Communication method and device

CN120898447APending Publication Date: 2025-11-04HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380095938.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-03-23
Publication Date
2025-11-04

AI Technical Summary

Technical Problem

The security functions and communication functions of existing communication devices are tightly coupled and cannot be configured flexibly, resulting in delays in security function configuration when application scenarios change, and making updates and upgrades difficult.

Method used

Through a communication method, the first entity is used to receive information to determine its configuration information, quickly and flexibly configure security functions, and the fourth entity is allowed to configure the first entity through signaling, adapt to changes in application scenarios, and independently manage security and communication functions.

Benefits of technology

It achieves flexible configuration and independent evolution of security functions, reduces computing resources and power consumption, and improves the response speed and reliability of security functions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120898447A_ABST
    Figure CN120898447A_ABST
Patent Text Reader

Abstract

The invention discloses a communication method and device. The method includes the fourth entity sending first information to the first entity. The first information can be used for determining first configuration information of the first entity, and the first configuration information is configuration information used by the first entity to provide security capability for the third entity. Then, the first entity may send first feedback information, the first feedback information being used to indicate whether the first entity successfully configures the first configuration information. Through the method, the fourth entity can configure the first entity through the first information, so that the first entity can be quickly and flexibly configured. Since the fourth entity can configure the first entity through the signaling, when the fourth entity senses that the application scene changes, the fourth entity can configure the first entity in time, so that the configuration of the first entity can meet the current requirement, and reliable safety support is provided for the third entity.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method and device Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a communication method and device. Background Art

[0002] To improve communication security, communication devices can be assigned security functions, which in turn provide security capabilities for the corresponding communication devices. Currently, in mobile communication networks, the security functions of communication devices are fixed. Only when the communication devices are upgraded or the network is upgraded will the corresponding security function nodes of the communication devices change, for example, by adding, updating, or deleting security functions. This makes security functions inflexible to actual application scenarios and the security requirements of communication devices.

[0003] Furthermore, security functions are tightly coupled with the communication functions of communication devices, which are managed by the management plane. For example, operators use operations administration and maintenance (OAM) equipment to establish, update, and delete communication functions of communication devices. Consequently, the communication functions of communication devices cannot be flexibly configured, and consequently, the security functions of communication devices cannot be flexibly configured.

[0004] Summary of the Invention

[0005] The present application provides a communication method and device for flexibly configuring the security functions of a communication device.

[0006] In a first aspect, embodiments of the present application provide a communication method. The method includes: a first entity receiving first information. The first information may be used to determine first configuration information of the first entity, where the first configuration information is configuration information used by the first entity to provide security capabilities for a third entity. The first entity may then send first feedback information, where the first feedback information indicates whether the first entity successfully configured the first configuration information.

[0007] Through this method, the first information received by the first entity can be used to configure the first entity, so that the first entity can be configured quickly and flexibly. The first information is, for example, sent by the fourth entity to the first entity. Since the fourth entity can configure the first entity through signaling, when the fourth entity perceives that the application scenario has changed, the fourth entity can configure the first entity in a timely manner, so that the configuration of the first entity can meet the current needs and provide reliable security support for the third entity. In addition, in a possible implementation, the first entity can be an entity independent of the third entity, the first entity can be used as a security function, and the third entity can be used as a communication function, so that the security function independent of the communication function can be flexibly configured, which is conducive to the independent evolution and update and upgrade of the security function.

[0008] In one possible implementation, the fourth entity may be the third entity. As the demander of security capabilities, the third entity may trigger the configuration of the first entity, thereby improving the third entity's control over the first entity as a security function, so that the first entity can provide security services to the third entity on demand.

[0009] In one possible design, the first information may be used to determine the first configuration information in one of the following ways.

[0010] Implementation method 1: The first information may be used to indicate a first parameter used for performing a management operation on the first entity, and the first parameter is used to determine the first configuration information.

[0011] Through this first implementation method, the first entity can receive the first parameter without the need for the first entity to analyze the security policy or security requirements to obtain the first parameter, thereby reducing the computing loss of the first entity and saving the computing resources and power of the first entity.

[0012] Implementation method 2: The first information is used to indicate a security policy of at least one entity, the at least one entity including a third entity, and the security policy is used to determine the first configuration information. The first information may be sent by the second entity to the first entity.

[0013] Optionally, the security policy may include: security capabilities that at least one entity needs to possess, and / or security capabilities that at least one entity does not need to possess.

[0014] In one possible manner, a security policy may be used to determine a first parameter used to perform a management operation on a first entity, and the first parameter is used to determine the first configuration information.

[0015] With this second implementation, the second entity can send a security policy to the first entity, which functions as a security function. The first entity then determines the first configuration information of the first entity based on the security policy. This eliminates the need for the second entity to determine parameters for performing management operations for each security function, thereby improving the efficiency of the second entity's security function configuration, reducing the second entity's computational overhead, and conserving the second entity's computing resources and power.

[0016] Implementation method three: The first information is used to indicate the security requirements of the third entity, and the security requirements are used to determine the first configuration information. The first information may be sent by the third entity to the first entity.

[0017] Optionally, the security requirement includes: security capabilities that the third entity needs to have, and / or security capabilities that the third entity does not need to have.

[0018] In one possible manner, the security requirement may be used to determine a first parameter used to perform a management operation on the first entity, and the first parameter is used to determine the first configuration information.

[0019] Through this third implementation, the third entity can send security requirements to the first entity, which functions as a security function. The first entity then determines the first configuration information of the first entity based on the security requirements. This eliminates the need for the third entity to analyze the security requirements, thereby reducing the computational overhead of the third entity and conserving its computing resources and power.

[0020] In one possible design, in implementations 1 through 3 above, the management operation may include one of the following: create, update, lock, unlock, or delete. This design allows for flexible execution of multiple operations on entities, ensuring that the configuration of the first entity meets current requirements, thereby providing reliable security support for the third entity.

[0021] In one possible design, in implementations 1 through 3 above, the first parameter may include at least one of the following: the type of management operation to be performed on the first entity; a first state, the first state including: an expected state of the first entity and / or an expected state of a security capability module within the first entity to perform the management operation; information indicating the security capability module within the first entity to perform the management operation; and information indicating the algorithm within the security capability module within the first entity to perform the management operation. With this design, the first entity can accurately and quickly perform the corresponding management operation based on the first parameter, ensuring that the configuration of the first entity meets current requirements, thereby providing reliable security support for the third entity.

[0022] In one possible design, the first feedback information also includes the first configuration information. For example, in implementations 1 and 2 above, if the first entity receives the first information from the second entity, and the second entity manages the first entity, the first feedback information also includes the first configuration information. This allows the second entity to obtain and save the first configuration information, thereby effectively managing the first entity.

