Communication method and device, equipment and storage medium
Through the combination of blockchain network and storage system, the first node acquires and decrypts the subscription data of the terminal device, solving the problem of authentication failure during roaming of the terminal device and achieving stable and secure communication quality.
Patent Information
- Application Number
- CN202410114715.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-26
- Publication Date
- 2025-07-29
AI Technical Summary
When terminal devices roam, real-time interaction between the service network and the home network leads to failure of authentication, affecting communication quality, especially when the home network is closed, the subscription data cannot be obtained.
Through the combination of the blockchain network and the storage system, the first node receives the key and data storage address, acquires and decrypts the subscribed data ciphertext of the terminal device, avoids direct interaction with the home network, and uses the separation of the data storage address of the blockchain network and the ciphertext of the storage system to achieve stable and secure data acquisition.
Improve communication quality and security, avoid single point of failure problems of home network servers, and ensure the stability and security of communication.
Smart Images

Figure CN120390214A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and in particular, to a communication method, apparatus, device, and storage medium. Background Art
[0002] In the field of mobile communication, when a terminal device roams and accesses a serving network, the serving network can obtain subscription data of the terminal device from the home network where the terminal device is registered.
[0003] Currently, the serving network, the home network, and the terminal device can complete the authentication of the terminal device based on multiple interactions, and the serving network obtains the subscription data of the terminal device according to the authentication result. However, in the above method, real-time interaction between the serving network and the home network is required when the terminal device performs authentication, which may cause authentication failure when the home network is closed, and further cause the serving network to be unable to obtain the subscription data of the terminal device, affecting the communication quality. Summary of the Invention
[0004] This application relates to a communication method, apparatus, device, and storage medium, which are used to solve the technical problem of poor communication quality in the prior art.
[0005] In a first aspect, this application provides a communication method, which includes:
[0006] A first node receives a first key and a data storage address sent by a node in a blockchain network;
[0007] The first node obtains a ciphertext of subscription data of a terminal device in a storage system according to the data storage address;
[0008] The first node decrypts the ciphertext of the subscription data according to the first key and the private key of the first node to obtain the subscription data.
[0009] In an implementation, the ciphertext of the subscription data is a ciphertext obtained by encrypting the subscription data by a second node using a symmetric key, and the terminal device is a device registered in the second node.
[0010] In an implementation, the first key includes a second key obtained by encrypting a symmetric key with a public key of the second node and a third key obtained by encrypting a public key of the first node with a private key of the second node.
[0011] In an implementation, the first node receives a first key and a data storage address sent by a node in a blockchain network, including:
[0012] The first node receives a first request sent by the terminal device, where the first request is used to request to provide network services to the terminal device;
[0013] The first node sends a second request to the nodes in the blockchain network, where the second request is used to obtain the subscription data of the terminal device;
[0014] The first node receives the first key and the data storage address sent by the nodes in the blockchain network.
[0015] In one implementation, the second request is a request processed by encrypting based on the private key of the first node.
[0016] In one implementation, the second request includes the identifier of the terminal device.
[0017] In one implementation, the first node obtains the ciphertext of the subscription data of the terminal device in the storage system according to the data storage address, including:
[0018] The first node sends the data storage address to the storage system;
[0019] The first node receives the ciphertext of the subscription data sent by the storage system.
[0020] In one implementation, the first node decrypts the ciphertext of the subscription data according to the first key and the private key of the first node to obtain the subscription data, including:
[0021] The first node decrypts according to the second key and the third key to obtain the key for encrypting the public key of the first node with the symmetric key;
[0022] The first node decrypts the key for encrypting the public key of the first node with the symmetric key according to the private key of the first node to obtain the symmetric key;
[0023] The first node decrypts the ciphertext of the subscription data according to the symmetric key to obtain the subscription data.
[0024] In a second aspect, the present application provides a communication method, and the communication method includes:
[0025] The second node encrypts the subscription data of the terminal device according to the symmetric key to obtain the ciphertext of the subscription data, and sends the ciphertext of the subscription data to the storage system;
[0026] The second node generates a first key, and sends the first key to the nodes in the blockchain network, where the first key is used to decrypt the ciphertext of the subscription data.
[0027] In one embodiment, the second node encrypts the subscription data of the terminal device according to the symmetric key to obtain the ciphertext of the subscription data, including:
[0028] The second node randomly generates a symmetric key;
[0029] The second node encrypts the subscription data according to the symmetric key to obtain the ciphertext of the subscription data.
[0030] In one embodiment, the second node generates a first key, including:
[0031] The second node encrypts the symmetric key according to the public key of the second node to obtain a second key;
[0032] The second node encrypts the public key of the first node according to the private key of the second node to obtain a third key;
[0033] Wherein, the first key includes the second key and the third key, and the first node is a network that provides network services to the terminal device.
[0034] In one embodiment, before the second node generates the first key, the method further includes:
[0035] The second node signs a roaming agreement with the first node and generates a third key;
[0036] The second node sends the third key to the nodes in the blockchain network.
[0037] In a third aspect, the present application provides a communication method, and the communication method includes:
[0038] A node in the blockchain network receives a second request sent by the first node, and the second request is used to obtain the subscription data of the terminal device;
[0039] The node in the blockchain network sends a first key and a data storage address to the first node according to the second request, where the first key is used to decrypt the ciphertext of the subscription data, and the data storage address is the storage address of the ciphertext of the subscription data.
[0040] In one embodiment, the node in the blockchain network sends a first key and a data storage address to the first node according to the second request, including:
[0041] The node in the blockchain network verifies the second request based on a pre-set protocol to obtain the first key and the data storage address;
[0042] The nodes in the blockchain network send a first key and a data storage address to the first node.
[0043] In one implementation, the nodes in the blockchain network verify the second request based on a pre-set protocol to obtain the first key and the data storage address, including:
[0044] The nodes in the blockchain network verify the second request according to a first protocol to obtain a verification result;
[0045] If the verification result is verification passed, the nodes in the blockchain network obtain the first key according to a second protocol and obtain the data storage address according to a third protocol.
[0046] Fourthly, the present application provides a communication method, and the communication method includes:
[0047] A storage system receives a ciphertext of subscribed data sent by a second node;
[0048] The storage system stores the ciphertext of the subscribed data and sends a data storage address corresponding to the ciphertext of the subscribed data to a node in the blockchain network.
[0049] In one implementation, after the storage system sends the data storage address to a node in the blockchain network, the method further includes:
[0050] The storage system receives a data storage address sent by the first node;
[0051] The storage system obtains the ciphertext of the subscribed data according to the data storage address;
[0052] The storage system sends the ciphertext of the subscribed data to the first node.
[0053] Fifthly, the present application provides a communication device, and the communication device includes a receiving module, an obtaining module, and a processing module, where:
[0054] The receiving module is configured to receive a first key and a data storage address sent by a node in the blockchain network;
[0055] The obtaining module is configured to obtain a ciphertext of subscribed data of a terminal device in a storage system according to the data storage address;
[0056] The processing module is configured to perform decryption processing on the ciphertext of the subscribed data according to the first key and the private key of the first node to obtain the subscribed data.
[0057] In one embodiment, the ciphertext of the subscription data is the ciphertext obtained by the second node encrypting the subscription data with a symmetric key, and the terminal device is a device registered in the second node.
[0058] In one embodiment, the first key includes a second key obtained by encrypting a symmetric key with the public key of the second node and a third key obtained by encrypting the public key of the first node with the private key of the second node.
[0059] In one embodiment, the receiving module is specifically configured to:
[0060] The first node receives a first request sent by a terminal device, where the first request is used to request to provide network services to the terminal device;
[0061] The first node sends a second request to the nodes in the blockchain network, where the second request is used to obtain the subscription data of the terminal device;
[0062] The first node receives the first key and the data storage address sent by the nodes in the blockchain network.
[0063] In one embodiment, the second request is a request processed by encrypting with the private key of the first node.
[0064] In one embodiment, the second request includes an identifier of the terminal device.
[0065] In one embodiment, the obtaining module is specifically configured to:
[0066] The first node sends the data storage address to the storage system;
[0067] The first node receives the ciphertext of the subscription data sent by the storage system.
[0068] In one embodiment, the processing module is specifically configured to:
[0069] The first node decrypts according to the second key and the third key to obtain the key for encrypting the public key of the first node with the symmetric key;
[0070] The first node decrypts the key for encrypting the public key of the first node with the symmetric key according to the private key of the first node to obtain the symmetric key;
[0071] The first node decrypts the ciphertext of the subscription data according to the symmetric key to obtain the subscription data.
