Communication method and device
By providing attribute endorsement services for users and using blockchain and smart contracts to manage user attribute information, the problems of user identity security and data access control in the telecommunications network are solved, and higher security and reliability are achieved.
Patent Information
- Application Number
- CN202410071582.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-17
- Publication Date
- 2025-07-18
AI Technical Summary
The lack of attribute information of users in the telecommunications network leads to the inability to use third-party credibility to enhance identity security and the inability to support complex data access and authorization services.
By providing users with attribute endorsement services, allocating and managing attribute information, security enhancement and access control are achieved using blockchain technology and smart contracts.
It enhances the security of telecommunications network services, realizes the reliability of data access and authorization, and improves the credibility of user identity and service security.
Smart Images

Figure CN120342644A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communications, and in particular, to a communication method and apparatus. Background Art
[0002] In the services of a telecommunications network, the configuration file (profile) corresponding to a user identification (ID) is strongly related to the telecommunications network services, lacking the user's attribute information, and the user is also unable to apply for attribute information from the operator or to a third party through the operator's network. As a result, the user identity can only be used in the telecommunications network, leading to the inability of the telecommunications network to enhance the security of the user identity using the credibility of a third party. Summary of the Invention
[0003] This application provides a communication method and apparatus, which allocate attribute information for a user by providing an attribute endorsement service, and can perform access control on the user based on the attribute information, thereby enhancing the security of telecommunications network services and realizing data access and authorization.
[0004] To achieve the above object, this application adopts the following technical solutions:
[0005] In a first aspect, a communication method is provided. This method can be executed by a first node, or by a component of the first node, such as a processor, a chip, or a chip system of the first node, or can also be implemented by a logic module or software that can implement all or part of the first node. The method includes: obtaining attribute information and sending the attribute information to a second node, where the attribute information is used to indicate the attribute corresponding to the second node that has been certified.
[0006] Based on this communication method, the first node can distribute the attribute information corresponding to the second node to the second node, so that the second node obtains the attribute that has been certified or endorsed by the first node. Thus, the operator or a third-party institution (such as a university, an enterprise, a bank, a functional department, etc.) can use its credible characteristics to enhance the security of the identity of the second node, enhance the security of telecommunications network services, or facilitate the second node to execute related services, such as data access authorization. In the embodiments of this application, the first node can be a blockchain node or a node for providing attribute endorsement or certification services (such as the following fourth node).
[0007] In a possible design, obtaining the attribute information may include: receiving a first request from the second node. The first request is used to request to obtain an attribute. Sending the attribute information to the second node according to the first request. Based on this design, the first node can obtain the attribute information for the second node according to the trigger of the second node. In other words, the second node can actively apply to the first node for the corresponding certified attribute according to the need.
[0008] In a possible design solution, sending the attribute information to the second node according to the first request may include: generating the attribute information using a smart contract according to the first request, where the smart contract is associated with the attribute endorsement service. Sending the attribute information to the second node. In this design solution, the first node may be a blockchain node, and a smart contract related to the attribute endorsement service may be deployed thereon, so that the first node can generate the attribute information for the second node based on the deployed smart contract. Moreover, deploying the smart contract related to the attribute endorsement service on the blockchain can achieve attribute interoperability among nodes providing different attribute endorsement or proof services, different second nodes, and operator nodes, etc.
[0009] In a possible design solution, the communication method described in the first aspect may further include: receiving a fifth request from a fourth node, where the first request is used to request the installation of a smart contract. Installing the smart contract according to the fifth request. Here, the fourth node is a node for providing attribute endorsement or proof services. Thus, in the case where the first node is a blockchain node, the blockchain node can deploy the smart contract related to the attribute endorsement service according to the request of the fourth node.
[0010] In a possible design solution, installing the smart contract according to the first request may include: sending second information to the fourth node according to the fifth request, where the second information is used to indicate whether it supports the installation of the smart contract. Receiving third information from the fourth node, where the third information is used to indicate the installation of the smart contract, and the third information is determined according to the second information corresponding to at least one blockchain node on the blockchain. Thus, after receiving the smart contract installation request, the blockchain node can consensus the installation request to other blockchain nodes on the blockchain, and each blockchain node can feedback to the blockchain node the information on whether it can support the installation of the smart contract, so that the fourth node can indicate whether the blockchain node installs the smart contract according to whether each blockchain node can support the installation of the smart contract.
[0011] In a possible design solution, in the case where the result of whether it supports the installation of the smart contract is recorded on the blockchain by the first node, the second information may include the address on the blockchain of the result of whether it supports the installation of the smart contract. Thus, the blockchain nodes participating in the feedback of the second information can publish the second information they feedback on the blockchain, so as to facilitate other blockchain nodes to know the situation of whether they can support the installation of the smart contract.
[0012] In a possible design solution, the third information may include the result of whether at least one blockchain node on the blockchain supports the installation of the smart contract, and / or, the address on the blockchain of the result of whether at least one blockchain node supports the installation of the smart contract.
[0013] In a possible design solution, the communication method described in the first aspect may further include: receiving fourth information from a fourth node, where the fourth information is used to indicate usage information of a smart contract. Thus, after determining to install the smart contract, the blockchain node may also obtain the usage information of the smart contract from the fourth node, which can be understood as the configuration file corresponding to the smart contract, so that the blockchain node can complete the usage of the smart contract according to the usage information.
[0014] In a possible design solution, the fourth information may include at least one of the following: an attribute endorsement service corresponding to the smart contract, the address of the smart contract, the input parameters of the smart contract, the output parameters of the smart contract, or an application template for attribute information.
[0015] In a possible design solution, the communication method described in the first aspect may further include: sending attribute information to a blockchain node. Receiving first information from the blockchain node, where the first information is used to indicate the address of the attribute information on the blockchain. Based on this design solution, the first node may be a node for providing an attribute endorsement or certification service. Thus, after generating the attribute information, the first node may publish the attribute information on the blockchain so that other nodes can also obtain the corresponding attribute information from the blockchain. And the first node may store the address of the attribute information on the blockchain.
[0016] In a possible design solution, the first request may include at least one of the following: the identifier of the second node, information indicating the type of attribute requested to be obtained, the identity proof information corresponding to the second node, the signature of the third node on the identity proof information corresponding to the second node, or information indicating the content of the attribute requested to be obtained. In the embodiments of the present application, the third node may be a node for proving the identity of the second node, such as a device corresponding to a third-party authoritative institution.
[0017] In a possible design solution, the attribute information may include the attribute corresponding to the second node and the signature of the fourth node related to the attribute corresponding to the second node. Thus, the signed attribute of the second node is sent to the second node in the form of attribute information, so that the second node can obtain an attribute with credibility.
[0018] In a possible design solution, the attribute information may further include at least one of the following: the issuance time of the attribute, the validity period of the attribute, the identifier of the second node, or the signature of the blockchain node on the attribute corresponding to the second node.
[0019] In a possible design, the communication method described in the first aspect may further include: sending first information to a second node, where the first information is used to indicate the address of the attribute information on the blockchain. Thus, the first node may also send the address of its corresponding attribute information on the blockchain to the second node, so that the second node can query it or inform other nodes to query, to ensure the authenticity and legality of the attribute.
[0020] In a second aspect, a communication method is provided. This method may be executed by a second node, or by components of the second node, such as a processor, a chip, or a chip system of the second node, etc., and may also be implemented by a logic module or software that can implement all or part of the second node. The method includes: receiving attribute information from a first node, where the attribute information is used to indicate the attributes corresponding to the second node that have been certified. Determining the attributes corresponding to the second node according to the attribute information.
[0021] In a possible design, the attribute information may include the attributes corresponding to the second node and the signature of a fourth node related to the attributes corresponding to the second node.
[0022] In a possible design, the attribute information may further include at least one of the following: the issuance time of the attribute information, the validity period of the attribute information, the identifier of the second node, or the signature of the blockchain node on the attributes corresponding to the second node.
[0023] In a possible design, the communication method described in the second aspect may further include: receiving first information from a first node, where the first information is used to indicate the address of the attribute information on the blockchain.
[0024] In a possible design, the communication method described in the first aspect may further include: sending a first request to the first node, where the first request is used to request to obtain attributes.
[0025] In a third aspect, a communication method is provided. This method may be executed by a blockchain node, or by components of the blockchain node, such as a processor, a chip, or a chip system of the blockchain node, etc., and may also be implemented by a logic module or software that can implement all or part of the blockchain node. The method includes: receiving a fifth request from a fourth node, where the fifth request is used to request to install a smart contract corresponding to the attribute endorsement service supported by the fourth node. Installing the smart contract according to the fifth request.
[0026] In a possible design solution, installing a smart contract according to the fifth request may include: sending second information to a fourth node according to the fifth request, where the second information is used to indicate whether the installation of the smart contract is supported. Receiving third information from the fourth node, where the third information is used to indicate the installation of the smart contract, and the second information is determined according to the second information corresponding to at least one blockchain node on the blockchain.
[0027] In a possible design solution, in the case where the result of whether to support the installation of the smart contract is recorded on the blockchain by the blockchain node, the second information may include the address on the blockchain of the result of whether to support the installation of the smart contract.
[0028] In a possible design solution, the third information may include the result of whether to support the installation of the smart contract corresponding to at least one blockchain node on the blockchain, and / or the address on the blockchain of the result of whether to support the installation of the smart contract corresponding to at least one blockchain node.
[0029] In a possible design solution, the communication method described in the third aspect may further include: receiving fourth information from the fourth node, where the fourth information is used to indicate the usage information of the smart contract.
[0030] In a possible design solution, the fourth information may include at least one of the following: the attribute endorsement service corresponding to the smart contract, the address of the smart contract, the input parameters of the smart contract, the output parameters of the smart contract, or the application template of the attribute information.
[0031] In a fourth aspect, a communication method is provided. This method may be executed by a fourth node, or by components of the fourth node, such as the processor, chip, or chip system of the fourth node, and may also be implemented by a logic module or software that can implement all or part of the fourth node. The method includes: generating a fifth request and sending the fifth request to a blockchain node. The fifth request is used to request the installation of a smart contract corresponding to the attribute endorsement service supported by the fourth node.
[0032] In a possible design solution, the communication method described in the fourth aspect may further include: receiving second information from the blockchain node, where the second information is used to indicate whether the installation of the smart contract is supported. Sending third information to the blockchain node, where the third information is used to indicate the installation of the smart contract, and the third information is determined according to the second information corresponding to at least one blockchain node on the blockchain.
[0033] In a possible design solution, in the case where the result of whether to support the installation of the smart contract is recorded on the blockchain by the blockchain node, the second information may include the address on the blockchain of the result of whether to support the installation of the smart contract.
[0034] In a possible design, the third information may include the result of whether at least one blockchain node on the blockchain supports installing a smart contract, and / or the address on the blockchain of the result of whether at least one blockchain node supports installing a smart contract.
[0035] In a possible design, the communication method described in the fourth aspect may further include: sending fourth information to a blockchain node, where the fourth information is used to indicate usage information of a smart contract.
[0036] In a possible design, the fourth information may include at least one of the following: an attribute endorsement service corresponding to the smart contract, the address of the smart contract, the input parameters of the smart contract, the output parameters of the smart contract, or an application template for attribute information.
[0037] In a possible design, the communication method described in the fourth aspect may further include: receiving a first request from a second node. The first request is used to request to obtain an attribute. Sending attribute information to the second node according to the first request.
[0038] In a possible design, the attribute information may include an attribute corresponding to the second node and a signature of a fourth node related to the attribute corresponding to the second node.
[0039] In a possible design, the attribute information may further include at least one of the following: the issuance time of the attribute, the validity period of the attribute, the identifier of the second node, or a signature of the blockchain node on the attribute corresponding to the second node.
[0040] In a possible design, the communication method described in the fourth aspect may further include: receiving first information from a fourth node, where the first information is used to indicate the address of the attribute information on the blockchain.
[0041] Wherein, for the description of the technical effects of the method in any one of the second to fourth aspects above, reference may be made to the relevant description of the technical effects of the method in the first aspect above, and details are not described herein again.
[0042] Fifth aspect, a communication method is provided. This method may be executed by an operator node, or by components of an operator node, such as a processor, a chip, or a chip system of the operator node, etc., and may also be implemented by a logic module or software that can implement all or part of the operator node. The method includes: determining that a first terminal device and a second terminal device access a network corresponding to the operator node. In the case of determining that the first terminal device receives a call request from the second terminal device, sending an attribute corresponding to the second terminal device to the first terminal device.
[0043] Based on this communication method, the operator node can introduce the proven attributes of the user during the call between users. For example, the proven attributes of the calling user can be displayed on the incoming call interface of the user, so as to achieve the interoperability of credibility and enhance the security of the telecommunications network services.
[0044] In a possible design solution, the communication method described in the fifth aspect may further include: sending a sixth request to the blockchain node, where the sixth request is used to request to obtain the attributes corresponding to the second terminal device. Receiving the attribute information corresponding to the second terminal device from the blockchain node, where the attribute information corresponding to the second terminal device includes the attributes corresponding to the second terminal device and the signature of the fourth node related to the attributes corresponding to the second terminal device. Thus, the operator node can obtain the attribute information corresponding to the second terminal device from the blockchain to display the proven attributes of the second terminal device during the call.
[0045] In a possible design solution, the attribute information corresponding to the second terminal device may further include the identifier of the second terminal device and / or the signature of the blockchain node for the attributes corresponding to the second terminal device.
[0046] In the sixth aspect, a communication method is provided. This method can be executed by the fifth node, or by components of the fifth node, such as the processor, chip, or chip system of the fifth node, etc., and can also be implemented by a logic module or software that can implement all or part of the fifth node. The method includes: receiving a second request from the second node, where the second request is used to request access to the data of the fifth node, and the second request includes the attribute information corresponding to the second node. Determining whether the second node meets the requirement of accessing the data of the fifth node according to the attribute information corresponding to the second node and the proof information, where the proof information is used to verify the attributes corresponding to the second node.
[0047] Based on this communication method, the fifth node can perform data access control on the second node according to the attribute information of the second node, so as to improve the reliability and security of data access, and further enhance the security of the service.
[0048] In a possible design solution, the second request may further include the address of the attribute information corresponding to the second node on the blockchain. Thus, the fifth node can query the corresponding attribute information and / or proof information from the blockchain based on this address to prove the attributes corresponding to the second node and ensure the authenticity and legality of the attributes.
[0049] In a possible design solution, the communication method described in the sixth aspect may further include: sending a third request to the blockchain node, where the third request is used to request to obtain the proof information. Receiving the proof information from the blockchain node.
[0050] In a possible design solution, the proof information may include the credential information of the fourth node related to the attribute corresponding to the second node. For example, the certificate of the fourth node related to the attribute corresponding to the second node.
[0051] In a possible design solution, the proof information may further include: the hash of the attribute corresponding to the second node, and / or the attribute corresponding to the second node.
[0052] In a possible design solution, receiving the second request from the second node may include: receiving the identification information from the second node, where the identification information includes the identification of the second node and the signature of the fourth node related to the identification of the second node. When the identification of the second node is verified, it is determined to establish a secure authentication with the second node. When the secure authentication is completed, the second request from the second node is received. Thus, the fifth node and the second node can perform secure authentication based on the identification of the second node. Only when the secure authentication passes can a secure connection be established between the fifth node and the second node for message or information interaction.
[0053] In a possible design solution, the communication method described in the sixth aspect may further include: sending information for data access to the blockchain node, where the information for data access includes information for indicating the requirements that the second node needs to meet for accessing the data of the fifth node and information for indicating obtaining the data of the fifth node. Based on this design solution, the fifth node can publish the information related to its accessed data on the blockchain for the second node to obtain, so as to achieve data access.
[0054] In a possible design solution, the communication method described in the sixth aspect may further include: when the second node meets the requirements for accessing the data of the fifth node, sending a first key to the second node, where the first key is determined according to the attribute corresponding to the second node, and the first key is used to decrypt the encrypted data of the fifth node. Based on this design solution, after the fifth node encrypts and stores its data, when it is determined that the second node meets the data access requirements, the fifth node can also send a key to the second node to facilitate the second node to decrypt the encrypted data.
[0055] In a possible design solution, the information for indicating obtaining the data of the fifth node may include the storage address where the encrypted data of the fifth node is located, and / or the information for indicating the encrypted data of the fifth node.
[0056] In a possible design solution, the data of the fifth node may be encrypted by a second key, and the information for indicating obtaining the data of the fifth node may further include: the encrypted second key, and the first key is specifically used to decrypt the encrypted second key.
[0057] In a possible design solution, the communication method described in the sixth aspect may further include: sending the data of the fifth node that has been encrypted to the storage node corresponding to the storage address. Thus, the fifth node stores its encrypted data in the storage node uniformly. Compared with the fifth node separately sending encrypted data to multiple second nodes, the signaling overhead is reduced.
[0058] In a possible design solution, the communication method described in the sixth aspect may further include: sending information for indicating the access record of the second node to the blockchain node. Thus, the fifth node can also record the access information of the second node and publish it on the blockchain to facilitate querying and learning about the access situation of the second node.