[0023] Implementation method 4: The first information includes first configuration information, wherein the first information may be sent by the second entity to the first entity.

[0024] Through this fourth implementation method, the first entity can obtain the first configuration information from the second entity without the first entity having to analyze the security policy or security requirements to obtain the first configuration information, thereby reducing the computing loss of the first entity and saving the computing resources and power of the first entity.

[0025] In one possible design, if a first entity receives first information from a second entity, and the second entity manages the first entity, the first entity may also send second information to a third entity. The second information indicates a first security capability that the first entity provides to the third entity, where the first security capability is determined based on the first information. With this design, the first entity can promptly notify the third entity of the first security capability that it can provide, allowing the third entity to invoke the first entity to support the first security capability.

[0026] In one possible design, the first entity may also receive third information from a third entity, where the third information indicates whether the first security capabilities meet the requirements of the third entity. When the third information indicates that the first security capabilities meet the requirements of the third entity, the first feedback information may indicate that the first entity successfully configured the first configuration information. With this design, the first entity can determine whether the first security capabilities meet the requirements of the third entity and can further adjust the first entity's configuration based on the requirements of the third entity.

[0027] In one possible design, the second information includes: indication information of the first security capability and identification information of the first entity. With this design, the first entity can accurately notify the third entity of the first security capability of the first entity.

[0028] In one possible design, if a first entity receives first information from a third entity, the first entity may also send fourth information to a second entity. The fourth information includes the first configuration information and is used to register the first configuration information of the first entity. The second entity manages the first entity. With this design, the second entity can obtain the first configuration information and thus effectively manage the first entity.

[0029] In one possible design, the first entity may receive fifth information from the second entity, where the fifth information indicates whether the first entity's first configuration information was successfully registered. When the fifth information indicates that the first entity's first configuration information was successfully registered, the first feedback information may indicate that the first entity successfully configured the first configuration information. With this design, the first entity can promptly learn whether the first configuration information was successfully registered and, based on the registration result, can provide the third entity with security capabilities permitted by the second entity.

[0030] In a second aspect, embodiments of the present application provide a communication method. The method includes: a fourth entity sending first information. The first information is used to determine first configuration information of the first entity, where the first configuration information is configuration information used by the first entity to provide security capabilities for a third entity, and the fourth entity is either the third entity or a second entity that manages the first entity. The fourth entity may then receive first feedback information, where the first feedback information indicates whether the first entity successfully configured the first configuration information.

[0031] Through this method, the fourth entity can configure the first entity through the first information, thereby enabling the first entity to be configured quickly and flexibly. Since the fourth entity can configure the first entity through signaling, when the fourth entity perceives a change in the application scenario, the fourth entity can promptly configure the first entity, thereby enabling the configuration of the first entity to meet current needs and provide reliable security support for the third entity. In addition, in this method, the first entity can be an entity independent of the third entity. The first entity can serve as a security function, and the third entity can serve as a communication function. This allows for flexible configuration of security functions independent of the communication function, which is conducive to the independent evolution and update and upgrade of the security function.

[0032] In addition, in this method, the fourth entity may be the third entity. As the demander of security capabilities, the third entity may trigger the configuration of the first entity, thereby improving the third entity's control over the first entity as a security function, so that the first entity can provide security services to the third entity on demand.

[0033] In one possible design, the first information may be used to determine the first configuration information in one of the following ways.

[0034] Implementation method 1: The first information is used to indicate a first parameter used for performing a management operation on the first entity, and the first parameter is used to determine the first configuration information.

[0035] Through this implementation method one, the fourth entity can send the first parameter to the first entity without the first entity having to analyze the security policy or security requirements to obtain the first parameter, thereby reducing the computing loss of the first entity and saving the computing resources and power of the first entity.

[0036] Implementation method 2: The first information is used to indicate a security policy of at least one entity, the at least one entity includes a third entity, and the security policy is used to determine the first configuration information. The first information may be sent by the second entity to the first entity.

[0037] Optionally, the security policy includes: security capabilities that at least one entity needs to have, and / or security capabilities that at least one entity does not need to have.

[0038] In a possible manner, the security policy is used to determine a first parameter used to perform a management operation on the first entity, and the first parameter is used to determine the first configuration information.

[0039] With this second implementation, the second entity can send a security policy to the first entity, which functions as a security function. The first entity then determines the first configuration information of the first entity based on the security policy. This eliminates the need for the second entity to determine parameters for performing management operations for each security function, thereby improving the efficiency of the second entity's security function configuration, reducing the second entity's computational overhead, and conserving the second entity's computing resources and power.

[0040] Implementation method three: The first information is used to indicate the security requirements of the third entity, and the security requirements are used to determine the first configuration information. The first information may be sent by the third entity to the first entity.

[0041] Optionally, the security requirements include: security capabilities that the third entity needs to have, and / or security capabilities that the third entity does not need to have.

[0042] In a possible manner, the security requirement is used to determine a first parameter used to perform a management operation on the first entity, and the first parameter is used to determine the first configuration information.

[0043] Through this third implementation, the third entity can send security requirements to the first entity, which functions as a security function. The first entity then determines the first configuration information of the first entity based on the security requirements. This eliminates the need for the third entity to analyze the security requirements, thereby reducing the computational overhead of the third entity and conserving its computing resources and power.

[0044] In one possible design, in implementations 1 through 3 above, the management operation includes one of the following: a create operation, an update operation, a lock operation, an unlock operation, and a delete operation. This design allows for flexible execution of multiple operations on entities, ensuring that the configuration of the first entity meets current requirements, thereby providing reliable security support for the third entity.

[0045] In one possible design, in implementations 1 through 3 above, the first parameter includes at least one of the following: the type of management operation to be performed on the first entity; a first state, the first state including: an expected state of the first entity and / or an expected state of a security capability module within the first entity on which the management operation is to be performed; information indicating the security capability module within the first entity on which the management operation is to be performed; and information indicating the algorithm within the security capability module within the first entity that is to perform the management operation. In this way, the first entity can accurately and quickly perform the corresponding management operation based on the first parameter, ensuring that the configuration of the first entity meets current requirements, thereby providing reliable security support for the third entity.

[0046] In one possible design, the first feedback information also includes the first configuration information. For example, in implementations 1 and 2 above, if the first entity receives the first information from the second entity, and the second entity manages the first entity, the first feedback information also includes the first configuration information. This allows the second entity to obtain and save the first configuration information, thereby effectively managing the first entity.

[0047] Implementation method 4: The first information includes first configuration information, wherein the first information may be sent by the second entity to the first entity.