[0072] Sixth aspect, the present application provides a communication device, which includes an encryption module, a sending module, and a generating module, where:
[0073] The encryption module is configured to encrypt the subscription data of the terminal device according to a symmetric key to obtain the ciphertext of the subscription data;
[0074] The sending module is configured to send the ciphertext of the subscription data to a storage system;
[0075] The generating module is configured to generate a first key;
[0076] The sending module is further configured to send the first key to a node in the blockchain network, and the first key is used to decrypt the ciphertext of the subscription data.
[0077] In one implementation, the encryption module is specifically configured to:
[0078] Randomly generate a symmetric key;
[0079] Encrypt the subscription data according to the symmetric key to obtain the ciphertext of the subscription data.
[0080] In one implementation, the generating module is specifically configured to:
[0081] Encrypt the symmetric key according to the public key of the second node to obtain a second key;
[0082] Encrypt the public key of the first node according to the private key of the second node to obtain a third key;
[0083] Wherein, the first key includes the second key and the third key, and the first node is a network that provides network services to the terminal device.
[0084] In one implementation, the generating module is further configured to:
[0085] Sign a roaming agreement with the first node and generate a third key;
[0086] Send the third key to a node in the blockchain network.
[0087] Seventh aspect, the present application provides a communication device, which includes a receiving module and a sending module, where:
[0088] The receiving module is configured to receive a second request sent by the first node, and the second request is used to obtain the subscription data of the terminal device;
[0089] The sending module is configured to send a first key and a data storage address to the first node according to the second request, where the first key is used to decrypt the ciphertext of the subscription data, and the data storage address is the storage address of the ciphertext of the subscription data.
[0090] In one implementation, the sending module is specifically configured to:
[0091] Verify the second request based on a pre-set protocol to obtain the first key and the data storage address;
[0092] Send the first key and the data storage address to the first node.
[0093] In one implementation, the sending module is specifically configured to:
[0094] Verify the second request according to a first protocol to obtain a verification result;
[0095] If the verification result is verification passed, obtain the first key according to a second protocol and obtain the data storage address according to a third protocol.
[0096] In an eighth aspect, the present application provides a communication device, which includes a receiving module, a storage module, and a sending module, where:
[0097] The receiving module is configured to store the ciphertext of the subscription data sent by the second node in the storage system;
[0098] The storage module is configured to store the ciphertext of the subscription data in the storage system;
[0099] The sending module is configured to send the data storage address corresponding to the ciphertext of the subscription data to a node in the blockchain network.
[0100] In one implementation, the sending module is further configured to:
[0101] Receive the data storage address sent by the first node;
[0102] Obtain the ciphertext of the subscription data according to the data storage address;
[0103] Send the ciphertext of the subscription data to the first node.
[0104] In a ninth aspect, the present application provides a communication device, including: a memory, a transceiver, and a processor:
[0105] The memory is used to store a computer program;
[0106] The transceiver is used to send and receive data under the control of the processor;
[0107] The processor is configured to read the computer program in the memory and perform the following operations:
[0108] Receive a first key and a data storage address sent by a node in the blockchain network;
[0109] Obtain the ciphertext of the subscription data of the terminal device in the storage system according to the data storage address;
[0110] Decrypt the ciphertext of the subscription data according to the first key and the private key of the first node to obtain the subscription data.
[0111] In a tenth aspect, the present application provides a communication device, including: a memory, a transceiver, and a processor:
[0112] The memory is used to store a computer program;
[0113] The transceiver is configured to transmit and receive data under the control of the processor;
[0114] The processor is configured to read the computer program in the memory and perform the following operations:
[0115] Encrypt the subscription data of the terminal device according to a symmetric key to obtain the ciphertext of the subscription data, and send the ciphertext of the subscription data to the storage system;
[0116] Generate a first key, and send the first key to a node in the blockchain network, where the first key is used to decrypt the ciphertext of the subscription data.
[0117] In an eleventh aspect, the present application provides a communication device, including: a memory, a transceiver, and a processor:
[0118] The memory is used to store a computer program;
[0119] The transceiver is configured to transmit and receive data under the control of the processor;
[0120] The processor is configured to read the computer program in the memory and perform the following operations:
[0121] Receive a second request sent by a first node, where the second request is used to obtain the subscription data of the terminal device;
[0122] According to the second request, send a first key and a data storage address to the first node, where the first key is used to decrypt the ciphertext of the subscription data, and the data storage address is the storage address of the ciphertext of the subscription data.
[0123] In a twelfth aspect, the present application provides a communication device, including: a memory, a transceiver, and a processor:
[0124] The memory is used for storing a computer program;
[0125] The transceiver is used for transceiving data under the control of the processor;
[0126] The processor is used for reading the computer program in the memory and performing the following operations:
[0127] Receiving the ciphertext of the subscription data sent by a second node;
[0128] Storing the ciphertext of the subscription data, and sending the data storage address corresponding to the ciphertext of the subscription data to a node in the blockchain network.
[0129] In a thirteenth aspect, the present application provides a processor-readable storage medium storing a computer program, and the computer program is used for causing a processor to execute the method described in the first aspect, or execute the method described in the second aspect, or execute the method described in the third aspect, or execute the method described in the fourth aspect.
[0130] The present application provides a communication method, device, equipment and storage medium. In this method, a first node can receive a first key and a data storage address sent by a node in the blockchain network. The first node can obtain the ciphertext of the subscription data of the terminal device in the storage system according to the data storage address. The first node can decrypt the ciphertext of the subscription data according to the first key and the private key of the first node to obtain the subscription data. In the above method, since the first node can obtain the ciphertext of the subscription data in the storage system based on the data storage address in the blockchain network, the first node can obtain the subscription data of the terminal device in real time, improving the stability and reliability of obtaining the subscription data, and further improving the communication quality. And since the storage address of the subscription data is in the blockchain network and the ciphertext of the subscription data is in the storage system, there is no need for direct interaction between the service network accessed by the terminal device and the home network of the terminal device, and the problem of single point of failure of the server in the home network can be avoided, thereby improving the communication security.
[0131] It should be understood that the content described in the above-mentioned invention content part is not intended to limit the key or important features of the embodiments of the present application, nor is it used to limit the scope of the present application. Other features of the present application will become easily understood through the following description. Description of the Drawings
[0132] To more clearly illustrate the technical solutions in the present application or the prior art, the following will briefly introduce the drawings required for the embodiments or the description of the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0133] Figure 1 Schematic diagram of a communication structure provided by an embodiment of the present application;
[0134] Figure 2 Flowchart of a communication method provided by an embodiment of the present application;
[0135] Figure 3 Another schematic diagram of a communication method provided by an embodiment of the present application;
[0136] Figure 4 Another schematic diagram of a communication method provided by an embodiment of the present application;
[0137] Figure 5 Another schematic diagram of a communication method provided by an embodiment of the present application;
[0138] Figure 6 Another schematic diagram of a communication method provided by an embodiment of the present application;
[0139] Figure 7 Process schematic diagram of a communication method provided by an embodiment of the present application;
[0140] Figure 8 Schematic diagram of the structure of a communication device provided by an embodiment of the present application;
[0141] Figure 9 Another schematic diagram of the structure of a communication device provided by an embodiment of the present application;
[0142] Figure 10 Another schematic diagram of the structure of a communication device provided by an embodiment of the present application;
[0143] Figure 11 Another schematic diagram of the structure of a communication device provided by an embodiment of the present application;
[0144] Figure 12 Schematic diagram of the structure of a communication device provided by an embodiment of the present application;
[0145] Figure 13 Another schematic diagram of the structure of a communication device provided by an embodiment of the present application;
[0146] Figure 14 Another schematic diagram of the structure of a communication device provided by an embodiment of the present application;
[0147] Figure 15 This is a schematic structural diagram of another communication device provided by an embodiment of the present application. Detailed implementation manners
[0148] In the embodiments of the present application, the term "and / or" describes the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally represents an "or" relationship between the associated objects before and after.
[0149] In the embodiments of the present application, the term "a plurality of" refers to two or more, and other quantifiers are similar.
[0150] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0151] The embodiments of the present application provide a communication method, apparatus, device, and storage medium. The first node can receive a first key and a data storage address sent by a node in the blockchain network, and obtain the ciphertext of the subscribed data in the storage system according to the data storage address. Then, according to the first key and the private key of the first node, decrypt the ciphertext of the subscribed data to obtain the subscribed data. In this way, the first node can obtain the subscribed data of the terminal device in the blockchain network and the storage system without interacting with the home network of the terminal device, improving communication stability and communication security.
[0152] Among them, the method and the apparatus are based on the same inventive concept. Since the principles of solving problems by the method and the apparatus are similar, the implementation of the apparatus and the method can be referred to each other, and the repeated parts will not be described again.
