Communication method and communication device

Through the two-factor verification mechanism of the first authorization center and the second authorization center, the access token is generated and verified, which solves the risk of terminal devices accessing pseudo-network in the subnet scenario and improves the security of the subnet scenario.

CN120301599APending Publication Date: 2025-07-11HUAWEI TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202410048005.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-11
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

In the subnet scenario, the risk of terminal devices accessing pseudo-network is high, and the prior art is difficult to effectively verify whether the network element has the right to serve the subnet, resulting in security risks.

Method used

Through the two-factor verification mechanism of the first authorization center and the second authorization center, an access token is generated and verified to ensure that the network element has the right to serve the subnet and avoid terminal devices from accessing the pseudo-network.

Benefits of technology

It improves the security of subnet scenarios, ensures that terminal devices are not misled to the pseudo-network when accessing the subnet, and enhances the security and reliability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120301599A_ABST
    Figure CN120301599A_ABST
Patent Text Reader

Abstract

The invention provides a communication method and a communication device, and relates to the technical field of communication. The method comprises: receiving a first request message from a first network element, the first request message being used for requesting to obtain authorization of the first network element to access a first service on behalf of a first sub-network, the first network element serving the first sub-network, the first request message comprising identification information of the first network element and identification information of the first sub-network; verifying whether the first network element is allowed to serve the first subnet; a first message is sent to the first network element, the first message is used for indicating that the first network element is authorized to access the first service, the first message comprises an access token, the access token comprises first information and first signature information, and the first signature information is a signature of the first information; the first information comprises at least one of the following items: identification information of the first service, identification information of the first subnet and identification information of the first network element. According to the method in the embodiment of the invention, the security of a subnet scene can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technologies, and particularly to a communication method and a communication device. Background Art

[0002] A subnet refers to a network deployed for subnet sites (such as enterprises, campuses, venues, etc.), and can be used for subnet users (such as visitors to the subnet site or members or employees of the subnet site, etc.) to access and use the subnet services provided by the subnet site (such as extended reality (XR) games, in-site augmented reality (AR) navigation, immersive conferences, etc.).

[0003] With the development of communication technologies, subnet scenarios have been introduced in some communication systems. However, there are security risks in subnet scenarios. For example, when a terminal device accesses a subnet, there may be a risk that the terminal device accesses a fake network. Summary of the Invention

[0004] This application provides a communication method and a communication device, which can improve the security of subnet scenarios.

[0005] In a first aspect, a communication method is provided, which is applied to a first authorization center. The first authorization center is an authorization center of a first operator or a subnet authorization center, and includes:

[0006] Receiving a first request message from a first network element. The first request message is used to request authorization for the first network element to access a first service of a second operator on behalf of a first subnet. The first network element serves the first subnet, and the first request message includes identification information of the first network element and identification information of the first subnet; verifying whether the first network element is allowed to serve the first subnet; sending a first message to the first network element. The first message is used to indicate authorization for the first network element to access the first service, and the first message includes an access token. The access token includes first information and first signature information, and the first signature information is a signature of the first information. The first information includes at least one of the following: identification information of the first service, identification information of the first subnet, and identification information of the first network element.

[0007] In an embodiment of this application, when the first network element requests authorization to access the first service on behalf of the first subnet, the first authorization center verifies whether the first network element is allowed to serve the first subnet, and sends a first message carrying an access token to the first network element. In this way, it can be ensured that the first network element has the right to serve the first subnet, and when a terminal device requests to register to the first subnet through the first network element, the risk of the terminal device accessing a fake network can be avoided, thereby improving the security of the subnet scenario.

[0008] In some possible implementations, before receiving the first request message from the first network element, the method further includes:

[0009] Receiving a second request message from the first network element, where the second request message is used to request registering the first network element to the first authorization center; verifying, according to the second request message, whether the first network element has the right to serve the first subnet; or, receiving a third request message from a fourth network element, where the third request message is used to request registering the first network element to the first authorization center; verifying, according to the third request message, whether the first network element has the right to serve the first subnet.

[0010] In some possible implementations, the second request message or the third request message includes the identification information of the first network element and the identification information of the at least one subnet, and the at least one subnet includes the first subnet.

[0011] In some possible implementations, the method further includes: sending a fourth request message to a second authorization center of a second operator, where the fourth request message is used to request obtaining authorization for the first network element to access a first service on behalf of the first subnet.

[0012] In some possible implementations, the fourth request message includes second information and second signature information, where the second signature information is a signature of the second authorization center on the second information, and the second information includes at least one of the following: the identification information of the first network element, the identification information of the first subnet.

[0013] In some possible implementations, after sending the fourth request message to the second authorization center of the second operator, the method further includes: receiving a second message from the second authorization center, where the second message is used to indicate that the second authorization center authorizes the first network element to access the first service.

[0014] In some possible implementations, the second message includes the access token, and the first signature information in the access token is obtained by the second authorization center signing the first information.

[0015] In a second aspect, a communication method is provided, which is applied to a second authorization center of a second operator and includes:

[0016] Receive a fourth request message from a first authorization center, where the first authorization center is an authorization center or a subnet authorization center of a first operator, and the fourth request message is used to request authorization for the first network element to access a first service of a second operator on behalf of a first subnet; send a second message to the first authorization center, where the second message is used to instruct the second authorization center to authorize the first network element to access the first service, and the second message includes an access token, and the access token includes first information and first signature information, and the first signature information is a signature of the second authorization center on the first information, and the first information includes at least one of the following: identification information of the first service, identification information of the first subnet, and identification information of the first network element.

[0017] In an embodiment of the present application, the fourth request message includes a signature of the first authorization center on second information. The second authorization center receives the fourth request message and sends a second message carrying an access token to the first authorization center. In this way, through the double verification of the first authorization center and the second authorization center, it can be ensured that the first network element has the right to serve the first subnet, and when the terminal device requests to register to the first subnet through the first network element, the terminal device can be prevented from accessing a pseudo network, thereby improving the security of the subnet scenario.

[0018] In some possible implementation manners, the fourth request message includes second information and second signature information, where the second signature information is a signature of the first authorization center on the second information, and the second information includes at least one of the following: identification information of the first network element and identification information of the first subnet.

[0019] In a third aspect, a communication method is provided, which is applied to a first network element and includes:

[0020] Send a first request message to a first authorization center, where the first authorization center is an authorization center or a subnet authorization center of a first operator, and the first request message is used to request authorization for accessing a first service of a second operator on behalf of a first subnet, and the first network element serves the first subnet, and the first request message includes identification information of the first network element and identification information of the first subnet; receive a first message sent by the first authorization center, where the first message is used to instruct to authorize the first network element to access the first service, and the first message includes an access token, and the access token includes first information and first signature information, and the first signature information is a signature on the first information, and the first information includes at least one of the following: identification information of the first service, identification information of the first subnet, and identification information of the first network element.

[0021] In an embodiment of the present application, the first request message is used to request authorization to obtain a first service on behalf of a first subnet from a second operator. The first network element receives a first message sent by a first authorization center for instructing the first network element to access the first service, which can ensure that the first network element has the right to serve the first subnet. In this way, when a terminal device requests to register to the first subnet through the first network element, it can avoid the terminal device accessing a fake network, thereby improving the security of the subnet scenario.

[0022] In some possible implementation manners, before sending the first request message to the first authorization center, the method further includes: sending a second request message to the first authorization center, where the second request message is used to request registering the first network element to the first authorization center, and the second request message includes identification information of the first network element and identification information of the at least one subnet, and the at least one subnet includes the first subnet.

[0023] In some possible implementation manners, the method further includes:

[0024] Receiving a fifth request message from a terminal device, where the fifth request message is used to request registering the terminal device to the first subnet; where sending the first request message to the first authorization center includes: in response to the fifth request message, sending the first request message to the first authorization center. In some possible implementation manners, the fifth request message includes identification information of the first subnet.

[0025] In some possible implementation manners, the first service is an authentication service, and the method further includes: sending a sixth request message to a second network element, where the sixth request message is used to request authenticating a terminal device that requests to register to the first subnet, and the sixth request message includes at least one of the following: identification information of the terminal device, identification information of the first subnet, and the access token; receiving a third message from the second network element, where the third message includes an authentication vector, and the authentication vector includes a first field and a first random number, and the first field is determined according to a first key, the first random number, and identification information of the first subnet, and the first key is determined according to a shared key between the terminal device and the second operator, and the authentication vector is used for the terminal device to authenticate the first subnet; sending a fourth message to the terminal device, where the fourth message includes the authentication vector.

[0026] Fourthly, a communication method is provided, which is applied to a second network element and includes:

[0027] Receive a sixth request message from a first network element, where the sixth request message is used to request to provide a first service to a terminal device that requests to register with a first subnet. The sixth request message includes at least one of the following: identification information of the terminal device, identification information of the first subnet, and an access token. The access token includes first information and first signature information. The first signature information is a signature of the first information by a second authorization center of a second operator to which the second network element belongs. The first information includes at least one of the following: identification information of the first subnet, identification information of the first network element, and identification information of the first service; verify the first signature information; and provide the first service to the terminal device when the verification of the first signature information passes.