[0048] Through this fourth implementation method, the second entity can send the first configuration information to the first entity without the first entity having to analyze the security policy or security requirements to obtain the first configuration information, thereby reducing the computing loss of the first entity and saving the computing resources and power of the first entity.

[0049] In one possible design, the first entity may be established through the following steps: after receiving a request message from a third entity, the second entity sends second feedback information to the third entity. The request message is used to request the establishment of the first entity; the second feedback information is used to indicate information for establishing the first entity. The second entity may then receive sixth information from the first entity, the sixth information including the first configuration information of the first entity, and the sixth information indicating whether the first entity successfully configured the first configuration information.

[0050] Through this method, when the first entity does not exist, the third entity can request the second entity to establish the first entity based on the needs of the third entity, thereby enabling the first entity to be established quickly and flexibly. Furthermore, since the first entity can be established through signaling, when the third entity perceives a change in the application scenario, the third entity can promptly request the second entity to establish the first entity, thereby ensuring that the establishment of the first entity meets current needs and provides reliable security support for the third entity. In addition, in this method, the third entity, as the demander of security capabilities, can trigger the establishment of the first entity, improving the third entity's control over the first entity as a security function, allowing the first entity to provide security services to the third entity on demand. In addition, in this method, the first entity can be an entity independent of the third entity. The first entity can serve as a security function, and the third entity can serve as a communication function. This allows for the flexible establishment of security functions independent of the communication function, facilitating the independent evolution and update and upgrade of the security function.

[0051] In one possible design, the second feedback information includes the download address of the first entity. With this design, the third entity can quickly obtain the content of the first entity, and the second feedback information contains less information, which can save signaling overhead.

[0052] In one possible design, the request information includes indication information of the security capability module in the first entity. This design can accurately indicate the content of the first entity, thereby increasing the speed of establishing the first entity.

[0053] In one possible design, the second entity may further send seventh information to the third entity, where the seventh information indicates a second security capability, where the second security capability is the security capability of the first entity. In this way, the second entity can promptly notify the third entity of the second security capability that the first entity can provide, so that the third entity can invoke the first entity to support the second security capability.

[0054] In one possible design, the seventh information includes: indication information of the second security capability and identification information of the first entity. Through this design, the second entity can accurately notify the third entity of the second security capability of the first entity.

[0055] In a third aspect, embodiments of the present application provide a communication method. The method includes: after receiving a request message from a third entity, a second entity sends second feedback information to the third entity. The request message is used to request the establishment of a first entity, where the first entity is an entity that provides security capabilities to the third entity; the second feedback information is used to indicate information for establishing the first entity. The second entity may then receive sixth information from the first entity, the sixth information including the first configuration information of the first entity, and the sixth information indicating whether the first entity successfully configured the first configuration information.

[0056] In one possible design, the second feedback information includes a download address of the first entity.

[0057] In one possible design, the request information includes indication information of a security capability module in the first entity.

[0058] In one possible design, the second entity may send seventh information to the third entity, where the seventh information is used to indicate a second security capability, where the second security capability is the security capability of the first entity.

[0059] In one possible design, the seventh information includes: indication information of the second security capability and identification information of the first entity.

[0060] In a fourth aspect, embodiments of the present application provide a communication method. The method includes: a third entity sending a request message to a second entity, the request message being used to request the establishment of a first entity, where the first entity is an entity providing security capabilities to the third entity. The third entity may then receive second feedback information from the second entity, the second feedback information being used to indicate information for establishing the first entity, and establish the first entity based on the second feedback information.

[0061] In one possible design, the second feedback information includes a download address of the first entity.

[0062] In one possible design, the request information includes indication information of a security capability module in the first entity.

[0063] In one possible design, the third entity receives seventh information from the second entity, where the seventh information is used to indicate a second security capability, and the second security capability is the security capability of the first entity.

[0064] In one possible design, the seventh information includes: indication information of the second security capability and identification information of the first entity.

[0065] In a fifth aspect, embodiments of the present application provide a communication device that can be used to implement the communication method of the first aspect, that is, to perform the operations of the first entity in the method of the first aspect. In one possible implementation, the communication device may include a module or unit corresponding to each of the methods / operations / steps / actions described in the first aspect. The module or unit may be implemented as hardware circuitry, software, or a combination of hardware circuitry and software.

[0066] In one possible implementation, the apparatus includes: a communication unit and a processing unit. The communication unit is configured to receive and / or send information; the processing unit is configured to: receive first information via the communication unit, the first information being used to determine first configuration information of the communication apparatus, the first configuration information being configuration information used by the communication apparatus to provide security capabilities for a third entity; and send first feedback information via the communication unit, the first feedback information being used to indicate whether the communication apparatus has successfully configured the first configuration information.

[0067] In the first implementation, the first information is used to indicate a first parameter used to perform a management operation on the communication device, and the first parameter is used to determine the first configuration information.

[0068] In the second implementation, the first information is used to indicate a security policy of at least one entity, the at least one entity includes a third entity, and the security policy is used to determine the first configuration information.

[0069] Optionally, the security policy includes: security capabilities that at least one entity needs to have, and / or security capabilities that at least one entity does not need to have.

[0070] In one possible manner, the security policy is used to determine a first parameter used to perform a management operation on the communication device, and the first parameter is used to determine the first configuration information.

[0071] In implementation manner three, the first information is used to indicate the security requirements of the third entity, and the security requirements are used to determine the first configuration information.

[0072] Optionally, the security requirements include: security capabilities that the third entity needs to have, and / or security capabilities that the third entity does not need to have.

[0073] In one possible manner, the security requirement is used to determine a first parameter used to perform a management operation on the communication device, and the first parameter is used to determine the first configuration information.

[0074] In one possible design, in implementations one to three, the management operation includes one of the following: a creation operation, an update operation, a lock operation, an unlock operation, and a delete operation.

[0075] In one possible design, in implementation methods one to three, the first parameter includes at least one of the following: the type of management operation performed on the communication device; a first state, the first state including: the expected state of the communication device, and / or the expected state of the security capability module in the communication device to perform the management operation; indication information of the security capability module in the communication device to perform the management operation; indication information of the algorithm for the management operation to be performed in the security capability module of the communication device.

[0076] In one possible design, in implementation method one and implementation method two, the first feedback information also includes first configuration information.

[0077] In implementation method four, the first information includes first configuration information.

[0078] In one possible design, the processing unit is also used to: receive first information from a second entity through the communication unit, where the second entity is an entity that manages the communication device; and send second information to a third entity through the communication unit, where the second information is used to indicate a first security capability provided by the communication device to the third entity, and the first security capability is determined based on the first information.