[0153] The technical solutions provided by the embodiments of this application can be applied to a variety of systems. For example, the applicable systems can be Long Term Evolution (LTE) systems, LTE Frequency Division Duplex (FDD) systems, LTE Time Division Duplex (TDD) systems, Long Term Evolution Advanced (LTE-A) systems, Universal Mobile Telecommunications System (UMTS), Worldwide Interoperability for Microwave Access (WiMAX) systems, 5G New Radio (NR) systems and their evolved communication systems, etc. These various systems may include terminal devices and network devices. The system may also include a core network part, such as an Evolved Packet System (EPS), a 5G System (5GS), etc.
[0154] The terminal device involved in the embodiments of the present application can be a device that provides voice and / or data connectivity to users, such as a handheld device with wireless connection capabilities, or other processing devices connected to a wireless modem, etc. In different systems, the name of the terminal device may also be different. For example, in a 5G system, the terminal device can be called a user equipment (UE). The wireless terminal device can be a USB storage device, other personal computer memory devices, and dongles. It can also communicate with one or more core networks (CN) via a radio access network (RAN). The wireless terminal device can be a mobile terminal device, such as a mobile phone (or a "cellular" phone) and a computer with a mobile terminal device. For example, it can be a portable, pocket-sized, handheld, computer-integrated, or vehicle-mounted mobile device that exchanges voice and / or data with the radio access network. For example, personal communication service (PCS) phones, cordless phones, session initiated protocol (SIP) phones, wireless local loop (WLL) stations, personal digital assistants (PDAs), personal computers, tablets, machine-type communication (MTC) terminal devices, and other devices. The wireless terminal device can also be called a system, subscriber unit, subscriber station, mobile station, mobile, remote station, access point, remote terminal, access terminal, user terminal, user agent, user device, and wireless access points and routers / modems that meet the limitations of this definition. The embodiments of the present application do not limit this.
[0155] In the field of mobile communication, when a terminal device roams and accesses a serving network, the serving network can obtain the subscription data of the terminal device from the home network where the terminal device is registered, and then can provide network services to the terminal device based on the subscription data. For example, when a terminal device roams and accesses a serving network, the operator of the serving network needs to request the subscription data of the terminal device from a centralized authentication server, where the authentication server is managed by the operator of the home network of the terminal device. Currently, the serving network, the home network, and the terminal device can complete the authentication of the terminal device based on multiple interactions, and the serving network can obtain the subscription data of the terminal device according to the authentication result. For example, when the terminal device needs to be authenticated, the terminal device can apply to the home network for an authentication vector for two-way authentication through the serving network. In this way, the serving network needs to interact with the terminal device and the home network multiple times.
[0156] However, the authentication server managed by the operator of the home network introduces a single point of failure. Moreover, during the process of the serving network obtaining the subscription data of the terminal device, the serving network needs to interact with the home network and the terminal device in real time. If the home network is shut down, it will cause the authentication of the terminal device to fail, and the serving network cannot obtain the subscription data of the terminal device, and thus cannot provide network services to the terminal device, affecting the communication quality.
[0157] To solve the above technical problems, an embodiment of the present application provides a communication method. A first node can receive a first request sent by a terminal device, where the first request is used to request to provide network services to the terminal device. The first node can send a second request to a node in the blockchain network, where the second request is used to obtain the subscription data of the terminal device. The first node can receive a first key and a data storage address sent by a node in the blockchain network. The first node obtains the ciphertext of the subscription data of the terminal device in the storage system according to the data storage address, and decrypts the ciphertext of the subscription data according to the first key and the private key of the first node to obtain the subscription data. In the above method, since the first key includes a second key obtained by encrypting a symmetric key with the public key of a second node and a third key (re-encryption key) obtained by encrypting the public key of the network providing network services with the private key of the second node, any network that provides network services to the terminal device can decrypt the ciphertext of the subscription data based on the first key and the private key of the network, saving communication resources and improving the security of the subscription data. Moreover, since there is no need for direct interaction between the serving network accessed by the terminal device and the home network of the terminal device, the communication security can be improved and the communication quality can be improved.
[0158] Next, in combination with Figure 1 , the communication structure of the embodiment of the present application will be described.
[0159] Figure 1Schematic diagram of a communication structure provided by an embodiment of this application. Please refer to Figure 1 , including: a blockchain network, a storage system, a first node, a second node, proxy server 1, and proxy server 2. The first node can be used to provide network services to a terminal device, and the terminal device can be a device registered with the second node. For example, the first node can be a service network node for roaming access by the terminal device, and the second node can be a node of the home network where the terminal device is located. Among them, the subscription data of the terminal device can be stored in the second node.
[0160] Please refer to Figure 1 , the first node can be connected to proxy server 1. Proxy server 1 can be a node registered in the blockchain network, and proxy server 1 can be used to connect the first node and the blockchain network. For example, the first node can upload data to the blockchain network based on proxy server 1, and the first node can also download data in the blockchain network based on proxy server 1.
[0161] Please refer to Figure 1 , the second node can be connected to proxy server 2. Proxy server 2 can be a node registered in the blockchain network, and proxy server 2 can be used to connect the second node and the blockchain network. For example, the second node can upload data to the blockchain network based on proxy server 2, and the second node can download data in the blockchain network based on this proxy server 2.
[0162] Please refer to Figure 1 , the storage system can be connected to a node in the blockchain network. The storage system can store the ciphertext of the subscription data of the terminal device, where the storage system can be a distributed file storage system. In this way, based on the blockchain network and the storage system, the storage and control of the subscription data of the terminal device can be separated, improving the accuracy of obtaining the subscription data. Moreover, there is no need for direct interaction between the service network accessed by the terminal device and the home network of the terminal device, and the problem of single-point failure of the server in the home network can be avoided, thereby improving communication security.
[0163] Next, the communication method provided by this application will be described in detail in combination with specific embodiments.
[0164] Figure 2 Flowchart of a communication method provided by an embodiment of this application. Please refer to Figure 2 , the method flow includes:
[0165] S201. The first node receives a first key and a data storage address sent by a node in the blockchain network.
[0166] Among them, the first node may be a network node that provides network services to a terminal device. For example, a core network that provides network services to a terminal device may be composed of the first nodes. When the terminal device roams and accesses the core network, the core network may provide network services to the terminal device based on the subscription data of the terminal device.
[0167] Among them, the first key may include a second key and a third key. Among them, the second key may be a key obtained by encrypting a symmetric key with the public key of the second node. For example, the terminal device may be a device registered with the second node. Therefore, the second node may obtain the subscription data of the terminal device. For example, if the public key of the second node may be PK1 and the symmetric key may be K, the second key may be PK1+K. It should be noted that the symmetric key may be a key randomly generated by the second node, and the embodiments of the present application do not limit this.
[0168] Among them, the third key may be a key obtained by encrypting the public key of the first node with the private key of the second node. For example, if the private key of the second node may be SK1 and the public key of the first node may be PK2, the third key may be SK1+PK2. Among them, the third key may be a re-encrypted key, and the second node may obtain the public key of the first node according to any feasible implementation manner, and the embodiments of the present application do not limit this.
[0169] Among them, the data storage address may be the address of the ciphertext of the subscription data of the terminal device in the storage system. For example, the storage system may obtain the ciphertext of the subscription data of the terminal device and store the ciphertext of the subscription data in the storage system. The storage system may obtain the data storage address corresponding to the ciphertext of the subscription data and store the data storage address of the ciphertext of the subscription data in the blockchain network.
[0170] Among them, the ciphertext of the subscription data may be a ciphertext obtained by the second node encrypting the subscription data with the symmetric key. For example, the second node may randomly generate a symmetric key and encrypt the subscription data of the terminal device with the symmetric key to obtain the ciphertext of the subscription data. After the second node obtains the ciphertext of the subscription data, it may store the ciphertext of the subscription data in the storage system.
[0171] It should be noted that the first key and the data storage address may be data pre-stored in the blockchain network. When the terminal device requests the first node to provide network services, the first node may receive the first key and the data storage address sent by the first target node in the blockchain network.
[0172] S202. The first node obtains the ciphertext of the subscription data of the terminal device in the storage system according to the data storage address.
[0173] Optionally, the first node can obtain the ciphertext of the subscription data of the terminal device in the storage system according to the following feasible implementation: The first node sends a data storage address to the storage system, and the first node receives the ciphertext of the subscription data sent by the storage system.
[0174] For example, after the first node receives the data storage address sent by the node in the blockchain network, it can send the data storage address to the storage system. The storage system can obtain the ciphertext of the subscription data according to the data storage address and send the ciphertext of the subscription data to the first node.
[0175] S203. The first node decrypts the ciphertext of the subscription data according to the first key and the private key of the first node to obtain the subscription data.
