Shared network element management method, system and device and operator equipment

The POP authorizes POP to access shared network elements and determines their permissions. Combined with hybrid encryption and asymmetric encryption, the main operator security problem in multi-operator shared network elements management is solved, and secure shared network elements management and data transmission is realized.

CN120282143APending Publication Date: 2025-07-08CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410681900.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-05-29
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

在多运营商共享网元的情况下,通过X接口管理共享网元导致主运营商的安全性问题未得到有效解决。

Method used

The network management of shared network elements is accessed through MOP, and the permissions of POP for each parameter and attribute are determined based on the signed protocol content, and the management data transmission is protected and managed by using hybrid encryption and asymmetric encryption methods to limit the access control permissions of POP.

Benefits of technology

Enhanced the security of shared network element management, ensure that POP can only manage designated shared network elements, protect the security of the main operator, and improve the security of managing data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120282143A_ABST
    Figure CN120282143A_ABST
Patent Text Reader

Abstract

The invention relates to a shared network element management method, a shared network element management system, a shared network element management device and operator equipment. The method comprises the following steps: an MOP authorizes a POP to access network management of a shared network element through an X interface; the MOP is a newly signed POP and a shared network element used by the newly signed POP to sort related network management parameters and attributes; according to the protocol content signed with the POP, the MOP determines the authority of the POP for each parameter and attribute; and the MOP informs the POP of the permission of the POP for each parameter and attribute, so that the POP manages the shared network element. By adopting the method, the security of shared network element management can be enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of wireless communication technologies, and in particular, to a method, system, device, and operator equipment for managing shared network elements. Background Art

[0002] With the deployment and development of IMT-2020 and subsequent networks, the expenditures for network construction and maintenance are increasing day by day. At the same time, with the rise of 5G vertical industry applications, in order to empower the vertical industries, the basic network capabilities and corresponding computing power resources need to be further enhanced. To solve the above contradictions, it has gradually become a development trend for multiple operators to share network resources (network elements such as network devices, computing power devices, and base stations).

[0003] However, in the case of multiple operators sharing network elements, if a sharing operator wants to manage the network elements of the primary operator that it shares and uses, it must go through the X interface. Since the X interface directly leads to the network management operating system of the primary operator, it is not conducive to the security of the primary operator's management information.

[0004] Therefore, there are security problems in the current shared network element management technology. Summary of the Invention

[0005] Embodiments of this application provide a method, system, device, operator equipment, storage medium, and computer program product for managing shared network elements, which can improve the security of shared network element management.

[0006] A method for managing shared network elements, the method includes:

[0007] The MOP authorizes the POP to access the network management of the shared network element through the X interface;

[0008] The MOP is the network management parameters and attributes involved in the newly signed POP and the shared network elements used by it;

[0009] According to the content of the agreement signed with the POP, the MOP determines the permissions of the POP for each of the parameters and attributes;

[0010] The MOP notifies the POP of its permissions for each of the parameters and attributes for the POP to manage the shared network element.

[0011] In one of the embodiments, the method further includes:

[0012] If the management data is sent from the POP to the MOP, if hybrid encryption is applied, the MOP generates a pair of public and private keys for the POP; the public key is used for the POP to encrypt the session key, and the private key is used for the MOP to decrypt the session key, and the session key is a symmetric key;

[0013] The MOP sends the public key to the POP.

[0014] In one embodiment, after the MOP sends the public key to the POP, it further includes:

[0015] The POP randomly generates the session key;

[0016] The POP uses the session key to encrypt the management data to be transmitted, obtaining the encrypted management data;

[0017] The POP uses the public key sent by the MOP to encrypt the session key, obtaining the encrypted session key;

[0018] The POP combines the encrypted management data and the encrypted session key and sends them to the MOP.

[0019] In one embodiment, the method further includes:

[0020] If the management data is sent from the POP to the MOP and asymmetric encryption is applied, the MOP generates a pair of public and private keys for the POP; the public key is used by the POP to encrypt the management data to be transmitted, and the private key is used by the MOP to decrypt the management data to be transmitted;

[0021] The MOP sends the public key to the POP.

[0022] In one embodiment, the method further includes:

[0023] If the management data is sent from the MOP to the POP and hybrid encryption is applied, the POP generates a pair of public and private keys for the MOP; the public key is used by the MOP to encrypt the session key, and the private key is used by the POP to decrypt the session key, and the session key is a symmetric key;

[0024] The POP sends the public key to the MOP.

[0025] In one embodiment, after the POP sends the public key to the MOP, it further includes:

[0026] The MOP randomly generates the session key;

[0027] The MOP uses the session key to encrypt the management data to be transmitted, obtaining the encrypted management data;

[0028] The MOP uses the public key sent by the POP to encrypt the session key, obtaining the encrypted session key;

[0029] The MOP combines the encrypted management data and the encrypted session key and sends them to the POP.

[0030] In one embodiment, the method further includes:

[0031] If the management data is sent from the MOP to the POP and asymmetric encryption is applied, the POP generates a pair of public key and private key for the MOP; the public key is used by the MOP to encrypt the management data to be transmitted, and the private key is used by the POP to decrypt the management data to be transmitted;

[0032] The POP sends the public key to the MOP.

[0033] In one embodiment, the permissions are divided into two groups: read-only and modifiable, and the permissions of the POP for each parameter and attribute respectively correspond to read-only or modifiable.

[0034] In one embodiment, a primary operator domain is set in the MOP, and a shared operator domain is set in the POP. Both the primary operator domain and the shared operator domain reflect the corresponding relationship between the POP and the shared network element.

[0035] In one embodiment, the method further includes:

[0036] Using the historical public key and historical private key of the POP for the shared network element as the public key and the private key respectively.

[0037] A shared network element management system, the system includes:

[0038] MOP, which is used to authorize the POP to access the network management of the shared network element through the X interface, sort out the network management parameters and attributes involved for the newly signed POP and the shared network element it uses, determine the permissions of the POP for each parameter and attribute according to the protocol content signed with the POP, and notify the POP of its permissions for each parameter and attribute;

[0039] POP, which is used to manage the shared network element according to the permissions.

[0040] A shared network element management device, the device includes:

[0041] A management authorization module, which is used for the MOP to authorize the POP to access the network management of the shared network element through the X interface;

[0042] A parameter determination module, which is used for the MOP to sort out the network management parameters and attributes involved for the newly signed POP and the shared network element it uses;

[0043] A permission determination module, configured to determine, according to the content of the agreement signed with the POP, the MOP's permissions for each of the parameters and attributes of the POP;

[0044] A permission notification module, configured to notify the POP by the MOP of its permissions for each of the parameters and attributes, for the POP to manage the shared network element.