[0079] In one possible design, the processing unit is also used to: receive third information from a third entity through the communication unit, the third information being used to indicate whether the first security capability meets the requirements of the third entity; when the third information is used to indicate that the first security capability meets the requirements of the third entity, the first feedback information is used to indicate that the communication device has successfully configured the first configuration information.

[0080] Optionally, the second information includes: indication information of the first security capability and identification information of the communication device.

[0081] In one possible design, the processing unit is also used to: receive first information from a third entity through the communication unit; send fourth information to the second entity through the communication unit, the fourth information including first configuration information, and the fourth information is used to register the first configuration information of the communication device, and the second entity is the entity that manages the communication device.

[0082] In one possible design, the processing unit is also used to: receive fifth information from the second entity through the communication unit, the fifth information being used to indicate whether the first configuration information of the communication device is successfully registered; when the fifth information is used to indicate that the first configuration information of the communication device is successfully registered, the first feedback information is used to indicate that the communication device has successfully configured the first configuration information.

[0083] In a sixth aspect, embodiments of the present application provide a communication device that can be used to implement the communication method of the second aspect, that is, to perform the operations of the fourth entity in the method of the second aspect. In one possible implementation, the communication device may include a module or unit corresponding to each of the methods / operations / steps / actions described in the second aspect. The module or unit may be implemented as hardware circuitry, software, or a combination of hardware circuitry and software.

[0084] In one possible implementation, the apparatus includes: a communication unit and a processing unit. The communication unit is configured to receive and / or send information; the processing unit is configured to: send first information via the communication unit, the first information being used to determine first configuration information of a first entity, the first configuration information being configuration information used by the first entity to provide security capabilities for a third entity, the communication apparatus being the third entity or a second entity that manages the first entity; and receive first feedback information via the communication unit, the first feedback information being used to indicate whether the first entity successfully configured the first configuration information.

[0085] In the first implementation, the first information is used to indicate a first parameter used to perform a management operation on the first entity, and the first parameter is used to determine the first configuration information.

[0086] In the second implementation, the first information is used to indicate a security policy of at least one entity, the at least one entity includes a third entity, and the security policy is used to determine the first configuration information.

[0087] Optionally, the security policy includes: security capabilities that at least one entity needs to have, and / or security capabilities that at least one entity does not need to have.

[0088] In one possible manner, the security policy is used to determine a first parameter used to perform a management operation on the first entity, and the first parameter is used to determine the first configuration information.

[0089] In implementation manner three, the first information is used to indicate the security requirements of the third entity, and the security requirements are used to determine the first configuration information.

[0090] Optionally, the security requirements include: security capabilities that the third entity needs to have, and / or security capabilities that the third entity does not need to have.

[0091] In one possible manner, the security requirement is used to determine a first parameter used to perform a management operation on the first entity, and the first parameter is used to determine the first configuration information.

[0092] In one possible design, in implementations one to three, the management operation includes one of the following: a creation operation, an update operation, a lock operation, an unlock operation, and a delete operation.

[0093] In one possible design, in implementation methods one to three, the first parameter includes at least one of the following: the type of management operation performed on the communication device; a first state, the first state including: the expected state of the communication device, and / or the expected state of the security capability module in the communication device to perform the management operation; indication information of the security capability module in the communication device to perform the management operation; indication information of the algorithm for the management operation to be performed in the security capability module of the communication device.

[0094] In one possible design, in implementation method one and implementation method two, the first feedback information also includes first configuration information.

[0095] In implementation method four, the first information includes first configuration information.

[0096] In a seventh aspect, embodiments of the present application provide a communication device that can be used to implement the communication method of the third aspect, i.e., to perform the operations of the second entity in the method of the third aspect. In one possible implementation, the communication device may include a module or unit corresponding to each of the methods / operations / steps / actions described in the third aspect. The module or unit may be implemented as hardware circuitry, software, or a combination of hardware circuitry and software.

[0097] In one possible implementation, the apparatus includes: a communication unit and a processing unit. The communication unit is configured to receive and / or send information; the processing unit is configured to: receive, via the communication unit, request information from a third entity requesting the establishment of a first entity, where the first entity is an entity providing security capabilities to the third entity; send, via the communication unit, second feedback information to the third entity, where the second feedback information indicates information for establishing the first entity; and receive, via the communication unit, sixth information from the first entity, where the sixth information includes first configuration information of the first entity and indicates whether the first entity has successfully configured the first configuration information.

[0098] In one possible design, the second feedback information includes a download address of the first entity.

[0099] In one possible design, the request information includes indication information of a security capability module in the first entity.

[0100] In one possible design, the processing unit is further used to: send seventh information to the third entity through the communication unit, where the seventh information is used to indicate the second security capability, and the second security capability is the security capability of the first entity.

[0101] In one possible design, the seventh information includes: indication information of the second security capability and identification information of the first entity.

[0102] In an eighth aspect, embodiments of the present application provide a communication device, which may be used to implement the communication method of the fourth aspect, i.e., to perform the operations of the third entity in the method of the fourth aspect. In one possible implementation, the communication device may include a module or unit corresponding to each of the methods / operations / steps / actions described in the fourth aspect. The module or unit may be implemented as hardware circuitry, software, or a combination of hardware circuitry and software.

[0103] In one possible implementation, the apparatus includes: a communication unit and a processing unit. The communication unit is configured to receive and / or send information; the processing unit is configured to: send a request message to a second entity via the communication unit, the request message being used to request the establishment of a first entity, where the first entity is an entity providing security capabilities to a third entity; receive second feedback information from the second entity via the communication unit, the second feedback information being used to indicate information for establishing the first entity; and establish the first entity based on the second feedback information.

[0104] In one possible design, the second feedback information includes a download address of the first entity.

[0105] In one possible design, the request information includes indication information of a security capability module in the first entity.

[0106] In one possible design, the processing unit is further used to: receive seventh information from the second entity through the communication unit, where the seventh information is used to indicate a second security capability, and the second security capability is the security capability of the first entity.

[0107] In one possible design, the seventh information includes: indication information of the second security capability and identification information of the first entity.

[0108] In the ninth aspect, an embodiment of the present application provides a communication device, comprising a processor: configured to enable the device to execute any of the above aspects and any possible implementation methods of any aspect by executing a computer program (or computer executable instructions) stored in a memory, and / or through a logic circuit.

[0109] In a possible implementation, the device further includes a memory.

[0110] In one possible implementation, the processor and the memory are integrated together.

[0111] In another possible implementation, the memory is located outside the communication device.

[0112] The communication device also includes a communication interface, which is used for the communication device to communicate with other devices, such as sending or receiving data and / or signals. Exemplarily, the communication interface can be a transceiver, circuit, bus, module or other type of communication interface.