[0176] Among them, the first node can obtain the subscription data according to the following feasible implementation: The first node decrypts according to the second key and the third key to obtain the ciphertext of the symmetric key encrypted with the public key of the first node. The first node decrypts the key of the symmetric key encrypted with the public key of the first node according to the private key of the first node to obtain the symmetric key. The first node decrypts the ciphertext of the subscription data according to the symmetric key to obtain the subscription data. For example, the second key can be PK1 (public key of the second node) + K (symmetric key), the third key can be SK1 (private key of the second node) + PK2 (public key of the first node), and the ciphertext of the subscription data can be K + subscription data. After the first node obtains the second key and the third key, it can decrypt according to PK1 in the second key and SK1 in the third key to obtain K + PK2. The first node can decrypt K + PK2 according to the private key SK2 of the first node to obtain K, and then can decrypt K + subscription data according to K to obtain the subscription data. In this way, any first node can decrypt the ciphertext of the subscription data in combination with the first key according to its own private key, saving communication resources.
[0177] The embodiment of the present application provides a communication method. The first node receives the first key and the data storage address sent by the first target node in the blockchain network. The first node obtains the ciphertext of the subscription data of the terminal device in the storage system according to the data storage address. The first node decrypts the ciphertext of the subscription data according to the first key and the private key of the first node to obtain the subscription data. In this way, the first node can decrypt the ciphertext of the subscription data based on the first key and the private key of the first node. And since the third key in the first key is obtained by encrypting the public key of the first node with the private key of the second node, the second node does not need to set up a complex decryption key for the network providing network services, which can save communication resources. And since there is no need for direct interaction between the service network accessed by the terminal device and the home network of the terminal device, the communication security can be improved and the communication quality can be improved.
[0178] Based on the embodiments shown below, in conjunction with Figure 2 , the above communication method will be described in detail. Figure 3
[0179] Figure 3 It is a schematic diagram of another communication method provided by an embodiment of this application. Please refer to Figure 3 , and the method flow includes:
[0180] S301. The terminal device sends a first request to the first node.
[0181] Among them, the first request is used to request to provide network services to the terminal device. For example, the first node can receive the first request sent by the terminal device and provide network services to the terminal device according to the first request. For example, when a user UE registered in the second node roams into the service range of the first node, it can send a first request to the first node, and the first node can provide communication services to the user UE.
[0182] S302. The first node sends a second request to the nodes in the blockchain network.
[0183] Among them, the second request can be used to obtain the subscription data of the terminal device. For example, when the first node provides network services to the terminal device, the first node can obtain the subscription data of the terminal device, and then provide network services to the terminal device based on the subscription data. Optionally, the second request can be a request encrypted based on the private key of the first node. For example, the first node can generate a request to obtain the subscription data of the terminal device and encrypt the request based on the private key of the first node to obtain the second request. In this way, the nodes in the blockchain network can verify the first node according to the public key of the first node and the second request. For example, in the actual application process, the nodes in the blockchain network can verify the first node that requests to obtain the subscription data to determine whether the first node can obtain the subscription data of the terminal device (such as, the first node signs a roaming agreement with the second node, etc.).
[0184] Optionally, the second request may include the identifier of the terminal device. For example, the second request may include the identifier of the terminal device, so that the nodes in the blockchain network can determine the data storage address corresponding to the terminal device according to the identifier of the terminal device.
[0185] S303. The nodes in the blockchain network send a first key and a data storage address to the first node according to the second request.
[0186] Optionally, a node in the blockchain network may verify the first node according to the second request. If the verification is passed, the node in the blockchain network may send the first key and the data storage address to the first node. For example, the nodes in the blockchain network may include the public keys of multiple networks that are allowed to obtain subscription data. If a node in the blockchain network can decrypt the second request according to any one of the public keys, it indicates that the first node is a network that is allowed to obtain subscription data. The node in the blockchain network may send the first key and the data storage address to the first node. If a node in the blockchain network cannot decrypt the second request based on multiple public keys, it indicates that the first node is a network that is not allowed to obtain subscription data. The node in the blockchain network may refuse to send the first key and the data storage address to the first node.
[0187] S304. The first node sends the data storage address to the storage system.
[0188] Among them, after the first node receives the data storage address sent by the node in the blockchain network, it may send the data storage address to the storage system.
[0189] S305. The storage system sends the ciphertext of the subscription data to the first node.
[0190] Among them, after the storage system receives the data storage address sent by the first node, it may obtain the ciphertext of the subscription data according to the data storage address and send the ciphertext of the subscription data to the first node.
[0191] S306. The first node decrypts the ciphertext of the subscription data according to the private key of the first node and the first key to obtain the subscription data.
[0192] It should be noted that the process of decrypting the ciphertext of the subscription data in step S306 may refer to step S203, which is not limited in this embodiment of the present application.
[0193] This embodiment of the present application provides a communication method. The terminal device sends a first request to the first node. The first node sends a second request to the node in the blockchain network. According to the second request, the first key and the data storage address are sent to the first node. The first node sends the data storage address to the storage system. The storage system sends the ciphertext of the subscription data to the first node. The first node decrypts the ciphertext of the subscription data according to the private key of the first node and the first key to obtain the subscription data. In this way, based on the blockchain network and the storage system, the storage and control of the subscription data of the terminal device can be separated, the accuracy of obtaining the subscription data and the security of the subscription data can be improved, and there is no need for direct interaction between the service network accessed by the terminal device and the home network of the terminal device, and the problem of single point of failure of the server in the home network can be avoided, thereby improving communication security.
[0194] Based on any of the above embodiments, hereinafter, in combination with Figure 4 , another communication method will be described.
[0195] Figure 4 It is a schematic diagram of another communication method provided by an embodiment of the present application. Please refer to Figure 4 , including:
[0196] S401. A node in the blockchain network receives a second request sent by a first node.
[0197] Among them, the second request is used to obtain subscription data of a terminal device, and a node in the blockchain network can receive the second request sent by the first node.
[0198] S402. The node in the blockchain network verifies the second request based on a pre-set protocol to obtain a first key and the data storage address.
[0199] Among them, the pre-set protocol can be used to verify the first node, determine the first key and the data storage address. For example, a node in the blockchain network can verify the first node that sends the second request based on the pre-set protocol. If the verification is passed, the node in the blockchain network can generate the first key based on the pre-set protocol and determine the data storage address based on the pre-set protocol.
[0200] Among them, the node in the blockchain network can obtain the first key and the data storage address according to the following feasible implementation manner: The node in the blockchain network verifies the second request according to a first protocol to obtain a verification result. If the verification result is that the verification is passed, the node in the blockchain network obtains the first key according to a second protocol and obtains the data storage address according to a third protocol.
[0201] Among them, the pre-set protocols may include a first protocol (ACCESS CONTROL, AC), a second protocol (RE-ENCRYPTION, RE), and a third protocol (ADRESS PROVIDING, AP). Among them, the first protocol AC can be used to verify the first node that sends the second request, the second protocol RE can generate a first key, and the third protocol AP can determine the data storage address where the ciphertext of the subscription data of the terminal device is stored in the storage system according to the identifier of the terminal device. For example, a node in the blockchain network can determine whether the public key stored in the blockchain network can decrypt the second request based on the first protocol. If it can be decrypted, it means that the verification of the first node by the first protocol is passed. A node in the blockchain network can generate a first key based on the second protocol RE, and set the preservation duration of the first key, and delete the first key when the first key reaches the preservation duration. A node in the blockchain network can determine the data storage address corresponding to the ciphertext of the subscription data of the terminal device according to the third protocol AP and the identifier of the terminal device in the second request.
[0202] Optionally, a node in the blockchain network can store a first correspondence, where the first correspondence may include the identifiers of at least one terminal device and the data storage address corresponding to each identifier. For example, the first correspondence can be as shown in Table 1:
[0203] Table 1
[0204] Identifier of the terminal device Data storage address Identifier 1 Address 1 Identifier 2 Address 2 Identifier 3 Address 3 …… ……
[0205] It should be noted that Table 1 is only an example of the first correspondence, not a limitation on the first correspondence.
[0206] For example, if the identifier of the terminal device in the second request is identifier 1, the node in the blockchain network can determine that the data storage address of the ciphertext of the subscription data of the terminal device in the storage system is address 1 based on the third protocol; if the identifier of the terminal device in the second request is identifier 2, the node in the blockchain network can determine that the data storage address of the ciphertext of the subscription data of the terminal device in the storage system is address 2 based on the third protocol; if the identifier of the terminal device in the second request is identifier 3, the node in the blockchain network can determine that the data storage address of the ciphertext of the subscription data of the terminal device in the storage system is address 3 based on the third protocol.
[0207] S403. The node in the blockchain network sends the first key and the data storage address to the first node.