[0028] In an embodiment of the present application, the second network element receives a sixth request message from the first network element, verifies the first signature information in the sixth request message, and provides the first service to the terminal device when the verification of the first signature information passes. In this way, it can be ensured that the first network element has the right to serve the first subnet, and when the terminal device requests to register with the first subnet through the first network element, it is possible to prevent the terminal device from accessing a fake network, thereby improving the security of the subnet scenario.

[0029] In some possible implementation manners, the verifying the first signature information includes: verifying the first signature information using the public key of the second authorization center.

[0030] In some possible implementation manners, the first service is an authentication service. The providing the first service to the terminal device when the verification of the first signature information passes includes: sending a seventh request message to a third network element, where the seventh request message is used to obtain an authentication vector, and the seventh request message includes the identification information of the first subnet and the identification information of the terminal device; receiving a fifth message from the third network element, where the fifth message includes an authentication vector, and the authentication vector includes a first field and a first random number. The first field is determined according to a first key, the first random number, and the identification information of the first subnet. The first key is determined according to a shared key between the terminal device and the third network element. The authentication vector is used for the terminal device to authenticate the first subnet.

[0031] In some possible implementation manners, the seventh request message includes first indication information, where the first indication information is used to instruct the third network element to send the authentication vector.

[0032] In some possible implementation manners, after receiving the fifth message from the third network element, the method further includes: the first network element sending a third message, where the third message includes the authentication vector.

[0033] In a fifth aspect, a communication method is provided, which is applied to a third network element and includes:

[0034] Receiving a seventh request message from a second network element, where the seventh request message is used to obtain an authentication vector, and the seventh request message includes identification information of a terminal device requesting to register to a first subnet and identification information of the first subnet; sending a fifth message to the second network element, where the fifth message includes an authentication vector, and the authentication vector includes a first field and a first random number, the first field is determined according to a first key, the first random number, and the identification information of the first subnet, the first key is determined according to a shared key between the terminal device and the third network element, and the authentication vector is used for the terminal device to authenticate the first subnet.

[0035] In an embodiment of the present application, the fifth message includes an authentication vector for the terminal device to authenticate the first subnet. The third network element sending the fifth message to the second network element helps the terminal device authenticate the subnet according to the authentication vector, and can avoid the terminal device accessing a fake network, thereby helping to improve the security of the subnet scenario.

[0036] In some possible implementation manners, the seventh request message includes first indication information, where the first indication information is used to instruct the third network element to send the authentication vector, and the method further includes: carrying the authentication vector in the fifth message according to the first indication information.

[0037] In a sixth aspect, a communication method is provided, which is applied to a terminal device and includes:

[0038] Sending a fifth request message to a first network element, where the fifth request message is used to request to register the terminal device to a first subnet; receiving a fourth message from the first network element, where the fourth message includes an authentication vector, and the authentication vector includes a first field and a first random number, the first field is determined according to a first key, the first random number, and the identification information of the first subnet, the first key is determined according to a shared key between the terminal device and a second operator, and the authentication vector is used for the terminal device to authenticate the first subnet, and the second operator is the home operator of the terminal device.

[0039] In an embodiment of the present application, the fourth message includes an authentication vector for the terminal device to authenticate the first subnet. The terminal device receiving the fourth message from the first network element can authenticate the subnet according to the authentication vector, and can avoid the terminal device accessing a fake network, thereby being able to improve the security of the subnet scenario.

[0040] In some possible implementations, the method further includes: the terminal device calculates a second field according to the first key, the first random number, and the identification information of the first subnet; if the second field is the same as the first field, the terminal device accesses the first subnet; or, if the second field is different from the first field, the terminal device stops accessing the first subnet.

[0041] In a seventh aspect, a communication device is provided, including: a module or unit configured to execute the method in any one of the above aspects or any one of the possible implementations in any one of the above aspects.

[0042] In an eighth aspect, a communication device is provided, including: a processor and a memory, the processor is coupled to the memory, the memory is configured to store a computer program (which can also be referred to as code, or instruction), when the computer program is executed by the processor, the device executes the method in any one of the above aspects or any one of the possible implementations in any one of the above aspects.

[0043] In some possible implementations, the device further includes a memory coupled to the processor.

[0044] In some possible implementations, there is one or more processors, and / or, there is one or more memories.

[0045] In some possible implementations, the memory can be integrated with the processor, or the memory is separately provided from the processor.

[0046] In a ninth aspect, a computer-readable storage medium is provided, on which a computer program (which can also be referred to as code, or instruction) is stored, when the computer program runs on a computer, the computer executes the method in any one of the above aspects or any one of the possible implementations in any one of the above aspects.

[0047] In a tenth aspect, a computer program product is provided, including: a computer program (which can also be referred to as code, or instruction), when the computer program runs on a computer, the computer executes the method in any one of the above aspects or any one of the possible implementations in any one of the above aspects.

[0048] In an eleventh aspect, a chip is provided, including: a processor and a memory, the memory is configured to store a computer program (which can also be referred to as code, or instruction), the processor is configured to call and run the computer program stored in the memory, so that a device or equipment installed with the chip executes the method in any one of the above aspects or any one of the possible implementations in any one of the above aspects. Description of the Drawings

[0049] Figure 1It is a schematic block diagram of an application scenario in an embodiment of the present application.

[0050] Figure 2 It is a schematic block diagram of another application scenario in an embodiment of the present application.

[0051] Figure 3 It is a schematic block diagram of yet another application scenario in an embodiment of the present application.

[0052] Figure 4 It is a schematic block diagram of yet another application scenario in an embodiment of the present application.

[0053] Figure 5 It is a schematic flowchart of a communication method provided by an embodiment of the present application.

[0054] Figure 6 It is a schematic structural diagram of a communication device provided by an embodiment of the present application.

[0055] Figure 7 It is a schematic structural diagram of a communication device provided by another embodiment of the present application.

[0056] Figure 8 It is a schematic structural diagram of a communication device provided by yet another embodiment of the present application.

[0057] Figure 9 It is a schematic structural diagram of a communication device provided by yet another embodiment of the present application.

[0058] Figure 10 It is a schematic structural diagram of a communication device provided by yet another embodiment of the present application.

[0059] Figure 11 It is a schematic structural diagram of a communication device provided by yet another embodiment of the present application.

[0060] Figure 12 It is a schematic structural diagram of a device provided by an embodiment of the present application. Detailed implementation manners

[0061] Next, the technical solutions in the embodiments of the present application will be described with reference to the accompanying drawings in the embodiments of the present application.

[0062] In the description of this application, unless otherwise specified, " / " means that the objects associated before and after are in an "or" relationship. For example, A / B can represent A or B. The "and / or" in this application is only a description of the association relationship of the associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B can be singular or plural. Also, in the description of this application, unless otherwise specified, "a plurality of" means two or more than two. "At least one (item)" or its similar expression means any combination of these items, including any combination of a single item or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c can be single or plural. In addition, for the convenience of clearly describing the technical solutions of the embodiments of this application, in the embodiments of this application, terms such as "first" and "second" are used to distinguish the same items or similar items with basically the same functions and roles. Those skilled in the art can understand that terms such as "first" and "second" do not limit the quantity and execution order, and terms such as "first" and "second" do not necessarily mean different. It should be understood that in this application, descriptions such as "in... cases", "if...", "when...", "if...", etc. can be used interchangeably.

[0063] The technical solutions of the embodiments of this application can be applied to various communication systems, such as: the fifth generation (5G) system or new radio (NR), long term evolution (LTE) system, LTE frequency division duplex (FDD) system, LTE time division duplex (TDD), etc. The technical solutions provided by this application can also be applied to future communication systems, such as the sixth generation mobile communication system, and also satellite communication systems, etc.

[0064] The terminal device in the embodiments of the present application may refer to user equipment (UE), station, access terminal, user unit, user station, mobile station, mobile station (MS), remote station, remote terminal, mobile terminal (MT), user terminal, terminal, wireless communication device, user agent or user device, etc., and the embodiments of the present application do not limit this. The terminal device in the embodiments of the present application may also be a mobile phone, cellular phone, cordless phone, session initiation protocol (SIP) phone, wireless local loop (WLL) station, personal digital assistant (PDA), handheld device with wireless communication function, computing device or other processing device connected to a wireless modem, large screen, in-vehicle device, wearable device, terminal device in a 5G network or terminal device in a future evolved public land mobile network (PLMN), etc., and the embodiments of the present application do not limit this. The terminal device in the embodiments of the present application may also be a tablet computer (Pad), laptop computer, palmtop computer, mobile internet device (MID), wearable device, virtual reality (VR) device, augmented reality (AR) device, wireless terminal in industrial control, wireless terminal in self-driving, wireless terminal in remote medical surgery, wireless terminal in smart grid, wireless terminal in transportation safety, wireless terminal in smart city, wireless terminal in smart home, etc., and the embodiments of the present application do not limit this.

[0065] In some embodiments, the terminal device can be used as a base station. Optionally, the terminal device can act as a scheduling entity to provide sidelink signals between terminal devices in vehicle to everything (V2X) or device to device (D2D), etc. For example, a cellular phone and a vehicle can communicate using the sidelink signal, or a cellular phone and a smart home device can also communicate using the sidelink signal without relaying communication signals through a base station.