[0113] In a tenth aspect, an embodiment of the present application provides a communication system, comprising: a communication device for performing the operation of the first entity in the method provided in the first aspect or the second aspect, and a communication device for performing the operation of the second entity in the method provided in the first aspect or the second aspect. The communication device for performing the operation of the first entity in the method provided in the first aspect or the second aspect is, for example, the communication device in the fifth aspect, and the communication device for performing the operation of the second entity in the method provided in the first aspect or the second aspect is, for example, the communication device that can serve as the second entity in the sixth aspect.

[0114] In one possible design, the system further includes: a communication device for performing the operations of the third entity in the method provided in the first aspect or the second aspect. The communication device for performing the operations of the third entity in the method provided in the first aspect or the second aspect is, for example, the communication device that can serve as the third entity in the sixth aspect.

[0115] In an eleventh aspect, an embodiment of the present application provides a communication system, comprising: a communication device for performing the operations of the first entity in the method provided in the third aspect or the fourth aspect, and a communication device for performing the operations of the second entity in the method provided in the third aspect or the fourth aspect. The communication device for performing the operations of the second entity in the method provided in the third aspect or the fourth aspect is, for example, the communication device in the seventh aspect.

[0116] In one possible design, the system further includes: a communication device for performing the operation of the third entity in the method provided in the third aspect or the fourth aspect. The communication device for performing the operation of the third entity in the method provided in the third aspect or the fourth aspect is, for example, the communication device in the eighth aspect.

[0117] In the twelfth aspect, an embodiment of the present application provides a communication system, including: the communication device in the seventh aspect and the communication device in the eighth aspect.

[0118] In a thirteenth aspect, an embodiment of the present application further provides a computer program, which, when executed on a computer, enables the computer to execute the method provided in any of the above aspects.

[0119] In the fourteenth aspect, an embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a computer, the computer executes the method provided in any one of the above aspects.

[0120] In the fifteenth aspect, an embodiment of the present application further provides a chip, which is used to read a computer program stored in a memory and execute the method provided in any of the above aspects.

[0121] In a sixteenth aspect, embodiments of the present application further provide a chip system, comprising a processor configured to support a computer device in implementing the method provided in any of the above aspects. In one possible design, the chip system further comprises a memory configured to store programs and data necessary for the computer device. The chip system may be composed of a chip alone, or may include a chip and other discrete components.

[0122] In the seventeenth aspect, an embodiment of the present application further provides a computer program product comprising computer-executable instructions, which, when run, enables some or all of the steps of the method described in any of the above aspects to be executed.

[0123] The technical effects that can be achieved in any of the above-mentioned aspects from the third to the seventeenth can refer to the description of the technical effects that can be achieved by any possible design in the above-mentioned first or second aspects, and the repetitions will not be discussed. BRIEF DESCRIPTION OF THE DRAWINGS

[0124] FIG1 is an architecture diagram of a communication system provided in an embodiment of the present application;

[0125] FIG2 is a structural diagram of a transmission unit provided in an embodiment of the present application;

[0126] FIG3 is a schematic diagram of a state transition provided in an embodiment of the present application;

[0127] FIG4 is a schematic diagram of configuration information of a transmission unit provided in an embodiment of the present application;

[0128] FIG5 is a flow chart of a first communication method provided in an embodiment of the present application;

[0129] FIG6 is a flow chart of a second communication method provided in an embodiment of the present application;

[0130] FIG7 is a flow chart of a third communication method provided in an embodiment of the present application;

[0131] FIG8 is a flow chart of a fourth communication method provided in an embodiment of the present application;

[0132] FIG9 is a schematic diagram of a transmission unit update scenario provided in an embodiment of the present application;

[0133] FIG10 is a flowchart of a fifth communication method provided in an embodiment of the present application;

[0134] FIG11 is a flowchart of a sixth communication method provided in an embodiment of the present application;

[0135] FIG12 is a flow chart of a seventh communication method provided in an embodiment of the present application;

[0136] FIG13 is a flow chart of an eighth communication method provided in an embodiment of the present application;

[0137] FIG14 is a flowchart of a ninth communication method provided in an embodiment of the present application;

[0138] FIG15 is a flowchart of a tenth communication method provided in an embodiment of the present application;

[0139] FIG16 is a flowchart of an eleventh communication method provided in an embodiment of the present application;

[0140] FIG17 is a structural diagram of a communication device provided in an embodiment of the present application;

[0141] FIG18 is a structural diagram of another communication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0142] The present application provides a communication method and apparatus. The method and apparatus are based on the same technical concept. Since the method and apparatus solve similar problems, the implementation of the apparatus and method can refer to each other, and the repetitive parts will not be repeated.

[0143] The embodiments of the present application will be described in detail below with reference to the accompanying drawings.

[0144] Figure 1 is an architecture diagram of a communication system provided by an embodiment of the present application. As shown in Figure 1, the communication system includes: a terminal device, an access network (AN) device, and a core network (CN) device. The terminal device can access the data network through the AN device and the CN device.

[0145] In this application, a terminal device, which may also be referred to as user equipment (UE), mobile station (MS), or mobile terminal (MT), is a device with wireless transceiver capabilities that can be used to provide voice or data connectivity to users. A terminal device may also be an Internet of Things device.

[0146] For example, terminal devices include handheld devices with wireless connection functions, in-vehicle devices, etc. Currently, the terminal devices may be mobile phones, tablet computers, laptop computers, PDAs, mobile internet devices (MIDs), wearable devices (such as smart watches, smart bracelets, pedometers, etc.), in-vehicle devices (such as cars, bicycles, electric vehicles, airplanes, ships, trains, high-speed trains, etc.), satellite terminals, virtual reality (VR) devices, augmented reality (AR) devices, smart point of sale (POS) machines, customer-premises equipment (CPE), wireless terminals in industrial control, smart home devices (such as refrigerators, televisions, air conditioners, electric meters, etc.), intelligent robots, robotic arms, workshop equipment, wireless terminals in unmanned driving, wireless terminals in telemedicine, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, wireless terminals in smart homes, and flying devices (such as intelligent robots, hot air balloons, drones, and airplanes). The terminal device may also be other devices with terminal functions. For example, the terminal device may also be a device that serves as a terminal in D2D communication.

[0147] The embodiments of this application do not limit the device form factor of the terminal. The device used to implement the functions of the terminal device can be the terminal device; it can also be a device that supports the terminal device to implement the functions, such as a chip system. The device can be installed in the terminal device or used in conjunction with the terminal device. In the embodiments of this application, the chip system can be composed of chips or include chips and other discrete devices.