[0208] Among them, nodes in the blockchain network may send a first key and a data storage address to the first node, or nodes in the blockchain network may separately send the first key and the data storage address to the first node. This application embodiment does not make a limitation on this.
[0209] An embodiment of this application provides a communication method. A node in the blockchain network receives a second request sent by the first node. The node in the blockchain network verifies the second request according to a first protocol to obtain a verification result. If the verification result is verification passed, the node in the blockchain network obtains a first key according to a second protocol and obtains a data storage address according to a third protocol. The node in the blockchain network sends the first key and the data storage address to the first node. In this way, nodes in the blockchain network can control access to subscribed data, and the access control of subscribed data can be separated from the storage of subscribed data, thereby improving the security of subscribed data.
[0210] Based on any of the above embodiments, below, in combination with Figure 5 , a detailed description of another communication method is given.
[0211] Figure 5 It is a schematic diagram of another communication method provided by an embodiment of this application. Please refer to Figure 5 , and the method process includes:
[0212] S501. The second node encrypts the subscribed data of the terminal device according to the symmetric key to obtain the ciphertext of the subscribed data.
[0213] Among them, the second node may be the home network of the terminal device. For example, the second node may be the home network registered by the terminal device, and this home network can obtain the subscribed data of the terminal device.
[0214] Among them, the second node may obtain the ciphertext of the subscribed data according to the following feasible implementation: The second node randomly generates a symmetric key, and the second node encrypts the subscribed data according to the symmetric key to obtain the ciphertext of the subscribed data. In this way, the security of the subscribed data can be improved.
[0215] Among them, the symmetric key may be an encryption method, and the second node may randomly generate the symmetric key based on any feasible implementation. This application embodiment does not make a limitation on this.
[0216] It should be noted that the method for the second node to encrypt the subscribed data according to the symmetric key will not be elaborated in this application embodiment.
[0217] Optionally, after obtaining the ciphertext of the subscription data, the second node may also periodically update the symmetric key and update the data related to the symmetric key. For example, the second key may periodically update the symmetric key, and thus may periodically update the ciphertext of the subscription data related to the symmetric key (the ciphertext obtained by encrypting the subscription data with the symmetric key), and the second key (the key obtained by encrypting the symmetric key with the public key of the second node), so as to improve the security of the subscription data.
[0218] S502. The second node sends the ciphertext of the subscription data to the storage system.
[0219] Among them, after obtaining the ciphertext of the subscription data, the second node may send the ciphertext of the subscription data to the storage system, and the storage system may store the ciphertext of the subscription data.
[0220] S503. The second node generates a first key.
[0221] Among them, the second node may generate the first key according to the following feasible implementation manner: the second node encrypts the symmetric key with the public key of the second node to obtain a second key, and the second node encrypts the public key of the first node with the private key of the second node to obtain a third key, where the first key includes the second key and the third key.
[0222] Among them, the second node may obtain the public key of the first node in the blockchain network, or may obtain the public key of the first node based on any feasible implementation manner, and the embodiments of the present application do not limit this.
[0223] Among them, since the third key may be the key obtained by encrypting the public key of the first node with the private key of the second node, the second node only needs to set the re-encryption key (the third key) for each network providing network services, and the network providing network services may accurately and securely obtain the subscription data of the terminal device according to its own private key, the second key, and the third key, thereby improving the security of the subscription data.
[0224] Among them, before the second node generates the first key, the above communication method further includes: the second node signs a roaming protocol with the first node, generates a third key, and the second node sends the third key to the nodes in the blockchain network.
[0225] Among them, the second node can generate a corresponding third key according to the signed roaming agreement. For example, if the second node signs a roaming agreement with the first node A, the second node can generate a third key of SK1 (private key of the second node) + PK2 (public key of the first node A). If the second node signs a roaming agreement with the first node B and the first node C, the second node can generate a third key of SK1 + PK3 (public key of the first node B) and a third key of SK1 + PK4 (public key of the first node C). After the second node generates the third key, it can send the third key to the nodes in the blockchain network, so that the blockchain network can implement access control to the service network.
[0226] For example, Table 2 can be the service network that signs a roaming agreement with the second node:
[0227] Table 2
[0228] Service network that has signed the roaming agreement Public key of the service network Third key Network A PK2 SK1 + PK2 Network B PK3 SK1 + PK3 Network C PK4 SK1 + PK4 …… …… ……
[0229] S504. The second node sends the first key to the nodes in the blockchain network.
[0230] Among them, the first key is used to decrypt the ciphertext of the subscription data. For example, the second node can send the second key (symmetric key encrypted by the public key of the second node) and the third key (public key of the first node encrypted by the private key of the second node) to the nodes in the blockchain network.
[0231] An embodiment of the present application provides a communication method. The second node encrypts the subscription data of the terminal device according to the symmetric key to obtain the ciphertext of the subscription data. The second node sends the ciphertext of the subscription data to the storage system. The second node generates the first key. The second node sends the first key to the nodes in the blockchain network. In this way, the second node can pre-send the first key to the nodes in the blockchain network and send the ciphertext of the subscription data to the storage system. Therefore, when the first node provides network services to the terminal device, it can interact with the nodes in the blockchain network and the storage system in real time, so as to obtain the subscription data, improve the stability of communication, and moreover, there is no need for the service network accessed by the terminal device to directly interact with the home network registered by the terminal device, improving the security of communication.
[0232] Based on any of the above embodiments, below, in combination with Figure 6 , a detailed description of another communication method will be given.
[0233] Figure 6 It is a schematic diagram of another communication method provided by an embodiment of the present application. Please refer to Figure 6 , including:
[0234] S601. The storage system receives the ciphertext of the subscription data sent by the second node.
[0235] S602. The storage system stores the ciphertext of the subscription data and sends the data storage address corresponding to the ciphertext of the subscription data to the nodes in the blockchain network.
[0236] After obtaining the ciphertext of the subscription data, the storage system can store the ciphertext of the subscription data, and the storage system can send the data storage address corresponding to the ciphertext of the subscription data to the nodes in the blockchain network, thereby realizing the separation of the access control of the access network and the storage of the subscription data, thereby improving the security of the subscription data and the security of communication.
[0237] S603. The storage system receives the data storage address sent by the first node.
[0238] S604. The storage system obtains the ciphertext of the subscription data according to the data storage address.
[0239] Among them, the storage system can obtain the ciphertext of the subscription data according to the data storage address. For example, the storage system may include the ciphertext of subscription data A, the ciphertext of subscription data B, and the ciphertext of subscription data C. If the data storage address received by the storage system stores the ciphertext of subscription data A, the storage system can obtain the ciphertext of subscription data A. If the data storage address received by the storage system stores the ciphertext of subscription data B, the storage system can obtain the ciphertext of subscription data B. If the data storage address received by the storage system stores the ciphertext of subscription data C, the storage system can obtain the ciphertext of subscription data C.
[0240] S605. The storage system sends the ciphertext of the subscription data to the first node.
[0241] The embodiment of the present application provides a communication method. The storage system receives the ciphertext of the subscription data sent by the second node, the storage system stores the ciphertext of the subscription data, and sends the data storage address corresponding to the ciphertext of the subscription data to the nodes in the blockchain network. The storage system receives the data storage address sent by the first node, the storage system obtains the ciphertext of the subscription data according to the data storage address, and the storage system sends the ciphertext of the subscription data to the first node. In this way, the nodes in the blockchain network can be used for access control of service network requests, and the storage system can store the subscription data of the terminal device, thereby realizing the separation of the storage and control of the subscription data and improving the security of the subscription data.
[0242] Based on any of the above embodiments, below, in combination with Figure 7 , the process of the above communication method will be described.
[0243] Figure 7 It is a schematic diagram of the process of a communication method provided by an embodiment of the present application. Please refer to Figure 7, including: a storage system, a second node, a first node, nodes in a blockchain network, and a terminal device. Among them, the second node can randomly generate a symmetric key, encrypt the subscription data of the terminal device according to the symmetric key to obtain the ciphertext of the subscription data, and the second node can send the ciphertext of the subscription data to the storage system. After receiving the ciphertext of the subscription data, the storage system can store the ciphertext of the subscription data and send the data storage address corresponding to the ciphertext of the subscription data to the nodes in the blockchain network. The second node can generate a first key (the public key of the second node encrypts the symmetric key, and the private key of the second node encrypts the public key of the first node), and send the first key to the nodes in the blockchain network. The nodes in the blockchain network can store the first key and the data storage address.