[0045] An operator device includes a memory and a processor. The memory stores a computer program. When the processor executes the computer program, the following steps are implemented:

[0046] The MOP authorizes the POP to access the network management of the shared network element through the X interface;

[0047] The MOP sorts out the network management parameters and attributes involved for the newly signed POP and the shared network element it uses;

[0048] According to the content of the agreement signed with the POP, the MOP determines the POP's permissions for each of the parameters and attributes;

[0049] The MOP notifies the POP of its permissions for each of the parameters and attributes, for the POP to manage the shared network element.

[0050] A computer-readable storage medium stores a computer program. When the computer program is executed by a processor, the following steps are implemented:

[0051] The MOP authorizes the POP to access the network management of the shared network element through the X interface;

[0052] The MOP sorts out the network management parameters and attributes involved for the newly signed POP and the shared network element it uses;

[0053] According to the content of the agreement signed with the POP, the MOP determines the POP's permissions for each of the parameters and attributes;

[0054] The MOP notifies the POP of its permissions for each of the parameters and attributes, for the POP to manage the shared network element.

[0055] A computer program product includes a computer program, characterized in that when the computer program is executed by a processor, it implements the shared network element management method provided in the embodiments of the present application, and the method may be:

[0056] The MOP authorizes the POP to access the network management of the shared network element through the X interface;

[0057] The MOP is for sorting out the network management parameters and attributes involved in the newly signed POP and the shared network elements used by it;

[0058] According to the content of the agreement signed with the POP, the MOP determines the permissions of the POP for each of the parameters and attributes;

[0059] The MOP notifies the POP of its permissions for each of the parameters and attributes for the POP to manage the shared network elements.

[0060] The above-mentioned shared network element management method, system, device, operator equipment, storage medium and computer program product authorize the POP to access the network management of the shared network element through the X interface by the MOP, sort out the network management parameters and attributes involved in the newly signed POP and the shared network elements used by it, determine the permissions of the POP for each parameter and attribute according to the content of the agreement signed with the POP, and notify the POP of its permissions for each parameter and attribute; after the MOP authorizes the POP to manage its shared network elements, it can specify the shared network elements for the POP, as well as the permissions of the network management parameters and attributes involved in the POP's use of the shared network elements, so that the POP can only manage the specified shared network elements and is restricted by the permissions, enhancing the security of shared network element management. Description of the Drawings

[0061] Figure 1 It is an application environment diagram of the shared network element management method in an embodiment;

[0062] Figure 2 It is a flowchart of the shared network element management method in an embodiment;

[0063] Figure 3 It is a schematic diagram of the process of verifying and authorizing access to the shared network element in an embodiment;

[0064] Figure 4 It is a flowchart of the process of the MOP transmitting the session key to the POP in an embodiment;

[0065] Figure 5 It is a flowchart of the process of the POP transmitting the session key to the MOP in an embodiment;

[0066] Figure 6 It is a schematic diagram of the main operator domain and the shared operator domain in an embodiment;

[0067] Figure 7 It is a schematic diagram of the main operator domain and the shared operator domain in another embodiment;

[0068] Figure 8 It is a structural block diagram of the shared network element management device in an embodiment;

[0069] Figure 9 It is the internal structure diagram of the operator device in an embodiment. Specific implementation manners

[0070] In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0071] Figure 1 It is a schematic diagram of an application scenario of a shared network element management method provided by an embodiment of the present application. As Figure 1 shown, this scenario includes an operator and its operating system, shared network elements and dedicated network elements. Among them, data transmission between the shared network elements of the same operator and the operating system, and between the dedicated network elements and the operating system, is all carried out through the Q interface, and data transmission between different operators is carried out through the X interface. Among them, the shared network elements and dedicated network elements include but are not limited to the operator's network devices, computing power devices, base stations, etc.

[0072] Among them, the network device can be a dedicated hardware device that connects nodes such as the operator's servers and terminals to form an information communication network, including but not limited to switches, routers, firewalls, bridges, hubs, gateways, VPN (Virtual Private Network) servers, network interface cards, wireless access points, modems, optical terminal machines, optical fiber transceivers, optical cables, etc.

[0073] The computing power device can be various hardware devices that provide computing power for the operator, including but not limited to central processing units, graphics processing units, ASIC (Application Specific Integrated Circuit) chips, FPGA (Field Programmable Gate Array), edge computing devices, etc.

[0074] The base station can be a Base Transceiver Station (BTS) in Global System of Mobile communication (GSM) or Code Division Multiple Access (CDMA), or a NodeB (NB) in Wideband Code Division Multiple Access (WCDMA), or an Evolutional NodeB (eNB or eNodeB) in LTE, or a relay station or an access point, or a base station in a 5G network, etc., which is not limited herein.

[0075] In the traditional technology, network elements can be shared between two or more operators. Taking the sharing of network elements between two operators in Figure 1 as an example, the framework for shared network resource management is described. Among them, the management of dedicated network elements can use only the conventional Q interface between the operating system and the dedicated network elements. For example, the operating system of operator A can directly manage the dedicated network element A2 through its own Q interface, and the operating system of operator B can directly manage the dedicated network element B2 through its own Q interface. For the management of shared network elements, the cooperation and information exchange between operators are required. For example, operators A and B exchange resource management information for sharing through the X interface. Both operators can be either the primary operator or the sharing operator. When operator A is the primary operator, both the shared network element B1 and the dedicated network element B2 of the sharing operator B can access the shared network element A1 of the primary operator A through the X interface. When operator B is the primary operator, both the shared network element A1 and the dedicated network element A2 of the sharing operator A can access the shared network element B1 of the primary operator B through the X interface. Thus, it can be seen that in the case of multi-operator sharing of network elements, if the sharing operator wants to manage the network elements of the primary operator it shares, it must go through the X interface. Based on this, there are security problems of the primary operator caused by the management of shared network elements in the traditional technology. Based on the above traditional technology, the embodiments of the present application provide a method for managing shared network elements, authorizing the POP to access the network management of the shared network element through the X interface by the MOP, sorting out the network management parameters and attributes involved for the newly signed POP and the shared network elements it uses, determining the permissions of the POP for each parameter and attribute according to the protocol content signed with the POP, and notifying the POP of its permissions for each parameter and attribute; after the MOP authorizes the POP to manage its shared network elements, the shared network elements can be specified for the POP, as well as the permissions of the network management parameters and attributes involved in the POP's use of the shared network elements, so that the POP can only manage the specified shared network elements and is restricted by the permissions, enhancing the security of shared network element management.

[0076] It should be noted that the beneficial effects or the technical problems solved by the embodiments of the present application are not limited to this one, and there may be other implicit or related problems. For specific details, please refer to the descriptions of the following embodiments.

