ID.
[0227] In some embodiments, the ID resource allocation and signature management function module can implement ID resource allocation according to a certain user ID range or user ID prefix. Among them, the user ID range is, for example, from 4600310000 to 4600320000, the user ID prefix is, for example, 4600 or 46003, and the user ID range can also be referred to as the user ID number segment.
[0228] The ID routing authentication service can obtain the certificates issued by the certificate authority and the signature data of the ID routing relationship information from the ID resource management center regularly or periodically; it can also determine the validity of the obtained certificates, and when it is determined that the certificate of the ID home server is valid, decrypt the signature data of the ID routing relationship information corresponding to the ID home server based on the certificate of the ID home server, so as to provide legal authentication of the ID routing relationship information of the ID home server for the ID access gateway and the ID router. Among them, at least one ID routing authentication service can be deployed in each ID routing domain, and it can be seen that Figure 2 In the system architecture shown, one ID routing authentication service is deployed in each ID routing domain.
[0229] The ID access gateway can obtain the ID routing relationship information from the ID home server to complete the authentication of the identity of the ID home server; it can also determine the validity of the obtained ID routing relationship information through the ID routing authentication service located in the same ID routing domain as the ID access gateway; it can also be used to forward the determined valid ID routing relationship information to the directly connected ID routers or ID access gateways around. Among them, at least one ID access gateway can be deployed in each ID routing domain, and it can be seen that Figure 2 In the system architecture shown, one ID access gateway is deployed in each ID routing domain.
[0230] In some embodiments, the ID access gateway can also directly obtain the certificates issued by the certificate authority and the signature data of the ID routing relationship information from the ID resource management center; it can also determine the validity of the obtained certificates, and when it is determined that the certificate of the ID home server is valid, decrypt the signature data of the ID routing relationship information corresponding to the ID home server based on the certificate of the ID home server, so as to authenticate the validity of the obtained ID routing relationship information.
[0231] In some embodiments, such as in the 5GC network architecture, the ID access gateway can be an NRF entity, or the network element function of the ID access gateway can be implemented by the NRF entity.
[0232] The ID home server is used to receive the user ID resources allocated by the ID resource allocation and signature management function module and send or publish the ID routing relationship information to the ID access gateway.
[0233] In some embodiments, the ID home server can directly obtain the allocated user ID resources from the ID resource allocation and signature management function module and store them, or after the ID resource allocation and signature management function module allocates user ID resources to the ID home server, the allocated user ID resources can be pre-configured in the ID home server by manual means, and the present application does not make specific restrictions on this.
[0234] In some embodiments, such as in a 5GC network architecture, the ID home server can be an NF entity, or rather, the network element function of the ID home server can be implemented by an NF entity.
[0235] The ID router can be used to determine the validity of the certificates of the ID access gateway or ID router directly connected to the ID router to complete identity authentication, and receive the ID routing relationship information sent by the ID access gateway or ID router directly connected to the ID router; it can also be used to determine the validity of the received ID routing relationship information through the ID routing authentication service located in the same routing domain as the ID router; it can also be used to forward the determined valid ID routing relationship information to the directly connected ID routers or ID access gateways in the vicinity.
[0236] In some embodiments, the ID router can also directly obtain the certificate issued by the certificate authority and the ID routing relationship information signature data from the ID resource management center; it can also determine the validity of the obtained certificate, and decrypt the ID routing relationship information signature data corresponding to the ID home server based on the certificate of the ID home server when determining that the certificate of the ID home server is valid, so as to authenticate the validity of the received ID routing relationship information.
[0237] In some embodiments, such as in a 5GC network architecture, the ID router can be an NRF entity, or rather, the network element function of the ID router can be implemented by an NRF entity.
[0238] In some embodiments, the ID routing relationship information can also include a routing valid domain, which can be used to indicate the routing distribution range of the ID routing relationship information. The routing distribution range is understood as the (valid) distribution range or transmission range of the ID routing relationship information in the ID routing network.
[0239] In some embodiments, the routing valid domain can be represented by common network domain identifiers such as the fully qualified domain name (FQDN) format. As an example, if the routing valid domain of the ID routing relationship information is <E.F>, and the service domain of the ID home server in this ID routing relationship information is <E.F.G.H>, and the service domain of the ID access gateway in the same ID routing domain as the ID home server is <E.F.G>, then the routing valid domain of this ID routing relationship information is larger than the service domain of this ID access gateway. Therefore, this ID access gateway needs to forward this ID routing relationship information to the ID router or ID access gateway directly connected to this ID access gateway. If the service domain of the ID router directly connected to this ID access gateway is <E.F>, then the transmission of this ID routing relationship information stops after reaching this ID router. Among them, the service domains of functional entities such as the ID home server, ID access gateway, and ID router can be the host IDs of each functional entity, and the host IDs of each functional entity can be represented by common network entity identifiers such as the FQDN or domain name of each functional entity.