[0244] Please refer to Figure 7 , the terminal device sends a first request to the first node for requesting the first node to provide network services. After receiving the first request, the first node can send a second request for obtaining the subscription data of the terminal device to the nodes in the blockchain network. The nodes in the blockchain network can verify the first node. If the verification passes, the nodes in the blockchain network can determine the first key and the data storage address, and send the first key and the data storage address to the first node. After receiving the data storage address, the first node can send the data storage address to the storage system. The storage system can obtain the ciphertext of the subscription data according to the data storage address and send the ciphertext of the subscription data to the first node. After receiving the ciphertext of the subscription data, the first node can decrypt the ciphertext of the subscription data according to the private key of the first node and the first key to obtain the subscription data.
[0245] In this way, since the third key is a re-encryption key, the first node can decrypt the ciphertext of the subscription data according to its own private key and the first key. Moreover, since the access control of the service network and the storage of the subscription data are separated, the security of the subscription data can be improved. And since there is no need for direct interaction between the service network accessed by the terminal device and the home network of the terminal device, the security and stability of communication can be improved.
[0246] Figure 8 It is a schematic structural diagram of a communication device provided by an embodiment of the present application. Please refer to Figure 8 , the communication device 800 includes a receiving module 801, an obtaining module 802, and a processing module 803, where:
[0247] The receiving module 801 is configured to receive the first key and the data storage address sent by the nodes in the blockchain network;
[0248] The obtaining module 802 is configured to obtain the ciphertext of the subscription data of the terminal device in the storage system according to the data storage address;
[0249] The processing module 803 is configured to decrypt the ciphertext of the subscription data according to the first key and the private key of the first node to obtain the subscription data.
[0250] In one embodiment, the ciphertext of the subscription data is the ciphertext obtained by encrypting the subscription data by a second node using a symmetric key, and the terminal device is a device registered in the second node.
[0251] In one embodiment, the first key includes a second key obtained by encrypting the symmetric key with the public key of the second node and a third key obtained by encrypting the public key of the first node with the private key of the second node.
[0252] In one embodiment, the receiving module 801 is specifically configured to:
[0253] The first node receives a first request sent by a terminal device, where the first request is used to request to provide a network service to the terminal device;
[0254] The first node sends a second request to the nodes in the blockchain network, where the second request is used to obtain the subscription data of the terminal device;
[0255] The first node receives the first key and the data storage address sent by the nodes in the blockchain network.
[0256] In one embodiment, the second request is a request encrypted based on the private key of the first node.
[0257] In one embodiment, the second request includes the identifier of the terminal device.
[0258] In one embodiment, the obtaining module 802 is specifically configured to:
[0259] The first node sends the data storage address to the storage system;
[0260] The first node receives the ciphertext of the subscription data sent by the storage system.
[0261] In one embodiment, the processing module 803 is specifically configured to:
[0262] The first node decrypts according to the second key and the third key to obtain the key for encrypting the public key of the first node with the symmetric key;
[0263] The first node decrypts the key obtained by encrypting the public key of the first node with the symmetric key according to the private key of the first node to obtain the symmetric key;
[0264] The first node decrypts the ciphertext of the subscription data according to the symmetric key to obtain the subscription data.
[0265] Figure 9 It is a schematic structural diagram of another communication device provided by an embodiment of the present application. Please refer to Figure 9 The communication device 900 includes an encryption module 901, a sending module 902, and a generating module 903, where:
[0266] The encryption module 901 is configured to encrypt the subscription data of the terminal device according to a symmetric key to obtain the ciphertext of the subscription data;
[0267] The sending module 902 is configured to send the ciphertext of the subscription data to the storage system;
[0268] The generating module 903 is configured to generate a first key;
[0269] The sending module 902 is further configured to send the first key to a node in the blockchain network, and the first key is used to decrypt the ciphertext of the subscription data.
[0270] In an implementation manner, the encryption module 901 is specifically configured to:
[0271] Randomly generate a symmetric key;
[0272] Encrypt the subscription data according to the symmetric key to obtain the ciphertext of the subscription data.
[0273] In an implementation manner, the generating module 903 is specifically configured to:
[0274] Encrypt the symmetric key according to the public key of the second node to obtain a second key;
[0275] Encrypt the public key of the first node according to the private key of the second node to obtain a third key;
[0276] Wherein, the first key includes the second key and the third key, and the first node is a network that provides network services to the terminal device.
[0277] In an implementation manner, the generating module 903 is further configured to:
[0278] Sign a roaming agreement with the first node and generate a third key;
[0279] Send the third key to a node in the blockchain network.
[0280] Figure 10 This is a schematic structural diagram of another communication device provided by an embodiment of the present application. Please refer to Figure 10 , the communication device 1000 includes a receiving module 1001 and a sending module 1002, where:
[0281] The receiving module 1002 is configured to receive a second request sent by a first node, where the second request is used to obtain subscription data of a terminal device;
[0282] The sending module 1002 is configured to send a first key and a data storage address to the first node according to the second request, where the first key is used to decrypt the ciphertext of the subscription data, and the data storage address is the storage address of the ciphertext of the subscription data.
[0283] In one implementation manner, the sending module 1002 is specifically configured to:
[0284] Verify the second request based on a pre-set protocol to obtain the first key and the data storage address;
[0285] Send the first key and the data storage address to the first node.
[0286] In one implementation manner, the sending module 1002 is specifically configured to:
[0287] Verify the second request according to a first protocol to obtain a verification result;
[0288] If the verification result is verification passed, obtain the first key according to a second protocol and obtain the data storage address according to a third protocol.
[0289] Figure 11 This is a schematic structural diagram of another communication device provided by an embodiment of the present application. Please refer to Figure 11 , the communication device 1100 includes a receiving module 1101, a storage module 1102, and a sending module 1103, where:
[0290] The receiving module 1101 is configured to store the ciphertext of the subscription data received by the storage system from a second node;
[0291] The storage module 1102 is configured to store the ciphertext of the subscription data by the storage system;
[0292] The sending module 1103 is configured to send the data storage address corresponding to the ciphertext of the subscription data to a node in the blockchain network.
[0293] In one implementation manner, the sending module 1103 is further configured to:
[0294] Receive the data storage address sent by the first node;
[0295] Obtain the ciphertext of the subscribed data according to the data storage address;
[0296] Send the ciphertext of the subscribed data to the first node.
[0297] It should be noted that the division of units in the embodiments of the present application is illustrative. It is only a logical function division, and there may be other division methods in actual implementation. In addition, in each embodiment of the present application, each functional unit may be integrated in a processing unit, or each unit may exist physically alone, or two or more units may be integrated in one unit. The above integrated units may be implemented in the form of hardware or in the form of software functional units.
[0298] If the above integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a processor-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) or a processor to execute all or part of the steps of the methods in the embodiments of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.
[0299] It should be noted here that the above device provided by the present application can implement all the method steps implemented by the above method embodiments and can achieve the same technical effects. The same parts and beneficial effects as those in the method embodiments in this embodiment will not be specifically described herein.
[0300] Figure 12 It is a schematic structural diagram of a communication device provided by an embodiment of the present application. Please refer to Figure 12 , the communication device includes a memory 1210, a transceiver 1220, and a processor 1230:
[0301] The memory 1210 is used to store computer programs;
[0302] The transceiver 1220 is used to send and receive data under the control of the processor;
[0303] The processor 1230 is configured to read the computer program in the memory and perform the following operations:
[0304] Receive a first key and a data storage address sent by a node in the blockchain network;
[0305] Obtain the ciphertext of the subscription data of the terminal device in the storage system according to the data storage address;
[0306] Decrypt the ciphertext of the subscription data according to the first key and the private key of the first node to obtain the subscription data.
[0307] In one embodiment, the ciphertext of the subscription data is the ciphertext obtained by the second node encrypting the subscription data with a symmetric key, and the terminal device is a device registered in the second node.
[0308] In one embodiment, the first key includes a second key obtained by encrypting the symmetric key with the public key of the second node and a third key obtained by encrypting the public key of the first node with the private key of the second node.
[0309] In one embodiment, the first node receiving the first key and the data storage address sent by a node in the blockchain network includes:
[0310] Receive a first request sent by the terminal device, where the first request is used to request to provide network services to the terminal device;
[0311] Send a second request to the nodes in the blockchain network, where the second request is used to obtain the subscription data of the terminal device;
[0312] Receive the first key and the data storage address sent by the nodes in the blockchain network.
[0313] In one embodiment, the second request is a request encrypted based on the private key of the first node.
[0314] In one embodiment, the second request includes the identifier of the terminal device.
[0315] In one embodiment, the first node obtaining the ciphertext of the subscription data of the terminal device in the storage system according to the data storage address includes:
[0316] Send the data storage address to the storage system;
[0317] Receive the ciphertext of the subscription data sent by the storage system.