[0077] Before introducing the specific embodiments of the present application, the professional terms involved in the present application will be explained first:

[0078] TMN: Telecommunication Management Network, the telecommunication management network;

[0079] OS: Operations System, the operating system;

[0080] MOP: Master Operator, the main operator;

[0081] POP: Participating Operator, the sharing operator;

[0082] NE: Network Element, the network element;

[0083] Q interface: The interface between the NE and the OS;

[0084] X interface: The interface between the operating system function blocks located in different telecommunication management networks;

[0085] SP: Service Provider, the service provider;

[0086] SC: Service Customer, the service customer;

[0087] SU: Service User, the service user.

[0088] The technical solution of the present application and how the technical solution of the present application solves the above technical problems will be described in detail below with specific embodiments. These several specific embodiments below can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below with reference to the accompanying drawings.

[0089] In one embodiment, as Figure 2 shown, a method for managing shared network elements is provided. Taking the application of this method to the MOP device as an example for illustration, it includes the following steps:

[0090] Step S102, the MOP authorizes the POP to access the network management of the shared network element through the X interface.

[0091] Among them, network management can be the management of shared network elements among operator devices.

[0092] In implementation, if the MOP and the POP can communicate with each other through the X interface, the MOP can authorize the POP to access the shared network elements of the MOP through the X interface and manage the shared network elements of the MOP.

[0093] For example, referring to Figure 1 , assuming that operator A is the MOP and operator B is the POP, then the OS of operator A can authorize operator B to access and manage its shared network elements through the X interface.

[0094] Figure 3 A schematic diagram of the process of verifying and authorizing access to shared network elements is provided. According to Figure 3 , the POP may not directly use the shared network elements by itself, but the SP, SC, or SU connected to the POP uses the shared network elements. Assuming that operator A is the POP and operator B is the MOP, after the MOP and the POP have signed an agreement to use the shared network elements, operator A can send a registration request to operator B. The request includes whether operator A is a shared operator or whether the SC / SU connected to operator A uses the shared network elements. After operator A obtains the registration information sent by operator B, it sends a request to operator B to authenticate and authorize the access to the shared network elements. Next, if only operator A uses the shared network elements, operator B authorizes operator A to access the shared network elements; if the SC / SU of operator A uses the shared network elements, operator B authorizes operator A and its SC / SU to access the shared network elements. After that, regardless of whether there are SC / SUs behind the shared operator, only the shared operator is authorized to manage the shared network elements through the X interface, and the SC / SUs can only access the shared network elements through the network but have no right to manage the shared network elements.

[0095] Step S104, the MOP sorts out the network management parameters and attributes involved for the newly signed POP and the shared network elements it uses.

[0096] Among them, the network management parameters and attributes can be various parameters and attributes related to the POP using the shared network elements of the MOP. For example, network traffic, spectrum resources, etc.

[0097] In implementation, the MOP can sign a shared network element usage agreement with the authorized POP to allow the POP to use the specified shared network elements of the MOP. The MOP can also manage the specified shared network elements for the POP and sort out the various parameters and attributes involved.

[0098] For example, the OS of operator A can sign a sharing network element usage agreement with operator B, allowing operator B to use the shared network element A1, and sort out the various parameters and attributes involved in operator B's management of the shared network element A1.

[0099] Step S106, according to the content of the agreement signed with the POP, the MOP determines the permissions of the POP for each parameter and attribute.

[0100] In implementation, according to the sharing network element usage agreement signed between the MOP and the POP, the MOP can respectively determine the permissions of the POP for the various parameters and attributes involved in the POP's management of its shared network element.

[0101] For example, for the various parameters and attributes involved in operator B's management of the shared network element A1, the OS of operator A can determine that the permissions of operator B for each parameter and attribute are read-only or modifiable.

[0102] Step S108, the MOP notifies the POP of its permissions for each parameter and attribute for the POP to manage the shared network element.

[0103] In implementation, the MOP can notify the POP of the determined permissions of the POP for each parameter and attribute. The POP performs network management on the MOP's shared network element according to the received permissions.

[0104] For example, operator A sends the permissions of each parameter and attribute involved in operator B's use of the shared network element A1 to operator B. The OS of operator B performs network management on the shared network element A1 according to the received permissions.

[0105] The above sharing network element management method authorizes the POP to access the network management of the shared network element through the X interface by the MOP, sorts out the network management parameters and attributes involved for the newly signed POP and the shared network element it uses, determines the permissions of the POP for each parameter and attribute according to the content of the agreement signed with the POP, and notifies the POP of its permissions for each parameter and attribute; after the MOP authorizes the POP to manage its shared network element, it can specify the shared network element for the POP, as well as the permissions of the network management parameters and attributes involved in the POP's use of the shared network element, enabling the POP to only manage the specified shared network element and being restricted by the permissions, enhancing the security of sharing network element management.

[0106] In one embodiment, as Figure 4 shown, the method further includes:

[0107] Step S202, if the management data is sent from the POP to the MOP, and if hybrid encryption is applied, the MOP generates a pair of public and private keys for the POP; the public key is used by the POP to encrypt the session key, and the private key is used by the MOP to decrypt the session key, where the session key is a symmetric key.

[0108] Step S204, the MOP sends the public key to the POP.

[0109] Among them, the management data can be various data for the POP to manage the shared network elements of the MOP.

[0110] In implementation, after the MOP notifies the POP of its permissions for each parameter and attribute, if the management data is sent from the POP to the MOP and hybrid encryption is used, the MOP can generate a pair of public and private keys for the POP that uses its shared network elements, and send the public key to the POP. After receiving the public key, the POP can use the public key to encrypt the session key (symmetric) and send it to the MOP, and the MOP uses the private key it generates to decrypt the received session key (symmetric).

[0111] In this embodiment, by having the MOP generate a pair of public and private keys for the POP and send the public key to the POP if the management data is sent from the POP to the MOP and hybrid encryption is applied, the encryption of the session key can be achieved when the management data is transmitted from the POP to the MOP, ensuring the security of the management data transmission.

[0112] In one embodiment, after the above step S204, it further includes: the POP randomly generates a session key; the POP uses the session key to encrypt the management data to be transmitted, obtaining the encrypted management data; the POP uses the public key sent by the MOP to encrypt the session key, obtaining the encrypted session key; the POP combines the encrypted management data and the encrypted session key and sends them to the MOP.

[0113] In implementation, after the MOP sends the public key to the POP, the POP can randomly generate a session key, use the session key to encrypt the management data to be transmitted to obtain the encrypted management data, the POP can also use the received public key to encrypt the randomly generated session key to obtain the encrypted session key, and then, the POP can combine the encrypted management data and the encrypted session key and send them to the MOP.

[0114] In this embodiment, a session key is randomly generated by POP, and the management data to be transmitted is encrypted using the session key to obtain encrypted management data. The session key is encrypted using the public key sent by MOP to obtain an encrypted session key. The encrypted management data and the encrypted session key are combined and sent to MOP, which can implement the hybrid encryption of the management data when the management data is transmitted from POP to MOP, ensuring the security of the management data transmission.