[0240] As an example, the ID routing relationship information can be represented as <user ID, ID home server host ID, routing valid domain (optional)>.
[0241] This application provides a security solution for autonomy within the ID routing domain. The ID resource management center is used to implement hierarchical issuance of certificates and allocation of user ID resources, and centrally sign and store the ID routing relationship information corresponding to each ID home server. As a result, functional entities such as the ID access gateway, ID routing authentication service, and ID router can determine the validity of the ID routing relationship information published in this ID routing network through the certificates issued by the ID resource management center.
[0242] In some implementation manners, the security domain of this ID routing network can be divided into a trusted domain and an untrusted domain. As an example, the trusted domain can include the ID routing authentication service, ID access gateway, and ID router. The trustworthiness of each functional entity can be determined through certificates within the trusted domain. The untrusted domain can include the ID resource management center and ID home server. In addition to determining the trustworthiness of functional entities through certificates within the untrusted domain, it is also necessary to determine the validity of the ID routing relationship information published in this ID routing network through certificates.
[0243] Figure 3 This is a schematic illustration diagram of a communication method provided for an embodiment of this application. As Figure 3 shown, this method can include S301, S302, and S303.
[0244] S301. The first functional entity receives first information from the second functional entity. The first information indicates a first routing relationship, which is the relationship between the identification information of the second functional entity and the first user identification information.
[0245] In the embodiments of the present application, when the second functional entity completes configuration and the device accesses the network, it can register and report its own capabilities and attributes to the first functional entity. For example, the second functional entity can send first information to the first functional entity. The first information is used to indicate a first routing relationship, which is the relationship between the identification information of the second functional entity and the first user identification information. Herein, the first information can also be referred to as a routing advertisement message. The second functional entity sending the first information to the first functional entity can also be referred to as the second functional entity publishing a routing advertisement message to the first functional entity.
[0246] As an example, the first functional entity can be an ID access gateway, and the second functional entity can be an ID home server.
[0247] As an example, the identification information of the second functional entity can be understood as the host ID of the second functional entity. The host ID of the second functional entity can be represented by common network entity identifiers such as the FQDN of the second functional entity or other domain names, etc.; the first routing relationship can be understood as ID routing relationship information, and the first user identification information can be understood as the user ID registered and reported by the second functional entity. The user ID can be represented by the prefix of the user ID, the number segment of the user ID, and the value of the user ID. The number segment of the user ID can also be referred to as the range or number segment range of the user ID.
[0248] As an example, the first routing relationship can be represented as <the first user identification information, the identification information of the second functional entity>.
[0249] It should be understood that the number of the first routing relationships can be one or more. When the number of the first routing relationships is more than one, the first routing relationships can be represented in the form of a list.
[0250] S302. The first functional entity sends second information to the third functional entity. The second information is used to request to determine the validity of the first routing relationship.
[0251] In the embodiments of the present application, after the first functional entity receives the first information sent by the second functional entity, it needs to determine the validity of the first routing relationship indicated by the first information, so that the second functional entity determined by the first functional entity when performing service discovery based on the user ID can meet the service requirements.
[0252] In an implementable manner, the first functional entity can send second information to the third functional entity to request the third functional entity to determine the validity of the first routing relationship. The second information can include the first routing relationship.
[0253] As an example, when the first functional entity is an ID access gateway and the second functional entity is an ID home server, the third functional entity may be an ID routing authentication service located in the same ID routing domain as the ID access gateway and the ID home server.
[0254] In one implementable manner, after receiving the second information, the third functional entity may match the first routing relationship with the local cache of the third functional entity to determine the validity of the first routing relationship.
[0255] As an example, the third functional entity may periodically obtain the certificate issued by the certificate authority and the signed second routing relationship from the ID resource management center, decrypt the signed second routing relationship through certificate management and signature rules, and save the decrypted second routing relationship to establish a local cache of the second routing relationship. The second routing relationship may be understood as the relationship between the identification information of the second functional entity and the second user identification information belonging to the second functional entity. The second user identification information may be understood as the user ID resource allocated by the ID resource allocation and signature management function module for the second functional entity.
[0256] Exemplarily, Figure 4 FIG. is a schematic diagram of a certificate management and signature rule provided for an embodiment of the present application. As Figure 4 shown, the certificate issued by the certificate authority may include a root certificate, a trust domain certificate, a certificate of the first functional entity, and a certificate of the second functional entity. It should be understood that the certificate issued by the certificate authority is not limited to Figure 4 the certificates shown in.
[0257] As Figure 4 shown, the root certificate may be understood as a trust certificate or a self-signed certificate. The root certificate may include a root certificate signature, a root certificate key, and root certificate extension information. The key may include a public key and a private key. As an example, the root certificate may be a root certificate authority (CA) certificate.