[0066] The network device in the embodiments of the present application can refer to a radio access network (RAN) node (or device) that connects a terminal device to a wireless network, and can also be referred to as a base station. For example, the network device can be a Node B, an evolved Node B (eNodeB), a next-generation Node B (gNB) in a 5G mobile communication system, a transmission reception point (TRP), an access point (AP), a base station in a future mobile communication system, or an access node (AP) in a WiFi system, a radio controller in a cloud radio access network (CRAN) scenario, a relay station, an access point, a vehicle-mounted device, a wearable device, a network device in other future evolved communication systems, etc.

[0067] In some embodiments, multiple RAN nodes may cooperate to assist a terminal device in achieving wireless access, and different RAN nodes may respectively implement some functions of a base station. For example, an RAN node (i.e., the network device in this application) may be a central unit (CU), a distributed unit (DU), a CU-control plane (CP), a CU-user plane (UP), or a radio unit (RU), etc. The CU and the DU may be separately provided, or may also be included in the same network element, such as a baseband unit (BBU). The RU may be included in a radio frequency device or a radio frequency unit, such as included in a remote radio unit (RRU), an active antenna unit (AAU), or a remote radio head (RRH). In different systems, the CU (or CU-CP and CU-UP), DU, or RU may also have different names, but those skilled in the art can understand their meanings. For example, in an open radio access network (ORAN) system, the CU may also be referred to as an open CU (O-CU), the DU may also be referred to as an open DU (O-DU), the CU-CP may also be referred to as O-CU-CP, the CU-UP may also be referred to as O-CU-UP, and the RU may also be referred to as O-RU. Any one of the CU (or CU-CP, CU-UP), DU, and RU in this application may be implemented by a software module, a hardware module, or a combination of a software module and a hardware module. It should be understood that this application does not limit the specific technologies and specific device forms adopted by the network device.

[0068] In some embodiments, the network device may be fixed or mobile, and this application embodiment does not limit this. For example, a helicopter or a drone may be configured as a mobile network device, and one or more cells may move according to the position of the mobile network device. In other examples, a helicopter or a drone may be configured to be used as a device for communicating with another network device.

[0069] In some embodiments, the network device may be deployed on land or in the air, and this application embodiment does not limit this. For example, the network device may be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; it may also be deployed on water; it may also be deployed on airplanes, balloons, and satellites in the air.

[0070] In the embodiments of the present application, a terminal device or a network device may include a hardware layer, an operating system layer running on the hardware layer, and an application layer running on the operating system layer. The hardware layer includes hardware such as a central processing unit (CPU), a memory management unit (MMU), and a memory (also referred to as main memory). The operating system may be any one or more computer operating systems that implement service processing through processes. For example, Linux operating system, Unix operating system, Android operating system, iOS operating system, or Windows operating system, etc. The application layer includes applications such as a browser, an address book, a word processing software, and an instant messaging software. Moreover, in the embodiments of the present application, the specific structure of the execution subject of the method provided in the embodiments of the present application is not particularly limited, as long as it can communicate according to the method provided in the embodiments of the present application by running a program recorded with the code of the method provided in the embodiments of the present application.

[0071] In addition, various aspects or features of the present application may be implemented as a method, an apparatus, or an article of manufacture using standard programming and / or engineering techniques. The term "article of manufacture" used in the present application covers a computer program accessible from any computer-readable device, carrier, or medium. For example, the computer-readable medium may include, but is not limited to: magnetic storage devices (such as hard disks, floppy disks, or magnetic tapes, etc.), optical discs (such as compact discs (CDs), digital versatile discs (DVDs), etc.), smart cards, and flash memory devices (such as erasable programmable read-only memories (EPROMs), cards, sticks, or key drives, etc.). Additionally, the various storage media described herein may represent one or more devices and / or other machine-readable media for storing information. The term "machine-readable medium" may include, but is not limited to, wireless channels and various other media capable of storing, containing, and / or carrying instructions and / or data.

[0072] In some embodiments, the network may authenticate the terminal device based on a subscriber identity module (SIM) card. For example, a shared key is shared between the SIM card of a UE and the unified data management (UDM) function of its home public land mobile network (HPLMN). When the UE accesses, the network may authenticate the UE based on the shared key.

[0073] Similarly, the terminal device also needs to authenticate the network, especially when the terminal device accesses through a visited public land mobile network (VPLMN) or when the terminal device accesses through a stand alone non public network (SNPN). The following combines Figure 1 , taking access through VPLMN as an example, to introduce the process of the terminal device authenticating the network.

[0074] Figure 1 is a schematic block diagram of an application scenario in an embodiment of the present application. Among them, the public land mobile network (PLMN) 1 can represent operator 1, and PLMN2 can represent operator 2.

[0075] An operator can issue a certificate to a network element, and the certificate can include a PLMN identity (ID). For example, before the PLMN1 network function (NF) service consumer (such as Figure 1 the PLMN1 access and mobility management function (AMF) in) sends a message to the PLMN2 NF service provider (producer) (such as the PLMN2 authentication server function (AUSF) in the figure), it can obtain an access token from the PLMN1 network repository function (NRF). The access token includes the PLMN1 ID. When the PLMN1 AMF sends a request message (such as an authentication request) to the PLMN2 AUSF, it can carry the access token.

[0076] At the same time, the PLMN1 AMF will also carry the PLMN ID when sending a request message. In the scenario shown in Figure 1 , the request message sent by the PLMN1 AMF can carry the ID of PLMN1. When establishing an N32-f secure connection (generating an N32-f interface) between the PLMN1 security edge protection proxy (SEPP) and the PLMN2 SEPP, they can mutually verify the PLMN IDs of each other and save the PLMN ID corresponding to the N32-f secure connection (or N32-f interface) in the context.

[0077] As shown Figure 1 in the figure, the request message of the PLMN1 AMF can be first sent to the PLMN1 SEPP, and then sent by the PLMN1 SEPP to the PLMN2 SEPP through the N32-f interface; when the PLMN2 SEPP receives the message, it can verify whether the PLMN ID carried in the request message is consistent with the PLMN ID corresponding to the N32-f secure connection that receives the message. If the two are consistent (consistency means that the AMF claims in the request message that the PLMN it represents is the same as the PLMN where the message is originated), the PLMN2 SEPP will send the message to the PLMN2 AUSF; the PLMN2 AUSF verifies whether the PLMN ID in the access token carried in the request message is consistent with the PLMN ID carried in the request message. If they are consistent, the PLMN2 AUSF can verify that the AMF is the service network element corresponding to the PLMN ID authenticated by the PLMN2 NRF (that is, the PLMN1 AMF can serve the PLMN1). In this authentication process, the double verification based on the SEPP and the access token can ensure that the AMF can legally represent the PLMN it claims to be.

[0078] The above method can solve the problem of verifying the legality of the service network element of PLMN1 by PLMN2. However, there may still be a problem of network element forgery during the authentication process. For example, the UE requests to access PLMN3, but when the AMF sends a request message to the AUSF, it carries the identifier of PLMN1, that is, the request message sent by the AMF to the AUSF indicates that the UE requests to access PLMN1. The AMF is a legal service network element of PLMN1 but not a legal service network element of PLMN3. At this time, if the UE does not perform authentication, it will cause the UE to wrongly regard PLMN1 as PLMN3 and access it, thus causing risks.

[0079] In some embodiments, the non-access stratum (NAS) security key calculated by the AUSF and the UDM may include the PLMN ID, and the NAS security key calculated locally by the UE may also include the PLMN ID. In this way, the UE can authenticate the serving network when the NAS security mode is started, that is, when the UE finds that it cannot use the NAS security key calculated locally to decrypt / integrity verify the message, the UE can find an abnormality and thus can terminate the communication. However, the disadvantage of this method is that the UE cannot confirm whether the abnormality is caused by the deception behavior of the serving network, and the UE cannot determine the next action after the abnormality occurs.

[0080] Embodiments of this application can also be applied to a non - public network (NPN) scenario. For the NPN scenario, the interface between the NPN and the PLMN is similar to the interface between the PLMNs in Figure 1 (i.e., the PLMN1 in Figure 1 can be an NPN), and the method for verifying whether the AMF has the right to serve the NPN is also similar to the method for verifying whether the AMF has the right to serve the PLMN1 described above.

[0081] In embodiments of this application, the NPN can be a subnet. First, some concepts related to the subnet will be introduced below.

[0082] Subnet venue: Venues such as enterprises, campuses, and stadiums are called subnet venues.

[0083] Subnet tenant: The owner of the subnet venue.

[0084] Subnet user: Visitors to the subnet venue, or members or employees of the subnet venue, etc.

[0085] Subnet service: Services provided by the subnet tenant for the subnet users, such as extended reality (XR) games, in - venue augmented reality (AR) navigation, immersive conferences, etc.

[0086] Subnet: A network deployed for the subnet venue, used for subnet users to access and use the subnet services provided by the subnet venue.

[0087] Subnet operator: Deploys the subnet for the subnet tenant to provide access for the subnet users accessing the subnet venue.