[0115] In one embodiment, the method further includes: if the management data is sent from POP to MOP and asymmetric encryption is applied, MOP generates a pair of public and private keys for POP; the public key is used by POP to encrypt the management data to be transmitted, and the private key is used by MOP to decrypt the management data to be transmitted; MOP sends the public key to POP.

[0116] In implementation, after MOP notifies POP of its permissions for each parameter and attribute, if the management data is sent from POP to MOP and asymmetric encryption is used, MOP can generate a pair of public and private keys for the POP that uses its shared network element and send the public key to the POP. After receiving the public key, the POP can use the public key to encrypt the management data to be transmitted and send it to MOP, and MOP uses the private key it generates to decrypt the received management data to be transmitted.

[0117] In this embodiment, by if the management data is sent from POP to MOP and asymmetric encryption is applied, MOP generates a pair of public and private keys for POP and sends the public key to POP, the asymmetric encryption of the management data when the management data is transmitted from POP to MOP can be achieved, ensuring the security of the management data transmission.

[0118] In one embodiment, as Figure 5 shown, the method further includes:

[0119] Step S302, if the management data is sent from MOP to POP and hybrid encryption is applied, POP generates a pair of public and private keys for MOP; the public key is used by MOP to encrypt the session key, and the private key is used by POP to decrypt the session key, and the session key is a symmetric key;

[0120] Step S304, POP sends the public key to MOP.

[0121] In implementation, after the MOP notifies the POP of its permissions for each parameter and attribute, if the management data is sent from the MOP to the POP and hybrid encryption is used, the POP can generate a pair of public and private keys for the MOP that shares its shared network element and send the public key to the MOP. After receiving the public key, the MOP can use the public key to encrypt the session key (symmetric) and send it to the POP, and the POP uses its own generated private key to decrypt the received session key (symmetric).

[0122] In this embodiment, by having the management data sent from the MOP to the POP, if hybrid encryption is applied, the POP generates a pair of public and private keys for the MOP and sends the public key to the MOP, it is possible to achieve the encryption of the session key when the management data is transmitted from the MOP to the POP, ensuring the security of the management data transmission.

[0123] In one embodiment, after the above step S304, it further includes: the MOP randomly generates a session key; the MOP uses the session key to encrypt the management data to be transmitted to obtain encrypted management data; the MOP uses the public key sent by the POP to encrypt the session key to obtain an encrypted session key; the MOP combines the encrypted management data and the encrypted session key and sends them to the POP.

[0124] In implementation, after the POP sends the public key to the MOP, the MOP can randomly generate a session key, use the session key to encrypt the management data to be transmitted to obtain encrypted management data, the MOP can also use the received public key to encrypt the randomly generated session key to obtain an encrypted session key, and then, the MOP can combine the encrypted management data and the encrypted session key and send them to the POP.

[0125] In this embodiment, by having the MOP randomly generate a session key, use the session key to encrypt the management data to be transmitted to obtain encrypted management data, use the public key sent by the POP to encrypt the session key to obtain an encrypted session key, and combine the encrypted management data and the encrypted session key and send them to the POP, it is possible to achieve the hybrid encryption of the management data when the management data is transmitted from the MOP to the POP, ensuring the security of the management data transmission.

[0126] In one embodiment, the method further includes: if the management data is sent from the MOP to the POP and asymmetric encryption is applied, the POP generates a pair of public and private keys for the MOP; the public key is used for the MOP to encrypt the management data to be transmitted, and the private key is used for the POP to decrypt the management data to be transmitted; the POP sends the public key to the MOP.

[0127] In implementation, after the POP notifies the MOP of its permissions for each parameter and attribute, if the management data is sent from the MOP to the POP and asymmetric encryption is used, the POP can generate a pair of public and private keys for the MOP that shares its shared network element, and send the public key to the MOP. After receiving the public key, the MOP can use the public key to encrypt the management data to be transmitted and send it to the POP, and the POP uses its own generated private key to decrypt the received management data to be transmitted.

[0128] In this embodiment, by if the management data is sent from the MOP to the POP, and if asymmetric encryption is applied, the POP generates a pair of public and private keys for the MOP and sends the public key to the MOP, the asymmetric encryption of the management data can be achieved when the management data is transmitted from the MOP to the POP, ensuring the security of the management data transmission.

[0129] In one embodiment, the permissions are divided into two groups: read-only and modifiable. The permissions of the POP for each parameter and attribute respectively correspond to read-only or modifiable.

[0130] In implementation, the MOP can respectively set the permissions of the POP to be read-only or modifiable for each parameter and attribute involved in the POP's management of its shared network element, group the parameters or attributes with read-only permissions into one group, and group the parameters or attributes with modifiable permissions into another group.

[0131] In this embodiment, the permissions are divided into two groups: read-only and modifiable. The permissions of the POP for each parameter and attribute respectively correspond to read-only or modifiable, which can protect the parameters or attributes with read-only permissions from being tampered with and ensure the security of the main operator.

[0132] In one embodiment, a main operator domain is set in the MOP, and a shared operator domain is set in the POP. Both the main operator domain and the shared operator domain reflect the corresponding relationship between the POP and the shared network element.

[0133] Among them, the main operator domain can be the domain in the MOP that contains information related to the POP's use of the shared network element. The shared operator domain can be the domain in the POP that contains information related to the current POP's use of the shared network element.

[0134] In implementation, a main operator domain can be set in the MOP, and the domain name of the main operator domain represents the shared network elements used by each POP connected to the current MOP. A shared operator domain can also be set in the POP, and the domain name of the shared operator domain represents the shared network element used by this POP.

[0135] Figure 6 A schematic diagram of the main operator domain and the shared operator domain is provided. According to Figure 6, in the OS of the TMN of MOP and POP, the home operator domain and the shared operator domain can be set respectively according to the shared network elements used by the POP. For example, assume that there are shared network elements 1, 2, 3, and 4 in the MOP. If the shared operator D uses the shared network elements 3 and 4, the shared operator C uses the shared network element 2, and the shared operator B uses the shared network element 1, then 4 home operator domains can be set in the OS of the MOP, and the domain names are respectively: the users of the shared network element 4 share the shared operator D, the users of the shared network element 3 share the shared operator D, the users of the shared network element 2 share the shared operator C, and the users of the shared network element 1 share the shared operator B; also, a shared operator domain can be set in the OS of the shared operator D, and the domain name is: the shared operator D uses the shared network element 4, a shared operator domain can be set in the OS of the shared operator D, and the domain name is: the shared operator D uses the shared network element 3, a shared operator domain can be set in the OS of the shared operator C, and the domain name is: the shared operator C uses the shared network element 2, and a shared operator domain can be set in the OS of the shared operator B, and the domain name is: the shared operator B uses the shared network element 1.