[0258] The trust domain certificate may be a certificate issued by the certificate authority of the ID resource management center for the ID routing domain to which the first functional entity and the second functional entity belong. The trust domain certificate may be the same as or different from the trust domain certificates of other ID routing domains. The present application does not make specific limitations on this. The trust domain certificate may include a certificate signature, a certificate key, signer information, and root certificate extension information. As an example, the trust domain certificate may be a trust domain CA certificate.
[0259] The certificate of the first functional entity can be the certificate issued by the certificate authority of the ID resource management center for the first functional entity. The certificate of the first functional entity can include certificate signature, certificate key, signer information, and root certificate extension information. As an example, the certificate of the first functional entity can be the CA certificate of the first functional entity.
[0260] The certificate of the second functional entity can be the certificate issued by the certificate authority of the ID resource management center for the second functional entity. The certificate of the second functional entity can include certificate signature, certificate key, signer information, and root certificate extension information. As an example, the certificate of the second functional entity can be the CA certificate of the second functional entity.
[0261] In this embodiment, the trust domain certificate can be signed by the root certificate, so the signer information in the trust domain certificate points to the root certificate. As an example, the root certificate signing the trust domain certificate can be understood as the root certificate's key signing the trust domain certificate, so the root certificate can be called the superior certificate of the trust domain certificate. Similarly, the certificate of the first functional entity can be signed by the trust domain certificate, so the signer information in the certificate of the first functional entity points to the trust domain certificate, and the certificate of the second functional entity can be signed by the trust domain certificate, so the signer information in the certificate of the second functional entity points to the trust domain certificate. Therefore, the trust domain certificate can be called the superior certificate of the certificate of the first functional entity and the certificate of the second functional entity.
[0262] After the ID resource allocation and signature management function module allocates user ID resources to the second functional entity, it can use the certificate of the second functional entity to sign the second routing relationship and store it in the database. It should be noted that this application does not limit the algorithm used for signature. For example, the algorithm used for signature can adopt one or more algorithms such as encryption / decryption and integrity protection.
[0263] In some embodiments, the second routing relationship can further include a routing valid domain of the second routing relationship, and the routing valid domain can be used to indicate the routing publication scope of the second routing relationship.
[0264] In some embodiments, the root certificate can be pre-configured in the third functional entity.
[0265] Based on Figure 4For the certificate management and signature rules shown, after the third functional entity periodically obtains the certificate issued by the certificate issuing center and the signed second routing relationship from the ID resource management center, it can decrypt the trust domain certificate using the private key of the root certificate to determine the validity of the trust domain certificate. If the trust domain certificate is valid, it can decrypt the certificate of the second functional entity using the private key of the trust domain certificate to determine the validity of the certificate of the second functional entity. When the certificate of the second functional entity is valid, it can decrypt the signed second routing relationship using the private key of the certificate of the second functional entity and establish cached data of the second routing relationship for subsequent query and authentication.
[0266] As an example, the second routing relationship may include one or more key values (keys), and the key value can be represented as <second user identification information, identification information of the second functional entity>. It should be understood that the number of key values is the same as the number of second user identification information.
[0267] Therefore, after receiving the second information, the third functional entity can match the first routing relationship with the second routing relationship stored in the third functional entity to determine the validity of the first routing relationship. As an example, when there is a key value in the second routing relationship that matches the first routing relationship, the first routing relationship can be considered valid. For example, if the first routing relationship matches the first key value in the second routing relationship, the identification information of the second functional entity in the first routing relationship is the same as the identification information of the second functional entity in the first key value, and the first user identification information in the first routing relationship is a subset of the second user identification information in the first key value.
[0268] It should be understood that the routing valid domain of the second routing relationship is the routing distribution range of each key value in the second routing relationship.
[0269] S303, the first functional entity receives the third information from the third functional entity, and the third information indicates the validity of the first routing relationship.
[0270] In this embodiment, after determining the validity of the first routing relationship, the third functional entity can send the third information to the first functional entity to indicate the validity of the first routing relationship.
[0271] In a possible implementation, the third information may include a determination result of the validity of the first routing relationship, and the determination result may be any one of the following: valid, invalid, or unknown. It should be understood that when the determination result is valid, it can be considered that the authentication of the first routing relationship is successful; when the determination result is invalid, it can be considered that the authentication of the first routing relationship fails; when the determination result is unknown, it can be considered that the authentication function for determining the validity of the first routing relationship of the third functional entity is not enabled. Optionally, when the number of the first routing relationships is multiple, the third functional entity may send multiple third information to the first functional entity, and each third information may include a determination result of the validity of each first routing relationship, or the third information may include a determination result of the validity of each first routing relationship, and this application does not limit this.
[0272] Correspondingly, the first functional entity may receive the third information. When the determination result of the validity of the first routing relationship is valid, the first functional entity may save the first routing relationship to the local database; when the determination result of the validity of the first routing relationship is invalid, the first functional entity does not save the first routing relationship; when the determination result of the validity of the first routing relationship is unknown, the first functional entity may process the first routing relationship based on the local configuration policy. As an example, the local configuration policy may be that when the determination result of the validity of the first routing relationship is unknown, the first functional entity may save or not save the first routing relationship. If the first routing relationship is saved, it is necessary to indicate that the determination result of the validity of the saved first routing relationship is unknown. Optionally, the local configuration policy may be pre-configured in the first functional entity in advance.