[0088] In the subnet scenario, multiple subnets can share operator resources. Therefore, one PLMN may serve multiple subnets. For example, in Figure 2 , PLMN1 may have deployed an AMF that directly serves the PLMN1 large - network users (i.e., the direct - to - consumer (2C) users of PLMN1), and this AMF can be called the PLMN1 AMF; PLMN1 may also have deployed an AMF for Subnet 1, and this AMF serves Subnet 1, then this AMF can be called the Subnet 1 AMF; PLMN1 may also have deployed an AMF for Subnet 2, and this AMF serves Subnet 2, then this AMF can be called the Subnet 2 AMF. The above - mentioned Subnet 1 AMF, Subnet 2 AMF, and PLMN1 AMF can be independent logical network elements, or may also be network elements composed of any modules or devices (such as logical network elements), without limitation.

[0089] The above Figure 1The method for verifying whether an AMF is authorized to serve an NPN in an application scenario is applied to Figure 2 When the subnet scenario shown in

[0090] For example, in Figure 2 , PLMN1 AMF, Subnet 1 AMF, and Subnet 2 AMF can all communicate with PLMN2 AUSF through PLMN1 SEPP. However, the N32-f interface is only bound to PLMN1. After PLMN2 SEPP receives a message from PLMN1 SEPP, it cannot confirm whether the source AMF of the message received from the N32-f interface is authorized to serve the subnet it claims to serve. That is to say, in the subnet scenario, PLMN2 also cannot confirm whether the AMF is authorized to provide services to the subnet. Therefore, there is also a risk of network element forgery. To support dynamic subnet deployment, the service relationship between the AMF and the subnet is usually dynamic and difficult to maintain through static configuration. The existing fixed configuration mechanism cannot support the dynamic deployment of subnets.

[0091] At the same time, in the subnet scenario, the UE also cannot confirm whether the exception is caused by the deception behavior of the serving network, nor can it determine the next action after the exception occurs.

[0092] To solve one or more of the above technical problems, the present application proposes a communication method and a communication device, which can ensure that the first network element is authorized to serve the first subnet. When the terminal device requests to register to the first subnet through the first network element, it can avoid the terminal device accessing a fake network, thereby improving the security of the subnet scenario.

[0093] Next, in combination with Figure 3 and Figure 4 the application scenarios in the embodiments of the present application are introduced.

[0094] Figure 3 is a schematic block diagram of an application scenario in the embodiments of the present application. In Figure 3 , there may be a trust relationship between the authorization center of PLMN1 and the authorization center of PLMN2. Messages between the authorization center of PLMN1 and the authorization center of PLMN2 can be forwarded through PLMN1 SEPP and PLMN2 SEPP. The subnet AMF can communicate with PLMN2 SEPP through PLMN1 SEPP.

[0095] The PLMN1 authorization center can be used to verify the identity of the subnet AMF and verify the subnet information (such as the subnet list) served by the AMF; the PLMN1 authorization center can generate an access token, and the subnet identifier (list) of the subnet allowed to be served by the AMF can be carried in the access token; the PLMN1 authorization center signs the access token and sends it to the PLMN2 authorization center; the PLMN1 authorization center can receive the final access token from the PLMN2 authorization center and send it to the subnet AMF.

[0096] The PLMN2 authorization center can receive the access token from the PLMN1 authorization center and verify the signature of the PLMN1 authorization center; the PLMN2 authorization center can also add relevant information of PLMN2 (such as the service identifier of the AUSF allowed to be accessed, etc.) to the access token, sign the finally generated access token, and send it to the PLMN1 authorization center.

[0097] The operation and management system can be a network management system (for example, operation administration and maintenance (OAM)), or a network orchestration system (for example, management and network orchestration (MANO) or the application server (APP server) of the K8s system). When deploying the subnet, the information of the subnet served by the subnet AMF can be registered in the operation and management system, and this information can be used by the PLMN1 authorization center to verify the subnet information served by the subnet AMF. There can be an interface between the operation and management system and the authorization center so that the PLMN1 authorization center can verify the subnet information served by the subnet AMF.

[0098] Figure 4 It is a schematic block diagram of another application scenario in the embodiments of the present application. In Figure 4 there can be its own subnet authorization center for the subnet (that is, the subnet authorization center in Figure 4 ), which is responsible for managing the permissions of the subnet AMF.

[0099] When deploying the subnet, the information of the subnet served by the subnet AMF can be registered in the subnet operation and management system, and there can be an interface between the subnet operation and management system and the subnet authorization center so that the subnet authorization center can verify the subnet information served by the subnet AMF.

[0100] A trust relationship may exist between the subnet and PLMN1. For example, the Subnet Authorization Center and the PLMN1 Authorization Center can verify each other's certificates. Optionally, there may be no trust relationship between the subnet and PLMN2, and a trust relationship may exist between PLMN1 and PLMN2. For example, the message sent by the Subnet Authorization Center to the PLMN2 Authorization Center can be forwarded by the PLMN1 Authorization Center.

[0101] An N32-f secure connection can be established between the Subnet SEPP and the PLMN1 SEPP, and an N32-f secure connection can be established between the PLMN1 SEPP and the PLMN2 SEPP. Optionally, the message sent by the Subnet AMF to the PLMN2 AUSF can be forwarded by the PLMN1 SEPP.

[0102] The following Figure 5 gives a detailed example of the communication method in the embodiments of the present application.

[0103] Figure 5 is a schematic flowchart of the communication method provided by an embodiment of the present application. Figure 5 The method 500 shown may include steps S510 to S530, specifically as follows:

[0104] S510, a first network element sends a first request message to a first authorization center.

[0105] Among them, the first authorization center can be the authorization center of the first operator or the subnet authorization center. For example, the first operator can refer to Figure 3 PLMN1 in Figure 4 or PLMN1 in Figure 3 The first authorization center can be the PLMN1 authorization center in Figure 4 or the subnet authorization center in

[0106] The first network element can be the AMF. For example, the first network element can be the Figure 3 subnet AMF in Figure 4 or the subnet AMF in

[0107] Optionally, the first network element can serve the first subnet, or in other words, the first network element can be the service for the first subnet. Figure 3 In some embodiments, the first request message can be used to request authorization for the first network element to access the first service of the second operator on behalf of the first subnet. Among them, the second operator can refer to Figure 4 PLMN2 in

[0108] Optionally, the first request message can include the identification information of the first network element and the identification information of the first subnet.

[0109] Optionally, the first service may be an authentication service. Optionally, the first service may be an authentication service of a second operator, for example, an authentication service provided by a second network element or a third network element of the second operator. For example, the first service may be Figure 3 or Figure 4 the authentication service provided by PLMN2AUSF or PLMN2UDM in

[0110] Optionally, the first network element may serve multiple subnets. In this case, the first request message sent by the first network element may include a list of subnets served by the first network element (for example, the list of subnets may include multiple subnets served by the first network element), and the list of subnets may include a first subnet.

[0111] In some embodiments, before S510 above, method 500 may further include step S506, which is as follows:

[0112] S506, the terminal device sends a fifth request message to the first network element.

[0113] Wherein, the fifth request message may be used to request to register the terminal device to the first subnet. Optionally, the fifth request message may include identification information of the first subnet.

[0114] Optionally, the fifth request message may be sent to the first network element through an access network device (such as a base station).

[0115] Optionally, the first network element may obtain the identification information of the first subnet from the access network device, or the fifth request message may include the identification information of the first subnet.

[0116] Optionally, the first network element may send a first request message to the first authorization center when receiving the fifth request message. For example, in response to the fifth request message, the first network element may send a first request message to the first authorization center.

[0117] In some embodiments, before S510 above, the first network element itself may send a registration request to the first authorization center to request registration to the first authorization center. For example, before S510 above, method 500 may further include steps S501 and S502, which are as follows:

[0118] S501, the first network element sends a second request message to the first authorization center.

[0119] Wherein, the second request message may be used to request to register the first network element to the first authorization center.

[0120] For example, when deploying a subnet, a new subnet AMF instance can be created, or an AMF that has been deployed in the existing network can be configured as a subnet service. At this time, the AMF can send a second request message to the first authorization center (such as a subnet authorization center or a PLMN1 authorization center) by itself to request registering the AMF to the authorization center.

[0121] Optionally, after registering the first network element to the first authorization center, registration information of the first network element can be obtained.

[0122] Optionally, the second request message may include identification information of the first network element and identification information of at least one subnet, and the at least one subnet may include a first subnet. Optionally, the first network element can serve the at least one subnet.

[0123] S502, the first authorization center verifies whether the first network element has the right to serve the first subnet according to the second request message.

[0124] For example, the first authorization center or the certificate management center can pre-issue a certificate for the first network element. Among them, the signature information of the certificate can include a signature (such as by a certificate service center) of the identification information of the subnet served by the first network element; the first authorization center can verify whether the first network element has the right to serve the first subnet indicated by the second request message according to the certificate. Among them, the certificate management center can be Figure 3 the certificate management center of PLMN1, or Figure 4 the certificate management center of the subnet. Among them, the certificate issued for the first network element can be pre-configured in the first network element.

[0125] In some embodiments, before the above S510, the first network element can be registered to the first authorization center by other network devices (such as a fourth network element). For example, before the above S510, method 500 can further include steps S503 and S504, which are as follows:

[0126] S503, the fourth network element sends a third request message to the first authorization center.