[0318] In one embodiment, the first node decrypts the ciphertext of the subscription data according to the first key and the private key of the first node to obtain the subscription data, including:
[0319] Decrypt according to the second key and the third key to obtain the key for encrypting the public key of the first node with the symmetric key;
[0320] Decrypt the key for encrypting the public key of the first node with the symmetric key according to the private key of the first node to obtain the symmetric key;
[0321] Decrypt the ciphertext of the subscription data according to the symmetric key to obtain the subscription data.
[0322] Among them, in Figure 12 The bus architecture may include any number of interconnected buses and bridges, specifically, various circuits represented by one or more processors represented by the processor 1203 and the memory represented by the memory 1210 are linked together. The bus architecture can also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art, so they will not be further described herein. The bus interface provides an interface. The transceiver 1220 may be multiple elements, that is, including a transmitter and a receiver, and provides a unit for communicating with various other devices on a transmission medium, and these transmission mediums include wireless channels, wired channels, optical fiber cables, and other transmission mediums. The processor 1230 is responsible for managing the bus architecture and general processing, and the memory 1201 may store data used by the processor 1230 when executing operations.
[0323] Optionally, the processor 1230 may be a central processing unit (CPU), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or a complex programmable logic device (CPLD), and the processor may also adopt a multi-core architecture.
[0324] The processor 1230 is used to execute any of the methods provided in the embodiments of the present application according to the obtained executable instructions by calling the computer program stored in the memory 1210. The processor 1230 and the memory 1210 may also be physically separated.
[0325] Figure 13 It is a schematic structural diagram of another communication device provided in the embodiments of the present application. Please refer toFigure 13 The communication device includes a memory 1310, a transceiver 1320, and a processor 1330:
[0326] The memory 1310 is used to store computer programs;
[0327] The transceiver 1320 is used to transmit and receive data under the control of the processor;
[0328] The processor 1330 is used to read the computer program in the memory and perform the following operations:
[0329] Encrypt the subscription data of the terminal device according to the symmetric key to obtain the ciphertext of the subscription data, and send the ciphertext of the subscription data to the storage system;
[0330] Generate a first key, and send the first key to a node in the blockchain network, where the first key is used to decrypt the ciphertext of the subscription data.
[0331] In an implementation, the second node encrypts the subscription data of the terminal device according to the symmetric key to obtain the ciphertext of the subscription data, including:
[0332] Randomly generate a symmetric key;
[0333] Encrypt the subscription data according to the symmetric key to obtain the ciphertext of the subscription data.
[0334] In an implementation, the second node generates the first key, including:
[0335] Encrypt the symmetric key according to the public key of the second node to obtain a second key;
[0336] Encrypt the public key of the first node according to the private key of the second node to obtain a third key;
[0337] Wherein, the first key includes the second key and the third key, and the first node is a network that provides network services to the terminal device.
[0338] In an implementation, before the second node generates the first key, the method further includes:
[0339] Sign a roaming agreement with the first node and generate a third key;
[0340] Send the third key to a node in the blockchain network.
[0341] Wherein, in Figure 13Among them, the bus architecture may include any number of interconnected buses and bridges, specifically, various circuits represented by one or more processors represented by processor 1303 and a memory represented by memory 1310 are linked together. The bus architecture may also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art, and thus will not be further described herein. The bus interface provides an interface. The transceiver 1320 may be a plurality of components, that is, including a transmitter and a receiver, and provides a unit for communicating with various other devices on a transmission medium, and these transmission media include wireless channels, wired channels, optical fiber cables, and other transmission media. The processor 1330 is responsible for managing the bus architecture and general processing, and the memory 1301 may store data used by the processor 1330 when executing operations.
[0342] Optionally, the processor 1330 may be a central processing unit (CPU), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or a complex programmable logic device (CPLD), and the processor may also adopt a multi-core architecture.
[0343] The processor 1330 is used to execute any of the methods provided in the embodiments of the present application according to the obtained executable instructions by calling the computer program stored in the memory 1310. The processor 1330 and the memory 1310 may also be physically separated.
[0344] Figure 14 It is a schematic structural diagram of another communication device provided in the embodiments of the present application. Please refer to Figure 14 This communication device includes a memory 1310, a transceiver 1320, and a processor 1330:
[0345] The memory 1310 is used to store a computer program;
[0346] The transceiver 1320 is used to transmit and receive data under the control of the processor;
[0347] The processor 1330 is used to read the computer program in the memory and perform the following operations:
[0348] Receive a second request sent by a first node, where the second request is used to obtain subscription data of a terminal device;
[0349] According to the second request, send a first key and a data storage address to the first node, where the first key is used to decrypt the ciphertext of the subscription data, and the data storage address is the storage address of the ciphertext of the subscription data.
[0350] In one embodiment, for a node in the blockchain network to send a first key and a data storage address to the first node according to the second request, it includes:
[0351] Verify the second request based on a pre-set protocol to obtain the first key and the data storage address;
[0352] Send the first key and the data storage address to the first node.
[0353] In one embodiment, for a node in the blockchain network to verify the second request based on a pre-set protocol to obtain the first key and the data storage address, it includes:
[0354] Verify the second request according to a first protocol to obtain a verification result;
[0355] If the verification result is verification passed, then obtain the first key according to a second protocol and obtain the data storage address according to a third protocol.
[0356] Among them, in Figure 14 The bus architecture may include any number of interconnected buses and bridges, specifically, various circuits of one or more processors represented by the processor 1403 and the memory represented by the memory 1410 are linked together. The bus architecture can also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art, so they will not be further described herein. The bus interface provides an interface. The transceiver 1420 can be multiple elements, that is, including a transmitter and a receiver, and provides a unit for communicating with various other devices on a transmission medium, and these transmission media include wireless channels, wired channels, optical cables, and other transmission media. The processor 1430 is responsible for managing the bus architecture and general processing, and the memory 1401 can store the data used by the processor 1430 when executing operations.
[0357] Optionally, the processor 1430 may be a central processing unit (CPU), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or a complex programmable logic device (CPLD). The processor may also adopt a multi-core architecture.
[0358] The processor 1430 is configured to execute any of the methods provided in the embodiments of the present application according to the obtained executable instructions by invoking the computer program stored in the memory 1410. The processor 1430 and the memory 1410 may also be physically separated.
[0359] Figure 15 It is a schematic structural diagram of another communication device provided in the embodiments of the present application. Please refer to Figure 15 This communication device includes a memory 1510, a transceiver 1520, and a processor 1530:
[0360] The memory 1510 is used to store a computer program;
[0361] The transceiver 1520 is used to send and receive data under the control of the processor;
[0362] The processor 1530 is used to read the computer program in the memory and perform the following operations:
[0363] Receive the ciphertext of the subscription data sent by the second node;
[0364] Store the ciphertext of the subscription data and send the data storage address corresponding to the ciphertext of the subscription data to the nodes in the blockchain network.
[0365] In one implementation, after the storage system sends the data storage address to the nodes in the blockchain network, the method further includes:
[0366] Receive the data storage address sent by the first node;
[0367] Obtain the ciphertext of the subscription data according to the data storage address;
[0368] Send the ciphertext of the subscription data to the first node.
[0369] Among them, in Figure 15Among them, the bus architecture may include any number of interconnected buses and bridges, specifically various circuits of one or more processors represented by the processor 1503 and the memory represented by the memory 1510 are linked together. The bus architecture may also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, etc., which are well known in the art, and thus will not be further described herein. The bus interface provides an interface. The transceiver 1520 may be multiple components, that is, including a transmitter and a receiver, and provides a unit for communicating with various other devices on the transmission medium, and these transmission media include wireless channels, wired channels, optical fiber cables and other transmission media. The processor 1530 is responsible for managing the bus architecture and general processing, and the memory 1501 may store data used by the processor 1530 when executing operations.
[0370] Optionally, the processor 1530 may be a central processing unit (CPU), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or a complex programmable logic device (CPLD), and the processor may also adopt a multi-core architecture.
[0371] It should be noted here that the above-mentioned physical device provided by the present application can implement all the method steps implemented by the physical device in the above method embodiment, and can achieve the same technical effect. The same parts and beneficial effects as those in the method embodiment will not be specifically described herein.
[0372] The embodiment of the present application also provides a processor-readable storage medium, and the processor-readable storage medium stores a computer program, and the computer program is used to make the processor execute the method described in any one of the above method embodiments.
[0373] The processor-readable storage medium may be any available medium or data storage device that can be accessed by a computer, including but not limited to magnetic memories (such as floppy disks, hard disks, magnetic tapes, magneto-optical disks (MO), etc.), optical memories (such as CDs, DVDs, BDs, HVDs, etc.), and semiconductor memories (such as ROM, EPROM, EEPROM, non-volatile memory (NAND FLASH), solid state drives (SSD)), etc.
[0374] The embodiment of the present application also provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the method described in any one of the above method embodiments.
[0375] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage and optical storage, etc.) that contain computer-usable program code.