[0136] In this embodiment, a home operator domain is set in the MOP, and a shared operator domain is set in the POP. Both the home operator domain and the shared operator domain reflect the correspondence between the POP and the shared network elements, and a shared network element can be specified for each POP, so that the POP can only manage the specified shared network elements, ensuring the security of the shared network element management.

[0137] In one embodiment, the method further includes: using the historical public key and historical private key of the POP using the shared network element as the public key and private key respectively.

[0138] Among them, the historical public key can be a public key generated in the past. The historical private key can be a private key generated in the past.

[0139] In implementation, if hybrid encryption is applied, the public key and private key generated when the POP used the shared network element in the past can be respectively recorded as the historical public key and historical private key. When the POP uses the shared network element again, new public key and private key do not need to be generated, and the historical public key can be directly used to encrypt the session key, and the historical private key can be used to decrypt the session key.

[0140] For example, if it is currently determined that the shared operator B uses the shared network element 1, and the home operator A queries that the shared operator B has used the shared network element 1 before and generated a public key and a private key , then the home operator A does not need to generate new public key and private key for the shared operator B to use the shared network element 1, and can directly use the previously generated public key and private key to encrypt and decrypt the session key.

[0141] In this embodiment, by using the historical public key and historical private key of the POP shared network element as the public key and private key respectively, since there is no need to generate the public key and private key for each encryption, the computational amount of the asymmetric encryption in the hybrid encryption is reduced, and the efficiency of the shared network element management is improved.

[0142] To facilitate those skilled in the art to deeply understand the embodiments of the present application, a specific example will be described below.

[0143] For the security problem in the case of multi-operator shared network elements when exchanging management information through the X interface, the present application proposes a method for multi-operators to achieve the security of management information under shared network elements through the X interface. By dividing the permissions of the involved network management parameters and attributes into two groups of read-only or modifiable, the access control permissions of the shared operators are restricted. And in the management systems of the primary operator and the shared operator, they are divided into multiple domains in the network management systems of the primary operator and the shared operator by different partitioning methods in different dimensions, placing the different permissions of the shared operator for various management parameters and attributes in the shared network element and the encryption keys; only between the corresponding domains in the management systems of the primary operator and the shared operator can information be exchanged, and access control of the network management system is performed through inter-domain communication and parameter permissions; at the same time, the management information between the primary operator and the shared operator can be achieved by encrypting the management information with the symmetric encryption method and then encrypting the symmetric key with the asymmetric encryption method to ensure the security of the transmitted data. In addition, the present application also improves the RSA-based asymmetric encryption method in the above encryption method, saving computing power.

[0144] The functions of the present application for the management of shared network elements through the X interface related to security mainly include the following three aspects:

[0145] First aspect, access control for the management of shared network elements: According to the content in the sharing contract agreement signed by the shared operator, set what kind of access (read-only or modifiable parameters / attributes) is allowed for the shared operator for each parameter / attribute. Refer to Figure 1 , taking the example of shared operator B sharing shared network element A1 of operator A, the specific steps are as follows:

[0146] Step S11, in the OS of the TMN of the primary operator and the shared operator, divide into multiple domains according to the shared network element and the shared operator as the dimension, as Figure 6 shown;

[0147] Step S12, the primary operator in the OS of the TMN, for the newly signed shared operator and the shared network element it uses, according to the content in the sharing contract agreement signed by the shared operator, set what kind of access (read-only or modifiable parameters / attributes) is allowed for the shared operator for each parameter / attribute;

[0148] Step S13: Organize the involved network management parameters and attributes and place them in the corresponding fields, such as Figure 7 as shown; meanwhile, when the main operator is the information sender, leave positions in the corresponding fields for the public key, private key generated at the sender side, and the session key generated by the receiver. When the main operator is the information receiver, leave positions in the corresponding fields for the private key sent by the sender to the receiver and the session key generated by the receiver;

[0149] Step S14: After the process of "verifying and authorizing access to shared network elements" as shown in Figure 3 the main operator, according to the content in the contract agreement signed with the sharing operator, clarifies the permissions of sharing operator B for various parameters and attributes in shared network element A1, that is: the permissions are divided into two groups: read-only or modifiable. Corresponding the permissions of various parameters and attributes of operator B in shared network element A1 to the two groups of read-only or modifiable respectively. For the parameters and attributes classified as "read-only", operator B can only read but not modify; for the parameters and attributes classified as "modifiable", operator B can modify;

[0150] Step S15: Between the corresponding fields of the main operator and the sharing operator, the main operator informs the sharing operator of the permissions for various parameters and attributes in the shared network element (information is exchanged between the fields).

[0151] Second aspect: Confidentiality of transmission data related to shared network element management: Encrypt the data transmitted between the main operator's OS and the sharing operator's OS through interface X using the method of hybrid encryption, and place the corresponding keys in the corresponding fields generated in the first aspect above. The specific steps to achieve data confidentiality when the sharing operator sends data to the main operator are as follows:

[0152] Step S21: The main operator generates a pair of public key and private key for the sharing operator that shares its network element. The public key is used for the sharing operator to encrypt the session key, and the private key is used for the main operator to decrypt the session key, and place the keys in the corresponding field of the main operator ( Figure 6 the field in is "User Sharing Operator B of Shared Network Element 1");

[0153] Step S22: The main operator sends the public key to the sharing operator that shares its network element, and the sharing operator places it in its own corresponding field ( Figure 6 the field in is "Sharing Operator B Using Shared Network Element 1");

[0154] Step S23: The sharing operator randomly generates a session key (symmetric key) to encrypt the transmission content, and encrypts this session key with the public key sent by the main operator to itself. Combine the two parts and send them to the main operator together;

[0155] Step S24, the primary operator confirms the receipt of the encrypted management data and the session key. After that, the primary operator:

[0156] (1) First, separate the encrypted transmission content from the session key encrypted with the public key;

[0157] (2) Then, decrypt the session key with the private key;

[0158] (3) Decrypt the transmission content with the decrypted session key to obtain the content sent by the sharing operator;

[0159] Step S25, when ensuring the confidentiality of the data sent by the sharing operator to the primary operator, the same method can also be used, and vice versa.