[0059] In a possible design solution, the attribute information corresponding to the second node may include the attribute corresponding to the second node and the signature of the fourth node associated with the attribute corresponding to the second node.
[0060] In the seventh aspect, a communication method is provided. This method can be executed by the second node, or by components of the second node, such as the processor, chip, or chip system of the second node, etc., and can also be implemented by a logic module or software that can implement all or part of the second node. The method includes: generating a second request and sending the second request to the fifth node. The second request is used to request access to the data of the fifth node, and the second request includes the attribute information corresponding to the second node.
[0061] In a possible design solution, the second request may further include the address of the attribute information corresponding to the second node on the blockchain.
[0062] In a possible design solution, sending the second request to the fifth node may include: establishing a security authentication with the fifth node according to the identifier of the second node. After the security authentication is completed, send the second request to the fifth node.
[0063] In a possible design solution, the communication method described in the seventh aspect may further include: receiving a first key from the fifth node, where the first key is determined according to the attribute corresponding to the second node, and the first key is used to decrypt the data of the fifth node that has been encrypted.
[0064] In a possible design solution, the communication method described in the seventh aspect may further include: sending a fourth request to the blockchain node, where the fourth request is used to request information for accessing the data of the fifth node. Receiving the information for data access from the blockchain node, the information for data access includes information for indicating the requirements that need to be met for the second node to access the data of the fifth node and information for indicating obtaining the data of the fifth node. Obtaining the encrypted data of the fifth node according to the information for data access. Decrypting the encrypted data of the fifth node according to the first key.
[0065] In a possible design, the information for indicating obtaining the data of the fifth node may include the storage address where the encrypted data of the fifth node is located, and / or the information for indicating the encrypted data of the fifth node.
[0066] In a possible design, the data of the fifth node may be encrypted with a second key, and the information for indicating obtaining the data of the fifth node may further include: the encrypted second key, and the first key is specifically used to decrypt the encrypted second key.
[0067] In a possible design, obtaining the encrypted data of the fifth node according to the information for data access may include: sending a seventh request to the storage node corresponding to the storage address, where the seventh request is used to request obtaining the data of the fifth node. Receiving the encrypted data of the fifth node from the storage node.
[0068] In a possible design, decrypting the encrypted data of the fifth node according to the first key may include: decrypting the encrypted second key according to the first key. Decrypting the data of the fifth node encrypted with the second key according to the second key.
[0069] In a possible design, the attribute information corresponding to the second node may include the attribute corresponding to the second node and the signature of the fourth node associated with the attribute corresponding to the second node.
[0070] In an eighth aspect, a communication method is provided. This method may be executed by a blockchain node, or by components of a blockchain node, such as a processor, a chip, or a chip system of a blockchain node, etc., and may also be implemented by a logic module or software that can implement all or part of the blockchain node. The method includes: receiving a fourth request from a second node, where the fourth request is used to request obtaining the information for accessing the data of a fifth node. Sending the information for data access to the second node, and the information for data access includes the information for indicating the requirements that need to be met for the second node to access the data of the fifth node and the information for indicating obtaining the data of the fifth node.
[0071] In a possible design, the communication method described in the eighth aspect may further include: receiving the information for data access from the fifth node.
[0072] In a possible design, the information for indicating obtaining the data of the fifth node may include the storage address where the encrypted data of the fifth node is located, and / or the information for indicating the encrypted data of the fifth node.
[0073] In a possible design solution, the data of the fifth node can be encrypted with a second key, and the information for indicating obtaining the data of the fifth node can further include: the encrypted second key.
[0074] In a possible design solution, the communication method described in the eighth aspect can further include: receiving information from the fifth node for indicating the access record of the second node.
[0075] Among them, for the technical effects of the method described in the seventh aspect or the eighth aspect, reference can be made to the relevant description of the technical effects of the method described in the sixth aspect above, and details are not repeated here.
[0076] In a ninth aspect, a communication method is provided. This method can be executed by a blockchain node, or by components of a blockchain node, such as a processor, a chip, or a chip system of the blockchain node, etc., and can also be implemented by a logic module or software that can implement all or part of the blockchain node. The method includes: receiving an eighth request from a second node, where the eighth request is used to request to invoke a first smart contract, and the first smart contract is used to determine whether the second node can access the data of the fifth node. Determine whether the second node can access the data of the fifth node according to the eighth request and the first smart contract.
[0077] Based on this communication method, the blockchain node can invoke the smart contract according to the request of the second node to perform data access control on the second node, thereby improving the reliability and security of data access, and further enhancing the security of the service. Among them, the implementation process of the blockchain node deploying the first smart contract can refer to the relevant implementation in the method described in the third aspect above, and details are not repeated here.
[0078] In a possible design solution, the eighth request can include attribute information corresponding to the second node.
[0079] In a possible design solution, the attribute information corresponding to the second node can include the attribute corresponding to the second node and the signature of the fourth node related to the attribute corresponding to the second node.
[0080] In a possible design solution, the communication method described in the ninth aspect can further include: when the second node can access the data of the fifth node, sending a first key to the second node, and the first key is used to decrypt the encrypted data of the fifth node.
[0081] In a possible design solution, the communication method described in the ninth aspect can further include: receiving information for data access from the fifth node, and the information for data access includes information for indicating requirements that the second node needs to meet to access the data of the fifth node and information for indicating obtaining the data of the fifth node.
[0082] In a possible design, the communication method described in the ninth aspect may further include: receiving a fourth request from a second node, where the fourth request is used to request information for accessing data of a fifth node. Sending information for data access to the second node.
[0083] In a possible design, the information for indicating obtaining data of a fifth node may include the storage address where the data of the fifth node after encryption is located, and / or information for indicating the data of the fifth node after encryption.
[0084] In a possible design, the data of the fifth node is encrypted by a second key, and the information for indicating obtaining data of the fifth node may further include: the second key after encryption.
[0085] In a possible design, the communication method described in the ninth aspect may further include: generating and recording the access situation of the fifth node when the second node can access the data of the fifth node.
[0086] In the tenth aspect, a communication method is provided. This method may be executed by a second node, or by components of the second node, such as a processor, a chip, or a chip system of the second node, etc., and may also be implemented by a logic module or software that can implement all or part of the second node. The method includes: generating an eighth request and sending the eighth request to a blockchain node. The eighth request is used to request to invoke a first smart contract, and the first smart contract is used to determine whether the second node can access the data of the fifth node.
[0087] In a possible design, the eighth request may include attribute information corresponding to the second node.
[0088] In a possible design, the attribute information corresponding to the second node may include the attribute corresponding to the second node and the signature of a fourth node related to the attribute corresponding to the second node.
[0089] In a possible design, the communication method described in the tenth aspect may further include: receiving a first key from the blockchain node, and the first key is used to decrypt the data of the fifth node after encryption.
[0090] In a possible design, the communication method described in the tenth aspect may further include: sending a fourth request to the blockchain node, where the fourth request is used to request information for accessing data of a fifth node. Receiving information for data access from the blockchain node, and the information for data access includes information for indicating requirements that the second node needs to meet to access the data of the fifth node and information for indicating obtaining data of the fifth node. Obtaining the data of the fifth node after encryption according to the information for data access. Decrypting the data of the fifth node after encryption according to the first key.
[0091] In a possible design, the information for indicating to obtain the data of the fifth node may include the storage address where the encrypted data of the fifth node is located, and / or the information for indicating the encrypted data of the fifth node.
[0092] In a possible design, the data of the fifth node is encrypted with a second key, and the information for indicating to obtain the data of the fifth node may further include: the encrypted second key.
[0093] In a possible design, obtaining the encrypted data of the fifth node according to the information for data access may include: sending a seventh request to the storage node corresponding to the storage address, where the seventh request is used to request to obtain the data of the fifth node. Receiving the encrypted data of the fifth node from the storage node.
[0094] In a possible design, decrypting the encrypted data of the fifth node according to the first key may include: decrypting the encrypted second key according to the first key. Decrypting the data of the fifth node encrypted with the second key according to the second key.
[0095] Wherein, for the technical effects of the method described in the ninth aspect or the tenth aspect, reference may be made to the relevant description of the technical effects of the method described in the sixth aspect above, and details are not repeated here.
[0096] In the eleventh aspect, a communication device is provided for implementing the above various methods. The communication device may be the first node in the first aspect above, or a device including the first node above, or a device included in the first node above, such as a chip. The communication device includes corresponding modules, units, or means for implementing the method described in the first aspect above, and the module, unit, or means may be implemented by hardware, software, or by hardware executing corresponding software. The hardware or software includes one or more modules or units corresponding to the above functions.
[0097] In some possible designs, the communication device includes: a processing module and a transceiver module. Wherein, the processing module is used to obtain attribute information. The transceiver module is used to send the attribute information to the second node, where the attribute information is used to indicate the attributes corresponding to the authenticated second node.
[0098] In a possible design, the processing module for obtaining attribute information may include: the processing module for controlling the transceiver module to receive a first request from the second node. Where the first request is used to request to obtain attributes. The processing module for controlling the transceiver module to send the attribute information to the second node according to the first request.
[0099] In a possible design solution, a processing module is used to control a transceiver module to send attribute information to a second node according to a first request, and may include: a processing module for generating attribute information using a smart contract according to the first request, and the smart contract is associated with an attribute endorsement service. A processing module for controlling the transceiver module to send the attribute information to the second node.
[0100] In a possible design solution, the transceiver module is further configured to receive a fifth request from a fourth node, and the fifth request is used to request the installation of a smart contract. The processing module is further configured to install the smart contract according to the fifth request.
[0101] In a possible design solution, the processing module is further configured to install the smart contract according to the fifth request, and may include: a processing module for controlling the transceiver module to send a second message to a first node according to the fifth request, where the second message is used to indicate whether the installation of the smart contract is supported. A processing module for controlling the transceiver module to receive a third message from the fourth node, where the third message is used to indicate the installation of the smart contract, and the third message is determined according to the second messages corresponding to at least one blockchain node on the blockchain.
[0102] In a possible design solution, when the result of whether the installation of the smart contract is supported is recorded on the blockchain by the first node, the second message may include the address on the blockchain of the result of whether the installation of the smart contract is supported.
[0103] In a possible design solution, the third message may include the results of whether the installation of the smart contract is supported corresponding to at least one blockchain node on the blockchain, and / or the addresses on the blockchain of the results of whether the installation of the smart contract is supported corresponding to at least one blockchain node.
[0104] In a possible design solution, the transceiver module is further configured to receive a fourth message from the first node, where the fourth message is used to indicate the usage information of the smart contract.
[0105] In a possible design solution, the fourth message may include at least one of the following: the attribute endorsement service corresponding to the smart contract, the address of the smart contract, the input parameters of the smart contract, the output parameters of the smart contract, or the application template of the attribute information.
[0106] In a possible design solution, the transceiver module is further configured to send attribute information to a blockchain node. The transceiver module is further configured to receive a first message from the blockchain node, where the first message is used to indicate the address of the attribute information on the blockchain.
[0107] In a possible design solution, the first request may include at least one of the following: the identifier of the second node, information indicating the type of the attribute to be requested, the identity proof information corresponding to the second node, or the signature of the third node on the identity proof information corresponding to the second node.
[0108] In a possible design solution, the attribute information may include the attribute corresponding to the second node and the signature of the fourth node related to the attribute corresponding to the second node.
[0109] In a possible design solution, the attribute information may further include at least one of the following: the issuance time of the attribute, the validity period of the attribute, the identifier of the second node, or the signature of the blockchain node on the attribute corresponding to the second node.
[0110] In a possible design solution, the transceiver module is further configured to send first information to the second node, where the first information is used to indicate the address of the attribute information on the blockchain.
[0111] In a possible design solution, the transceiver module may include a receiving module and a sending module. Wherein, the sending module is used to implement the sending function of the communication device described in the eleventh aspect, and the receiving module is used to implement the receiving function of the communication device described in the eleventh aspect.
[0112] In a possible design solution, the communication device described in the eleventh aspect may further include a storage module, and the storage module stores programs or instructions. When the processing module executes the programs or instructions, the communication device described in the eleventh aspect can execute the method described in the first aspect.
[0113] In the twelfth aspect, a communication device is provided for implementing the above various methods. The communication device may be the second node in the second aspect above, or a device including the second node above, or a device included in the second node above, such as a chip. The communication device includes corresponding modules, units, or means for implementing the method described in the second aspect above, and the module, unit, or means may be implemented by hardware, software, or by hardware executing corresponding software. The hardware or software includes one or more modules or units corresponding to the above functions.
[0114] In some possible designs, the communication device includes: a processing module and a transceiver module. Wherein, the transceiver module is used to receive attribute information from the first node, and the attribute information is used to indicate the attribute corresponding to the second node that has been authenticated. The processing module is used to determine the attribute corresponding to the second node according to the attribute information.
[0115] In a possible design solution, the attribute information may include the attribute corresponding to the second node and the signature of the fourth node related to the attribute corresponding to the second node.
[0116] In a possible design, the attribute information may further include at least one of the following: the issuance time of the attribute, the validity period of the attribute, the identifier of the second node, or the signature of the blockchain node on the attribute corresponding to the second node.
[0117] In a possible design, the transceiver module is further configured to receive first information from the first node, where the first information is used to indicate the address of the attribute information on the blockchain.
[0118] In a possible design, the transceiver module is further configured to send a first request to the first node, where the first request is used to request to obtain an attribute.
[0119] In a possible design, the transceiver module may include a receiving module and a sending module. Wherein, the sending module is used to implement the sending function of the communication device described in the twelfth aspect, and the receiving module is used to implement the receiving function of the communication device described in the twelfth aspect.
[0120] In a possible design, the communication device described in the twelfth aspect may further include a storage module, and the storage module stores programs or instructions. When the processing module executes the programs or instructions, the communication device described in the twelfth aspect can execute the method described in the second aspect.
[0121] In a thirteenth aspect, a communication device is provided for implementing the above various methods. The communication device may be the blockchain node in the third aspect above, or a device including the above blockchain node, or a device included in the above blockchain node, such as a chip. The communication device includes corresponding modules, units, or means for implementing the method described in the third aspect above, and the module, unit, or means may be implemented by hardware, software, or by hardware executing corresponding software. The hardware or software includes one or more modules or units corresponding to the above functions.
[0122] In some possible designs, the communication device includes: a processing module and a transceiver module. Wherein, the transceiver module is used to receive a fifth request from the fourth node, where the fifth request is used to request to install a smart contract corresponding to the attribute endorsement service supported by the fourth node. The processing module is used to install the smart contract according to the fifth request.
[0123] In a possible design solution, the processing module, which is used to install a smart contract according to a fifth request, may include: a processing module for controlling the transceiver module to send second information to a fourth node according to the fifth request, where the second information is used to indicate whether the installation of the smart contract is supported. A processing module for controlling the transceiver module to receive third information from the fourth node, where the third information is used to indicate the installation of the smart contract, and the third information is determined according to the second information corresponding to at least one blockchain node on the blockchain.
[0124] In a possible design solution, when the result of whether the installation of the smart contract is supported is recorded on the blockchain by a blockchain node, the second information may include the address on the blockchain of the result of whether the installation of the smart contract is supported.
[0125] In a possible design solution, the third information may include the result of whether the installation of the smart contract is supported corresponding to at least one blockchain node on the blockchain, and / or the address on the blockchain of the result of whether the installation of the smart contract is supported corresponding to at least one blockchain node.
[0126] In a possible design solution, the transceiver module is further configured to receive fourth information from a first node, where the fourth information is used to indicate the usage information of the smart contract.
[0127] In a possible design solution, the fourth information may include at least one of the following: an attribute endorsement service corresponding to the smart contract, the address of the smart contract, the input parameters of the smart contract, the output parameters of the smart contract, or an application template for attribute information.
[0128] In a possible design solution, the transceiver module may include a receiving module and a sending module. The sending module is used to implement the sending function of the communication device described in the thirteenth aspect, and the receiving module is used to implement the receiving function of the communication device described in the thirteenth aspect.
[0129] In a possible design solution, the communication device described in the thirteenth aspect may further include a storage module that stores programs or instructions. When the processing module executes the programs or instructions, the communication device described in the thirteenth aspect can execute the method described in the third aspect.
[0130] In a fourteenth aspect, a communication device is provided for implementing the above various methods. The communication device may be the fourth node in the above fourth aspect, or a device including the above fourth node, or a device included in the above fourth node, such as a chip. The communication device includes corresponding modules, units, or means for implementing the method described in the above fourth aspect. The module, unit, or means may be implemented by hardware, software, or by hardware executing corresponding software. The hardware or software includes one or more modules or units corresponding to the above functions.
[0131] In some possible designs, the communication device includes: a processing module and a transceiver module. Among them, the processing module is used to generate a fifth request. The fifth request is used to request the installation of a smart contract corresponding to the attribute endorsement service supported by the fourth node. The transceiver module is used to send the fifth request to the blockchain node.
[0132] In a possible design, the transceiver module is further used to receive second information from the blockchain node, where the second information is used to indicate whether the installation of the smart contract is supported. The transceiver module is further used to send third information to the blockchain node, where the third information is used to indicate the installation of the smart contract, and the third information is determined according to the second information corresponding to at least one blockchain node on the blockchain.