[0273] In this embodiment, the first functional entity may authenticate the validity of the first routing relationship reported by the second functional entity for registration through the third functional entity, and save the determined valid first routing relationship, avoiding the problem of user ID conflicts reported by different second functional entities, and making the accuracy of the second functional entity found by the first functional entity based on the user ID for service discovery relatively high; in addition, in this embodiment, the first routing relationship is signed to verify the validity of the first routing relationship, avoiding man-in-the-middle tampering with the first routing relationship and improving communication efficiency.
[0274] Exemplarily, Figure 5 is a schematic illustration diagram of a communication method provided by another embodiment of this application. As Figure 5 shown, the method may include S301, S302, and S303, and may also include S304, S305, and S306.
[0275] S304, the first functional entity sends fourth information to the fourth functional entity, and the fourth information includes first user identification information and identification information of the first functional entity.
[0276] As an example, the fourth functional entity can be understood as an ID router or an ID access gateway directly connected to the first functional entity.
[0277] In some implementation manners, when the first routing relationship is valid, the third information may further include the routing valid domain of the first routing relationship. Among them, the routing valid domain of the first routing relationship can be determined by the routing valid domain of the second routing relationship. For example, when the first key value in the first routing relationship matches the first key value in the second routing relationship, the routing valid domain of the first routing relationship is the same as the routing valid domain of the first key value.
[0278] Therefore, when the third information indicates that the determination result of the validity of the first routing relationship is valid, the first functional entity further needs to determine whether the third information includes the routing valid domain of the first routing relationship. As an example, if the third information does not include the routing valid domain of the first routing relationship, the first functional entity may consider the routing valid domain of the first routing relationship to be the entire ID routing network, and the first functional entity may send the fourth information to the fourth functional entity; if the third information includes the routing valid domain of the first routing relationship, and the range of the routing valid domain is greater than the service domain of the first functional entity, the first functional entity may send the fourth information to the fourth functional entity, and the service domain of the fourth functional entity should be smaller than the routing valid domain of the first routing relationship, or in other words, the service domain of the fourth functional entity is included in the routing valid domain of the first routing relationship; if the third information includes the routing valid domain of the first routing relationship, and the range of the routing valid domain is not greater than the service domain of the first functional entity, then the first functional entity does not send the fourth information to the fourth functional entity.
[0279] In this embodiment, the fourth information may also be referred to as routing advertisement information, and the fourth information may include the first user identification information and the identification information of the first functional entity. Among them, the identification information of the first functional entity may be the host ID of the first functional entity, and the host ID of the first functional entity may be represented by common network entity identifiers such as the FQDN or domain name of the first functional entity.
[0280] As an example, the fourth information may be represented as <the first user identification information, the identification information of the first functional entity>. It should be understood that the first user identification information included in the fourth information is the first user identification information in the determined valid first routing relationship.
[0281] In some implementation manners, the first functional entity may send the fourth information by means of direct forwarding or aggregation forwarding.
[0282] As an example, if it is determined that the first user identification information in the valid first routing relationship includes: 460031000 to 460031500, 460031600 to 460031799 and 460031800, if the first functional entity sends the fourth information by direct forwarding, the fourth information may include: <4600310>00 to 460031500, identification information of the first functional entity>, <4600316>00 to 460031799, identification information of the first functional entity> and <4600318>00, identification information of the first functional entity> If the first functional entity sends the fourth information in an aggregate forwarding manner, the fourth information may include: <4600310>00 to 460031500, identification information of the first functional entity> and <4600316>00 to 460031800, identification information of the first functional entity>. It should be understood that 460031600 to 460031799 and 460031800 may be aggregated into 460031600 to 460031800.
[0283] In this example, when the first functional entity sends the fourth information by direct forwarding, the fourth information may also include the identification information of the second functional entity, and / or the routing validity domain of the first routing relationship; when the first functional entity sends the fourth information by aggregate forwarding, the fourth information may also include the routing validity domain of the first routing relationship.
[0284] Correspondingly, the fourth functional entity can receive and save the fourth information. If the fourth information only contains the first user identification information and the identification information of the first functional entity, the fourth functional entity can forward the received first user identification information, and can carry the identification information of the fourth functional entity when forwarding. It should be understood that the fourth functional entity can forward the information to other functional entities directly connected to the fourth functional entity; if the fourth information contains the routing validity domain of the first routing relationship, and the routing validity domain of the first routing relationship is larger than the service domain of the fourth functional entity, the fourth functional entity can forward the received first user identification information, and can carry the identification information of the fourth functional entity when forwarding, or can carry the identification information of the fourth functional entity and the routing validity domain of the first routing relationship. The service domain of the functional entity receiving the information forwarded by the fourth functional entity should be smaller than the routing validity domain of the first routing relationship; if the fourth information contains the identification information of the second functional entity, the fourth functional entity needs to authenticate the validity of the first routing relationship contained in the fourth information, and then execute S305. The identification information of the fourth functional entity can be the host ID of the fourth functional entity, and the host ID of the fourth functional entity can be represented by a common network entity identifier such as the FQDN or domain name of the fourth functional entity.