[0160] Thirdly, the improvement of the asymmetric encryption method in hybrid encryption: Since the asymmetric encryption method has a large computational amount, the primary operator may have multiple shared devices, and each device may be shared by multiple operators. If new public keys and private keys are randomly generated for each asymmetric encryption communication, the computational amount will be huge. Therefore, based on the RSA asymmetric encryption method, this application adds two dimensions of "shared network element type" and "shared operator name", and assigns prime numbers pn and qm. Among them, for each sharing operator sharing a specific network element, p and q are fixed. Thus, for each sharing operator sharing a specific network element, the public key and private key of the asymmetric encryption method in the hybrid encryption algorithm are fixed, saving computing power resources and not confusing the public keys and private keys of different sharing operations for sharing different network elements within the primary operator's TMN system. The specific steps are as follows:

[0161] Step S31, shared network element type 1 (such as a server) corresponds to prime number p1, shared network element type 2 (such as a base station) corresponds to prime number p2, shared network element type 3 (such as a video surveillance device) corresponds to prime number p3,...; shared operator 1 corresponds to prime number q1, shared operator 2 corresponds to prime number q2, shared operator 3 corresponds to prime number q3,...;

[0162] Step S32, for the asymmetric encryption method in the hybrid encryption of the communication between the primary operator and shared operator 1 of shared network element type 2:

[0163] Calculate the product of prime numbers p2 and q1, n = p2 q1;

[0164] Step S33, calculate the Euler's totient function of n , assuming p2 = 5, q1 = 11 (in fact, p and q may be hundreds of digits, and this application only gives an example for illustration), ;

[0165] Step S34, randomly select an integer e on the condition that 1 < e < m and e is relatively prime to m. Randomly select e = 17; calculate the modular multiplicative inverse of e with respect to (i.e., m), that is, find an integer , such that . Equivalent to ( is an integer), find . Essentially, it is to solve the binary linear equation , where . Solve it using the extended Euclidean algorithm to obtain a set of integer solutions , that is . .

[0166] The above method for multi-operator to achieve management information security under shared network elements through the X interface divides the permissions of network management parameters and attributes involved into two groups: read-only or modifiable, restricting the access control permissions of shared operators. And it is divided into multiple domains in the main operator's and shared operator's network management systems by different partitioning methods, placing the different permissions of various management parameters and attributes and the encryption keys in the shared network elements of the shared operator, and performing access control on the network management system through inter-domain communication and parameter permissions. At the same time, key encryption is used to ensure the security of management data transmitted through the X interface.

[0167] Combining the advantages and disadvantages of symmetric encryption and asymmetric encryption, the encryption scheme of this application uses a symmetric session key to encrypt management information and then uses an asymmetric public key to encrypt the session key, giving full play to the advantages of symmetric encryption with low computational complexity and fast encryption speed and the higher security characteristics of asymmetric encryption.

[0168] Since the method of asymmetric encryption has a large amount of calculation, the main operator may have multiple devices available for sharing, and each device may be shared by multiple operators. If new public keys and private keys are randomly generated for each asymmetric encryption communication, the amount of calculation will be huge. Therefore, based on the RSA asymmetric encryption method, this application adds two dimensions of "shared network element type" and "shared operator name", and assigns prime numbers pn and qm, (p and q are fixed for each shared operator sharing a specific network element), so that for each shared operator sharing a specific network element, the public key and private key of the asymmetric encryption method in the hybrid encryption algorithm are fixed, saving computing power resources and at the same time, the public keys and private keys of different shared operations for different shared network elements will not be confused within the main operator's TMN system.

[0169] The above method for managing information security in a shared network element through the X interface by multiple operators divides the management information in the OSs of the TMNs of the primary operator and the shared operator into multiple domains based on the shared network element and the owner operator of the shared network element: The division of domains in the primary operator is based on two dimensions: the shared network elements under a certain primary operator and the shared operator; the division of domains in the shared operator is based on one dimension: the shared network elements used by a certain shared operator. And only the corresponding domains between the primary operator and the shared operator can communicate with each other.

[0170] The primary operator divides the network management parameters and attributes related to the newly signed shared operator into two groups: read-only and modifiable, and restricts the access control permissions of the shared operator. And these parameters and attributes are placed in the corresponding domains; the primary operator corresponds the parameter and attribute permissions of the shared operator in the shared network elements used by it to these two groups respectively; between the corresponding domains of the primary operator and the shared operator, the primary operator notifies the shared operator of the permissions (read-only or modifiable) of the parameters and attributes in the shared network element.

[0171] The asymmetric / symmetric keys generated in the primary operator and the shared operator are also placed in the corresponding domains and communicate in the mutually corresponding domains between the two parties: The primary operator generates a pair of public and private keys for the shared operator that shares its network element, sends the public key to the shared operator for the shared operator to encrypt the session key, and the private key is used by the primary operator to decrypt the session key. The shared operator encrypts the management information with its own generated session key and encrypts the session key with the private key and sends them to the primary operator together. This process is also true vice versa (it is also possible to reverse the primary operator and the shared operator).

[0172] Add two dimensions of "shared network element type" and "shared operator name", assign prime numbers pn and qm, and substitute them into the RSA asymmetric encryption algorithm.

[0173] It should be understood that although Figure 2 、 4 and the steps in the flowcharts of 5 are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, Figure 2 、 4 and at least a part of the steps in 5 may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same moment, but can be executed at different moments. The execution order of these steps or stages is not necessarily sequential either, but can be executed alternately or in turn with at least a part of the steps or stages in other steps or other steps.

[0174] In one embodiment, a shared network element management system is provided, including:

[0175] MOP, which is used to authorize the POP to access the network management of the shared network element through the X interface, sort out the network management parameters and attributes involved for the newly signed POP and the shared network element it uses, determine the permissions of the POP for each of the parameters and attributes according to the content of the agreement signed with the POP, and notify the POP of its permissions for each of the parameters and attributes;

[0176] POP, which is used to manage the shared network element according to the permissions.

[0177] In implementation, if MOP and POP can communicate with each other through the X interface, MOP can authorize POP, permit POP to access the shared network element of MOP through the X interface and manage the shared network element of MOP. MOP signs a shared network element usage agreement with the authorized POP, permits the POP to use the specified shared network element of MOP. MOP can also manage the specified shared network element for the POP, sort out the involved parameters and attributes. According to the shared network element usage agreement signed between MOP and POP, MOP can manage the various parameters and attributes involved in the shared network element of the POP, respectively determine the permissions of the POP, and MOP can notify the POP of the permissions of the POP for each parameter and attribute. The POP performs network management on the shared network element of MOP according to the received permissions.

[0178] The above-mentioned shared network element management system authorizes the POP to access the network management of the shared network element through the X interface by MOP, sorts out the network management parameters and attributes involved for the newly signed POP and the shared network element it uses, determines the permissions of the POP for each parameter and attribute according to the content of the agreement signed with the POP, and notifies the POP of its permissions for each parameter and attribute; after MOP authorizes the POP to manage its shared network element, it can specify the shared network element for the POP, as well as the permissions of the network management parameters and attributes involved in the POP's use of the shared network element, so that the POP can only manage the specified shared network element and is restricted by the permissions, enhancing the security of shared network element management.