[0133] In a possible design, in the case where the result of whether the installation of the smart contract is supported is recorded on the blockchain by the blockchain node, the second information may include the address on the blockchain of the result of whether the installation of the smart contract is supported.
[0134] In a possible design, the third information may include the result of whether the installation of the smart contract is supported corresponding to at least one blockchain node on the blockchain, and / or the address on the blockchain of the result of whether the installation of the smart contract is supported corresponding to at least one blockchain node.
[0135] In a possible design, the transceiver module is further used to send fourth information to the blockchain node, where the fourth information is used to indicate the usage information of the smart contract.
[0136] In a possible design, the fourth information may include at least one of the following: the attribute endorsement service corresponding to the smart contract, the address of the smart contract, the input parameters of the smart contract, or the output parameters of the smart contract.
[0137] In a possible design, the transceiver module is further used to receive a first request from the second node. The first request is used to request to obtain an attribute. The transceiver module is further used to send attribute information to the second node according to the first request.
[0138] In a possible design, the attribute information may include the attributes corresponding to the second node and the signature of the fourth node related to the attributes corresponding to the second node.
[0139] In a possible design, the attribute information may further include at least one of the following: the issuance time of the attribute, the validity period of the attribute, the identifier of the second node, or the signature of the blockchain node on the attributes corresponding to the second node.
[0140] In a possible design, the transceiver module is further configured to receive first information from the fourth node, where the first information is used to indicate the address of the attribute information on the blockchain.
[0141] In a possible design, the transceiver module may include a receiving module and a sending module. Among them, the sending module is used to implement the sending function of the communication device described in the fourteenth aspect, and the receiving module is used to implement the receiving function of the communication device described in the fourteenth aspect.
[0142] In a possible design, the communication device described in the fourteenth aspect may further include a storage module, and the storage module stores programs or instructions. When the processing module executes the programs or instructions, the communication device described in the fourteenth aspect can execute the method described in the fourth aspect.
[0143] In the fifteenth aspect, a communication device is provided for implementing the above various methods. The communication device may be the operator node in the fifth aspect above, or a device including the above operator node, or a device included in the above operator node, such as a chip. The communication device includes corresponding modules, units, or means for implementing the method described in the fifth aspect above, and the modules, units, or means may be implemented by hardware, software, or by hardware executing corresponding software. The hardware or software includes one or more modules or units corresponding to the above functions.
[0144] In some possible designs, the communication device includes: a processing module and a transceiver module. Among them, the processing module is used to determine that the first terminal device and the second terminal device access the network corresponding to the operator node. When it is determined that the first terminal device receives a call request from the second terminal device, the transceiver module is used to send the attributes corresponding to the second terminal device to the first terminal device.
[0145] In a possible design, the transceiver module is further configured to send a sixth request to the blockchain node, where the sixth request is used to request to obtain the attributes corresponding to the second terminal device. The transceiver module is further configured to receive the attribute information corresponding to the second terminal device from the blockchain node, and the attribute information corresponding to the second terminal device includes the attributes corresponding to the second terminal device and the signature of the fourth node related to the attributes corresponding to the second terminal device.
[0146] In a possible design, the attribute information corresponding to the second terminal device may further include the identifier of the second terminal device and / or the signature of the blockchain node on the attributes corresponding to the second terminal device.
[0147] In a possible design, the transceiver module may include a receiving module and a transmitting module. Among them, the transmitting module is used to implement the transmitting function of the communication device described in the fifteenth aspect, and the receiving module is used to implement the receiving function of the communication device described in the fifteenth aspect.
[0148] In a possible design, the communication device described in the fifteenth aspect may further include a storage module that stores programs or instructions. When the processing module executes the programs or instructions, the communication device described in the fifteenth aspect can execute the method described in the fifth aspect.
[0149] In the sixteenth aspect, a communication device is provided for implementing the above various methods. The communication device may be the fifth node in the above sixth aspect, or a device including the above fifth node, or a device included in the above fifth node, such as a chip. The communication device includes corresponding modules, units, or means for implementing the method described in the above sixth aspect. The module, unit, or means may be implemented by hardware, software, or by hardware executing corresponding software. The hardware or software includes one or more modules or units corresponding to the above functions.
[0150] In some possible designs, the communication device includes: a processing module and a transceiver module. Among them, the transceiver module is used to receive a second request from the second node, where the second request is used to request access to the data of the fifth node, and the second request includes the attribute information corresponding to the second node. The processing module is used to determine whether the second node meets the requirement for accessing the data of the fifth node according to the attribute information corresponding to the second node and the proof information, and the proof information is used to verify the attributes corresponding to the second node.
[0151] In a possible design, the second request may further include the address of the attribute information corresponding to the second node on the blockchain.
[0152] In a possible design, the transceiver module is further used to send a third request to the blockchain node, where the third request is used to request to obtain the proof information, and receive the proof information from the blockchain node.
[0153] In a possible design, the proof information may include the credential information of the fourth node related to the attributes corresponding to the second node.
[0154] In a possible design, the proof information may further include: the hash of the attributes corresponding to the second node and / or the attributes corresponding to the second node.
[0155] In a possible design, a transceiver module for receiving a second request from a second node may include: a transceiver module for receiving identification information from the second node, where the identification information includes the identification of the second node and the signature of the first node associated with the identification of the second node. When the identification of the second node is verified, the transceiver module is controlled by the processing module to determine to establish a security authentication with the second node. When the security authentication is completed, the transceiver module is used to receive the second request from the second node.
[0156] In a possible design, the transceiver module is further used to send information for data access to a blockchain node, where the information for data access includes information for indicating requirements that need to be met for the second node to access data of a fifth node and information for indicating obtaining data of the fifth node.
[0157] In a possible design, the transceiver module is further used to send a first key to the second node when the second node meets the requirements for accessing data of the fifth node, where the first key is determined according to the attributes corresponding to the second node, and the first key is used to decrypt the encrypted data of the fifth node.
[0158] In a possible design, the information for indicating obtaining data of the fifth node may include the storage address where the encrypted data of the fifth node is located, and / or information for indicating the encrypted data of the fifth node.
[0159] In a possible design, the data of the fifth node may be encrypted with a second key, and the information for indicating obtaining data of the fifth node may further include: the encrypted second key, and the first key is specifically used to decrypt the encrypted second key.
[0160] In a possible design, the transceiver module is further used to send the encrypted data of the fifth node to the storage node corresponding to the storage address.
[0161] In a possible design, the transceiver module is further used to send information for indicating the access record of the second node to the blockchain node.
[0162] In a possible design, the attribute information corresponding to the second node may include the attributes corresponding to the second node and the signature of the fourth node associated with the attributes corresponding to the second node.
[0163] In a possible design, the transceiver module may include a receiving module and a sending module. Among them, the sending module is used to implement the sending function of the communication device described in the sixteenth aspect, and the receiving module is used to implement the receiving function of the communication device described in the sixteenth aspect.
[0164] In a possible design, the communication device described in the sixteenth aspect may further include a storage module that stores programs or instructions. When the processing module executes the programs or instructions, the communication device described in the sixteenth aspect can execute the method described in the sixth aspect.
[0165] In a seventeenth aspect, a communication device is provided for implementing the above various methods. The communication device may be the second node in the above seventh aspect, or a device including the above second node, or a device included in the above second node, such as a chip. The communication device includes corresponding modules, units, or means for implementing the method described in the above seventh aspect, and the module, unit, or means may be implemented by hardware, software, or by hardware executing corresponding software. The hardware or software includes one or more modules or units corresponding to the above functions.
[0166] In some possible designs, the communication device includes a processing module and a transceiver module. Among them, the processing module is used to generate a second request. The second request is used to request access to the data of the fifth node, and the second request includes attribute information corresponding to the second node. The transceiver module is used to send the second request to the fifth node.
[0167] In a possible design, the second request may further include the address of the attribute information corresponding to the second node on the blockchain.
[0168] In a possible design, the transceiver module for sending the second request to the fifth node may include: the transceiver module is controlled by the processing module to establish a security authentication with the fifth node according to the identifier of the second node. In the case of completing the security authentication, the transceiver module is used to send the second request to the fifth node.
[0169] In a possible design, the transceiver module is further used to receive a first key from the fifth node, where the first key is determined according to the attribute corresponding to the second node, and the first key is used to decrypt the encrypted data of the fifth node.
[0170] In a possible design, the transceiver module is further used to send a fourth request to the blockchain node, where the fourth request is used to request information for accessing the data of the fifth node. The transceiver module is further used to receive the information for data access from the blockchain node, and the information for data access includes information for indicating the requirements that the second node needs to meet to access the data of the fifth node and information for indicating obtaining the data of the fifth node. The processing module is further used to obtain the encrypted data of the fifth node according to the information for data access. The processing module is further used to decrypt the encrypted data of the fifth node according to the first key.
[0171] In a possible design solution, the information used to indicate obtaining the data of the fifth node may include the storage address where the encrypted data of the fifth node is located, and / or the information used to indicate the encrypted data of the fifth node.
[0172] In a possible design solution, the data of the fifth node may be encrypted with a second key, and the information used to indicate obtaining the data of the fifth node may further include: the encrypted second key, and the first key is specifically used to decrypt the encrypted second key.
[0173] In a possible design solution, the processing module is further used to obtain the encrypted data of the fifth node according to the information for data access, and may include: the processing module is used to control the transceiver module to send a seventh request to the storage node corresponding to the storage address, where the seventh request is used to request to obtain the data of the fifth node. The processing module is used to control the transceiver module to receive the encrypted data of the fifth node from the storage node.
[0174] In a possible design solution, the processing module is used to control the transceiver module to decrypt the encrypted data of the fifth node according to the first key, and may include: the processing module is used to control the transceiver module to decrypt the encrypted second key according to the first key, and decrypt the data of the fifth node encrypted with the second key according to the second key.
[0175] In a possible design solution, the attribute information corresponding to the second node may include the attribute corresponding to the second node and the signature of the fourth node associated with the attribute corresponding to the second node.
[0176] In a possible design solution, the transceiver module may include a receiving module and a sending module. Among them, the sending module is used to implement the sending function of the communication device described in the seventeenth aspect, and the receiving module is used to implement the receiving function of the communication device described in the seventeenth aspect.
[0177] In a possible design solution, the communication device described in the seventeenth aspect may further include a storage module, and this storage module stores programs or instructions. When the processing module executes this program or instruction, the communication device described in the seventeenth aspect can execute the method described in the seventh aspect.
[0178] In an eighteenth aspect, a communication device is provided for implementing the various methods described above. The communication device may be the blockchain node in the eighth aspect above, or a device including the blockchain node above, or a device included in the blockchain node above, such as a chip. The communication device includes corresponding modules, units, or means for implementing the method described in the eighth aspect above. The module, unit, or means may be implemented by hardware, software, or by hardware executing corresponding software. The hardware or software includes one or more modules or units corresponding to the above functions.
[0179] In some possible designs, the communication device includes: a processing module and a transceiver module. Among them, the processing module is used to control the transceiver module to receive a fourth request from a second node, where the fourth request is used to request information for accessing data of a fifth node. The processing module is used to control the transceiver module to send information for data access to the second node. The information for data access includes information for indicating requirements that the data accessed by the second node from the fifth node needs to meet and information for indicating obtaining data of the fifth node.
[0180] In a possible design, the transceiver module is used to receive information for data access from a fifth node.
[0181] In a possible design, the information for indicating obtaining data of the fifth node may include the storage address where the encrypted data of the fifth node is located and / or information for indicating the encrypted data of the fifth node.
[0182] In a possible design, the data of the fifth node may be encrypted with a second key, and the information for indicating obtaining data of the fifth node may further include: the encrypted second key.
[0183] In a possible design, the transceiver module is further used to receive information for indicating the access record of the second node from the fifth node.
[0184] In a possible design, the transceiver module may include a receiving module and a sending module. Among them, the sending module is used to implement the sending function of the communication device described in the eighteenth aspect, and the receiving module is used to implement the receiving function of the communication device described in the eighteenth aspect.
[0185] In a possible design, the communication device described in the eighteenth aspect may further include a storage module, and the storage module stores a program or an instruction. When the processing module executes the program or the instruction, the communication device described in the eighteenth aspect can execute the method described in the eighth aspect.
[0186] In a nineteenth aspect, a communication device is provided for implementing the above various methods. The communication device may be the blockchain node in the ninth aspect above, or a device including the above blockchain node, or a device included in the above blockchain node, such as a chip. The communication device includes corresponding modules, units, or means for implementing the method described in the ninth aspect above. The module, unit, or means may be implemented by hardware, by software, or by hardware executing corresponding software. The hardware or software includes one or more modules or units corresponding to the above functions.
[0187] In some possible designs, the communication device includes: a processing module and a transceiver module. Among them, the transceiver module is configured to receive an eighth request from a second node, where the eighth request is used to request to invoke a first smart contract, and the first smart contract is used to determine whether the second node can access the data of a fifth node. The processing module is configured to determine whether the second node can access the data of the fifth node according to the eighth request and the first smart contract.
[0188] In a possible design, the eighth request may include attribute information corresponding to the second node.
[0189] In a possible design, the attribute information corresponding to the second node may include the attribute corresponding to the second node and the signature of a fourth node related to the attribute corresponding to the second node.
[0190] In a possible design, the transceiver module is further configured to send a first key to the second node when the second node can access the data of the fifth node, where the first key is used to decrypt the encrypted data of the fifth node.
[0191] In a possible design, the transceiver module is further configured to receive information for data access from the fifth node, and the information for data access includes information for indicating requirements that need to be met for the second node to access the data of the fifth node and information for indicating obtaining the data of the fifth node.
[0192] In a possible design, the transceiver module is further configured to receive a fourth request from the second node, where the fourth request is used to request to obtain information for accessing the data of the fifth node. The transceiver module is further configured to send the information for data access to the second node.
[0193] In a possible design, the information for indicating obtaining the data of the fifth node may include the storage address where the encrypted data of the fifth node is located, and / or information for indicating the encrypted data of the fifth node.
[0194] In a possible design, the data of the fifth node is encrypted with a second key. Information for indicating obtaining the data of the fifth node may further include: the encrypted second key.
[0195] In a possible design, the processing module is further configured to generate and record the access situation of the fifth node when the second node can access the data of the fifth node.
[0196] In a possible design, the transceiver module may include a receiving module and a transmitting module. Among them, the transmitting module is used to implement the transmitting function of the communication device described in the nineteenth aspect, and the receiving module is used to implement the receiving function of the communication device described in the nineteenth aspect.
[0197] In a possible design, the communication device described in the nineteenth aspect may further include a storage module, and the storage module stores programs or instructions. When the processing module executes the programs or instructions, the communication device described in the nineteenth aspect can execute the method described in the ninth aspect.
[0198] In the twentieth aspect, a communication device is provided for implementing the above various methods. The communication device may be the second node in the tenth aspect above, or a device including the second node above, or a device included in the second node above, such as a chip. The communication device includes corresponding modules, units, or means for implementing the method described in the tenth aspect above. The module, unit, or means may be implemented by hardware, software, or by hardware executing corresponding software. The hardware or software includes one or more modules or units corresponding to the above functions.
[0199] In some possible designs, the communication device includes: a processing module and a transceiver module. Among them, the processing module is used to generate an eighth request. The eighth request is used to request to call a first smart contract, and the first smart contract is used to determine whether the second node can access the data of the fifth node. The transceiver module is used to send the eighth request to the blockchain node.
[0200] In a possible design, the eighth request may include attribute information corresponding to the second node.
[0201] In a possible design, the attribute information corresponding to the second node may include the attribute corresponding to the second node and the signature of the fourth node related to the attribute corresponding to the second node.
[0202] In a possible design, the transceiver module is further configured to receive a first key from the blockchain node, and the first key is used to decrypt the encrypted data of the fifth node.
[0203] In a possible design solution, the transceiver module is further configured to send a fourth request to a blockchain node, where the fourth request is used to request information for accessing data of a fifth node. The transceiver module is further configured to receive information for data access from the blockchain node, and the information for data access includes information for indicating requirements that need to be met for the second node to access the data of the fifth node and information for indicating obtaining the data of the fifth node. The processing module is further configured to obtain the encrypted data of the fifth node according to the information for data access. The processing module is further configured to decrypt the encrypted data of the fifth node according to the first key.
[0204] In a possible design solution, the information for indicating obtaining the data of the fifth node may include the storage address where the encrypted data of the fifth node is located, and / or information for indicating the encrypted data of the fifth node.
[0205] In a possible design solution, the data of the fifth node is encrypted with a second key, and the information for indicating obtaining the data of the fifth node may further include: the encrypted second key.
[0206] In a possible design solution, the processing module being further configured to obtain the encrypted data of the fifth node according to the information for data access may include: the processing module is configured to control the transceiver module to send a seventh request to the storage node corresponding to the storage address, where the seventh request is used to request obtaining the data of the fifth node. The processing module is configured to control the transceiver module to receive the encrypted data of the fifth node from the storage node.
[0207] In a possible design solution, the processing module being further configured to decrypt the encrypted data of the fifth node according to the first key may include: the processing module is configured to decrypt the encrypted second key according to the first key. The processing module is configured to decrypt the fifth node's data encrypted with the second key according to the second key.