[0285] In some embodiments, if the identification information of the second functional entity is not included in the fourth information, the fourth functional entity considers the first user identification information in the received fourth information as the aggregated route and thus does not perform authentication.
[0286] S305. The fourth functional entity sends fifth information to the fifth functional entity. The fifth information is used to indicate a request to determine the validity of the first routing relationship.
[0287] In this embodiment, the fourth functional entity may request the fifth functional entity to determine the validity of the first routing relationship included in the fourth information. The fifth information may carry the first routing relationship included in the fourth information.
[0288] As an example, the fifth functional entity may be understood as an ID routing authentication service located in the same ID routing domain as the fourth functional entity.
[0289] In an implementable manner, after receiving the fifth information, the fifth functional entity may match the first routing relationship with the local cache of the fifth functional entity to determine the validity of the first routing relationship included.
[0290] In this embodiment, the manner in which the fifth functional entity determines the validity of the first routing relationship may refer to the manner in which the third functional entity determines the validity of the first routing relationship in S302, which will not be elaborated here.
[0291] S306. The fourth functional entity receives sixth information from the fifth functional entity. The sixth information indicates the validity of the first routing relationship.
[0292] In this embodiment, after determining the validity of the first routing relationship, the fifth functional entity may send sixth information to the third functional entity to indicate the validity of the first routing relationship.
[0293] In this embodiment, the relevant description of the sixth information may refer to the relevant description of the third information in S303. The relevant description after the fourth functional entity receives the sixth information may refer to the relevant description after the first functional entity receives the third information in S303 and S304, which will not be elaborated here. Among them, the fourth functional entity needs to carry the identification information of the fourth functional entity when forwarding information.
[0294] In some embodiments, when forwarding information, the fourth functional entity may also carry the identification information of the first functional entity.
[0295] In this embodiment, the fourth functional entity can determine the validity of the received first routing relationship, thereby improving the accuracy of the first routing relationship during transmission across ID routing domains or ID routing networks and enhancing communication efficiency. Additionally, in a future 6G network that realizes ID routing autonomy, when functional entities in the ID routing autonomous network perform ID routing discovery and learning within and between autonomous domains, this solution can be used to determine the validity of ID routing relationship information and avoid man-in-the-middle attacks from tampering with ID routing relationship information.
[0296] In some implementable ways, the first functional entity and the fourth functional entity can directly obtain the certificates issued by the certificate authority and the signed second routing relationship from the ID resource management center, decrypt the signed second routing relationship through certificate management and signature rules, and save the decrypted second routing relationship to establish a local cache of the second routing relationship, thereby being able to independently determine the validity of the first routing relationship.
[0297] Figure 6 It is a schematic illustration diagram of a communication method provided for another embodiment of this application. As Figure 6 shown, the method may include S601, S602, S603, S604, and S605.
[0298] S601, the first functional entity receives first information from the second functional entity, where the first information indicates a first routing relationship, and the first routing relationship is the relationship between the identification information of the second functional entity and the first user identification information.
[0299] In this embodiment, the specific implementation manner of S601 may refer to S301, which will not be elaborated here.
[0300] S602, the first functional entity determines the validity of the first routing relationship.
[0301] In this embodiment, the first functional entity can periodically obtain the certificates issued by the certificate authority and the signed second routing relationship from the ID resource management center, and use the root certificate to determine the validity of the trust domain certificate. If the trust domain certificate is valid, the first functional entity uses the trust domain certificate to determine the validity of the certificate of the second functional entity. When the certificate of the second functional entity is valid, the first functional entity uses the certificate of the second functional entity to decrypt the signed second routing relationship, thereby being able to determine the cached data of the second routing relationship for subsequent query and authentication.
[0302] In some embodiments, the root certificate can be pre-configured in the first functional entity.
[0303] In this embodiment, the specific implementation of S602 can refer to S302 and S303, which will not be elaborated here. For example, the manner in which the first functional entity determines the validity of the first routing relationship based on the cached data of the second routing relationship can refer to the manner in which the third functional entity determines the validity of the first routing relationship in S302, and the related operations of the first functional entity after determining the validity of the first routing relationship can refer to the related descriptions in S303.
[0304] S603. The first functional entity sends fourth information to the fourth functional entity, and the fourth information includes first user identification information and the identification information of the first functional entity.