[0127] Among them, the fourth network element can be an operation and management system. The operation and management system can be a network management system (such as OAM), or can also be a network orchestration system (such as MANO or the APP server of the K8s system). For example, the fourth network element can be Figure 3 the operation and management system in Figure 4 or can also be the subnet operation and management system in

[0128] The fourth network element can register the first network element with the first authorization center. For example, an operation and management system can send a third request message to the first authorization center (such as a subnet authorization center or a PLMN1 authorization center) according to trusted configuration information to request registering the AMF with the authorization center, where the configuration information can be manually configured and can include identification information of at least one subnet of the first network service, and the at least one subnet can include the first subnet. For another example, a network orchestration system can receive a subnet creation request requested manually, where the subnet creation request includes identification information of the subnet to be created. The network orchestration system can create a first network element for the subnet according to the subnet creation request and send a third request message to request registering the AMF with the authorization center, and the third request message includes identification information of the subnet served by the first network element.

[0129] Optionally, the third request message can be used to request registering the first network element with the first authorization center.

[0130] Optionally, the third request message can include identification information of the first network element and identification information of at least one subnet, the at least one subnet can include the first subnet, and the at least one subnet is served by the first network element.

[0131] S504. The first authorization center verifies whether the first network element has the right to serve the first subnet according to the third request message.

[0132] The first authorization center can trust the fourth network element. For example, the first authorization center can trust all messages from the fourth network element. Optionally, the first authorization center can verify whether the first network element has the right to serve the first subnet according to the third request message sent by the fourth network element. For example, the fourth network element can be an operation and management system, and the first authorization center verifies whether the first network element has the right to serve the first subnet according to the third request message sent by the fourth network element.

[0133] S520. The first authorization center verifies whether the first network element is allowed to serve the first subnet.

[0134] In some embodiments, the first authorization center can verify whether the first network element is allowed to serve the first subnet according to the registration information of the first network element (such as the registration information generated in the above steps S501 or S503).

[0135] In some embodiments, when verifying that the first network element is allowed to serve the first subnet, the first authorization center can send an authorization request to the second authorization center to request authorization for the first network element to access the first service of the second operator on behalf of the first subnet. For example, after the above S520, method 500 can further include step S522, which is specifically as follows:

[0136] S522, the first authorization center sends a fourth request message to the second authorization center.

[0137] Among them, the second authorization center may be the authorization center of the second operator. For example, the second authorization center may be the Figure 3 PLMN2 authorization center in Figure 4 or the PLMN2 authorization center in

[0138] The fourth request message may be used to request authorization for the first network element to represent the first subnet to access the first service of the second operator.

[0139] Optionally, the fourth request message may include second information and second signature information. Among them, the second information may include at least one of the following: identification information of the first network element, identification information of the first subnet. Optionally, the second signature information may be the signature of the first authorization center on the second information.

[0140] Optionally, the second information may further include identification information of the first service. Optionally, the second signature information may also include the signature of the first authorization center on the identification information of the first service, that is, the objects signed by the second signature information may include the identification information of the first network element, the identification information of the first subnet, and the identification information of the first service.

[0141] Optionally, when the first network element serves multiple subnets, the second information may include a subnet list served by the first network element, and the subnet list may include the first subnet, that is, the identification information of the first subnet may be included in the subnet list. At this time, the object signed by the second signature information may also include the subnet list.

[0142] In some embodiments, after receiving the fourth request message, the second authorization center may verify whether the first network element is allowed to serve the first subnet according to the second signature information (and / or the second information).

[0143] Optionally, there may be a trust relationship between the first authorization center and the second authorization center. For example, the first authorization center and the second authorization center may save each other's certificates, and the second authorization center may verify the second signature information based on the certificate. If the verification is successful, it may be determined that the first network element is allowed to serve the first subnet.

[0144] It should be noted that for the above Figure 4 application scenario, the first authorization center may be a subnet authorization center, the third authorization center may be the authorization center of the first operator, and the first authorization center may send the fourth request message to the second authorization center through the third authorization center.

[0145] Optionally, a trust relationship may exist between the first authorization center and the third authorization center, and a trust relationship may exist between the third authorization center and the second authorization center. For example, the first authorization center and the third authorization center may save each other's certificates. The third authorization center may verify the second signature information based on the certificate. If the verification is successful, it may be determined that the first network element is allowed to serve the first subnet. The third authorization center and the second authorization center may also save each other's certificates. The second authorization center may verify the third signature information based on the certificate. If the verification is successful, it may be determined that the first network element is allowed to serve the first subnet. Among them, the third signature information may be the signature of the third authorization center on the second information.

[0146] For example, the first authorization center may first send a fourth request message to the third authorization center. After receiving the fourth request message, the third authorization center may verify the second signature information. If the verification is successful, it may be determined that the first network element is allowed to serve the first subnet. At this time, the third authorization center may re-sign the second information to obtain the third signature information, replace the second signature information in the fourth request message with the third signature information, and then send the replaced fourth request message to the second authorization center.

[0147] At this time, the second authorization center (such as the PLMN2 authorization center) may verify whether the first network element is allowed to serve the first subnet according to the third signature information.

[0148] For example, taking Figure 4 as an example, the first authorization center may be a subnet authorization center, the third authorization center may be a PLMN1 authorization center, and the second authorization center is a PLMN2 authorization center. At this time, the subnet authorization center may first send a fourth request message to the PLMN1 authorization center. The PLMN1 authorization center may verify the second signature information and re-sign the first subnet identifier or subnet list and the identifier of the first network element with the certificate of the PLMN1 authorization center to obtain the third signature information. Then, the second signature information in the fourth request message is replaced with the third signature information, and then the PLMN1 authorization center sends the fourth request message (including the third signature information) to the PLMN2 authorization center.

[0149] Among them, the interface between the subnet authorization center and the PLMN1 authorization center is similar to the interface between the PLMN1 authorization center and the PLMN2 authorization center.

[0150] Optionally, when the second authorization center verifies that the first network element is allowed to serve the first subnet, the second authorization center may authorize the first service requested by the first network element, that is, determine to allow the first network element to access (or call) the first service of the second operator. Here, the second authorization center may determine to allow the first network element to access the first service of the second operator, or may also determine to allow the first service requested by all first operators (such as all network elements in the first operator).

[0151] Optionally, when authorizing the first service requested by the first network element, the second authorization center may also generate an access token.

[0152] Wherein, the access token may include first information and first signature information.

[0153] Optionally, the first information may include at least one of the following: identification information of the first service, identification information of the first subnet, and identification information of the first network element.

[0154] Optionally, the first signature information may be a signature of the first information. For example, the first signature information in the access token may be obtained by the second authorization center signing the first information.

[0155] In some embodiments, after generating the access token, the second authorization center may indicate to the first authorization center that it has authorized the first network element to access the first service. For example, after S522 above, method 500 may further include step S524, specifically as follows:

[0156] S524, the second authorization center sends a second message to the first authorization center.

[0157] Wherein, the second message may be used to indicate that the second authorization center authorizes the first network element to access the first service.

[0158] Optionally, the second message may include the access token generated by the second authorization center above.

[0159] In the embodiments of the present application, the fourth request message includes the signature of the second information by the first authorization center. The second authorization center receives the fourth request message and sends a second message carrying the access token to the first authorization center. In this way, through the dual verification of the first authorization center and the second authorization center, it can be ensured that the first network element has the right to serve the first subnet, and when the terminal device requests to register to the first subnet through the first network element, it can avoid the terminal device accessing a fake network, thereby improving the security of the subnet scenario.

[0160] Optionally, the access token carried by the second message may include a subnet list served by the first network element (such as the subnet list may include multiple subnets served by the first network element), and the subnet list may include the first subnet.

[0161] In S530, the first authorization center sends a first message to the first network element.

[0162] Wherein, the first message can be used to indicate authorizing the first network element to access the first service. Optionally, the first message may include an access token.

[0163] Optionally, the access token carried in the first message may include a subnet list served by the first network element (for example, the subnet list may include multiple subnets served by the first network element), and the subnet list may include the first subnet.

[0164] It should be noted that for the above Figure 4 application scenario, the PLMN1 authorization center may first send the first message to the subnet authorization center, and then the subnet authorization center sends the first message to the first network element.

[0165] In some embodiments, after the above S530, method 500 may further include step S531, specifically as follows:

[0166] S531, the first network element sends a sixth request message to the second network element.

[0167] Wherein, the second network element may be the AUSF of the second operator. For example, the second network element may be Figure 3 the PLMN2 AUSF in Figure 4 or the PLMN2 AUSF in

[0168] Optionally, the sixth request message can be used to request authentication of the terminal device that requests to register to the first subnet. For example, the terminal device that requests to register to the first subnet may be the terminal device that sends the fifth request message in the above S506.

[0169] Optionally, the sixth request message may include at least one of the following: identification information of the terminal device, identification information of the first subnet, access token.

[0170] Wherein, the identification information of the terminal device may be the subscription concealed identifier (SUCI) of the terminal device, and the access token may be the one received in the above S530.

[0171] Optionally, the access token carried in the sixth request message may include a subnet list served by the first network element (for example, the subnet list may include multiple subnets served by the first network element), and the subnet list may include the first subnet.

[0172] Optionally, the first authorization center may use the Hypertext Transfer Protocol (HTTP) to send a sixth request message to the second network element. Optionally, the message header of the sixth request message may carry the identification information of the first subnet.