[0208] In a possible design solution, the transceiver module may include a receiving module and a sending module. Among them, the sending module is used to implement the sending function of the communication device described in the twentieth aspect, and the receiving module is used to implement the receiving function of the communication device described in the twentieth aspect.
[0209] In a possible design solution, the communication device described in the twentieth aspect may further include a storage module, and the storage module stores programs or instructions. When the processing module executes the programs or instructions, the communication device described in the twentieth aspect can execute the method described in the tenth aspect.
[0210] In a twenty - first aspect, a communication device is provided (for example, the communication device may be a chip or a chip system). The communication device includes: a processor for implementing the functions involved in any one of the first to tenth aspects described above.
[0211] In a possible design, the communication device may further include a memory for storing necessary program instructions and data. The processor is coupled to the memory, and the processor is configured to execute the computer programs or instructions stored in the memory so that the communication device performs the methods described in any one of the first to tenth aspects above.
[0212] In a possible design, the communication device according to the twenty - first aspect may further include a transceiver. The transceiver may be a transceiver circuit or an interface circuit. The transceiver may be used for the communication device according to the twenty - first aspect to communicate with other communication devices.
[0213] In a possible design, the processor may be integrated with the memory.
[0214] In some possible designs, when the device is a chip system, it may be composed of chips or may include chips and other discrete devices.
[0215] In a twenty - second aspect, a communication device is provided. The communication device includes a processor and an interface circuit. The interface circuit is configured to receive signals from other communication devices outside the communication device and transmit them to the processor or send signals from the processor to other communication devices outside the communication device. The processor is configured to implement the methods described in any one of the first to tenth aspects above through logic circuits or by executing code instructions.
[0216] In a twenty-third aspect, a communication device is provided. The communication device may be a first node, or a module or unit (e.g., a chip, or a chip system, or a circuit) corresponding one by one to the methods / operations / steps / actions described in the first aspect and executed in the first node, or a device capable of being used in combination with the first node. Alternatively, the communication device may be a second node, or a module or unit (e.g., a chip, or a chip system, or a circuit) corresponding one by one to the methods / operations / steps / actions described in the second aspect, seventh aspect, or tenth aspect and executed in the second node, or a device capable of being used in combination with the second node. Alternatively, the communication device may be a first node, or a module or unit (e.g., a chip, or a chip system, or a circuit) corresponding one by one to the methods / operations / steps / actions described in the fourth aspect and executed in the first node, or a device capable of being used in combination with the first node. Alternatively, the communication device may be a blockchain node, or a module or unit (e.g., a chip, or a chip system, or a circuit) corresponding one by one to the methods / operations / steps / actions described in the third aspect, eighth aspect, or ninth aspect and executed in the blockchain node, or a device capable of being used in combination with the blockchain node. Alternatively, the communication device may be an operator node, or a module or unit (e.g., a chip, or a chip system, or a circuit) corresponding one by one to the methods / operations / steps / actions described in the fifth aspect and executed in the operator node, or a device capable of being used in combination with the operator node. Alternatively, the communication device may be a fifth node, or a module or unit (e.g., a chip, or a chip system, or a circuit) corresponding one by one to the methods / operations / steps / actions described in the sixth aspect and executed in the fifth node, or a device capable of being used in combination with the fifth node.
[0217] It can be understood that when the communication device provided in any one of the twenty-first aspect to the twenty-third aspect is a chip, the above-mentioned sending actions / functions can be understood as outputs, and the above-mentioned receiving actions / functions can be understood as inputs.
[0218] In a twenty-fourth aspect, a communication chip is provided. Instructions are stored in the communication chip, and when the communication chip runs on a communication device, the methods described in any one of the first aspect to the tenth aspect are implemented.
[0219] In a twenty-fifth aspect, a computer-readable storage medium is provided. A computer program or instructions are stored in the computer-readable storage medium, and when it runs on a communication device, the communication device can execute the methods described in any one of the first aspect to the tenth aspect.
[0220] In a twenty-sixth aspect, there is provided a computer program product containing instructions, including computer program code which, when running on a communication device, enables the communication device to execute the method described in any one of the first to tenth aspects above.
[0221] In a twenty-seventh aspect, there is provided a communication system, including: a communication device for implementing the method described in the first aspect above and a communication device for implementing the method described in the second aspect above.
[0222] In a twenty-eighth aspect, there is provided a communication system, including: a communication device for implementing the method described in the third aspect above and a communication device for implementing the method described in the fourth aspect above.
[0223] In a twenty-ninth aspect, there is provided a communication system, including: a communication device for implementing the method described in the fifth aspect above.
[0224] In a thirtieth aspect, there is provided a communication system, including: a communication device for implementing the method described in the sixth aspect above, a communication device for implementing the method described in the seventh aspect above, and a communication device for implementing the method described in the eighth aspect above.
[0225] In a thirty-first aspect, there is provided a communication system, including: a communication device for implementing the method described in the ninth aspect above and a communication device for implementing the method described in the tenth aspect above. BRIEF DESCRIPTION OF THE DRAWINGS
[0226] Figure 1 It is a schematic diagram of the architecture of a communication system provided by an embodiment of the present application;
[0227] Figure 2 It is a schematic flow diagram of a communication method provided by an embodiment of the present application;
[0228] Figure 3 It is a schematic flow diagram of another communication method provided by an embodiment of the present application;
[0229] Figure 4 It is a schematic flow diagram of yet another communication method provided by an embodiment of the present application;
[0230] Figure 5 It is a schematic flow diagram of yet another communication method provided by an embodiment of the present application;
[0231] Figure 6 It is a schematic flow diagram of yet another communication method provided by an embodiment of the present application;
[0232] Figure 7 It is a schematic flow diagram of yet another communication method provided by an embodiment of the present application;
[0233] Figure 8 A schematic structural diagram of a communication device provided by an embodiment of the present application;
[0234] Figure 9 A schematic structural diagram of another communication device provided by an embodiment of the present application. Detailed implementation manners
[0235] The embodiments of the present application will present various aspects, embodiments or features around a system that may include multiple devices, components, modules, etc. It should be understood and appreciated that each system may include additional devices, components, modules, etc., and / or may not include all the devices, components, modules, etc. discussed in conjunction with the drawings. In addition, combinations of these solutions may also be used.
[0236] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as wireless fidelity (Wi-Fi) systems, vehicle to everything (V2X) communication systems, device-to-device (D2D) communication systems, vehicle networking communication systems, worldwide interoperability for microwave access (WiMAX) communication systems, 4th generation (4G) mobile communication systems, such as long term evolution (LTE) systems, worldwide interoperability for microwave access (WiMAX) communication systems, 5th generation (5G) mobile communication systems, such as new radio (NR) systems, and future communication systems, such as 6th generation (6G) mobile communication systems, etc.
[0237] For ease of understanding, the technical terms involved in the embodiments of the present application will be introduced first below.
[0238] 1. Blockchain: A distributed ledger that combines multiple technologies such as cryptographic technology, peer-to-peer (P2P) network, and distributed database. As an open and transparent decentralized technology, blockchain transforms traditional authoritative centers and centralized trust into group consensus and decentralized trust respectively, and constructs an immutable distributed ledger guaranteed by cryptographic technology.
[0239] 2. Smart contract: It is a computer text that uses a computer as the main tool, embeds mathematical algorithms into the program to prove whether an event meets the agreed conditions, ensures that all parties reach an agreement according to the agreed conditions within the agreed time, and verifies and executes the contract terms. Simply put, a smart contract is a computer program that can automatically execute contract terms without the intervention of a third party.
[0240] Smart contracts use mathematical algorithms to verify whether a transaction meets the agreed conditions. For example, a contract stipulates a condition: "A car needs to be transported from place A to place B." To ensure that the transaction stipulated in this contract occurs when the condition is met, a function or an algorithm is required to verify whether this contract meets the agreed conditions.
[0241] 3. Consensus mechanism: It is one of the important mechanisms to ensure the security and reliability of the blockchain. It is achieved through algorithms and protocols between network nodes to ensure the consistency of data and transactions on the blockchain among all nodes, thereby preventing double-spending and other malicious behaviors. The consensus mechanism can prevent nodes in the network from tampering with data or performing other malicious behaviors, making the blockchain more secure and reliable. The implementation of the consensus mechanism requires the collaboration of multiple nodes, which increases the degree of decentralization of the blockchain. Under the action of the consensus mechanism, nodes do not need to trust any centralized institution, which makes the blockchain more decentralized and democratic. The consensus mechanism can be applied to fields such as digital currency, smart contracts, supply chain management, and medical record management, providing reliable technical support for the development and application of these fields. The implementation of the consensus mechanism requires the help of digital technologies such as computers and networks. Therefore, the development and application of the consensus mechanism promote the development of the digital economy. The continuous optimization and innovation of the consensus mechanism will provide more reliable and secure technical support for the development of the digital economy.
[0242] As described in the background technology, the profiles of users in telecommunications network services are all strongly related to telecommunications network services and lack user attribute information. For example, the social attribute of the user identifies the user as an employee of a certain company, making the user identity only used in the telecommunications network, and the telecommunications network cannot use the credibility of third parties to enhance security. For example, in the caller ID of a certain user, the information of the calling user displayed is "express delivery" or "harassing call". Such information can be used as user attribute information, but this information is generated based on the feedback of big data, that is, based on the feedback marks of other users. There are the following problems with the user attribute information generated in this way: 1. Poor authority: There are harassing calls with malicious marks; 2. Poor real-time performance: It needs to be identified by multiple people before being marked.
[0243] In addition, due to the lack of the introduction of user attributes, users are also unable to support complex upper-layer applications, such as data access and authorization.
[0244] To this end, embodiments of the present application provide a communication method and apparatus, which allocate attribute information for a user by providing an attribute endorsement service for the user, and can perform access control on the user based on the attribute information, thereby enhancing the security of telecommunications network services and realizing data access and authorization.
[0245] To better understand the embodiments of the present application, the following points are described before introducing the embodiments of the present application.
[0246] First, in the embodiments of the present application, "for indicating" may include for direct indication and for indirect indication. When describing that a certain "indication information" is used to indicate A, it may include that the indication information directly indicates A or indirectly indicates A, and does not mean that A must be carried in the indication information.
[0247] The information indicated by the indication information is called the information to be indicated. In the specific implementation process, there are many ways to indicate the information to be indicated. For example, but not limited to, the information to be indicated can be directly indicated, such as the information to be indicated itself or the index of the information to be indicated, etc. It is also possible to indirectly indicate the information to be indicated by indicating other information, where there is an association relationship between the other information and the information to be indicated. It is also possible to only indicate a part of the information to be indicated, while the other parts of the information to be indicated are known or pre-agreed. For example, it is also possible to use the arrangement order of each information pre-agreed (such as protocol regulations) to achieve the indication of specific information, thereby reducing the indication overhead to a certain extent. At the same time, the common parts of each information can be identified and indicated uniformly to reduce the indication overhead caused by separately indicating the same information.
[0248] In addition, the specific indication method can also be various existing indication methods, such as, but not limited to, the above indication methods and their various combinations, etc. The specific details of various indication methods can refer to the prior art and will not be elaborated herein. As described above, for example, when it is necessary to indicate multiple information of the same type, there may be a situation where the indication methods of different information are different. In the specific implementation process, the required indication method can be selected according to specific needs. The embodiments of the present application do not limit the selected indication method. In this way, the indication methods involved in the embodiments of the present application should be understood to cover various methods that can enable the party to be indicated to obtain the information to be indicated.
[0249] The information to be indicated can be sent as a whole or divided into multiple sub - information and sent separately. Moreover, the transmission periods and / or transmission timings of these sub - information can be the same or different. The specific transmission method is not limited in this application. Among them, the transmission periods and / or transmission timings of these sub - information can be predefined, for example, predefined according to a protocol, or can be configured by the transmitting device by sending configuration information to the receiving device. Among them, the configuration information can include, for example but not limited to, one or a combination of at least two of radio resource control (RRC) signaling, media access control (MAC) layer signaling, and physical layer signaling. Among them, MAC layer signaling includes, for example, MAC - control element (CE); physical (PHY) layer signaling includes, for example, downlink control information (DCI).
[0250] Second, in the embodiments of this application, the first, second, and various numerical numbers are only for the convenience of description and are not used to limit the scope of the embodiments of this application. For example, to distinguish different indication information. Another example is that the first information and the second information are only used to distinguish different information and do not limit their order. Those skilled in the art can understand that words such as "first" and "second" do not limit the quantity and execution order, and words such as "first" and "second" do not necessarily limit them to be different.
[0251] Third, in the embodiments of this application, descriptions such as "when...", "in the case of...", "if", and "when" all refer to the situation where the device (such as a terminal device or an access network device) will make corresponding processing under a certain objective situation, not to limit the time, and it is not required that the device (such as a terminal device or an access network device) must have a judgment action during implementation, nor does it mean there are other limitations.
[0252] At the same time, in the embodiments of this application, words such as "exemplary" or "for example" are used to represent examples, illustrations, or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the embodiments of this application should not be interpreted as being more preferred or having more advantages than other embodiments or design solutions. Exactly speaking, using words such as "exemplary" or "for example" aims to present relevant concepts in a specific way for easy understanding.
[0253] Finally, the network architecture and service scenarios described in the embodiments of this application are used to more clearly illustrate the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided by the embodiments of this application. Those of ordinary skill in the art will know that with the evolution of the network architecture and the emergence of new service scenarios, the technical solutions provided by the embodiments of this application are equally applicable to similar technical problems.
[0254] Please refer to Figure 1 , Figure 1 which is a schematic diagram of the architecture of a communication system provided by an embodiment of this application. As Figure 1 shown, the communication system includes: a distributed system 101 and at least one node 102a-102f that interacts with the distributed system. Among them, the distributed system includes a blockchain system, and the blockchain system includes one or more blockchain nodes that can communicate with each other.
[0255] The blockchain nodes can be terminal devices, access network devices, network elements or devices in the core network, servers, personal computers (PCs), virtual machines (VMs), application container engines (dockors), or blockchain all-in-one machines, etc.
[0256] The nodes that interact with the distributed system can include nodes that provide attribute endorsement or certification services, nodes that request to obtain attributes, nodes that provide operator services, nodes that provide data services, nodes that provide identity certification services, and nodes that provide storage services, etc. The nodes that interact with the distributed system can also communicate with each other, and can communicate with each other, which can be direct communication or indirect communication, and this is not limited. The nodes that interact with the distributed system can also be terminal devices, access network devices, network elements or devices in the core network, servers, PCs, VMs, application container engines (dockors), or blockchain all-in-one machines, etc.
[0257] Among them, the nodes that provide attribute endorsement or certification services can also be called attribute endorsement nodes, endorsement nodes, etc., and can be devices for implementing the services of an organization or institution (which can be simply referred to as the devices corresponding to the organization or institution), devices for providing the services of an operator (which can be simply referred to as the devices corresponding to the operator), devices for providing the services of an authoritative institution (which can be simply referred to as the devices corresponding to the authoritative institution), devices for providing the services of a third-party trusted institution (which can be simply referred to as the devices corresponding to the third-party trusted institution), or other devices corresponding to organizations or institutions that can provide attribute endorsement services, etc.
[0258] The nodes that request to obtain attributes can also be called attribute application nodes, attribute ownership nodes, etc., and can be devices corresponding to users, devices corresponding to organizations or institutions, etc.
[0259] The node providing operator services may also be referred to as an operator node, an operator service node, etc., and may be the equipment corresponding to the operator, such as the operator's server, network elements or equipment in the core network (such as operation administration and maintenance (OAM) network elements), or access network equipment, servers, etc.
[0260] The node providing data services may also be referred to as a data-owning node, a data node, etc., and may be equipment such as a database, a server, etc. that can provide data services.
[0261] The node providing identity authentication services may also be referred to as an authentication node, an identity authentication node, and may be the equipment corresponding to a third-party trusted institution, the equipment corresponding to an authoritative institution, or the equipment corresponding to other organizations or institutions that can provide identity authentication.
[0262] The node providing storage services may also be referred to as a storage node, an off-chain storage node, etc., and may be equipment such as a server, a distributed storage system, etc. that provides data storage functions.
[0263] It should be understood that the blockchain node may be the node providing attribute endorsement or certification services, the node requesting to obtain attributes, the node providing operator services, the node providing data services, the node providing identity authentication services, and the node providing storage services as mentioned above, or co-located with the above nodes, and this is not limited.
[0264] The above terminal device can be a terminal device with transceiver functions, or can also be a chip or chip system disposed in the terminal device. The terminal device can also be referred to as a user equipment (UE), access terminal, subscriber unit, user station, mobile station (MS), mobile unit, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent, or user device. The terminal device in the embodiments of the present application can be a mobile phone, cellular phone, smartphone, tablet computer (Pad), wireless data card, personal digital assistant (PDA), wireless modem, handset, laptop computer, machine type communication (MTC) terminal, computer with wireless transceiver functions, virtual reality (VR) terminal, augmented reality (AR) terminal, smart home device (such as a refrigerator, TV, air conditioner, electricity meter, etc.), intelligent robot, robotic arm, workshop equipment, wireless terminal in self-driving, wireless terminal in industrial control, wireless terminal in remote medical, wireless terminal in smart grid, wireless terminal in transportation safety, wireless terminal in smart city, wireless terminal in smart home, in-vehicle terminal, roadside unit (RSU) with terminal functions, etc., flight equipment (such as intelligent robot, hot air balloon, unmanned aerial vehicle, airplane), etc. The terminal device in the present application can also be an in-vehicle module, in-vehicle module group, in-vehicle component, in-vehicle chip, or in-vehicle unit built into a vehicle as one or more components or units. The terminal device can also be other devices with terminal functions. For example, the terminal device can also be a device that serves as a terminal function in D2D communication.