[0148] In this application, AN device is a device that provides wireless communication functions for terminal devices. As a node in the radio access network, the AN device can also be called a base station, a radio access network (RAN) node (or device), or an access point (AP). The AN device is used to help terminal devices achieve wireless access. The communication system may include multiple AN devices, and the multiple AN devices can be nodes of the same type or different types. In some scenarios, the roles of the AN device and the terminal device are relative. For example, network element #A can be a helicopter or a drone, which can be configured as a mobile base station and access the RAN through network element #B. For those terminal devices that access the RAN through network element #A, network element #A is a base station; but for network element #B, network element #A is a terminal device. AN devices and terminal devices are sometimes referred to as communication devices.

[0149] In one possible scenario, an AN device can be a base station, an evolved NodeB (eNodeB), a transmitting and receiving point (TRP), a transmitting point (TP), a next-generation NodeB (gNB), a next-generation base station in a sixth-generation (6G) mobile communication system, a base station in a future mobile communication system, a satellite, an access point (AP) in a wireless fidelity (WiFi) system, an integrated access and backhaul (IAB) node, or an AN device in a mobile switching center non-terrestrial network (NTN) communication system, i.e., it can be deployed on a high-altitude platform or satellite. AN devices can be macro base stations, micro base stations, or 110b for indoor stations, relay nodes or donor nodes, or wireless controllers in cloud RAN (CRAN) scenarios. AN devices can also function as base stations in device-to-device (D2D) communications, vehicle-to-vehicle (V2V) communications, drone communications, and machine communications. Optionally, the AN device may also be a server, a wearable device, a vehicle or an onboard device, etc. For example, the access network device in the vehicle to everything (V2X) technology may be a road side unit (RSU).

[0150] In another possible scenario, multiple AN devices collaborate to assist terminal devices in achieving wireless access, and different AN devices respectively implement part of the functions of the base station. For example, the AN device can be a centralized unit (CU), a distributed unit (DU), a CU-control plane (CP), a CU-user plane (UP), or a radio unit (RU). The CU and DU can be set separately, or they can also be included in the same network element, such as a baseband unit (BBU). The RU can be included in a radio frequency device or a radio frequency unit, such as a remote radio unit (RRU), an active antenna unit (AAU), or a remote radio head (RRH). It can be understood that the AN device can be a CU node, a DU node, or a device including a CU node and a DU node. In addition, the CU can be divided into an AN device in the access network RAN, or the CU can be divided into an AN device in the core network CN, which is not limited here.

[0151] In different systems, CU (or CU-CP and CU-UP), DU or RU may also have different names, but those skilled in the art can understand their meanings. For example, in the ORAN system, CU may also be called O-CU (Open CU), DU may also be called O-DU, CU-CP may also be called O-CU-CP, CU-UP may also be called O-CU-UP, and RU may also be called O-RU. For the convenience of description, this application uses CU, CU-CP, CU-UP, DU and RU as examples for description. Any unit of CU (or CU-CP, CU-UP), DU and RU in this application can be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.

[0152] In the embodiments of the present application, the form of the AN device is not limited. The device used to implement the functions of the AN device can be the AN device; it can also be a device that can support the AN device to implement the functions, such as a chip system. The device can be installed in the AN device or used in conjunction with the AN device.

[0153] AN devices and terminal devices can be fixed or mobile. They can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; on water; or in the air on aircraft, balloons, and satellites. The embodiments of this application do not limit the application scenarios of AN devices and terminal devices.

[0154] In this application, a CN device is a network element included in the CN part of a mobile communication system. For example, a CN device is a network function (NF) network element included in the CN part. The CN device can connect terminal devices to different data networks and perform services such as billing, mobility management, session management, and user plane forwarding. Currently, some examples of NF network elements include: unified data management (UDM) network element, unified data repository (UDR) network element, network exposure function (NEF) network element, application function (AF) network element, policy control function (PCF) network element, access and mobility management function (AMF) network element, session management function (SMF) network element, user plane function (UPF) network element, network repository function (NRF) network element, etc.

[0155] It should be understood that in mobile communication systems of different standards, the names of NF network elements with the same function may be different, and the embodiments of the present application do not limit the specific names of NF network elements with each function.

[0156] In order to manage the security functions of each node in the communication system, the communication system further includes a trusted engine and a trusted enabling unit (also referred to as a security capability node or security function, hereinafter referred to as a gear).

[0157] In this application, the engine can be used to manage the security functions of each node in the communication system. For example, the engine can generate network policies based on artificial intelligence or preset rules, and initiate a management process to the gear based on the generated network policies. The gear then configures and saves the gear profile, so that the gear can provide security capabilities to the nodes bound to the gear based on the gear profile.

[0158] The engine can be a NF; alternatively, an AN device can function as an engine if it meets the conditions required to manage security functions. These conditions include, for example, at least one of the following: the computing power of the AN device meets a set computing power requirement, or the number of nodes connected to the AN device exceeds a set threshold.

[0159] The engine may also have other functions, such as configuring and / or scheduling security capabilities, determining trust policies at the production network level, etc.

[0160] In this application, the gear can be bound to (or correspond to) one or more nodes in the communication system and provide security capabilities for the bound one or more nodes as a security function. For example, the security capabilities provided by the gear may include at least one of the following: authentication, encryption, decryption, authorization, etc. currently available in the 5G mobile communication system, the 6th generation (the 6th generation) th Systems that evolve after 5G, such as 5G generation (6G) mobile communication systems, may support blockchain, trust measurement, situational awareness, and privacy protection functions.

[0161] Gear can be deployed on the terminal device side, the AN device side, or the CN device side. In this application, gear can be an actual physical function or a virtual logical function. Gear and its bound node can be located in different devices, that is, gear can be deployed independently or as a logical function and integrated with the node to which it is bound.

[0162] For example, when a gear is bound to a terminal device, the gear can be deployed outside the bound terminal device or on the bound terminal device. For example, if gear 4 is bound to a UE, gear 4 can be deployed on the UE as a logical function, or independently deployed outside the UE as a physical function (as shown in Figure 1), or deployed as a logical function on a device outside the UE.

[0163] When a gear is bound to an AN device, it can be deployed outside the bound AN device or on the bound AN device. For example, if gear3 is bound to an AN device, gear3 can be deployed on the AN device as a logical function, or independently deployed outside the AN device as a physical function (as shown in Figure 1), or deployed as a logical function on a device outside the AN device. Optionally, when the AN device includes a CU and a DU, the gear can be deployed only on the CU or on both the CU and the DU.

[0164] When a gear is bound to a CN device, it can be deployed on the bound CN device or outside the bound CN device. For example, if gear1 is bound to NF1, gear1 can be deployed as a logical function on NF1 or independently deployed on the bus in the core network NF mode (as shown in Figure 1).