[0173] For example, for the above Figure 3 application scenario, when establishing an N32-f secure connection between PLMN1 SEPP and PLMN2 SEPP, PLMN1 SEPP may indicate the identification information of the subnets it supports (including the first subnet) to PLMN2 SEPP. In S531, the first network element may first send the sixth request message to PLMN1 SEPP, and then PLMN1 SEPP sends it to PLMN2 SEPP. After receiving the sixth request message, PLMN2 SEPP may verify that the subnet identification in the message header of the sixth request message is a subnet supported by this N32-f interface; in the case of successful verification, PLMN2 SEPP may send the sixth request message to PLMN2 AUSF. It should be noted that in this method, the first network element may also include the identification of PLMN1 in the message header of the sixth request message. PLMN2 SEPP only verifies that the message comes from the trusted PLMN1, and whether to allow the first network element to access the first service on behalf of the first subnet is verified by the access token in the sixth request message. This can avoid the need to update the interfaces of PLMN1 SEPP and PLMN2 SEPP to add subnet information every time a subnet is added to PLMN1.

[0174] For example, for the above Figure 4 application scenario, when establishing an N32-f secure connection between the subnet SEPP and PLMN1 SEPP, the subnet SEPP may indicate the identification information of the subnets it supports (including the first subnet) to PLMN1 SEPP. In S531, the first network element may first send the sixth request message to the subnet SEPP, and then the subnet SEPP sends it to PLMN1 SEPP; after receiving the sixth request message, PLMN1 SEPP may verify that the subnet identification in the message header of the sixth request message is a subnet supported by this N32-f interface. In the case that this N32-f interface supports the first subnet, PLMN1 SEPP may replace the subnet identification in the message header of the sixth request message with the identification of PLMN1 and send the sixth request message to PLMN2 SEPP. In this way, after receiving the sixth request message, PLMN2 SEPP may verify the sixth request message according to whether the N32-f interface supports PLMN1; in the case of successful verification, PLMN2 SEPP may send the sixth request message to PLMN2 AUSF.

[0175] In an embodiment of the present application, a second network element receives a sixth request message from a first network element, verifies the first signature information in the sixth request message, and provides a first service to a terminal device when the verification of the first signature information is passed. In this way, it can be ensured that the first network element has the right to serve the first subnet, and when the terminal device requests to register to the first subnet through the first network element, it can avoid the terminal device accessing a fake network, thereby improving the security of the subnet scenario.

[0176] In some embodiments, after the above S530, method 500 may further include step S532, which is specifically as follows:

[0177] S532, the second network element verifies the first signature information.

[0178] Optionally, the second network element may use the public key of a second authorization center to verify the first signature information.

[0179] In some embodiments, when the verification of the first signature information is passed, the second network element may provide the first service to the terminal device; otherwise, the second network element may refuse to provide the first service to the terminal device. During this verification process, the second network element also verifies the legitimacy of the first network element serving the first subnet according to the first signature information. The verification is passed when the identification information of the first subnet included in the sixth request message is the same as the first subnet in the first signature information; otherwise, the verification fails. It should be noted here that in step S510, the first request message sent by the first network element may include a list of subnets served by the first network element, and this subnet list includes the first subnet. Correspondingly, the fourth request message sent by the first authorization center in S522 may also include the above subnet list. Correspondingly, the access token in S524 and S531 may also include this subnet list. In this case, when the second network element verifies that the first subnet identifier in the sixth request message is included in the subnet list in the access token, the verification is passed.

[0180] In some embodiments, when the second network element provides the first service to the terminal device, the second network element may obtain an authentication vector from a third network element according to the identification information of the first subnet. For example, after the above S530, method 500 may further include steps S533, S534, and S535, which are specifically as follows:

[0181] S533, the second network element sends a seventh request message to the third network element.

[0182] Among them, the third network element may be a UDM of a second operator. For example, the third network element may be Figure 3 the PLMN2UDM in Figure 4 or the PLMN2 UDM in

[0183] Optionally, the seventh request message can be used to obtain an authentication vector. Optionally, the seventh request message can include the identification information of the first subnet and the identification information of the terminal device.

[0184] Optionally, the seventh request message can further include first indication information, which can be used to indicate the third network element to send an authentication vector.

[0185] In the embodiment of the present application, the fifth message includes an authentication vector for the terminal device to authenticate the first subnet. The third network element sends the fifth message to the second network element, which helps the terminal device authenticate the subnet according to the authentication vector, and can prevent the terminal device from accessing a fake network, thereby helping to improve the security of the subnet scenario.

[0186] S534. The third network element generates an authentication vector.

[0187] In some embodiments, after receiving the seventh request message, the third network element can generate an authentication vector.

[0188] Among them, the authentication vector can be used for the terminal device to authenticate the first subnet. Optionally, the authentication vector can include a first field and a first random number. Among them, the first field can be determined according to the first key (i.e., K in the following formula), the first random number, and the identification information of the first subnet. The first key can be determined according to the shared key between the terminal device and the third network element.

[0189] For example, the calculation method of the first field can be as follows:

[0190] First field = F(K, RAND, subnet identification)

[0191] Among them, F() can be a security function. For example, F() can be SHA-256; K can be a key derived from the shared key between the terminal device and the third network element; RAND can be a random number. In this method, the subnet identification, the random number, and K are used as the input parameters of the security function, and the first field is the output of the security function.

[0192] The above formula can represent that the subnet identification, the random number RAND, and K are used as the input parameters of the security function F(), and the first field is the output of the security function F().

[0193] It should be noted that the authentication vector can further include other parameters (such as other parameters in the prior art), and the embodiments of the present application do not limit this.

[0194] S535. The third network element sends the fifth message to the second network element.

[0195] Among them, the fifth message can include the authentication vector generated in S534 above.

[0196] Optionally, when the first indication information is included in the seventh request message (the seventh request message received by the third network element in S533 above), the third network element may carry an authentication vector (such as the authentication vector generated in S534 above) in the fifth message according to the first indication information.

[0197] In some embodiments, after S535 above, method 500 may further include step S536, which is as follows:

[0198] S536, the second network element sends a third message to the first network element.

[0199] Wherein, the third message may include the authentication vector generated in S534 above.

[0200] In some embodiments, after S536 above, method 500 may further include step S537, which is as follows:

[0201] S537, the first network element sends a fourth message to the terminal device.

[0202] Wherein, the fourth message may include the authentication vector generated in S534 above.

[0203] In the embodiments of the present application, the fourth message includes an authentication vector for the terminal device to authenticate the first subnet. The terminal device receives the fourth message from the first network element and can authenticate the subnet according to the authentication vector, which can avoid the terminal device from accessing a fake network and thus improve the security of the subnet scenario.

[0204] In some embodiments, after S537 above, method 500 may further include step S538, which is as follows:

[0205] S538, the terminal device verifies the first subnet.

[0206] The terminal device may calculate a second field according to the first key, the first random number, and the identification information of the first subnet; if the second field is the same as the first field, it may access the first subnet; or, if the second field is different from the first field, it may stop accessing the first subnet.

[0207] For example, the terminal device may deduce the K value (i.e., the first key) according to the first key stored in the local subscriber identity module (SIM) card, and calculate the second field using the same security function F() and the received RAND (i.e., the first random number). If the second field is the same as the first field, the verification is successful and it may access the first subnet; otherwise, the verification fails, it may stop accessing the first subnet and stop sending messages to the first subnet, that is, no subsequent access attempt is made.

[0208] In some embodiments, in the case of successful verification, the subsequent process can continue. For example, after S538 above, method 500 may further include steps S539, S540, S541, and S542, specifically as follows:

[0209] S539, the terminal device sends a first authentication response message to the first network element.

[0210] The first authentication response message may indicate the verification result of the terminal device for the first subnet. For example, the terminal device successfully or fails to verify the first subnet.

[0211] S540, the first network element sends an authentication request message to the second network element.

[0212] The authentication request message may be used to request the second network element to authenticate the terminal device.

[0213] S541, the second network element authenticates the terminal device.

[0214] S542, the second network element sends a second authentication response message to the first network element.

[0215] The second authentication response message may indicate the authentication result of the second network element for the terminal device. For example, it may indicate that the second network element successfully or fails to authenticate the terminal device.

[0216] In the embodiments of the present application, in the case where the first network element requests to obtain authorization for the first network element to access the first service on behalf of the first subnet, the first authorization center verifies whether the first network element is allowed to serve the first subnet and sends a first message carrying an access token to the first network element. In this way, it can be ensured that the first network element has the right to serve the first subnet, and when the terminal device requests to register with the first subnet through the first network element, the terminal device can be prevented from accessing a fake network, thereby improving the security of the subnet scenario.

[0217] As described above in conjunction with Figure 5 , the method embodiments of the present application have been described in detail. Next, in conjunction with Figures 6 to 12 , the device embodiments of the present application will be described in detail. It should be understood that the descriptions of the method embodiments and the device embodiments correspond to each other. Therefore, for the parts not described in detail, reference can be made to the previous method embodiments.

[0218] Figure 6 FIG. is a schematic structural diagram of a communication device provided by an embodiment of the present application. The device 600 may be used to perform the actions or steps executed by the above-mentioned first authorization center. For example, the device 600 may be a first authorization center, a module (or device) in the first authorization center, or a chip in the first authorization center.