[0265] Embodiments of the present application do not limit the device form of the terminal device. The device for implementing the functions of the terminal device may be the terminal device; it may also be a device capable of supporting the terminal device to implement the functions, such as a chip system. The device may be installed in the terminal device or used in matching with the terminal device. In the embodiments of the present application, the chip system may be composed of chips, or may include chips and other discrete devices.
[0266] An access network device, which can also be referred to as an access network node, a radio access network (RAN) node, a RAN entity, or an access node, etc., is located on the network side of the above communication system and is used to help terminal devices achieve wireless access. It is a device with wireless transceiver functions or a chip or chip system that can be set in the device. The access network device includes but is not limited to: base station, evolved NodeB (eNodeB), access point (AP), transmission reception point (TRP or transmission point, TP), next generation NodeB (gNB), the next generation base station in a 6G mobile communication system, the base station in a future mobile communication system, or the access node in a Wi-Fi system, etc. The access network device can be a macro base station, a micro base station or an indoor station, a relay node or a donor node, an open radio access network (ORAN), or a radio controller in a centralized radio access network (CRAN) scenario. The access network device can also be one or a group (including multiple antenna panels) of antenna panels of a base station in 5G, or, alternatively, it can also be a network node that constitutes a gNB, a TRP, a TP, or a transmission measurement function (TMF), such as a central unit (CU), a distributed unit (DU), a CU-control plane (CP), a CU-user plane (UP), or a radio unit (RU), an RSU with base station functions. Optionally, the access network device can also be a server, a wearable device, a vehicle or an in-vehicle device, etc. For example, the access network device in V2X technology can be an RSU. All or part of the functions of the network device in this application can also be implemented by software functions running on hardware, or by virtualized functions instantiated on a platform (such as a cloud platform). The access network device in this application can also be a logical node, a logical module, or software that can implement all or part of the functions of the access network device.
[0267] Among them, the CU and DU can be set separately or can also be included in the same network element, such as in a baseband unit (BBU). The RU can be included in a radio frequency device or a radio frequency unit, such as included in a remote radio unit (RRU), an active antenna unit (AAU), or a remote radio head (RRH). It can be understood that the access network device can be a CU node, or a DU node, or a device including a CU node and a DU node. In addition, the CU can be classified as a network device in the radio access network (RAN), or the CU can be classified as a network device in the core network (CN), which is not limited herein.
[0268] In different systems, the CU (or CU-CP and CU-UP), DU, or RU may also have different names, but those skilled in the art can understand their meanings. For example, in the ORAN system, the CU can also be called an O-CU (Open CU), the DU can also be called an O-DU, the CU-CP can also be called an O-CU-CP, the CU-UP can also be called an O-CU-UP, and the RU can also be called an O-RU. For the convenience of description, the CU, CU-CP, CU-UP, DU, and RU are used as examples in this application. Any one of the CU (or CU-CP, CU-UP), DU, and RU in this application can be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.
[0269] In the embodiments of this application, the form of the access network device is not limited. The device for implementing the functions of the access network device can be the access network device; it can also be a device capable of supporting the access network device to implement this function, such as a chip system. This device can be installed in the access network device or used in matching with the access network device.
[0270] The network elements or devices in the core network are devices deployed in the core network to provide services for terminal devices. In systems adopting different radio access technologies, the names of core network elements with similar radio communication functions may be different. For example, when the method of the embodiments of the present application is applied to a 5G system, the core network devices may be an access and mobility management function (AMF), a session management function (SMF), a user plane function (UPF), etc. Among them, the UPF processes user plane data. The AMF and SMF process control plane signaling. When the method of the embodiments of the present application is applied to an LTE system, the core network device may be a mobility management entity (MME). For the convenience of description only, in the embodiments of the present application, the devices that can provide services for terminal devices can be collectively referred to as core network elements, core network devices, or network functions (NF), etc., and no limitation is made thereto.
[0271] In addition, it should be understood that Figure 1 The illustrated communication system exemplarily shows several functions or types of nodes or devices. Figure 1 The illustrated communication system may also include other types of nodes, such as devices or nodes for implementing the services of card merchants or terminal manufacturers, etc., and no limitation is made thereto.
[0272] In the embodiments of the present application, the names of nodes, modules, devices, or network elements in different scenarios, architectures, or systems are exemplarily given, as well as the names of the communication interfaces between two of the nodes, modules, devices, or network elements. It does not exclude the possibility of name changes in future communication systems, scenarios, or architectures.
[0273] Next, it will be combined with Figures 2 - 7 to specifically elaborate on the communication method provided by the embodiments of the present application.
[0274] Exemplarily, Figure 2 is a schematic flowchart of a communication method provided by the embodiments of the present application. This communication method is based on Figure 1Taking the communication between the blockchain node shown and the node providing the attribute endorsement or proof service (hereinafter referred to as Node #1) as an example for illustration. Of course, the entity executing the actions of the blockchain node in this method can also be a device / module in the blockchain node, such as a chip, a processor, a processing unit, etc. in the blockchain node, which is not limited herein; the entity executing the actions of Node #1 in this method can also be a device / module in Node #1, such as a chip, a processor, a processing unit, etc. in Node #1, which is not specifically limited herein.
[0275] As Figure 2 shown, this communication method includes:
[0276] S201. Node #1 sends Request #1 to the blockchain node. Correspondingly, the blockchain node receives Request #1 from Node #1.
[0277] For Request #1, it is an installation request for a smart contract related to the attribute endorsement or proof service initiated by Node #1. For example, Request #1 is used to request the installation of the smart contract corresponding to the attribute endorsement service supported by Node #1. In the embodiments of this application, Request #1 can also be referred to as the fifth request, and Node #1 can also be referred to as the fourth node. Or rather, Request #1 corresponds to the fifth request, and Node #1 corresponds to the fourth node.
[0278] Specifically, Request #1 may include the identifier of Node #1, the attribute endorsement service corresponding to the smart contract, and the smart contract. Among them, the identifier of Node #1 is information used to uniquely identify the identity of Node #1. For example, the identifier of Node #1 can be a decentralized root credential (DRC), or a decentralized identity credential (DIC), or a decentralized self-control credential (DSCC), or a decentralized operator credential (DOC), or a self-control identity credential (SCIC). Among them, DRC, DIC, and DSCC can all be referred to as self-control identity (scID). Another example is that the identifier of Node #1 can be the identifier of the authentication certificate of Node #1.
[0279] Among them, DRC is the root ID preset in the card by the card merchant / device manufacturer at the time of factory shipment or by the institution; DIC is multiple temporary / derived identities derived from DRC; DSCC is independently generated by the user for the user's control of identity information, independent of DRC or DIC; DOC can be the credential information issued by the operator for the user; SCIC is derived based on DSCC. Each DRC, DIC, DSCC, or SCIC corresponds to file information. That is to say, the above DRC and DIC can be possessed by both users and institutions, and DOC, DSCC, and SCIC can be unique to users. It should be understood that the identification settings of nodes are different based on different node types. The identification settings of the following nodes #2 to #4 are similar to those of node #1, and will not be elaborated hereinafter.
[0280] In a possible implementation, the identification of node #1 can reuse the form of the embedded universal integrated circuit card (eUICC) of the universal integrated circuit card (UICC) specified by the Global System for Mobile Communications Association (GSMA). For example, the identification of node #1 can be "0x1234". Here, the identification of node #1 is only for illustration. In actual implementation, the identification of node #1 can also be other possible implementation methods, which will not be elaborated herein.
[0281] The attribute endorsement service is a service used to provide attribute authentication or proof for a node (such as node #2). The attribute proof can include the social attribute proof and objective attribute proof of the node. For example, the social attribute proof can include proving the work, education background, real-name authentication status, etc. of node #2, and the objective attribute proof can include proving the current location, current age, and whether node #2 has a certain permission, etc. Thus, the proven attributes are considered to be trustworthy and secure. In the embodiments of the present application, node #1 can be a device capable of providing the attribute endorsement service, such as a device corresponding to an operator, an authoritative institution, or a third-party trusted institution, etc., and can provide proven attributes for the nodes that can be served by it. In the embodiments of the present application, node #2 can also be referred to as the second node, or rather, node #1 corresponds to the fourth node.
[0282] The smart contract corresponding to the attribute endorsement service means that the attribute endorsement service provided by node #1 is installed or deployed in the form of a smart contract. One smart contract can correspond to one or a type of attribute endorsement service. That is to say, node #1 requests to install the attribute endorsement service it can provide onto the blockchain node in the form of a smart contract through request #1, so that the blockchain node provides the attribute endorsement service. It should be understood that the smart contract can be represented in the form of code or a program.
[0283] Optionally, Request #1 may further include the signature of Node #1 on Request #1, the signature of Node #1 on the smart contract, etc., for proving the authenticity and validity of the information or message. It should be understood that Node #1 may use its private key to sign the information or message.
[0284] In a possible design 1, Node #1 may send Request #1 to a certain blockchain node. Thus, based on the characteristics of the blockchain, a certain blockchain node (such as the first blockchain node) that receives Request #1 may inform other blockchain nodes on its blockchain of Request #1 through consensus, and some or all of the blockchain nodes on the blockchain may install the smart contract according to Request #1, so that the smart contract is installed on the blockchain.
[0285] In a possible design 2, Node #1 may send Request #1 to multiple blockchain nodes respectively. Thus, the multiple blockchain nodes that receive Request #1 install the smart contract according to Request #1 respectively, and at this time, there is no need to inform other blockchain nodes of Request #1 through consensus.
[0286] S202. The blockchain node installs the smart contract according to Request #1.
[0287] After receiving Request #1, the blockchain node may determine whether it can install the smart contract according to Request #1, and select whether to install the smart contract according to the judgment result. Exemplarily, the blockchain node may determine whether it can support the installation of the smart contract indicated by Request #1 according to its current installation resources, installation conditions, etc. If the current installation resources are rich and the installation conditions are good, the smart contract can be installed; otherwise, the smart contract may not be installed.
[0288] Optionally, the blockchain node may also verify Request #1, and then determine whether it can install the smart contract in the case of passing the verification. On the contrary, in the case of failing the verification, the blockchain node does not need to determine whether it can install the smart contract anymore, and at this time, it can be considered that Request #1 is invalid. Exemplarily, the blockchain node may use the public key to verify the signature in Request #1, and then determine whether it can install the smart contract according to the installation resources, installation conditions, etc. in the case of passing the signature verification.
[0289] In a possible design, after a blockchain node obtains Request #1 and completes the verification of the signature in Request #1, it can first vote / select / judge whether to support the installation of a smart contract according to Request #1, and then return the voting / selection / judgment result to Node #1. Then, Node #1 can indicate whether to install the smart contract on the blockchain node according to the voting / selection / judgment result fed back by the blockchain node. It should be understood that the voting / selection / judgment result can be determined by the blockchain node according to the installation resources, installation conditions, etc. as described above.
[0290] In this design, in a possible implementation, the blockchain node can send Message #1 to Node #1 according to Request #1. Correspondingly, Node #1 receives Message #1 from the blockchain node. Among them, Message #1 is used to indicate whether to support the installation of a smart contract. For example, Message #1 can include 1-bit indication information (which can also be called a cell or field or indication field) to indicate whether to support the installation of a smart contract. A bit value of 1 is used to indicate that the blockchain node supports the installation of the smart contract, and a bit value of 0 is used to indicate that the blockchain node does not support the installation of the smart contract, or a bit value of 0 is used to indicate that the blockchain node supports the installation of the smart contract, and a bit value of 1 is used to indicate that the blockchain node does not support the installation of the smart contract. There is no limitation on this. Optionally, Message #1 can also include the signature of the blockchain node on the result of whether to support the installation of the smart contract to prove the authenticity of this information.
[0291] Optionally, Message #1 can be sent carried in the response corresponding to Request #1, or can be sent carried in other messages. There is no limitation on this. In the embodiments of this application, Message #1 can also be called the second message, or rather, Message #1 corresponds to the second message.
[0292] In a possible implementation, the blockchain node can also trade / publish / record the voting / selection / judgment result (including the result of whether to support the installation of the smart contract and / or the signature on the result) on the blockchain. In this implementation, Message #1 can include the voting / selection / judgment result and / or the address of the voting / selection / judgment result on the blockchain (which can also be called the storage address, transaction address, etc.).
[0293] Thus, node #1 can determine Information #2 based on the information of at least one blockchain node, and send Information #2 to the blockchain node. Correspondingly, the blockchain node receives Information #2 from node #1 and determines whether to install a smart contract based on Information #2. In other words, Information #2 is determined based on the information of at least one blockchain node. Wherein, Information #2 is used to indicate whether to install a smart contract. For example, Information #2 can be similar to the above Information #1, or can include 1-bit indication information to indicate. Specifically, reference can be made to the relevant description of the above Information #1, which will not be elaborated herein. In the embodiments of the present application, Information #2 can also be referred to as the third information, or in other words, Information #2 corresponds to the third information.
[0294] Exemplarily, node #1 receives the information corresponding to each of one or more blockchain nodes participating in the installation of the smart contract on the blockchain, and counts the results indicating whether to support the installation of the smart contract indicated by the information corresponding to each of the one or more blockchain nodes. If the number of results supporting the installation of the smart contract is greater than (or greater than or equal to) the first threshold, then node #1 instructs the blockchain node to install the smart contract through Information #2. Otherwise, node #1 instructs the blockchain node not to install the smart contract through Information #2.
[0295] When Information #1 only includes the address of the voting / selection / judgment result on the blockchain, node #1 can query the voting / selection / judgment result of each blockchain node according to the address, and perform the above statistics and threshold comparison on it. When Information #1 includes the voting / selection / judgment result and the address of the voting / selection / judgment result on the blockchain, then node #1 can compare the voting / selection / judgment result of each blockchain node queried according to the address with the voting / selection / judgment result in Information #1. If they are the same, the above statistics and threshold comparison can be performed on it. Otherwise, the voting / selection / judgment result queried directly using the address can be used to perform the above statistics and threshold comparison on it, or the above statistics and threshold comparison can be directly cancelled.
[0296] Optionally, node #1 can also sign the installation result obtained from the threshold comparison using a private key. At this time, Information #2 can include the result of whether to install the smart contract and the signature of node #1 on the result of whether to install the smart contract.
[0297] In a possible implementation, node #1 can also indicate whether to install the smart contract on the blockchain node by feeding back the results indicating whether each blockchain node supports the installation of the smart contract. In other words, Information #2 can include the results indicating whether each of at least one blockchain node supports the installation of the smart contract, and / or the address of the results indicating whether each of at least one blockchain node supports the installation of the smart contract on the blockchain.
[0298] Thus, after the blockchain node receives Information #2, if there is a signature in Information #2, the blockchain node can verify the signature in Information #2. If the verification passes, it determines whether to install the smart contract according to the installation result indicated in Information #2.
[0299] When Information #2 indicates to install the smart contract, for Design 1 in S201 above, the blockchain node can inform Information #2 to other blockchain nodes on the blockchain it belongs to through consensus, so that each participating blockchain node can install the smart contract requested by Node #1 according to Information #2. When Information #2 indicates not to install the smart contract, the blockchain node can not perform the smart contract installation operation.
[0300] Optionally, after the blockchain node finishes installing the smart contract, the blockchain node can also send a response message to Node #1 to indicate that the smart contract installation is completed.
[0301] Based on the above S201 and S202, Node #1 publishes the attribute endorsement service in the form of a smart contract to the blockchain through Request #1, so that nodes applying for attributes (such as Node #2) can obtain the certified attributes by calling the smart contract on the blockchain. Thus, cross-domain attribute interoperability can be achieved among various nodes to achieve interoperability of credibility.
[0302] Furthermore, the communication method provided in the embodiments of the present application may further include the following steps:
[0303] S203: Node #1 sends Information #3 to the blockchain node. Correspondingly, the blockchain node receives Information #3 from Node #1.
[0304] In the embodiments of the present application, Information #3 is used to indicate the usage information of the smart contract. Information #3 can be used as the configuration file (profile) corresponding to the smart contract. Information #3 may include at least one of the following: the attribute endorsement service corresponding to the smart contract, the address of the smart contract, the input parameters of the smart contract, the output parameters of the smart contract, or the application template for attribute information. In the embodiments of the present application, Information #3 may also be referred to as the fourth information, or rather, Information #3 corresponds to the fourth information.