[0305] In this embodiment, the specific implementation of S603 can refer to S304, which will not be elaborated here.
[0306] S604. The fourth functional entity determines the validity of the first routing relationship.
[0307] In this embodiment, the fourth functional entity can periodically obtain the certificate issued by the certificate authority and the signed second routing relationship from the ID resource management center, and use the root certificate to determine the validity of the trust domain certificate. If the trust domain certificate is valid, use the trust domain certificate to determine the validity of the certificate of the second functional entity. If the certificate of the second functional entity is valid, use the certificate of the second functional entity to decrypt the signed second routing relationship, so as to determine the cached data of the second routing relationship for subsequent query authentication.
[0308] In some embodiments, the root certificate can be pre-configured in the fourth functional entity.
[0309] In this embodiment, the specific implementation of S604 can refer to S302, S303, S305, and S306, which will not be elaborated here. For example, the manner in which the fourth functional entity determines the validity of the first routing relationship based on the cached data of the second routing relationship is the same as the manner in which the third functional entity or the fifth functional entity determines the validity of the first routing relationship, and the related operations of the fourth functional entity after determining the validity of the first routing relationship can refer to the related descriptions in S306.
[0310] This embodiment provides a communication method for the first functional entity and the fourth functional entity to independently determine the validity of the first routing relationship, enabling the first functional entity and the fourth functional entity to determine the validity of the first routing relationship without requesting the assistance of other functional entities, reducing signaling loss.
[0311] Figure 7 It is a schematic structural diagram of a communication device provided in an embodiment of the present application. As Figure 7 shown, the communication device 700 may include: a receiving module 710, a processing module 720, and a transmitting module 730.
[0312] In one possible implementation, the apparatus 700 can be used to implement Figure 3 , Figure 5 or Figure 6 each step / operation performed by the first functional entity in the method shown.
[0313] As an example, when the apparatus 700 is used to implement the method implemented by the first functional entity in Figure 3 , the receiving module 710 can be used to implement the operations performed by the first functional entity in S301 and S303; the sending module 730 can be used to implement the operation performed by the first functional entity in S302.
[0314] When the apparatus 700 is used to implement the method implemented by the first functional entity in Figure 5 , the receiving module 710 can be used to implement the operations performed by the first functional entity in S301 and S303; the sending module 730 can be used to implement the operations performed by the first functional entity in S302 and S304.
[0315] When the apparatus 700 is used to implement the method implemented by the first functional entity in Figure 6 , the receiving module 710 can be used to implement the operation performed by the first functional entity in S601; the sending module 730 can be used to implement the operation performed by the first functional entity in S603, and the processing module 720 can be used to implement S602.
[0316] In one possible implementation, the apparatus 700 can be used to implement Figure 3 , Figure 5 or Figure 6 each step / operation performed by the second functional entity in the method shown.
[0317] As an example, when the apparatus 700 is used to implement the method implemented by the second functional entity in Figure 3 , the sending module 730 can be used to implement the operation performed by the second functional entity in S301.
[0318] When the apparatus 700 is used to implement the method implemented by the second functional entity in Figure 5 , the sending module 730 can be used to implement the operation performed by the second functional entity in S301.
[0319] When the apparatus 700 is used to implement the method implemented by the second functional entity in Figure 6 , the sending module 730 can be used to implement the operation performed by the second functional entity in S601.
[0320] In one possible implementation, the apparatus 700 can be used to implement Figure 3 or Figure 5Each step / operation performed by the third functional entity in the method shown.
[0321] As an example, when the apparatus 700 is used to implement the method implemented by the third functional entity in Figure 3 the receiving module 710 may be used to implement the operation performed by the third functional entity in S302; the sending module 730 may be used to implement the operation performed by the third functional entity in S303.
[0322] When the apparatus 700 is used to implement the method implemented by the third functional entity in Figure 5 the receiving module 710 may be used to implement the operation performed by the third functional entity in S302; the sending module 730 may be used to implement the operation performed by the third functional entity in S303.
[0323] In a possible implementation manner, the apparatus 700 may be used to implement Figure 5 or Figure 6 each step / operation performed by the fourth functional entity in the method shown.
[0324] As an example, when the apparatus 700 is used to implement the method implemented by the fourth functional entity in Figure 5 the receiving module 710 may be used to implement the operations performed by the fourth functional entity in S304 and S306; the sending module 730 may be used to implement the operation performed by the fourth functional entity in S305.
[0325] When the apparatus 700 is used to implement the method implemented by the fourth functional entity in Figure 6 the receiving module 710 may be used to implement the operation performed by the fourth functional entity in S603; the processing module 720 may be used to implement S604.
[0326] In a possible implementation manner, the apparatus 700 may be used to implement Figure 5 each step / operation performed by the fifth functional entity in the method shown.
[0327] As an example, when the apparatus 700 is used to implement the method implemented by the fifth functional entity in Figure 5 the receiving module 710 may be used to implement the operation performed by the fifth functional entity in S305; the sending module 730 may be used to implement the operation performed by the fifth functional entity in S306.