[0376] The present application is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer-executable instructions. These computer-executable instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0377] These processor-executable instructions can also be stored in a processor-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the processor-readable memory generate a manufactured article including instruction means that implement the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0378] These processor-executable instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are performed on the computer or other programmable device to generate a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0379] Obviously, those skilled in the art can make various modifications and variations to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these modifications and variations.
Claims
1. A communication method, characterized in that, including: The first node receives a first key and a data storage address sent by a node in the blockchain network; The first node obtains the ciphertext of the subscription data of the terminal device in the storage system according to the data storage address; The first node decrypts the ciphertext of the subscription data according to the first key and the private key of the first node to obtain the subscription data.
2. The method according to claim 1, wherein The ciphertext of the subscription data is the ciphertext obtained by the second node encrypting the subscription data with a symmetric key, and the terminal device is a device registered in the second node.
3. The method according to claim 2, wherein The first key includes a second key obtained by encrypting the symmetric key with the public key of the second node and a third key obtained by encrypting the public key of the first node with the private key of the second node.
4. The method according to any one of claims 1 to 3, characterized in that The first node receives a first key and a data storage address sent by a node in the blockchain network, including: The first node receives a first request sent by the terminal device, and the first request is used to request to provide network services to the terminal device; The first node sends a second request to the nodes in the blockchain network, and the second request is used to obtain the subscription data of the terminal device; The first node receives the first key and the data storage address sent by the nodes in the blockchain network.
5. The method according to claim 4, wherein The second request is a request encrypted based on the private key of the first node.
6. The method according to claim 4 or 5, characterized in that, The second request includes the identifier of the terminal device.
7. The method according to any one of claims 1 to 6, characterized in that, The first node obtains the ciphertext of the subscription data of the terminal device in the storage system according to the data storage address, including: The first node sends the data storage address to the storage system; The first node receives the ciphertext of the subscription data sent by the storage system.
8. The method according to any one of claims 3-7, characterized in that, The first node decrypts the ciphertext of the subscription data according to the first key and the private key of the first node to obtain the subscription data, including: The first node decrypts according to the second key and the third key to obtain the key for encrypting the public key of the first node with the symmetric key; The first node decrypts the key for encrypting the public key of the first node with the symmetric key according to the private key of the first node to obtain the symmetric key; The first node decrypts the ciphertext of the subscription data according to the symmetric key to obtain the subscription data.
9. A communication method, characterized in that, including: The second node encrypts the subscription data of the terminal device with a symmetric key to obtain the ciphertext of the subscription data, and sends the ciphertext of the subscription data to the storage system; The second node generates a first key and sends the first key to the nodes in the blockchain network, and the first key is used to decrypt the ciphertext of the subscription data.
10. The method according to claim 9, wherein The second node encrypts the subscription data of the terminal device with a symmetric key to obtain the ciphertext of the subscription data, including: The second node randomly generates a symmetric key; The second node encrypts the subscription data according to the symmetric key to obtain the ciphertext of the subscription data.
11. The method according to claim 9 or 10, characterized in that, The second node generates a first key, including: The second node encrypts the symmetric key with the public key of the second node to obtain a second key; The second node encrypts the public key of the first node according to the private key of the second node to obtain a third key; Wherein, the first key includes the second key and the third key, and the first node is a network that provides network services to the terminal device.
12. The method according to any one of claims 9-11, characterized in that, Before the second node generates the first key, the method further includes: The second node signs a roaming agreement with the first node and generates a third key; The second node sends the third key to the nodes in the blockchain network.
13. A communication method, characterized in that Including: The nodes in the blockchain network receive a second request sent by the first node, and the second request is used to obtain the subscription data of the terminal device; The nodes in the blockchain network send a first key and a data storage address to the first node according to the second request. The first key is used to decrypt the ciphertext of the subscription data, and the data storage address is the storage address of the ciphertext of the subscription data.
14. The method according to claim 13, characterized in that, The nodes in the blockchain network send a first key and a data storage address to the first node according to the second request, including: The nodes in the blockchain network verify the second request based on a pre-set protocol to obtain the first key and the data storage address; The nodes in the blockchain network send the first key and the data storage address to the first node.
15. The method according to claim 14, characterized in that, The nodes in the blockchain network verify the second request based on a pre-set protocol to obtain the first key and the data storage address, including: The nodes in the blockchain network verify the second request according to a first protocol to obtain a verification result; If the verification result is verification passed, the nodes in the blockchain network obtain the first key according to a second protocol and obtain the data storage address according to a third protocol.
16. A communication method, characterized in that, Including: The storage system receives the ciphertext of the subscription data sent by the second node; The storage system stores the ciphertext of the subscription data and sends the data storage address corresponding to the ciphertext of the subscription data to the nodes in the blockchain network.
17. The method according to claim 16, wherein After the storage system sends the data storage address to the nodes in the blockchain network, the method further includes: The storage system receives the data storage address sent by the first node; The storage system obtains the ciphertext of the subscription data according to the data storage address; The storage system sends the ciphertext of the subscription data to the first node.
18. A communication device, characterized in that, Including a receiving module, an obtaining module, and a processing module, wherein: The receiving module is used to receive the first key and the data storage address sent by the nodes in the blockchain network; The obtaining module is used to obtain the ciphertext of the subscription data of the terminal device in the storage system according to the data storage address; The processing module is used to decrypt the ciphertext of the subscription data according to the first key and the private key of the first node to obtain the subscription data.
19. A communication device, characterized in that, Including an encryption module, a sending module, and a generating module, wherein: The encryption module is used to encrypt the subscription data of the terminal device according to a symmetric key to obtain the ciphertext of the subscription data; The sending module is used to send the ciphertext of the subscription data to the storage system; The generating module is configured to generate a first key; The sending module is further configured to send the first key to a node in the blockchain network, where the first key is used to decrypt the ciphertext of the subscription data.
20. A communication device, characterized in that, It includes a receiving module and a sending module, where: The receiving module is configured to receive a second request sent by a first node, where the second request is used to obtain the subscription data of the terminal device; The sending module is configured to send a first key and a data storage address to the first node according to the second request, where the first key is used to decrypt the ciphertext of the subscription data, and the data storage address is the storage address of the ciphertext of the subscription data.
21. A communication device, characterized in that, It includes a receiving module, a storage module and a sending module, where: The receiving module is configured to receive the ciphertext of the subscription data sent by a second node by the storage system; The storage module is configured to store the ciphertext of the subscription data by the storage system; The sending module is configured to send the data storage address corresponding to the ciphertext of the subscription data to a node in the blockchain network.
22. A communication device, characterized in that, It includes: a memory, a transceiver, a processor: The memory is configured to store a computer program; The transceiver is configured to send and receive data under the control of the processor; The processor is configured to read the computer program in the memory and perform the following operations: Receive a first key and a data storage address sent by a node in the blockchain network; Obtain the ciphertext of the subscription data of the terminal device in the storage system according to the data storage address; Perform decryption processing on the ciphertext of the subscription data according to the first key and the private key of the first node to obtain the subscription data.
23. A communication device, characterized in that, It includes: a memory, a transceiver, a processor: The memory is configured to store a computer program; The transceiver is configured to send and receive data under the control of the processor; The processor is configured to read the computer program in the memory and perform the following operations: Encrypt the subscription data of the terminal device according to the symmetric key to obtain the ciphertext of the subscription data, and send the ciphertext of the subscription data to the storage system; Generate a first key and send the first key to a node in the blockchain network, where the first key is used to decrypt the ciphertext of the subscription data.
24. A communication device, characterized in that, It includes: a memory, a transceiver, a processor: The memory is configured to store a computer program; The transceiver is configured to send and receive data under the control of the processor; The processor is configured to read the computer program in the memory and perform the following operations: Receive a second request sent by a first node, where the second request is used to obtain the subscription data of the terminal device; Send a first key and a data storage address to the first node according to the second request, where the first key is used to decrypt the ciphertext of the subscription data, and the data storage address is the storage address of the ciphertext of the subscription data.
25. A communication device, characterized in that, It includes: a memory, a transceiver, a processor: The memory is configured to store a computer program; The transceiver is configured to send and receive data under the control of the processor; The processor is configured to read the computer program in the memory and perform the following operations: Receive the ciphertext of the subscription data sent by a second node; Store the ciphertext of the subscription data and send the data storage address corresponding to the ciphertext of the subscription data to the nodes in the blockchain network.
26. A processor-readable storage medium, characterized in that, The processor-readable storage medium stores a computer program, and the computer program is used to cause the processor to execute the method according to any one of claims 1 to 8, or execute the method according to any one of claims 9 to 12, or execute the method according to any one of claims 13 to 15, or execute the method according to claim 16 or 17.