[0165] It should be understood that the above deployment forms are only exemplary. Regardless of whether the gear is deployed on the terminal device side, the AN device side, or the CN device side, it can form the basis for multi-party negotiation and trusted communication with a unified external interface.

[0166] Figure 2 illustrates a possible gear structure. As shown in Figure 2, the gear may include at least one security capability module (hereinafter referred to as an enabler module, e.g., E1 to E6 in Figure 2). Each enabler module may include an algorithm for providing security capabilities (also referred to as a security algorithm), and different enabler modules may include different algorithms.

[0167] Gear provides security capabilities for bound nodes. When a node requires security protection, it calls Gear, which then executes the algorithm in the requested enabler module, providing the node with the corresponding security capabilities. For example, when a node requires encryption, it calls Gear to execute the encryption algorithm in the enabler module named "Encryption."

[0168] In order for the gear to better provide security capabilities for the nodes bound to it, the gear must meet the security requirements of the nodes bound to it; the nodes can learn about the security capabilities provided by the gear, that is, learn about the enabler module in the gear and the algorithms supported by the enabler module.

[0169] By including both the engine and gear in the communication system, the engine can configure the gear that performs security functions, enabling flexible configuration of security functions. Furthermore, in this system, the gear that performs security functions and the nodes that perform communication functions can be separated, facilitating the independent evolution and upgrade of security functions.

[0170] It is understood that the above-mentioned network element or function can be a network component in a hardware device or a logical function. As a possible implementation method, the above-mentioned network element or function can be implemented by a single device, can be implemented by multiple devices, or can be a functional module within a single device. This embodiment of the present application does not specifically limit this.

[0171] It should be noted that the communication system shown in FIG1 does not constitute a limitation on the communication systems to which the embodiments of the present application can be applied. Therefore, the communication method provided in the embodiments of the present application can also be applied to communication systems of various standards, such as: long term evolution (LTE) communication systems, 5G communication systems, 6G communication systems and future communication systems, V2X, long term evolution - vehicle network (LTE-vehicle, LTE-V), vehicle to vehicle (vehicle to vehicle, V2V), vehicle network, machine type communication (Machine Type Communications, MTC), Internet of Things (Internet of things, IoT), long term evolution - machine to machine (LTE-machine to machine, LTE-M), machine to machine (machine to machine, M2M), Internet of Things, non-terrestrial network (NTN) system, etc. In addition, it should be noted that the embodiments of the present application do not limit the names of the network elements / functions in the communication system. Network elements / network functions that implement the same functions may have names in communication systems of different standards or in different scenarios. For example, when multiple network elements are integrated into the same physical device, the physical device may also have other names.

[0172] To facilitate understanding of this application, some of the terms used in this application are explained below.

[0173] 1) Gear status and the status of the enabler module in the gear:

[0174] The status of a gear may include: a configured state and a terminated state. Optionally, the status of a gear may also include: a ready state, a locked state, and a disabled state.

[0175] Among them, the prepared state is the state after the gear is started normally. When the gear is in the prepared state, the gear is available and waiting to be configured (or managed). The configured state is the activated state after the gear is configured. When the gear is in the configured state, the gear can be called and updated. When the gear is in the locked state, the gear can be called but cannot be updated. When the gear is in the closed state, the gear cannot be called but can be updated. The gear can be restored from the closed state to the configured state. The terminated state can also be called the off-line state, which is the end state of the gear's life cycle. When the gear is configured to the terminated state, the gear can delete all usage data. Since the gear that enters the terminated state is deleted after the current operation is completed, the terminated state will not be written to the gear profile for a long time.

[0176] The states of the enabler module in the gear may include: configuration state and termination state. Optionally, the states of the enabler module may also include lock state and shutdown state.

[0177] Among them, the configuration state is the activation state of the enabler module after it is configured. When the enabler module is in the configuration state, the enabler module can be called and updated. When the enabler module is in the locked state, the enabler module can be called but cannot be updated. When the enabler module is in the shutdown state, the enabler module cannot be called but can be updated. The enabler module can be restored from the shutdown state to the configuration state. The termination state can also be called the de-networking state, which is the end state of the enabler module's life cycle. When the enabler module is configured to the termination state, the enabler module can delete all usage data. Since the enabler module that enters the termination state is deleted after the current operation is completed, the termination state will not be written to the gear profile for a long time.

[0178] In some examples, the state of an enabler module in a gear can be determined based on the gear's state. For example, when a gear transitions from the ready state to the configured state, some enabler modules in the gear are activated and enter the configured state, while other enabler modules in the gear enter the disabled state. In other examples, the state of an enabler module in a gear can be configured individually. For example, the engine configures some enabler modules in the gear to enter the disabled state.

[0179] The status of the gear and the enabler module are not static; both the gear and the enabler module can undergo state transitions. In this application, managing the gear can include state transitions of the gear and / or the enabler module within the gear. Figure 3 illustrates possible state transitions. The following description of the state transitions of the gear and the enabler module within the gear will refer to Figure 3.

[0180] Gear state transitions: Gear can transition from the ready state to the configured state, closed state, or terminated state. Gear can transition from the configured state to the locked state, closed state, or terminated state. Gear can transition from the locked state to the configured state, closed state, or terminated state. Gear can transition from the closed state to the configured state or terminated state.

[0181] State transition of the enabler module in the gear: The enabler module can transition from the configured state to the locked state, the closed state, or the terminated state. The enabler module can transition from the locked state to the configured state, the closed state, or the terminated state. The enabler module can transition from the closed state to the configured state or the terminated state.

[0182] Optionally, the algorithm in the enabler module can also have corresponding states, and the algorithm in the enabler module can also perform state transitions. The specific details of the algorithm state can be found in the enabler module state, and the specific details of the algorithm state transition can be found in the enabler module state transition. These details are not repeated here.

[0183] In some possible approaches, instead of setting the status of the gear and the enabler module, two flags can be set: one flag indicating whether it can be called, and the other flag indicating whether it can be updated. In this way, the two flags can cover the status of the gear and the enabler module.

[0184] 2) gear profile:

[0185] In this application, a gear profile can be used to manage gear. For example, as shown in FIG4 , a gear profile can include one or more of the following:

[0186] (1) Gear attribute information: may include one or more of the gear's identity (ID) (i.e., gear ID), the gear's Internet Protocol (IP) address, and the gear's state (i.e., gear state).

[0187] (2) Information about the node bound to the gear: This may include the ID (i.e., node ID) and / or type of the node bound to the gear, such as a terminal device, an AN device, or a CN device.

[0188] (3) Information about the enabler module in the gear: This may include one or more of the name and / or ID of the enabler module (i.e., enabler names), the state of the enabler module (i.e., enabler state), the name and / or ID of the algorithm in the enabler module (i.e., enabler algorithms ID), and trusted root information (TRoot information).