[0179] In one embodiment, as Figure 8 shown, a shared network element management device is provided, including: a management authorization module 402, a parameter determination module 404, a permission determination module 406, and a permission notification module 408, where:

[0180] The management authorization module 402 is used for MOP to authorize the POP to access the network management of the shared network element through the X interface;

[0181] A parameter determination module 404, configured to sort out the network management parameters and attributes involved for the newly signed POP and the shared network elements used thereby;

[0182] An authority determination module 406, configured to determine, according to the protocol content signed with the POP, the authorities of the POP for each of the parameters and attributes by the MOP;

[0183] An authority notification module 408, configured to notify the POP of its authorities for each of the parameters and attributes by the MOP, so that the POP manages the shared network elements.

[0184] In one embodiment, the above-mentioned shared network element management device further includes a hybrid encryption module, configured to, if the management data is sent from the POP to the MOP and hybrid encryption is applied, generate a pair of public and private keys for the POP by the MOP; the public key is used for the POP to encrypt the session key, and the private key is used for the MOP to decrypt the session key, and the session key is a symmetric key; the MOP sends the public key to the POP.

[0185] In one embodiment, the above-mentioned hybrid encryption module is further configured to randomly generate the session key by the POP; the POP uses the session key to encrypt the management data to be transmitted to obtain encrypted management data; the POP uses the public key sent by the MOP to encrypt the session key to obtain an encrypted session key; the POP combines the encrypted management data and the encrypted session key and sends them to the MOP.

[0186] In one embodiment, the above-mentioned shared network element management device further includes an asymmetric encryption module, configured to, if the management data is sent from the POP to the MOP and asymmetric encryption is applied, generate a pair of public and private keys for the POP by the MOP; the public key is used for the POP to encrypt the management data to be transmitted, and the private key is used for the MOP to decrypt the management data to be transmitted; the MOP sends the public key to the POP.

[0187] In one embodiment, the above-mentioned hybrid encryption module is further configured to, if the management data is sent from the MOP to the POP and hybrid encryption is applied, generate a pair of public and private keys for the MOP by the POP; the public key is used for the MOP to encrypt the session key, and the private key is used for the POP to decrypt the session key, and the session key is a symmetric key; the POP sends the public key to the MOP.

[0188] In one embodiment, the above-mentioned hybrid encryption module is further configured to randomly generate the session key by the MOP; the MOP uses the session key to encrypt the management data to be transmitted, obtaining the encrypted management data; the MOP uses the public key sent by the POP to encrypt the session key, obtaining the encrypted session key; the MOP combines the encrypted management data and the encrypted session key and sends them to the POP.

[0189] In one embodiment, the above-mentioned asymmetric encryption module is further configured to, if the management data is sent from the MOP to the POP and asymmetric encryption is applied, the POP generates a pair of public key and private key for the MOP; the public key is used by the MOP to encrypt the management data to be transmitted, and the private key is used by the POP to decrypt the management data to be transmitted; the POP sends the public key to the MOP.

[0190] In one embodiment, the permissions are divided into two groups: read-only and modifiable, and the permissions of the POP for each of the parameters and attributes respectively correspond to read-only or modifiable.

[0191] In one embodiment, a main operator domain is set in the MOP, and a shared operator domain is set in the POP. Both the main operator domain and the shared operator domain reflect the corresponding relationship between the POP and the shared network element.

[0192] In one embodiment, the above-mentioned hybrid encryption module is further configured to use the historical public key and historical private key of the shared network element by the POP as the public key and the private key respectively.

[0193] For the specific limitations on the shared network element management device, reference may be made to the limitations on the shared network element management method in the foregoing text, which will not be elaborated here. Each module in the above-mentioned shared network element management device can be implemented in whole or in part by software, hardware, and their combination. The above-mentioned modules can be embedded in the processor of the computer device in hardware form or be independent of it, or can be stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to the above-mentioned modules.

[0194] Figure 9 It is a schematic structural diagram of an operator device provided by an embodiment of the present application. Figure 9 The shown operator device 700 includes: at least one processor 701, a memory 702, and at least one network interface 704. Each component in the operator device 700 is coupled together through a bus system 705. It can be understood that the bus system 705 is used to realize the connection and communication between these components. The bus system 705 includes not only a data bus, but also a power bus, a control bus, and a status signal bus. However, for the sake of clear illustration, inFigure 9 All kinds of buses are labeled as the bus system 705. In addition, in the embodiments of the present application, a transceiver 706 is further included. The transceiver can be multiple components, that is, it includes a transmitter and a receiver, and provides a unit for communicating with various other devices on the transmission medium.

[0195] It can be understood that the memory 702 in the embodiments of the present application can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus random access memory (DRRAM). The memory 702 of the systems and methods described in the embodiments of the present application is intended to include but not be limited to these and any other suitable types of memories.

[0196] In some embodiments, the memory 702 stores the following elements, executable modules, or data structures, or subsets thereof, or extended sets thereof: an operating system 7021. Among them, the operating system 7021 includes various system programs, such as a framework layer, a core library layer, a driver layer, etc., for implementing various basic services and processing hardware-based tasks.

[0197] In an embodiment of the present application, by invoking a program or instruction stored in the memory 702, the processor is configured to enable the MOP to authorize the POP to access the network management of the shared network element through the X interface; the MOP is the network management parameters and attributes involved in sorting the newly signed POP and the shared network element used by it; according to the protocol content signed with the POP, the MOP determines the permissions of the POP for each of the parameters and attributes; the transmitter is configured to notify the POP of its permissions for each of the parameters and attributes by the MOP, so that the POP manages the shared network element.

[0198] Some or all of the methods disclosed in the embodiments of the present application above can also be applied to the processor 701, or implemented by the processor 701, or implemented in cooperation with other components (such as a transceiver) by the processor 701. The processor 701 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the integrated logic circuit in the hardware of the processor 701 or the instructions in the form of software. The above-mentioned processor 701 may be a general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as being executed by a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software module may be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory 702, and the processor 701 reads the information in the memory 702 and combines its hardware to complete the steps of the above method.

[0199] It can be understood that the embodiments described in the embodiments of the present application can be implemented by hardware, software, firmware, middleware, microcode, or a combination thereof. For hardware implementation, the processing unit can be implemented in one or more application specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), general-purpose processors, controllers, microcontrollers, microprocessors, other electronic units for performing the functions described in the present application, or a combination thereof.

[0200] For software implementation, the technologies described in the embodiments of the present application can be implemented by modules (such as procedures, functions, etc.) that execute the functions described in the embodiments of the present application. The software code can be stored in a memory and executed by the processor 701. The memory can be implemented inside or outside the processor 701.

[0201] In one embodiment, the processor is further configured to, if the management data is sent from the POP to the MOP and hybrid encryption is applied, the MOP generates a pair of public and private keys for the POP; the public key is used by the POP to encrypt the session key, and the private key is used by the MOP to decrypt the session key, and the session key is a symmetric key; the MOP sends the public key to the POP.