[0219] Such as Figure 6As shown, the device 600 includes a receiving unit 610, a verification unit 620, and a sending unit 630, specifically as follows:

[0220] The receiving unit 610 is configured to receive a first request message from a first network element. The first request message is used to request authorization for the first network element to access a first service of a second operator on behalf of a first subnet. The first network element serves the first subnet, and the first request message includes identification information of the first network element and identification information of the first subnet.

[0221] The verification unit 620 is configured to verify whether the first network element is allowed to serve the first subnet.

[0222] The sending unit 630 is configured to send a first message to the first network element. The first message is used to indicate authorization for the first network element to access the first service. The first message includes an access token, and the access token includes first information and first signature information. The first signature information is a signature of the first information, and the first information includes at least one of the following: identification information of the first service, identification information of the first subnet, and identification information of the first network element.

[0223] Figure 7 It is a schematic structural diagram of a communication device provided by an embodiment of the present application. The device 700 can be used to perform the actions or steps executed by the above-mentioned second authorization center. For example, the device 700 can be a second authorization center, a module (or device) in the second authorization center, or a chip in the second authorization center.

[0224] As Figure 7 shown, the device 700 includes a receiving unit 710 and a sending unit 720, specifically as follows:

[0225] The receiving unit 710 is configured to receive a fourth request message from a first authorization center. The first authorization center is an authorization center of a first operator or a subnet authorization center, and the fourth request message is used to request authorization for the first network element to access the first service of the second operator on behalf of the first subnet.

[0226] The sending unit 720 is configured to send a second message to the first authorization center. The second message is used to indicate that the second authorization center authorizes the first network element to access the first service. The second message includes an access token, and the access token includes first information and first signature information. The first signature information is a signature of the first information by the second authorization center, and the first information includes at least one of the following: identification information of the first service, identification information of the first subnet, and identification information of the first network element.

[0227] Figure 8It is a schematic structural diagram of a communication device provided by an embodiment of the present application. The device 800 can be used to perform the actions or steps executed by the above-mentioned first network element. For example, the device 800 can be a first network element, a module (or device) in the first network element, or a chip in the first network element.

[0228] As Figure 8 shown, the device 800 includes a sending unit 810 and a receiving unit 820, specifically as follows:

[0229] The sending unit 810 is configured to send a first request message to a first authorization center, where the first authorization center is an authorization center of a first operator or a subnet authorization center. The first request message is used to request authorization to access a first service of a second operator on behalf of a first subnet. The first network element serves the first subnet, and the first request message includes identification information of the first network element and identification information of the first subnet;

[0230] The receiving unit 820 is configured to receive a first message sent by the first authorization center. The first message is used to indicate authorization for the first network element to access the first service. The first message includes an access token, and the access token includes first information and first signature information. The first signature information is a signature of the first information, and the first information includes at least one of the following: identification information of the first service, identification information of the first subnet, and identification information of the first network element.

[0231] Figure 9 It is a schematic structural diagram of a communication device provided by an embodiment of the present application. The device 900 can be used to perform the actions or steps executed by the above-mentioned second network element. For example, the device 900 can be a second network element, a module (or device) in the second network element, or a chip in the second network element.

[0232] As Figure 9 shown, the device 900 includes a receiving unit 910, a verification unit 920, and a service unit 930, specifically as follows:

[0233] The receiving unit 910 is configured to receive a sixth request message from the first network element. The sixth request message is used to request to provide a first service for a terminal device that requests to register to a first subnet. The sixth request message includes at least one of the following: identification information of the terminal device, identification information of the first subnet, and an access token. The access token includes first information and first signature information. The first signature information is a signature of the first information by a second authorization center of a second operator to which the second network element belongs. The first information includes at least one of the following: identification information of the first subnet, identification information of the first network element, and identification information of the first service;

[0234] A verification unit 920, configured to verify the first signature information;

[0235] A service unit 930, configured to provide the first service for the terminal device when the verification of the first signature information is passed.

[0236] Figure 10 It is a schematic structural diagram of a communication device provided by an embodiment of the present application. The device 1000 may be used to perform the actions or steps executed by the above-mentioned third network element. For example, the device 1000 may be a third network element, a module (or device) in the third network element, or a chip in the third network element.

[0237] As Figure 10 shown, the device 1000 includes a receiving unit 1010 and a sending unit 1020, specifically as follows:

[0238] The receiving unit 1010 is configured to receive a seventh request message from a second network element, where the seventh request message is used to obtain an authentication vector, and the seventh request message includes identification information of a terminal device requesting to register to a first subnet and identification information of the first subnet;

[0239] The sending unit 1020 is configured to send a fifth message to the second network element, where the fifth message includes an authentication vector, and the authentication vector includes a first field and a first random number. The first field is determined according to a first key, the first random number, and the identification information of the first subnet, and the first key is determined according to a shared key between the terminal device and the third network element. The authentication vector is used for the terminal device to authenticate the first subnet.

[0240] Figure 11 It is a schematic structural diagram of a communication device provided by an embodiment of the present application. The device 1100 may be used to perform the actions or steps executed by the above-mentioned terminal device. For example, the device 1100 may be a terminal device, a module (or device) in the terminal device, or a chip in the terminal device.

[0241] As Figure 11 shown, the device 1100 includes a sending unit 1110 and a receiving unit 1120, specifically as follows:

[0242] The sending unit 1110 is configured to send a fifth request message to a first network element, where the fifth request message is used to request to register the terminal device to a first subnet;

[0243] A receiving unit 1120, configured to receive a fourth message from the first network element, where the fourth message includes an authentication vector, the authentication vector includes a first field and a first random number, the first field is determined according to a first key, the first random number, and identification information of the first subnet, the first key is determined according to a shared key between the terminal device and a second operator, and the authentication vector is used for the terminal device to authenticate the first subnet, and the second operator is the home operator of the terminal device.

[0244] Figure 12 It is a schematic structural diagram of a device provided in an embodiment of the present application. Figure 12 The dashed lines in it indicate that the unit or module is optional. The device 1200 can be used to implement the method described in the foregoing method embodiment. The device 1200 can be a chip or a communication device.

[0245] The device 1200 may include one or more processors 1210. The processor 1210 can support the device 1200 to implement the method described in the foregoing method embodiment. The processor 1210 can be a general-purpose processor or a dedicated processor. For example, the processor can be a central processing unit (CPU). Alternatively, the processor can also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc.

[0246] The device 1200 may further include one or more memories 1220. A program is stored on the memory 1220, and the program can be executed by the processor 1210, so that the processor 1210 executes the method described in the foregoing method embodiment. The memory 1220 can be independent of the processor 1210 or integrated in the processor 1210.

[0247] The device 1200 may further include a transceiver 1230. The processor 1210 can communicate with other devices or chips through the transceiver 1230. For example, the processor 1210 can send and receive data with other devices or chips through the transceiver 1230.

[0248] It should be noted that for the content such as information interaction and execution process between the above-mentioned devices / units, since it is based on the same concept as the method embodiments of this application, for its specific functions and the technical effects brought, reference can be specifically made to the method embodiment part, and details will not be repeated here.

[0249] Those skilled in the art can clearly understand that for the convenience and conciseness of description, only the above-mentioned division of each functional unit and module is used as an example. In actual applications, the above functions can be allocated to different functional units and modules according to needs, that is, the internal structure of the device is divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiment can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit. In addition, the specific names of each functional unit and module are only for the convenience of mutual distinction and do not limit the protection scope of this application. The specific working process of the units and modules in the above system can refer to the corresponding process in the foregoing method embodiments, and details will not be repeated here.

[0250] The embodiment of this application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program. When the computer program is executed by a computer, the computer is enabled to implement the steps in each of the above method embodiments.

[0251] The embodiment of this application provides a computer program product. When the computer program product runs on an electronic device (such as a server or a terminal device), the electronic device is enabled to implement the steps in each of the above method embodiments.

[0252] The embodiment of this application provides a chip. The chip includes a processor and a memory. The memory is used to store a computer program, and the processor is used to call and run the computer program stored in the memory, so that an electronic device (such as a server or a terminal device) installed with the chip executes the steps in each of the above method embodiments.

[0253] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, to implement all or part of the processes in the above-described embodiment methods of this application, a computer program can be used to instruct relevant hardware to complete. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above-described various method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable storage medium can at least include: any entity or device that can carry the computer program code to the device / electronic device, recording medium, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium. For example, a USB flash drive, a mobile hard disk, a magnetic disk, or an optical disc, etc. In some jurisdictions, according to legislation and patent practice, the computer-readable storage medium cannot be an electrical carrier signal and a telecommunication signal.

[0254] In the above embodiments, the descriptions of the various embodiments have their own emphases. For the parts not detailed or recorded in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0255] Those of ordinary skill in the art can realize that the units and algorithm steps of the examples described in conjunction with the embodiments disclosed in this article can be implemented by electronic hardware, or by a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of this application.

[0256] In the embodiments provided in this application, it should be understood that the disclosed device / electronic device and method can be implemented in other ways. For example, the device / electronic device embodiments described above are only illustrative. For example, the division of the modules or units is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the devices or units can be in an electrical, mechanical, or other form.