[0328] Figure 8 It is a schematic structural diagram of a communication apparatus provided in another embodiment of the present application. Figure 8 The apparatus 800 shown may be used to implement the method performed by the first functional entity, the second functional entity, the third functional entity, the fourth functional entity, or the fifth functional entity in any of the foregoing embodiments.
[0329] As Figure 8 shown, the apparatus 800 of this embodiment includes: a memory 810, a processor 820, a communication interface 830, and a bus 840. Among them, the memory 810, the processor 820, and the communication interface 830 are communicatively connected to each other through the bus 840.
[0330] The memory 810 may be a read only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 810 may store a program. When the program stored in the memory 810 is executed by the processor 820, the processor 820 is configured to execute each step / operation performed by the first functional entity, the second functional entity, the third functional entity, the fourth functional entity, or the fifth functional entity in any of the foregoing embodiments.
[0331] The processor 820 may be a general-purpose central processing unit (CPU), a microprocessor, an application specific integrated circuit (ASIC), or one or more integrated circuits, and is configured to execute relevant programs to implement the communication method shown in the method embodiments of the present application.
[0332] The processor 820 may also be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the communication method shown in the method embodiments of the present application may be completed by the integrated logic circuit in the hardware of the processor 820 or by instructions in software form.
[0333] The foregoing processor 820 may also be a general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
[0334] The steps of the method disclosed in the embodiments of the present application can be directly implemented by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. The software module can be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory 810, and the processor 820 reads the information in the memory 810 and combines its hardware to complete the functions required to be executed by the units included in the communication device of the present application. For example, it can execute Figure 3 , Figure 5 or Figure 6 each step / function executed by the first functional entity, the second functional entity, the third functional entity, the fourth functional entity, or the fifth functional entity.
[0335] Optionally, the memory 810 and the processor 820 can be integrated together.
[0336] The communication interface 830 can use, but is not limited to, a transceiver device such as a transceiver to implement the communication between the device 800 and other devices or apparatuses.
[0337] The bus 840 can include a path for transmitting information between various components of the device 800 (for example, the memory 810, the processor 820, the communication interface 830).
[0338] In some embodiments of the present application, a computer program product is also provided. When the computer program product runs on a processor, it can implement the method shown in the foregoing embodiments. In some embodiments of the present application, a computer-readable storage medium is also provided. The computer-readable storage medium contains computer instructions. When the computer instructions run on a processor, they can implement the method shown in the foregoing embodiments.
[0339] It should be noted that the modules or components shown in the above embodiments may be one or more integrated circuits configured to implement the above methods. For example: one or more application specific integrated circuits (ASICs), or, one or more digital signal processors (DSPs), or, one or more field programmable gate arrays (FPGAs), etc. Again, when a certain module above is implemented in the form of a processing element calling program code, the processing element may be a general-purpose processor, such as a central processing unit (CPU) or other processors that can call program code, such as a controller. Again, these modules may be integrated together and implemented in the form of a system-on-a-chip (SOC).
[0340] In the above embodiments, it may be implemented in whole or in part by software, hardware, firmware, software modules, or any combination thereof. When implemented using software, it may be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions according to the embodiments of the present application are generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium may be any available medium that the computer can access or a data storage device such as a server or data center that includes one or more integrated available media. The available medium may be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium (for example, a solid state disk (SSD)).
[0341] The term "plurality" in this document refers to two or more. The term "and / or" in this document is merely a description of the associated relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Additionally, in this document, the character " / " generally indicates an "or" relationship between the preceding and following associated objects; in a formula, the character " / " indicates a "division" relationship between the preceding and following associated objects. Further, it should be understood that in the description of this application, terms such as "first" and "second" are only used for the purpose of distinguishing descriptions, and should not be construed as indicating or implying relative importance, nor as indicating or implying an order.
[0342] It can be understood that the various numerical numbers involved in the embodiments of this application are only for the convenience of description and are not used to limit the scope of the embodiments of this application.
[0343] It can be understood that in the embodiments of this application, the magnitudes of the sequence numbers of the above processes do not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of this application.
Claims
1. A communication method, characterized in that, The method is applied to a first functional entity, and the method includes: Receiving first information from a second functional entity, where the first information indicates a first routing relationship, and the first routing relationship is a relationship between the identification information of the second functional entity and first user identification information; Determining the validity of the first routing relationship.
2. The method according to claim 1, wherein The determining the validity of the first routing relationship includes: Sending second information to a third functional entity, where the second information is used to request determination of the validity of the first routing relationship; Receiving third information from the third functional entity, where the third information indicates the validity of the first routing relationship.
3. The method according to claim 2, wherein When the first routing relationship is valid, the third information further includes a routing valid domain of the first routing relationship.