[0305] Among them, the attribute endorsement service corresponding to the smart contract is used to indicate the attribute endorsement service provided by the installed smart contract; the address information of the smart contract is used to indicate the location where the installed smart contract is located; the input parameters of the smart contract are used to indicate the parameter settings input to the smart contract when using the smart contract to complete the attribute endorsement service; the output parameters of the smart contract are used to indicate the parameter settings output by the smart contract when using the smart contract to complete the attribute endorsement service; the application template for attribute information is used to indicate the filling template for the applied attribute content, that is, fill in the attribute content according to the template.
[0306] It should be understood that in addition to the several parameters shown above, Information #3 may further include other usage information related to the smart contract, such as the effective duration corresponding to the smart contract, the identifier of Node #1 corresponding to the smart contract, the identifier of the smart contract, etc., which are not limited herein.
[0307] Exemplarily, if the smart contract installed on the blockchain node is a smart contract providing an attribute endorsement service for a device (i.e., Node #1) corresponding to a certain social institution, then the attribute endorsement service corresponding to the smart contract may be: proving that Node #2 is an employee of the social institution; the address of the smart contract may be 0x1111; the input parameters of the smart contract may be at least one of the following: the ID of Node #2, the ID of Node #2 + job number, the ID of Node #2 + ID number, or the ID of Node #2 + work certificate, etc.; the output result of the smart contract may be: Node #2 is an employee of the social institution (this output result is signed by the device corresponding to the social institution).
[0308] Another exemplarily, if the smart contract installed on the blockchain node is a smart contract providing an attribute endorsement service for a device (i.e., Node #1) corresponding to a certain operator, then the attribute endorsement service corresponding to the smart contract may be: proving the current location of Node #2; the address of the smart contract may be 0x1280; the input parameters of the smart contract may be at least one of the following: the ID of Node #2, or the access information of Node #2 related to the device corresponding to the operator, etc., where the access information of Node #2 related to the device corresponding to the operator may be, for example, the ID of the access network device accessed by Node #2, the public land mobile network (PLMN) ID, etc.; the output result of the smart contract may be: the current location of Node #2 is Beijing / Shanghai, etc. (this output result is signed by the device corresponding to the operator).
[0309] After receiving Information #3, the blockchain node may record Information #3 on the blockchain through consensus and store the address of Information #3 on the blockchain. Thus, the blockchain node may apply for the smart contract to provide the corresponding endorsed or proven attributes according to the attributes of the node. It should be understood that Information #3 may be carried in Request #1 for sending, and in this case, S203 is an optional step.
[0310] Furthermore, an embodiment of the present application further provides a communication method for issuing proven attributes for a node. This communication method uses Figure 1Taking the communication between the blockchain node shown and the node that requests to obtain attributes (hereinafter referred to as node #2) as an example for illustration. Of course, the entity that executes the actions of the blockchain node in this method can also be a device / module in the blockchain node, such as a chip, a processor, a processing unit, etc. in the blockchain node, and no limitation is imposed thereon; the entity that executes the actions of node #2 in this method can also be a device / module in node #2, such as a chip, a processor, a processing unit, etc. in node #2, and no limitation is imposed thereon.
[0311] As Figure 3 shown, this communication method includes:
[0312] S301. Node #2 sends request #2 to the blockchain node. Correspondingly, the blockchain node receives request #2 from node #2.
[0313] Among them, request #2 is an attribute application initiated by node #2. For example, request #2 is used to request to obtain attributes. Request #2 may include the identifier of node #2, information indicating the type of the attribute to be requested, information indicating the identity of node #2, and other information for requesting to obtain attributes. In the embodiments of the present application, request #2 may also be referred to as the first request, and node #2 may also be referred to as the second node. Or rather, request #3 corresponds to the first request, and node #2 corresponds to the second node.
[0314] Among them, the specific description of the identifier of node #2 can refer to the relevant description of the identifier of node #1 in S201 above, and details are not repeated here; the information indicating the type of the attribute to be requested is used to indicate one or more attribute types requested by node #2.
[0315] The information indicating the identity of node #2 is used to prove whether the identity of node #2 is legal and true. The information indicating the identity of node #2 may include the identity certificate information corresponding to node #2 and / or the signature of node #3 on the identity certificate information corresponding to node #2. Among them, node #3 is the node corresponding to the institution or organization that can prove the identity of node #2, such as the device corresponding to a social authoritative institution, and has credibility for the authentication of the identity information of node #2. For example, if node #2 is a terminal device, the identity certificate information corresponding to node #2 may be an ID number, educational background information, etc. The signature of node #3 on the identity certificate information corresponding to node #2 is used to represent the authentication of the third party for proving the identity of node #2. In the embodiments of the present application, node #3 may also be referred to as the third node. Or rather, node #3 corresponds to the third node.
[0316] Thus, node #2 obtains the attributes related to it through request #2.
[0317] In a possible implementation, the blockchain node can also actively send the corresponding attribute information to Node 2# without Node #2 requesting it from the blockchain node. In this case, S301 can be considered an optional step.
[0318] S302. The blockchain node sends the attribute information to Node #2. Correspondingly, Node #2 receives the attribute information from the blockchain node.
[0319] Among them, the attribute information is used to indicate the attributes corresponding to Node #2 that have been proven. The attribute information can include the attributes corresponding to Node #2 and the signature of Node #1 related to the attributes corresponding to Node #2. Among them, Node #1 can sign the attributes corresponding to Node #2 using its private key. Node #1 related to the attributes corresponding to Node #2 refers to the node that provides attribute endorsement services for Node #2, which can be one or more, such as the devices corresponding to social authoritative institutions or the devices corresponding to third-party trusted institutions.
[0320] Exemplarily, the attribute information corresponding to Node #2 can be expressed as the correspondence between the identifier of Node #2 and the attributes and signature, such as scID2~{attributes, signature}, or {scID2, attributes, signature}, where scID2 represents the identifier of Node #2, attributes represents the attributes corresponding to Node #2, and signature represents the signature of Node #1 on the attributes corresponding to Node #2.
[0321] Optionally, the attribute information corresponding to Node #2 can further include at least one of the following: the issuance time of the attributes, the validity period of the attributes, the identifier of Node #2, or the signature of the blockchain node on the attributes corresponding to Node #2, etc. Among them, the blockchain node can also sign the attributes corresponding to Node #2 using its private key.
[0322] It should be understood that in the embodiments of the present application, Node #1 can provide one or more proven attributes for Node #2. Different attributes can also correspond to different Node #1s. Therefore, different attributes can correspond to different signatures, and different attributes can also correspond to the same signature. This is not limited.
[0323] In a possible design 1, the attribute information corresponding to Node #2 obtained from Node #1 that provides different attribute endorsement services can be pre-stored on the blockchain where the blockchain node is located or on the blockchain node. The attribute information has passed signature verification. Exemplarily, the blockchain node can query and obtain the attributes signed by Node #2 according to the identifier of Node #2 in Request #2, the type of attributes requested by Node #2, etc., so as to obtain the attribute information corresponding to Node #2.
[0324] In a possible design 2, a blockchain node deploys a smart contract corresponding to the attribute endorsement service provided by different node #1. The blockchain node can call the corresponding smart contract according to request #2 to generate attribute information. Exemplarily, the blockchain node can select the smart contract corresponding to the attribute endorsement service according to the attribute type requested by node #2 in request #2, and input relevant parameters into the selected smart contract, such as the identifier of node #2 and / or the identity proof information corresponding to node #2, etc., so as to obtain the attribute information corresponding to node #2 through the smart contract. Among them, the specific implementation process of the blockchain node deployment and how to use the smart contract corresponding to the attribute endorsement service can refer to the relevant descriptions in the Figure 2 smart contract installation interaction process shown above, which will not be elaborated here.
[0325] In a possible design 3, the blockchain node or other blockchain nodes on the blockchain where it is located are nodes providing attribute endorsement / verification services. The blockchain node can locally generate or obtain attribute information from the blockchain.
[0326] Thus, node #2 can obtain an attribute with credibility through the attribute information. Optionally, the attribute information corresponding to node #2 can be sent in the response corresponding to request #2, or can be sent in other messages, which is not limited here.
[0327] Optionally, after generating the attribute information corresponding to node #2, the blockchain node can record it on the blockchain and store the address of the attribute information corresponding to node #2 on the blockchain.
[0328] Furthermore, the blockchain node can also send the address of the attribute information corresponding to node #2 on the blockchain to node #2, so as to facilitate node #2 to prove the authenticity of its attribute in the process of interacting with other nodes based on the attribute in the future. In a possible implementation, the blockchain node can send information #4 to node #2. Correspondingly, node #2 receives information #4 from the blockchain node. Among them, information #4 is used to indicate the address of the attribute information corresponding to node #2 on the blockchain.
[0329] Optionally, information #4 can be sent in the same message as the attribute information, or can be sent separately in different messages, which is not limited here. In the embodiments of the present application, information #4 can also be referred to as the first information, or rather, information #4 corresponds to the first information.
[0330] Based on Figure 3 the communication method shown above, node #2 can obtain the endorsed attributes from node #1 providing different attribute endorsement services on the blockchain, so as to obtain attribute characteristics with credibility.
[0331] In addition to the above Figure 3In addition to the communication method shown, an embodiment of the present application further provides a communication method. In this communication method, a node (i.e., node #1) that provides endorsement services with different attributes can actively issue an attribute to a node (i.e., node #2) that requests to obtain an attribute, without node #2 triggering the acquisition. As Figure 4 shown, this communication method includes:
[0332] S401. Node #1 generates attribute information.
[0333] Among them, the attribute information is used to indicate the attributes corresponding to node #2 that have been endorsed / certified. The attribute information may include the attributes corresponding to node #2 and the signature of node #1 on the attributes corresponding to node #2. Among them, node #1 signs the attributes corresponding to node #2 using the private key. Exemplarily, the attribute information may be expressed as {scID2, attribute, signature}. Optionally, the attribute information may further include the identifier of node #2.
[0334] In an embodiment of the present application, node #1 can provide attribute endorsement / certification services for node #2 it serves, that is, node #1 indicates the attributes of node #2 that have been signed and endorsed by it to node #2 in the form of attribute information. It should be understood that node #1 can provide corresponding attribute certifications for different nodes #2, and issue the certified attributes to the corresponding nodes #2 in the form of attribute information.
[0335] In addition to actively issuing its attribute information to node #2, in a possible implementation, node #1 can also issue attribute information to node #2 according to the trigger of node #2. Exemplarily, node #2 sends request #2 to node #1. Correspondingly, node #1 receives request #2 from node #2. Among them, request #2 is used to request to obtain an attribute. The specific description of request #2 can refer to the relevant description of request #2 in S301 above, and will not be elaborated here.
[0336] S402. Node #1 sends the attribute information to node #2. Correspondingly, node #2 receives the attribute information from node #1.
[0337] After obtaining the attribute information, node #1 sends the attribute information to node #2. Correspondingly, after receiving the attribute information, node #2 can verify the signature in the attribute information using the public key. When the signature verification passes, node #2 obtains its corresponding attributes. For example, the attributes corresponding to node #2 in the attribute information include that node #2 is a formal employee in the organization corresponding to node #1, and the working years of node #2 in the organization corresponding to node #2 is 3 years, etc.
[0338] In a possible design, node #1 can also send attribute information to the blockchain node. Correspondingly, the blockchain node receives the attribute information from node #1. Thus, after receiving the attribute information, the blockchain node can also verify the signature in the attribute information using the public key. When the signature verification passes, the authenticity of the attribute is determined, and thus the attribute information can be recorded on the blockchain.
[0339] Optionally, the attribute information corresponding to node #2 can be sent in the response corresponding to request #2, or can be sent in other messages, and there is no limitation on this.
[0340] Optionally, the blockchain node can also feedback the address of the attribute information on the blockchain to node #1. In a possible implementation, the blockchain node sends message #4 to node #1. Correspondingly, node #1 receives message #4 from the blockchain node. Among them, message #4 is used to indicate the address of the attribute information on the blockchain. Thus, node #1 can know the storage address or record address of the attribute information on the blockchain according to message #4.
[0341] Furthermore, after node #1 obtains message #4, it can also send message #4 to node #2 to inform node #2 of the location of its corresponding attribute information on the blockchain, so as to facilitate node #2 to prove the authenticity of its attribute in the process of interacting with other nodes based on the attribute. Optionally, message #4 can be sent in the same message as the attribute information, or can be sent separately in different messages, and there is no limitation on this. In the embodiments of the present application, message #4 can also be referred to as the first message, or rather, message #4 corresponds to the first message.
[0342] Thus, based on Figure 4 the communication method shown, node #1 can directly provide attribute proof for node #2 so that node #2 can obtain an attribute with credibility.
[0343] It should be noted that the above Figure 3 and Figure 4 show the processes of node #2 obtaining the corresponding attribute information in two scenarios respectively. As can be seen from the above, both the blockchain node and node #1 can issue the corresponding attribute information for it based on the request of node #2, or can actively issue the corresponding attribute information to node #2. Therefore, in the embodiments of the present application, Figure 3 the blockchain node shown in Figure 4 and node #1 shown in
[0344] In addition, an embodiment of this application further provides a communication method, which is applicable to the scenario where Node #2 is a terminal device. The operator stores the proven attributes of the terminal device in the UICC by means of over-the-air card writing, such as displaying the proven attributes of the calling user in the user's incoming call interface. This communication method will be described by taking the communication between the node providing operator services (hereinafter referred to as the operator node) and the terminal device (Node #2) as shown in Figure 1 as an example. As shown in Figure 5 , this communication method includes:
[0345] S501. The operator node determines that the first terminal device and the second terminal device are connected to the network corresponding to the operator node.
[0346] Regarding the specific implementation process of the terminal device accessing the operator network in S501, reference can be made to the relevant description of the process of the terminal device accessing the network in the existing implementation method, and details will not be elaborated here.
[0347] S502. When it is determined that the first terminal device receives a call request from the second terminal device, the operator node sends the attributes corresponding to the second terminal device to the first terminal device. Correspondingly, when the first terminal device receives a call request from the second terminal device, the first terminal device receives the attributes corresponding to the second terminal device from the operator node.
[0348] That is to say, the operator node can, when the first terminal device receives a call request, inform the first terminal device of the attributes of the second terminal device that will be in a call with it, so that the first terminal device can identify the identity of the second terminal device through the attributes. Exemplarily, the operator node displays the attributes of the incoming second terminal device on the incoming call interface of the first terminal device. For example, the identity of the second terminal device is "courier", and the second terminal device is currently located in "Beijing".
[0349] In a possible scenario 1, the operator node can be the above-mentioned Node #1, which can locally provide an attribute endorsement service for the second terminal device, thereby generating the attributes corresponding to the second terminal device.
[0350] In a possible scenario 2, the operator node can obtain the attribute information corresponding to the second terminal device from the blockchain, so as to obtain the endorsed / proven attributes of the second terminal device. Among them, the attribute information corresponding to the second terminal device may include the identifier of the second terminal device, the attributes corresponding to the second terminal device, and the signature of Node #1 on the attributes corresponding to the second terminal device, etc. For the specific description of the attribute information, reference can be made to the relevant description of the attribute information in S302 above, and details will not be elaborated here.
[0351] In this scenario 2, in a possible implementation, the operator node may send Request #3 to the blockchain node. Correspondingly, the blockchain node receives Request #3 from the operator node. Among them, Request #3 is used to request the attributes corresponding to the second terminal device. Thus, the blockchain node sends the attribute information corresponding to the second terminal device to the operator node according to Request #3. Correspondingly, the operator node receives the attribute information corresponding to the second terminal device from the blockchain node. Among them, the specific description of Request #3 can refer to the relevant description of Request #2 in S301 or Request #2 in S401 above, which will not be elaborated here; the specific implementation process for the blockchain node to obtain the attribute information corresponding to the second terminal device can refer to the relevant description of Designs 1 to 3 in S302 above, which will not be elaborated here. In the embodiments of the present application, Request #3 may also be referred to as the Sixth Request, or rather, Request #3 corresponds to the Sixth Request.
[0352] Based on Figure 5 the communication method shown, the operator node can introduce the proven attributes of the user during the call between users to achieve the interconnection of credibility and enhance the security of telecom network services.
[0353] The above Figures 2 - 5 detailed the process of how Node #2 obtains the credible attributes. Further, based on this credible attribute, data access control for Node #2 can also be implemented, and the traceability of the access record can be ensured. Exemplarily, Figure 6 is a schematic flowchart of a communication method provided by an embodiment of the present application. This communication method is applicable to Figure 1 the communication between the node that requests to obtain attributes shown (i.e., Node #2 above), the node that provides data services (hereinafter referred to as Node #4), the blockchain node, and the node that provides storage services (hereinafter referred to as the storage node).
[0354] As Figure 6 shown, this communication method includes:
[0355] S601. Node #2 sends Request #4 to Node #4. Correspondingly, Node #4 receives Request #4 from Node #2.
[0356] Request #4 is a request initiated by Node #2 for accessing data. For example, Request #4 is used to request access to the data of Node #4. Request #4 includes the attribute information corresponding to Node #2. The attribute information corresponding to Node #2 includes the attribute corresponding to Node #2 and the signature of Node #1 on the attribute corresponding to Node #2. Among them, the process for Node #2 to obtain its corresponding attribute information can refer to the above Figures 2 - 5It can be obtained through any implementation method, and no further elaboration will be made here; the specific description of the attribute information corresponding to node #2 can also refer to the above - related description, and no further elaboration will be made here. Optionally, the attribute information corresponding to node #2 may also include the identifier of node #2, which can form a triple - tuple information of identifier, attribute, and signature.