[0257] The unit described as a separation component may or may not be physically separated. The component shown as a unit may or may not be a physical unit, that is, it may be located in one place or may be distributed across multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0258] The above embodiments are only used to illustrate the technical solutions of the present application, rather than limiting them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the various embodiments of the present application, and should all be included within the protection scope of the present application.

Claims

1. A communication method is applied to a first authorization center, where the first authorization center is an authorization center of a first operator or a subnet authorization center, and is characterized in that Comprising: Receiving a first request message from a first network element, the first request message being used to request authorization for the first network element to access a first service of a second operator on behalf of a first subnet, the first network element serving the first subnet, the first request message including identification information of the first network element and identification information of the first subnet; Verifying whether the first network element is allowed to serve the first subnet; Sending a first message to the first network element, the first message being used to indicate authorization for the first network element to access the first service, the first message including an access token, the access token including first information and first signature information, the first signature information being a signature of the first information, the first information including at least one of the following: Identification information of the first service, identification information of the first subnet, identification information of the first network element.

2. The method according to claim 1, characterized in that, Before receiving the first request message from the first network element, the method further includes: Receiving a second request message from the first network element, the second request message being used to request registering the first network element to the first authorization center; verifying whether the first network element has the right to serve the first subnet according to the second request message; or, Receiving a third request message from a fourth network element, the third request message being used to request registering the first network element to the first authorization center; verifying whether the first network element has the right to serve the first subnet according to the third request message.

3. The method according to claim 2, wherein The second request message or the third request message includes identification information of the first network element and identification information of the at least one subnet, the at least one subnet including the first subnet.

4. The method according to any one of claims 1 to 3, characterized in that, The method further includes: Sending a fourth request message to a second authorization center of the second operator, the fourth request message being used to request authorization for the first network element to access the first service of the second operator on behalf of the first subnet.

5. The method according to claim 4, characterized in that The fourth request message includes second information and second signature information, the second signature information being a signature of the second information by the first authorization center, the second information including at least one of the following: Identification information of the first network element, identification information of the first subnet.

6. The method according to claim 4 or 5, characterized in that, After sending the fourth request message to the second authorization center of the second operator, the method further includes: Receiving a second message from the second authorization center, the second message being used to indicate that the second authorization center authorizes the first network element to access the first service.

7. The method according to claim 6, wherein The second message includes the access token, and the first signature information in the access token is obtained by the second authorization center signing the first information.

8. A communication method, applied to a second authorization center of a second operator, characterized in that, Comprising: Receiving a fourth request message from a first authorization center, the first authorization center being an authorization center or a subnet authorization center of a first operator, the fourth request message being used to request authorization for the first network element to access the first service of the second operator on behalf of a first subnet; Send a second message to the first authorization center, where the second message is used to instruct the second authorization center to authorize the first network element to access the first service. The second message includes an access token, and the access token includes first information and first signature information. The first signature information is the signature of the second authorization center on the first information. The first information includes at least one of the following: The identification information of the first service, the identification information of the first subnet, and the identification information of the first network element.

9. The method according to claim 8, wherein The fourth request message includes second information and second signature information. The second signature information is the signature of the first authorization center on the second information. The second information includes at least one of the following: the identification information of the first network element and the identification information of the first subnet.

10. A communication method, applied to a first network element, characterized in that, including: Send a first request message to the first authorization center. The first authorization center is the authorization center or subnet authorization center of the first operator. The first request message is used to request authorization to access the first service of the second operator on behalf of the first subnet. The first network element serves the first subnet. The first request message includes the identification information of the first network element and the identification information of the first subnet; Receive a first message sent by the first authorization center. The first message is used to instruct to authorize the first network element to access the first service. The first message includes an access token, and the access token includes first information and first signature information. The first signature information is the signature on the first information. The first information includes at least one of the following: The identification information of the first service, the identification information of the first subnet, and the identification information of the first network element.

11. The method according to claim 10, wherein Before sending the first request message to the first authorization center, the method further includes: Send a second request message to the first authorization center. The second request message is used to request to register the first network element to the first authorization center. The second request message includes the identification information of the first network element and the identification information of at least one subnet, and the at least one subnet includes the first subnet.

12. The method according to claim 10 or 11, characterized in that The method further includes: Receive a fifth request message from the terminal device. The fifth request message is used to request to register the terminal device to the first subnet; wherein, sending the first request message to the first authorization center includes: In response to the fifth request message, send the first request message to the first authorization center.

13. The method according to claim 12, characterized in that The fifth request message includes the identification information of the first subnet.

14. The method according to any one of claims 10 to 13, characterized in that, The first service is an authentication service, and the method further includes: Send a sixth request message to the second network element. The sixth request message is used to request to authenticate the terminal device that requests to register to the first subnet. The sixth request message includes at least one of the following: The identification information of the terminal device, the identification information of the first subnet, and the access token; Receive a third message from the second network element, where the third message includes an authentication vector, the authentication vector includes a first field and a first random number, the first field is determined according to a first key, the first random number, and the identification information of the first subnet, the first key is determined according to the shared key between the terminal device and the second operator, and the authentication vector is used for the terminal device to authenticate the first subnet; Send a fourth message to the terminal device, where the fourth message includes the authentication vector.

15. A communication method, applied to a second network element, characterized in that, Comprising: Receive a sixth request message from a first network element, where the sixth request message is used to request to provide a first service to a terminal device requesting to register to a first subnet, and the sixth request message includes at least one of the following: the identification information of the terminal device, the identification information of the first subnet, an access token, the access token includes first information and first signature information, and the first signature information is a signature of the first information by a second authorization center of a second operator to which the second network element belongs, and the first information includes at least one of the following: the identification information of the first subnet, the identification information of the first network element, the identification information of the first service; Verify the first signature information; Provide the first service to the terminal device when the verification of the first signature information passes.

16. The method according to claim 15, wherein The verifying the first signature information includes: Verify the first signature information using the public key of the second authorization center.

17. The method according to claim 15 or 16, characterized in that The first service is an authentication service, and the providing the first service to the terminal device when the verification of the first signature information passes includes: Send a seventh request message to a third network element, where the seventh request message is used to obtain an authentication vector, and the seventh request message includes the identification information of the first subnet and the identification information of the terminal device; Receive a fifth message from the third network element, where the fifth message includes an authentication vector, the authentication vector includes a first field and a first random number, the first field is determined according to a first key, the first random number, and the identification information of the first subnet, the first key is determined according to the shared key between the terminal device and the third network element, and the authentication vector is used for the terminal device to authenticate the first subnet.

18. The method according to claim 17, wherein The seventh request message includes first indication information, and the first indication information is used to instruct the third network element to send the authentication vector.

19. The method according to claim 17 or 18, characterized in that After receiving the fifth message from the third network element, the method further includes: Send a third message to the first network element, where the third message includes the authentication vector.

20. A communication method, applied to a third network element, characterized in that, Comprising: Receive a seventh request message from a second network element, where the seventh request message is used to obtain an authentication vector, and the seventh request message includes the identification information of a terminal device requesting to register to a first subnet and the identification information of the first subnet; Send a fifth message to the second network element, where the fifth message includes an authentication vector, the authentication vector includes a first field and a first random number, the first field is determined according to a first key, the first random number, and the identification information of the first subnet, the first key is determined according to the shared key between the terminal device and the third network element, and the authentication vector is used for the terminal device to authenticate the first subnet.

21. The method according to claim 20, wherein The seventh request message includes first indication information, and the first indication information is used to instruct the third network element to send the authentication vector. The method further includes: Carry the authentication vector in the fifth message according to the first indication information.

22. A communication method, applied to a terminal device, characterized in that Includes: Send a fifth request message to the first network element, where the fifth request message is used to request to register the terminal device to the first subnet; Receive a fourth message from the first network element, where the fourth message includes an authentication vector, the authentication vector includes a first field and a first random number, the first field is determined according to a first key, the first random number, and the identification information of the first subnet, the first key is determined according to the shared key between the terminal device and the second operator, and the authentication vector is used for the terminal device to authenticate the first subnet, and the second operator is the home operator of the terminal device.

23. The method according to claim 22, characterized in that, The method further includes: The terminal device calculates a second field according to the first key, the first random number, and the identification information of the first subnet; If the second field is the same as the first field, then access the first subnet; or, If the second field is different from the first field, then stop accessing the first subnet.

24. A communication device, characterized in that, Includes: A module or unit for executing the method according to any one of claims 1 to 23.

25. A communication device, characterized in that, Includes: A processor and a memory, the processor is coupled to the memory, the memory is used to store a computer program, and when the computer program is executed by the processor, the device is caused to execute the method according to any one of claims 1 to 23.

26. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, and when the computer program runs on a computer, the computer is caused to execute the method according to any one of claims 1 to 23.

27. A computer program product, characterized in that, Includes: A computer program, and when the computer program runs on a computer, the computer is caused to execute the method according to any one of claims 1 to 23.

28. A chip, characterized in that, Includes: A processor and a memory, the memory is used to store a computer program, and the processor is used to call and run the computer program stored in the memory, so that the device or equipment installed with the chip executes the method according to any one of claims 1 to 23.

Citation Information

Cited By

  • Access control method, device and system, electronic equipment and storage medium

    CN121510010A