4. The method according to claim 1, wherein The determining the validity of the first routing relationship includes: Obtaining fourth information, where the fourth information includes information obtained by signing a second routing relationship with a key pair of a first certificate, the first certificate being a certificate of the second functional entity, and the second routing relationship being a relationship between the identification information of the second functional entity and user identification information belonging to the second functional entity; Determining the validity of the first routing relationship based on the fourth information.
5. The method according to claim 4, wherein The fourth information further includes the first certificate, and the determining the validity of the first routing relationship based on the fourth information includes: Determining the validity of the first certificate; When the first certificate is valid, determining the validity of the first routing relationship based on the first certificate.
6. The method according to claim 5, characterized in that, The fourth information further includes a second certificate, and the second certificate is a certificate of a routing domain to which the second functional entity belongs; Wherein, the determining the validity of the first certificate includes: Determining the validity of the second certificate; When the second certificate is valid, determining the validity of the first certificate based on the second certificate.
7. The method according to claim 6, characterized in that, The determining the validity of the second certificate includes: Determining the validity of the second certificate based on a root certificate, and the second certificate is signed by the root certificate.
8. The method according to any one of claims 4 to 7, characterized in that The second routing relationship further includes a routing valid domain of the second routing relationship.
9. The method according to any one of claims 2 to 8, characterized in that, When the first routing relationship is valid, the method further includes: Sending fifth information to a fourth functional entity, where the fifth information includes the first user identification information and the identification information of the first functional entity.
10. The method according to claim 9, characterized in that, The sending the fifth information to the fourth functional entity includes: When the routing valid domain of the first routing relationship is greater than the service domain of the first functional entity, sending the fifth information to the fourth functional entity.
11. The method according to claim 9 or 10, characterized in that, The fifth information further includes the identification information of the second functional entity, and / or, the routing valid domain of the first routing relationship.
12. A communication method, characterized in that, The method is applied to a second functional entity, and the method includes: Determining first information, where the first information indicates a first routing relationship, and the first routing relationship is a relationship between the identification information of the second functional entity and first user identification information; Sending the first information to the first functional entity.
13. A communication method, characterized in that, The method is applied to a third functional entity, and the method includes: Receive second information from a first functional entity, where the second information is used to request determination of the validity of a first routing relationship, and the first routing relationship is the relationship between the identification information of a second functional entity and the first user identification information; Send third information to the first functional entity, where the third information indicates the validity of the first routing relationship.
14. The method according to claim 13, wherein When the first routing relationship is valid, the third information further includes the routing valid domain of the first routing relationship.
15. The method according to claim 13 or 14, characterized in that The method further includes: Determine the validity of the first routing relationship.
16. The method according to claim 15, wherein The determination of the validity of the first routing relationship includes: Obtain sixth information, where the sixth information includes the information obtained by signing a second routing relationship with a key pair of a first certificate, the first certificate is the certificate of the second functional entity, and the second routing relationship is the relationship between the identification information of the second functional entity and the user identification information belonging to the second functional entity; Determine the validity of the first routing relationship based on the sixth information.
17. The method according to claim 16, characterized in that The sixth information further includes the first certificate, and the determination of the validity of the first routing relationship based on the sixth information includes: Determine the validity of the first certificate; When the first certificate is valid, determine the validity of the first routing relationship based on the first certificate.
18. The method according to claim 17, wherein The sixth information further includes a second certificate, and the second certificate is the certificate of the routing domain to which the second functional entity belongs; Wherein, the determination of the validity of the first certificate includes: Determine the validity of the second certificate; When the second certificate is valid, determine the validity of the first certificate based on the second certificate.
19. The method according to claim 18, wherein The determination of the validity of the second certificate includes: Determine the validity of the second certificate based on a root certificate, and the second certificate is signed by the root certificate.
20. The method according to any one of claims 16 to 19, characterized in that The second routing relationship further includes the routing valid domain of the second routing relationship.
21. A communication system, characterized in that, A communication device including means for performing the method according to any one of claims 1 to 11, claim 12 or any one of claims 13 to 20.
22. A communication device, characterized in that, A communication device including respective functional modules for implementing the method according to any one of claims 1 to 11, claim 12 or any one of claims 13 to 20.
23. A communication device, characterized in that, It includes: A processor, the processor is coupled to a memory, and the memory is used to store a computer program. When the processor calls the computer program, the device performs the method according to any one of claims 1 to 11, claim 12 or any one of claims 13 to 20.
24. A computer program product, characterized in that, It includes computer program code, and when the computer program code runs on a computer, the computer implements the method according to any one of claims 1 to 11, claim 12 or any one of claims 13 to 20.
25. A computer-readable medium, characterized in that, The computer-readable medium stores program code for execution by a computer, and the program code includes instructions for performing the method according to any one of claims 1 to 11, claim 12 or any one of claims 13 to 20.
Citation Information
Cited By
Communication method and communication apparatus
EP4815566A1
Communication method and communication apparatus
WO2025130890A1