[0357] That is to say, when node #2 needs to access the data of node #4, node #2 can generate and send request #4 to node #4 to apply for accessing the data of node #4. It should be understood that request #4 may also include access - data information such as the data type and data volume size that node #2 requests to access, to indicate the specific data content that node #2 wants to obtain. In the embodiment of the present application, request #4 can also be referred to as the second request, and node #4 can also be referred to as the fifth node. Or rather, request #4 corresponds to the second request, and node #4 corresponds to the fifth node.
[0358] In a possible design, node #2 needs to establish a security authentication with node #4 before it can perform data interaction with node #4. In other words, before node #2 sends request #4, it needs to complete a security authentication with node #4 to establish a secure connection for interaction.
[0359] In this design, node #4 can perform a security authentication with node #2 by verifying the identifier of node #2. In a possible implementation, node #2 sends identifier information to node #4. Correspondingly, node #2 receives identifier information from node #4. The identifier information may include the identifier of node #2, the identifier of node #1 related to the identifier of node #2, and the signature of node #1 related to the identifier of node #2, etc. The identifier of node #1 related to the identifier of node #2 is used to identify node #1 that assigns an identifier to node #2, and the signature of node #1 related to the identifier of node #2 refers to the signature of node #1 that assigns an identifier to node #2 for the identifier assigned to node #2, to prove the authenticity and legality of the identifier of node #2.
[0360] After node #4 obtains the identifier information of node #2, it can verify the identifier of node #2 by using the credential information of node #1 related to the identifier of node #2. When the identifier of node #2 passes the verification, node #4 determines to establish a security authentication with node #2. At this time, it is considered that the security authentication between node #2 and node #4 is completed, so that node #4 can establish a secure connection with node #2.
[0361] Exemplarily, the credential information of node #1 related to the identifier of node #2 can be the certificate of node #1 related to the identifier of node #2. This certificate of node #1 can include the public key, the digital signature of the public key, the information indicating the issuing authority of the public key, and the information indicating the owner of the public key (such as the identifier of node #1 related to the identifier of node #2), etc. Thus, node #4 can use the public key in the credential information to verify the signature of node #1 related to the identifier of node #2 in the identifier information. If the verification passes, it is considered that the identifier of node #2 is legal and authentic. In other words, if the verification passes, it is considered that node #2 is the real owner of the identifier. Thus, node #4 can establish a secure connection with node #2.
[0362] It should be understood that if the identifier of node #2 fails the verification, a secure connection cannot be established between node #2 and node #4.
[0363] Regarding the credential information of node #1 related to the identifier of node #2, node #4 can obtain it from the blockchain according to the identifier of node #2 and / or the identifier of node #1 related to the identifier of node #2. It can be understood that node #1 related to the identifier of node #2 publishes its credential information on the blockchain, so that node #4 can obtain the corresponding credential information from the blockchain. Alternatively, node #4 can directly obtain the corresponding credential information from the corresponding node #1 according to the identifier of node #1 related to the identifier of node #2. There is no limitation on this.
[0364] Thus, only when the security authentication is completed can node #2 send request #4 to node #4. Correspondingly, node #4 can receive request #4 from node #2.
[0365] Optionally, in the scenario where the attribute information corresponding to node #2 is published on the blockchain, request #4 can also include the address of the attribute information corresponding to node #2 on the blockchain, so that node #4 can query according to this address whether the attribute information corresponding to node #2 stored on the blockchain is consistent with the attribute information corresponding to node #2 carried in request #4 to verify the attribute information.
[0366] S602. Node #4 determines whether node #2 meets the requirement of accessing the data of node #4 according to the attribute information corresponding to node #2 and the proof information.
[0367] Among them, the proof information is used to verify the attributes corresponding to node #2, that is, the proof information is used to verify whether the attributes corresponding to node #2 carried in request #4 are the true and legal attributes of node #2, or whether node #2 is the real owner of the attributes. Exemplarily, the proof information includes the credential information of node #1 related to the attributes corresponding to node #2. Among them, node #1 related to the attributes corresponding to node #2 refers to the node that provides attribute endorsement services for node #2, which can be one or more, such as the devices corresponding to social authoritative institutions, the devices corresponding to third-party trusted institutions, and the credential information can be the certificate of node #1 related to the attributes corresponding to node #2, including the public key, the digital signature of the public key, the information indicating the issuing authority of the public key, and the information indicating the owner of the public key, etc.
[0368] Optionally, the proof information may further include the hash of the attributes corresponding to node #2, or the attributes corresponding to node #2, so as to verify whether the attributes corresponding to node #2 carried in request #4 are consistent with those in the proof information.
[0369] It should be understood that there may be one or more attributes corresponding to node #2, and the nodes #1 related to different attributes may be different, so the corresponding signature and credential information are also different.
[0370] That is to say, for node #4 in S602 to determine whether node #2 meets the requirement of accessing the data of node #4, it includes at least the following two verification processes:
[0371] Verification process 1: After obtaining request #4, node #4 can use the proof information to first verify the attributes corresponding to node #2 in request #4 to determine whether the attributes corresponding to node #2 in request #4 are true and legal, that is, to judge whether node #2 is the real owner of the attributes.
[0372] Exemplarily, node #4 verifies the signature in the attribute information corresponding to node #2 in request #4 according to the public key in the proof information. If the signature verification passes, it is considered that the attributes corresponding to node #2 in request #4 are true and legal, and the following verification process 2 is continued. Otherwise, it is considered that the attributes corresponding to node #2 in request #4 are untrustworthy, and node #4 can reject request #4, not support node #2 to access its data, or not authorize node #2 to access its data.
[0373] For the proof information, in a possible design, node #4 can obtain it from the blockchain, that is, the proof information is deployed on the blockchain. Node #4 can obtain the corresponding proof information from the blockchain according to the identifier of node #2 and / or the identifier of node #1 related to the attributes corresponding to node #2. Exemplarily, node #4 sends request #5 to the blockchain node. Correspondingly, the blockchain node receives request #5 from node #4. Among them, request #5 is used to request to obtain the proof information corresponding to node #2, and request #5 can include the identifier of node #1 related to the attributes corresponding to node #2, the identifier of node #2, etc. Thus, the blockchain node can obtain the proof information from the local or the blockchain where it is located according to request #5 and send the proof information to node #4. Optionally, the proof information corresponding to node #2 can be sent in the response corresponding to request #5, or can be sent in other messages, which is not limited herein. In the embodiments of the present application, request #5 can also be referred to as the third request, or rather, request #5 corresponds to the third request.
[0374] In addition to the above possible design, node #4 can also obtain the proof information from node #1 related to the attributes corresponding to node #2, which is not limited herein.
[0375] After completing the above verification process 1 and passing the verification, the following verification process 2 is executed: Node #4 determines whether it meets the requirements for accessing the data of node #4 according to the verified attributes corresponding to node #2. Among them, the requirements for accessing the data of node #4 are set according to the requirements for the attributes corresponding to node #2, which can be referred to as access policies, access conditions, etc., which is not limited herein.
[0376] Exemplarily, the requirements for accessing the data of node #4 are: (employees of Company A or employees of Company B or employees of Company C) and currently located in the country. The attributes corresponding to node #2 in request #4 include that node #2 is an employee of Company B and node #2 is currently located in the country. Thus, node #4 can determine that node #2 meets the requirements for accessing the data of node #4 according to the attributes corresponding to node #2 in request #4, so as to accept the data access request of node #2 or authorize node #2 to access the data.
[0377] On the contrary, if node #2 does not meet the requirements for accessing the data of node #4, for example, the attributes corresponding to node #2 in request #4 include that node #2 is an employee of Company B and node #2 is currently located abroad, then node #4 does not accept the data access request of node #2 or prohibits node #2 from accessing the data.
[0378] For node #2 that meets the requirement of accessing the data of node #4, node #4 can send the response corresponding to request #4 to node #2 to indicate that it can access the data of node #4. In a possible design 1, the response corresponding to request #4 may carry the data that node #2 wants to access. Thus, node #2 can obtain the access data according to the response corresponding to request #4.
[0379] In a possible design 2, to reduce the complexity of data access, node #4 can encrypt its data and store it uniformly on the storage node, and publish the information for accessing the data on the blockchain, so that node #2 that accesses the data can obtain the information for accessing the data from the blockchain and complete the data access.
[0380] Under this design 2, to enable node #2 to decrypt the encrypted data of node #4 obtained, when node #4 determines that node #2 meets the requirement of accessing the data of node #4, it can also generate and send a first key to node #2, that is, node #4 can send the first key to node #2, where the first key is used to decrypt the encrypted data of node #4, and the first key can be determined according to the attributes corresponding to node #2. Optionally, the first key can be sent in the response corresponding to the above request #4, or can be sent in other messages, and there is no limitation on this.
[0381] In addition, node #4 can also record the access situation of node #2 on the blockchain. In a possible implementation, node #4 sends the information indicating the access record of node #2 to the blockchain node. Correspondingly, the blockchain node receives the information indicating the access record of node #2 from node #4. Among them, the information indicating the access record of node #2 can be used to indicate when and where node #2 accessed what data of node #4. Thus, the blockchain node records the access situation of node #2.
[0382] In addition, under the above design 2, the communication method provided by the embodiments of the present application may further include the following steps:
[0383] S603, Node #4 sends the information for data access to the blockchain node. Correspondingly, the blockchain node receives the information for data access from node #4.
[0384] Among them, the information for data access is used to indicate how to access the data stored by node #4. The information for data access can be configured as a profile of node #4. The information for data access includes the information indicating the requirements that node #2 needs to meet to access the data of node #4 and the information indicating how to obtain the data of node #4.
[0385] The information used to indicate the requirements that the data accessed by Node #2 from Node #4 must meet can be referred to as an access policy or access condition, which is the requirement of Node #4 for Node #2 that requests to access the data, and can be set according to the attribute requirements corresponding to Node #2.
[0386] The information used to indicate obtaining the data of Node #4 may include the storage address where the encrypted data of Node #4 is located, and / or the information used to indicate the encrypted data of Node #4. Among them, the storage address where the encrypted data of Node #4 is located is used to indicate the location of the storage node storing the encrypted data of Node #4, and the information used to indicate the encrypted data of Node #4 can be represented by an index or a data feature description, so as to facilitate querying data of the corresponding type or feature.
[0387] In the embodiments of the present application, the encryption of the data of Node #4 may adopt symmetric key encryption or asymmetric key encryption, which is not limited herein. For example, Node #4 encrypts its data using a second key.
[0388] Optionally, the information used to indicate obtaining the data of Node #4 may further include the encrypted second key (i.e., the ciphertext of the second key). For example, the second key is K, and the encryption method for the second key may be ciphertext-policy attribute-based encryption (CPABE), and the ciphertext of the second key encrypted by CPABE is K1.
[0389] Thus, after the blockchain node obtains the information for data access corresponding to Node #4, it can publish or trade this information on the blockchain. Optionally, the blockchain node can send the address of the information for data access corresponding to Node #4 on the blockchain to Node #4.
[0390] Furthermore, Node #2 can obtain the information for data access from the blockchain. When Node #2 meets the requirements for accessing the data of Node #4, that is, Node #2 is authorized to access the data of Node #4, Node #2 can obtain the encrypted data of Node #4 from the storage node according to the information for indicating obtaining the data of Node #4 in the information for data access, as described in S604 below.
[0391] It should be understood that the embodiments of the present application do not limit the execution order of S603 and S601 - S602. S603 may be executed before S601 - S602, or after them.
[0392] S604: Node #2 sends Request #6 to the blockchain node. Correspondingly, the blockchain node receives Request #6 from Node #2.
[0393] Among them, Request #6 is used to request information for accessing the data of Node #4, and Request #6 includes the identifier of Node #4. Thus, after receiving Request #6, the blockchain node can query the information for data access corresponding to Node #4 based on the identifier of Node #4 and send it to Node #2. In the embodiments of the present application, Request #6 can also be referred to as the fourth request, or rather, Request #6 corresponds to the fourth request.
[0394] S605. The blockchain node sends the information for data access to Node #2. Correspondingly, Node #2 receives the information for data access from the blockchain node.
[0395] In a possible implementation, the information for data access can be sent carried in the response corresponding to Request #6, or can also be sent carried in other messages, and this is not limited.
[0396] Thus, after Node #2 receives the information for data access from the blockchain node, it can obtain the encrypted data of Node #4 based on the information for data access.
[0397] It should be understood that the embodiments of the present application do not limit the execution order of S604 - S605 and S601 - S602 either. S604 - S605 can be executed before S601 - S602, or can also be executed after them.
[0398] Optionally, Node #2 can also execute the above S601 according to the information indicating the requirements that need to be met for Node #2 to access the data of Node #4, so as to obtain the permission to access the data of Node #4. At this time, S604 can be executed before S601.
[0399] S606. Node #2 sends Request #7 to the storage node. Correspondingly, the storage node receives Request #7 from Node #2.
[0400] After Node #2 obtains the information for data access, it can determine the location of the storage node according to the storage address in the information indicating the data of Node #4 to be obtained, and send Request #7 to the corresponding storage node. Among them, Request #7 is used to request to obtain the data of Node #4, and Request #7 includes the identifier of Node #4, the index or feature description corresponding to the data of Node #4 that Node #2 wants to obtain. In the embodiments of the present application, Request #7 can also be referred to as the seventh request, or rather, Request #7 corresponds to the seventh request.
[0401] S607. The storage node sends the encrypted data of Node #4 to Node #2. Correspondingly, Node #2 receives the encrypted data of Node #4 from the storage node.
[0402] In a possible implementation, the data of node #4 after encryption can be sent in the response corresponding to request #7, or can be sent in other messages, and there is no restriction on this.
[0403] After node #2 obtains the data of node #4 after encryption, it can decrypt the data of node #4 after encryption according to the obtained first key to obtain the data of node #4.
[0404] In a possible design, the data of node #4 after encryption is the data of node #4 encrypted by the second key, and the first key can be used to decrypt the encrypted second key. That is to say, node #2 can decrypt to obtain the second key according to the first key, and then use the second key to decrypt to obtain the data of node #4, or node #2 can directly decrypt to obtain the data of node #4 according to the first key.
[0405] Based on Figure 6 The shown communication method, node #4 performs data access control on node #2 according to the attribute information corresponding to node #2, which can improve the reliability and security of data access.
[0406] In addition to the above Figure 6 shown data access control of node #2 by node #4, the blockchain node can also perform data access control on node #2 in the way of calling a smart contract. Exemplarily, Figure 7 is a schematic flowchart of another communication method provided by an embodiment of the present application. As Figure 7 shown, this communication method includes:
[0407] S701. Node #2 sends request #8 to the blockchain node. Correspondingly, the blockchain node receives request #8 from node #2.
[0408] Request #8 is used to request to call the first smart contract, and the first smart contract is used to determine whether node #2 can access the data of node #4. In other words, request #8 is used to request the blockchain node to call the first smart contract to determine whether node #2 can access the data of node #4. Among them, request #8 can include information such as the identifier of node #2, the identifier of node #4, the identifier of the first smart contract, and parameter information used as the input of the first smart contract. In the embodiments of the present application, request #8 can also be referred to as the eighth request, or in other words, request #8 corresponds to the eighth request.
[0409] In the embodiments of the present application, the first smart contract may be set based on the requirements for the attributes of node #2. Therefore, the parameter information used as the input of the first smart contract may be the attribute information corresponding to node #2. The attribute information corresponding to node #2 may include the attributes corresponding to node #2 and the signature of node #1 related to the attributes corresponding to node #2. For specific descriptions, reference may be made to the relevant descriptions of the attributes corresponding to node #2 in S601 above, and details will not be elaborated here.
[0410] In some possible designs, the identifier of node #2 and / or the identifier of node #4 may also be used as the input parameters of the first smart contract.
[0411] The first smart contract can be understood as being used to provide data access authorization services for node #2. Node #2 instructs the blockchain node to call the first smart contract through request #8 to determine whether it can access the data of node #4. In one possible implementation, the first smart contract may be requested by node #4 to be installed on the blockchain. The installation process of the first smart contract can be referred to Figure 1 the shown smart contract installation process, and details will not be elaborated here. Thus, the blockchain node can obtain the usage information corresponding to the first smart contract, such as the service type corresponding to the first smart contract, the input parameter settings of the first smart contract, the output parameter settings of the first smart contract, etc. Reference may be made to the relevant descriptions of information #3 above, and details will not be elaborated here.
[0412] S702. The blockchain node determines whether node #2 can access the data of node #4 according to request #8 and the first smart contract.
[0413] After obtaining request #8, the blockchain node can call the first smart contract according to request #8, input the parameters in request #8 as the input parameters of the first smart contract into the first smart contract, and determine whether node #2 can access the data of node #4 according to the output of the first smart contract. The first smart contract can be regarded as an access policy set.