[0202] In one embodiment, the processor is further configured to the POP randomly generates the session key; the POP uses the session key to encrypt the management data to be transmitted to obtain encrypted management data; the POP uses the public key sent by the MOP to encrypt the session key to obtain an encrypted session key; the POP combines the encrypted management data and the encrypted session key and sends them to the MOP.

[0203] In one embodiment, the processor is further configured to, if the management data is sent from the POP to the MOP and asymmetric encryption is applied, the MOP generates a pair of public and private keys for the POP; the public key is used by the POP to encrypt the management data to be transmitted, and the private key is used by the MOP to decrypt the management data to be transmitted; the MOP sends the public key to the POP.

[0204] In one embodiment, the processor is further configured to, if the management data is sent from the MOP to the POP and hybrid encryption is applied, the POP generates a pair of public key and private key for the MOP; the public key is used by the MOP to encrypt the session key, and the private key is used by the POP to decrypt the session key, and the session key is a symmetric key; the POP sends the public key to the MOP.

[0205] In one embodiment, the processor is further configured to the MOP randomly generates the session key; the MOP uses the session key to encrypt the management data to be transmitted, obtaining the encrypted management data; the MOP uses the public key sent by the POP to encrypt the session key, obtaining the encrypted session key; the MOP combines the encrypted management data and the encrypted session key and sends them to the POP.

[0206] In one embodiment, the processor is further configured to, if the management data is sent from the MOP to the POP and asymmetric encryption is applied, the POP generates a pair of public key and private key for the MOP; the public key is used by the MOP to encrypt the management data to be transmitted, and the private key is used by the POP to decrypt the management data to be transmitted; the POP sends the public key to the MOP.

[0207] In one embodiment, the permissions are divided into two groups: read-only and modifiable, and the POP's permissions for each parameter and attribute respectively correspond to read-only or modifiable.

[0208] In one embodiment, a primary operator domain is set in the MOP, and a shared operator domain is set in the POP, and both the primary operator domain and the shared operator domain reflect the corresponding relationship between the POP and the shared network element.

[0209] In one embodiment, the processor is further configured to use the historical public key and historical private key of the shared network element by the POP as the public key and the private key respectively.

[0210] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored, and when the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.

[0211] The embodiments of the present application further provide a computer program product containing instructions, which when running on a computer, causes the computer to execute the steps in the above-mentioned method embodiments.

[0212] Those of ordinary skill in the art can understand that all or part of the processes of the methods in the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, or optical memory, etc. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc.

[0213] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.

[0214] The above-described embodiments merely represent several implementation manners of the present application. Their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application should be subject to the appended claims.

Claims

1. A shared network element management method, characterized in that, The method includes: The MOP authorizes the POP to access the network management of the shared network element through the X interface; The MOP sorts out the network management parameters and attributes involved for the newly signed POP and the shared network element it uses; According to the content of the agreement signed with the POP, the MOP determines the permissions of the POP for each of the parameters and attributes; The MOP notifies the POP of its permissions for each of the parameters and attributes for the POP to manage the shared network element.

2. The method according to claim 1, wherein The method further includes: If the management data is sent from the POP to the MOP and hybrid encryption is applied, the MOP generates a pair of public and private keys for the POP; the public key is used by the POP to encrypt the session key, and the private key is used by the MOP to decrypt the session key, and the session key is a symmetric key; The MOP sends the public key to the POP.

3. The method according to claim 2, characterized in that, After the MOP sends the public key to the POP, it further includes: The POP randomly generates the session key; The POP uses the session key to encrypt the management data to be transmitted to obtain encrypted management data; The POP uses the public key sent by the MOP to encrypt the session key to obtain an encrypted session key; The POP combines the encrypted management data and the encrypted session key and sends them to the MOP.

4. The method according to claim 1, characterized in that, The method further includes: If the management data is sent from the POP to the MOP and asymmetric encryption is applied, the MOP generates a pair of public and private keys for the POP; the public key is used by the POP to encrypt the management data to be transmitted, and the private key is used by the MOP to decrypt the management data to be transmitted; The MOP sends the public key to the POP.

5. The method according to claim 1, wherein The method further includes: If the management data is sent from the MOP to the POP and hybrid encryption is applied, the POP generates a pair of public and private keys for the MOP; the public key is used by the MOP to encrypt the session key, and the private key is used by the POP to decrypt the session key, and the session key is a symmetric key; The POP sends the public key to the MOP.

6. The method according to claim 5, wherein After the POP sends the public key to the MOP, it further includes: The MOP randomly generates the session key; The MOP uses the session key to encrypt the management data to be transmitted to obtain encrypted management data; The MOP uses the public key sent by the POP to encrypt the session key to obtain an encrypted session key; The MOP combines the encrypted management data and the encrypted session key and sends them to the POP.

7. The method according to claim 1, wherein The method further includes: If the management data is sent from the MOP to the POP and asymmetric encryption is applied, the POP generates a pair of public and private keys for the MOP; the public key is used by the MOP to encrypt the management data to be transmitted, and the private key is used by the POP to decrypt the management data to be transmitted; The POP sends the public key to the MOP.

8. The method according to claim 1, characterized in that The permissions are divided into two groups: read-only and modifiable. The POP's permissions for each of the parameters and attributes correspond to either read-only or modifiable.

9. The method according to claim 1, wherein The MOP is provided with a primary operator domain, and the POP is provided with a shared operator domain. Both the primary operator domain and the shared operator domain reflect the corresponding relationship between the POP and the shared network element.

10. The method according to claim 2 or 5, characterized in that, The method further includes: Using the historical public key and historical private key of the POP for the shared network element as the public key and the private key respectively.

11. A shared network element management system, characterized in that, Including: The MOP is used to authorize the POP to access the network management of the shared network element through the X interface, sort out the network management parameters and attributes involved for the newly signed POP and the shared network element it uses, determine the POP's permissions for each of the parameters and attributes according to the protocol content signed with the POP, and notify the POP of its permissions for each of the parameters and attributes. The POP is used to manage the shared network element according to the permissions.

12. A shared network element management device, characterized in that, The device includes: The management authorization module is used for the MOP to authorize the POP to access the network management of the shared network element through the X interface. The parameter determination module is used for the MOP to sort out the network management parameters and attributes involved for the newly signed POP and the shared network element it uses. The permission determination module is used for the MOP to determine the POP's permissions for each of the parameters and attributes according to the protocol content signed with the POP. The permission notification module is used for the MOP to notify the POP of its permissions for each of the parameters and attributes for the POP to manage the shared network element.

13. An operator device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 10 are implemented.

14. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 10 are implemented.

15. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 10 are implemented.