[0414] In one possible design, the input of the first smart contract includes the attribute information corresponding to node #2, and the output of the first smart contract is used to indicate whether node #2 can access the data of node #4. Among them, the output of the first smart contract may include a first output, and the first output may be represented by 0 or 1. When the first output is 0, it indicates that node #2 cannot access the data of node #4, and when the first output is 1, it indicates that node #2 can access the data of node #4.
[0415] After the blockchain node completes the judgment, the blockchain node may send a response corresponding to request #8 to node #2, and the response corresponding to request #8 is used to indicate whether node #2 can access the data of node #4. Exemplarily, the response corresponding to request #8 carries indication information 1, and the indication information 1 can indicate whether node #2 can access the data of node #4 through 1 bit. For example, a bit value of 1 is used to indicate that node #2 can access the data of node #4, and a bit value of 0 is used to indicate that node #2 cannot access the data of node #4. Thus, after receiving the response corresponding to request #8, node #2 can determine whether it can access the data of node #4.
[0416] In the scenario where the data of node #4 is encrypted and stored by node #4 in a storage node outside the blockchain, the output of the first smart contract may further include a second output, and the second output is used to indicate the first key for decrypting the encrypted data of node #4. When node #2 can access the data of node #4, the second output may be a non-null first key; when node #2 cannot access the data of node #4, the second output may be a first key with a null value.
[0417] In this scenario, when node #2 can access the data of node #4, the blockchain node also needs to send the first key to node #2. The first key may be sent in the response corresponding to the above request #8, or may be sent using other messages.
[0418] In this scenario, in one possible design, the first key can directly decrypt the encrypted data of node #4 to obtain the data of node #4. In another possible design, the first key is used to decrypt an encrypted second key, and the second key is used to encrypt the data of node #4. That is, the data of node #4 is encrypted by node #4 using the second key and then stored in the storage node. At this time, the data of node #4 needs to be decrypted by the first key to obtain the second key, and then the encrypted data of node #4 is decrypted by the second key.
[0419] Thus, node #2 can obtain the encrypted data of node #4 from the storage node and decrypt the data of node #4 according to the first key. Among them, the specific implementation process for node #2 to obtain the encrypted data from the storage node can refer to the relevant descriptions in S603 - S607 above, and will not be elaborated here.
[0420] In addition, the blockchain node can also generate and record the access situation of node #2, such as recording the access situation on the blockchain to record what data of node #4 node #2 accessed at what time and where.
[0421] Based on Figure 7In the shown communication method, the blockchain node can call the first smart contract to perform data access control on Node #2 according to the attribute information corresponding to Node #2, which can improve the reliability and security of data access.
[0422] In each of the above embodiments, the method and / or steps implemented by the blockchain node can also be implemented by components available for the blockchain node (such as a processor, a chip, a chip system, a circuit, a logic module, or software); the method and / or steps implemented by Node #1 can also be implemented by components available for Node #1 (such as a processor, a chip, a chip system, a circuit, a logic module, or software); the method and / or steps implemented by Node #2 can also be implemented by components available for Node #2 (such as a processor, a chip, a chip system, a circuit, a logic module, a DU, or software); the method and / or steps implemented by Node #3 can also be implemented by components available for Node #3 (such as a processor, a chip, a chip system, a circuit, a logic module, or software); the method and / or steps implemented by Node #4 can also be implemented by components available for Node #4 (such as a processor, a chip, a chip system, a circuit, a logic module, or software); the method and / or steps implemented by the operator node can also be implemented by components available for the operator node (such as a processor, a chip, a chip system, a circuit, a logic module, or software); the method and / or steps implemented by the storage node can also be implemented by components available for the storage node (such as a processor, a chip, a chip system, a circuit, a logic module, or software).
[0423] The above mainly introduces the solution provided by the present application. Correspondingly, the present application also provides a communication device, which is used to implement various methods in the above method embodiments. The communication device can be Node #1 in the above method embodiments, or a device including Node #1, or a component available for Node #1, such as a chip or a chip system. Or, the communication device can be Node #2 in the above method embodiments, or a device including Node #2, or a component available for Node #2, such as a chip or a chip system. Or, the communication device can be Node #3 in the above method embodiments, or a device including Node #3, or a component available for Node #3, such as a chip or a chip system. Or, the communication device can be Node #4 in the above method embodiments, or a device including Node #4, or a component available for Node #4, such as a chip or a chip system. Or, the communication device can be the operator node in the above method embodiments, or a device including the operator node, or a component available for the operator node, such as a chip or a chip system. Or, the communication device can be the storage node in the above method embodiments, or a device including the storage node, or a component available for the storage node, such as a chip or a chip system.
[0424] In some embodiments, in order to implement the above functions, the communication device includes the corresponding hardware structures and / or software modules for executing each function. Those skilled in the art should easily realize that, for each example of the units and algorithm steps described in combination with the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the manner of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.
[0425] The embodiments of the present application can divide the functional modules of the communication device according to the above method embodiments. For example, each functional module can be divided corresponding to each function, or two or more functions can be integrated into one processing module. The above integrated modules can be implemented in the form of hardware or in the form of software functional modules. It should be noted that the division of modules in the embodiments of the present application is illustrative, only a logical function division, and there can be other division methods in actual implementation.
[0426] Taking the communication device as any one of nodes #1 to #4, or the operator node or the storage node in the above method embodiments as an example, Figure 8 is a schematic structural diagram of a communication device provided by an embodiment of the present application. As Figure 8 shown, the communication device 800 includes: a processing module 801 and a transceiver module 802. Among them, the processing module 801 is used to execute the processing functions of any one of nodes #1 to #4, or the operator node or the storage node in the above method embodiments. The transceiver module 802 is used to execute the transceiver functions of any one of nodes #1 to #4, or the operator node or the storage node in the above method embodiments.
[0427] Among them, all relevant contents of each step involved in the above method embodiments can be cited in the function descriptions of the corresponding functional modules, and will not be repeated here.
[0428] Since the communication device 800 provided in this embodiment can execute the above method, the technical effects it can obtain can refer to the above method embodiments and will not be repeated here.
[0429] In a possible design solution, in the embodiments of the present application, the transceiver module 802 may include a receiving module and a sending module ( Figure 8 not shown in the figure). Among them, the sending module and the receiving module are respectively used to implement the sending function and the receiving function of the communication device 800.
[0430] In a possible design, the communication device 800 may further include a storage module ( Figure 8 not shown in Figures 2 - 7 ), and the storage module stores programs or instructions. When the processing module 801 executes the programs or instructions, the communication device 800 can perform the functions of any one of nodes #1 to #4, or the operator node or the storage node, in any of the methods shown in
[0431] In some embodiments, the processing module 801 involved in the communication device 800 may be implemented by a processor or processor-related circuit components, and may be a processor or a processing unit; the transceiver module 802 may be implemented by a transceiver or transceiver-related circuit components, and may be a transceiver or a transceiver unit.
[0432] Exemplarily, Figure 9 FIG. Figure 9 shows a schematic structural diagram of another communication device provided by an embodiment of the present application. The communication device may be any one of nodes #1 to #4 in the above method embodiment, or an operator node or a storage node, or may be a chip (system) or other components or assemblies that can be disposed in any one of nodes #1 to #4, or an operator node or a storage node. As
[0433] shown in Figure 9 , the communication device 900 may include a processor 901. In a possible design, the communication device 900 may further include a memory 902 and / or a transceiver 903. Among them, the processor 901 is coupled to the memory 902 and the transceiver 903, and may be connected through a communication bus, for example.
[0434] Among them, the processor 901 is the control center of the communication device 900, and may be a single processor or a collective term for multiple processing elements. For example, the processor 901 includes one or more CPUs, and may also be a specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application. For example: one or more digital signal processors (DSPs), or one or more field programmable gate arrays (FPGAs).
[0435] In a possible design, the processor 901 can execute various functions of the communication device 900 by running or executing software programs stored in the memory 902 and calling data stored in the memory 902.
[0436] In a specific implementation, as an example, the processor 901 may include one or more CPUs, such as Figure 9 the CPU0 and CPU1 shown in
[0437] In a specific implementation, as an example, the communication device 900 may also include multiple processors, such as Figure 9 the processor 901 and the processor 904 shown in. Each of these processors may be a single-core processor or a multi-core processor. The processor here may refer to one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions).
[0438] Among them, the memory 902 is used to store the software program for executing the solution of this application and is controlled by the processor 901 for execution. The specific implementation method may refer to the above method embodiments and will not be elaborated here.
[0439] In a possible design, the memory 902 may be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM), or other optical disc storage (including compressed optical discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), a magnetic disk storage medium, or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but not limited to this. The memory 902 may be integrated with the processor 901 or exist independently and is coupled to the processor 901 through the interface circuit of the communication device 900 ( Figure 9 not shown in), and this application embodiment does not make specific limitations on this.
[0440] The transceiver 903 is used for communication with other communication devices. For example, when the communication device 900 is a terminal device, the transceiver 903 can be used to communicate with the access network device or another terminal device. Another example is that when the communication device 900 is a network device, the transceiver 903 can be used to communicate with the terminal device or another network device.
[0441] In a possible design, the transceiver 903 may include a receiver and a transmitter (Figure 9 is not shown separately). Among them, the receiver is used to implement the receiving function, and the transmitter is used to implement the sending function.
[0442] In a possible design solution, the transceiver 903 may be integrated with the processor 901, or may exist independently, and is coupled to the processor 901 through the interface circuit of the communication device 900 ( Figure 9 not shown in the figure), and the embodiments of the present application do not make specific limitations on this.
[0443] It should be noted that Figure 9 the structure of the communication device 900 shown in the figure does not constitute a limitation on the communication device. The actual communication device may include more or fewer components than shown in the figure, or combine certain components, or have different component arrangements.
[0444] In addition, the technical effects of the communication device 900 may refer to the technical effects of the method described in the above method embodiments, and will not be elaborated here.
[0445] The embodiments of the present application also provide a computer-readable storage medium, on which a computer program or instruction is stored. When the computer program or instruction is executed by the computer, the functions of the above method embodiments are implemented.
[0446] The embodiments of the present application also provide a computer program product. When the computer program product is executed by the computer, the functions of the above method embodiments are implemented.
[0447] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using a software program, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions according to the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from a website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that the computer can access or a data storage device such as a server or data center that contains one or more media integrated therein. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid state disk (SSD)), etc.
[0448] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. A professional technician can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.
[0449] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be described herein again.
[0450] In several embodiments provided by this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of the device or unit can be in electrical, mechanical, or other forms.
[0451] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0452] In addition, in each embodiment of this application, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.
[0453] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or an access network device, etc.) to execute all or part of the steps of the methods described in each embodiment of this application. The foregoing storage medium includes: USB flash drives, mobile hard disks, ROM, random access memory RAM, magnetic disks, or optical discs and other various media that can store program codes.
[0454] Although this application is described in combination with various embodiments herein, however, in the process of implementing the claimed application, those skilled in the art can understand and implement other variations of the disclosed embodiments by viewing the drawings, the disclosure content, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "one" does not exclude a plurality of cases. A single processor or other unit can implement several functions listed in the claims. Certain measures are recited in mutually different dependent claims, but this does not mean that these measures cannot be combined to produce good results.
[0455] Although the present application has been described in connection with specific features and their embodiments, it will be apparent that various modifications and combinations can be made without departing from the spirit and scope of the present application. Accordingly, the present specification and the drawings are merely exemplary illustrations of the present application as defined by the appended claims, and are considered to cover any and all modifications, variations, combinations, or equivalents within the scope of the present application. Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these changes and modifications.
Claims
1. A communication method, characterized in that, The method includes: The first node obtains attribute information, where the attribute information is used to indicate the attributes corresponding to the second node that has been authenticated; The first node sends the attribute information to the second node.
2. The method according to claim 1, wherein The method further includes: The first node sends first information to the second node, where the first information is used to indicate the address of the attribute information on the blockchain.
3. The method according to claim 1 or 2, characterized in that, The obtaining of the attribute information includes: The first node receives a first request from the second node, where the first request is used to request to obtain attributes; The first node sends the attribute information to the second node according to the first request.
4. The method according to claim 3, wherein The first node sending the attribute information to the second node according to the first request includes: The first node generates the attribute information according to the first request using a smart contract, where the smart contract is associated with an attribute endorsement service; The first node sends the attribute information to the second node.
5. A communication method, characterized in that, The method includes: The second node receives the attribute information from the first node, where the attribute information is used to indicate the attributes corresponding to the second node that has been authenticated; The second node determines the attributes corresponding to the second node according to the attribute information.
6. The method according to claim 5, wherein The method further includes: The second node receives first information from the first node, where the first information is used to indicate the address of the attribute information on the blockchain.
7. The method according to claim 5 or 6, characterized in that, The method further includes: The second node sends a first request to the first node, where the first request is used to request to obtain attributes.
8. The method according to any one of claims 3, 4 or 7, characterized in that The first request includes at least one of the following: the identifier of the second node, information indicating the type of the attribute to be requested, the identity authentication information corresponding to the second node, or the signature of the third node on the identity authentication information corresponding to the second node.
9. The method according to any one of claims 1 - 8, characterized in that, The attribute information includes the attributes corresponding to the second node and the signature of the fourth node related to the attributes corresponding to the second node.
10. A communication method, characterized in that, The method includes: The fifth node receives a second request from the second node, where the second request is used to request to access the data of the fifth node, and the second request includes the attribute information corresponding to the second node; The fifth node determines whether the second node meets the requirement for accessing the data of the fifth node according to the attribute information corresponding to the second node and the proof information, where the proof information is used to verify the attributes corresponding to the second node.
11. The method according to claim 10, wherein The second request further includes the address of the attribute information corresponding to the second node on the blockchain.
12. The method according to claim 10 or 11, characterized in that, The method further includes: The fifth node sends a third request to the blockchain node, where the third request is used to request to obtain the proof information; The fifth node receives the proof information from the blockchain node.
13. The method according to any one of claims 10 to 12, characterized in that The method further includes: When the second node meets the requirement for accessing the data of the fifth node, the fifth node sends a first key to the second node, where the first key is determined according to the attributes corresponding to the second node, and the first key is used to decrypt the encrypted data of the fifth node.
14. The method according to claim 13, wherein The method further includes: The fifth node sends information for data access to the blockchain node, and the information for data access includes information for indicating requirements that the data accessed by the second node from the fifth node needs to meet and information for indicating obtaining the data of the fifth node.
15. The method according to claim 14, characterized in that, The information for indicating obtaining the data of the fifth node includes the encrypted storage address where the data of the fifth node is located, and / or information for indicating the encrypted data of the fifth node.
16. The method according to claim 15, characterized in that, The data of the fifth node is encrypted with a second key, and the information for indicating obtaining the data of the fifth node further includes: the encrypted second key, and the first key is specifically used to decrypt the encrypted second key.
17. A communication method, characterized in that, The method includes: The second node generates a second request for requesting access to the data of the fifth node, and the second request includes the attribute information corresponding to the second node. The second node sends the second request to the fifth node.
18. The method according to claim 17, wherein The second request further includes the address of the attribute information corresponding to the second node on the blockchain.
19. The method according to claim 17 or 18, characterized in that, The method further includes: The second node receives a first key from the fifth node, and the first key is determined according to the attribute corresponding to the second node, and the first key is used to decrypt the encrypted data of the fifth node.
20. The method according to claim 19, wherein The method further includes: The second node sends a fourth request to the blockchain node, and the fourth request is used to request obtaining information for accessing the data of the fifth node. The second node receives the information for data access from the blockchain node, and the information for data access includes information for indicating requirements that the second node needs to meet when accessing the data of the fifth node and information for indicating obtaining the data of the fifth node. The second node obtains the encrypted data of the fifth node according to the information for data access. The second node decrypts the encrypted data of the fifth node according to the first key.
21. The method according to claim 20, characterized in that, The information for indicating obtaining the data of the fifth node includes the encrypted storage address where the data of the fifth node is located, and / or information for indicating the encrypted data of the fifth node.
22. The method according to claim 21, wherein The data of the fifth node is encrypted with a second key, and the information for indicating obtaining the data of the fifth node further includes: the encrypted second key, and the first key is specifically used to decrypt the encrypted second key.
23. The method according to claim 22, wherein The second node decrypting the encrypted data of the fifth node according to the first key includes: The second node decrypts the encrypted second key according to the first key. The second node decrypts the data of the fifth node encrypted with the second key according to the second key.
24. A communication device, characterized in that, Includes a module for executing the method according to any one of claims 1-23.
25. A communication device, characterized in that, Includes: A processor; The processor is used to run a computer program or instruction so that the method according to any one of claims 1-23 is implemented.
26. A communication chip, characterized in that, Instructions are stored therein, which cause the method according to any one of claims 1-23 to be implemented when the chip runs on a communication device.
27. A computer-readable storage medium, characterized in that, A computer program or instructions are stored in the storage medium, and when the computer program or instructions are executed by a communication device, the method according to any one of claims 1-23 is implemented.
28. A computer program product, characterized in that, It includes computer program code, and when the computer program code runs on a communication device, the communication device implements the method according to any one of claims 1-23.
Citation Information
Cited By
Communication method and apparatus
WO2025152988A1