[0189] (4) Parameters used for regular gear updates, version iterations, etc.: for example, the lifetime vector, etc.

[0190] 3) Gear configuration method:

[0191] In this application, the configuration method of gear may include one of the following methods:

[0192] Method 1: Remote Download: The gear, the device where the gear resides, or a node bound to the gear downloads at least one of the following from a first server: the gear, the enabler module within the gear, and the code image of the algorithm within the enabler. The first server can be a server provided by the operator, a server that includes all gears supported by the network or system where the gear resides (this server can be called a full gear), or a cloud server. Optionally, before performing the remote download, the gear, the device where the gear resides, or the node bound to the gear can first obtain the download address (i.e., the address of the first server) and obtain download permission.

[0193] Method 2: Local configuration: A node can be bound to one or more gears. The gear contains all enabler modules supported by the network or system where the gear is located; or the gear is a default template gear, for example, the gear includes a default enabler module. In some examples, in the gear, the enabler modules corresponding to security capabilities not required by the node are in a disabled state, making these enabler modules unable to be called. In other examples, some enabler modules and algorithms are running in the gear, that is, these some enabler modules and algorithms are activated, and other enabler modules can be activated when needed, so that the node can call the activated enabler modules and algorithms.

[0194] In this application, an entity can be a terminal device, an AN device, a CN device, an engine, or a gear. An entity can be a network element in a hardware device or a logical function, such as a software function running on dedicated hardware or a virtualized function instantiated on a platform (e.g., a cloud platform).

[0195] In this application, information can also be replaced by messages or signaling, etc.

[0196] In this application, the "security capabilities possessed by an entity" can be replaced by verbs with the same or similar meanings, such as "have", "support", etc.

[0197] In this application, homomorphic encryption is an encryption algorithm that satisfies the property of homomorphic operation on ciphertext. Processing homomorphically encrypted data produces output data, and decrypting this output data produces the same result as processing the original, unencrypted data using the same method.

[0198] In this application, non-homomorphic encryption means that homomorphic encryption is not set.

[0199] In this application, trust measurement, also known as remote attestation, can transfer the trustworthiness of the terminal platform to the network environment, thereby achieving trusted communication among users in the network.

[0200] In this application, unless otherwise specified, the number of nouns means "singular noun or plural noun", that is, "one or more". "At least one" means one or more, and "plurality" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of singular or plural items.

[0201] In addition, it should be understood that, in the description of this application, words such as "first" and "second" are only used for the purpose of distinguishing the description, and should not be understood as indicating or implying relative importance, nor should they be understood as indicating or implying order.

[0202] Currently, in mobile communication networks, operators manage communication devices through management systems. The security functions of communication devices are fixed and only change when the communication devices are upgraded or the network is upgraded, such as when security functions are added, updated, or deleted. Consequently, when application scenarios change, security functions cannot be updated flexibly and promptly, resulting in time delays in security function configuration. Communication devices also cannot proactively trigger the security function management process, making it impossible to configure security functions according to their needs.

[0203] Furthermore, security functions are currently tightly coupled with the communication functions of communication devices. Management of communication functions of communication devices is delegated from the management plane. For example, operators use OAM equipment to establish, update, and delete communication functions of communication devices. Consequently, communication functions of communication devices cannot be flexibly configured, making it difficult to upgrade security functions and preventing flexible configuration of security functions.

[0204] The following describes a method for solving the above-mentioned technical problem, in conjunction with the accompanying drawings. In the following method, a first entity is bound to or corresponds to a third entity and can provide security capabilities to the third entity. Because the third entity requires security capabilities, the third entity can also be referred to as the demander. The second entity can be used to manage the first entity. The fourth entity can be the second entity or the third entity. For example, the first entity is a gear, the second entity is an engine, the third entity is a node bound to the gear, and the fourth entity is either the engine or a node bound to the gear.

[0205] To solve the above problems, an embodiment of the present application provides a communication method, which can be applied to the communication system shown in Figure 1. The flow of the method will be described in detail below with reference to the flowchart shown in Figure 5.

[0206] S501: A fourth entity sends first information; in response, the first entity receives the first information. The first information may be used to determine first configuration information of the first entity, where the first configuration information is configuration information used by the first entity to provide security capabilities for a third entity. For example, if the first entity is a gear, the first configuration information may be a gear profile.

[0207] Optionally, the fourth entity sends the first information in one of the following scenarios.

[0208] Scenario 1: The fourth entity is the second entity (for example, engine), and the second entity generates a security policy. The security policy may be the security policy of the network where the second entity is located. Exemplarily, the security policy may include: security capabilities that at least one entity needs to have, and / or security capabilities that at least one entity does not need to have. The at least one entity includes a third entity. For example, the security policy is shown in Table 1. According to the second and third rows of Table 1, if the third entity is an NF, the security capabilities that the third entity needs to have include blockchain, and the security capabilities that it does not need to have include homomorphic encryption. According to the second and fourth rows of Table 1, if the third entity is a terminal device, the security capabilities that the third entity needs to have may include trust measurement, and the security capabilities that it does not need to have include homomorphic encryption. According to the second row of Table 1, if the third entity is an AN device, the security capabilities that the third entity does not need to have include homomorphic encryption.

[0209] Table 1

[0210] The following describes how the second entity obtains the security policy.

[0211] In some possible approaches, when the network's application scenario changes, for example, when the second entity determines through situational awareness that the network's application scenario has changed, the second entity may generate the security policy based on artificial intelligence (AI) technology. For example, the second entity may use the current application scenario as input data for a first AI model to obtain a security policy corresponding to the current application scenario. The first AI model may be pre-trained or trained online in real time.

[0212] In other possible implementations, the second entity may generate a security policy based on the first expert database and / or the first preset rule. The first expert database may include at least one set of correspondences between application scenarios and security policies. The first preset rule may include a correspondence between at least one condition and a security policy. Thus, when the second entity determines that at least one of the above conditions is satisfied, it may generate a corresponding security policy. The following example illustrates the correspondence between at least one condition and a security policy in the first preset rule.

[0213] For example, the at least one condition includes at least one of the following: network evolution from 5G to 6G and / or compatibility, and network online upgrade to 6G. The security policy corresponding to the at least one condition includes: all nodes in the network must have 6G security capabilities (e.g., blockchain).

[0214] For another example, the at least one condition includes at least one of the following: the operator has configured the first entity but has not bound the third entity to the first entity; the operator has bound the first entity to the third entity but has not yet activated the first entity. The security policy corresponding to the at least one condition includes: the third entity must possess at least one security capability that the first entity can provide.

[0215] In other possible approaches, the operator may set a security policy and input the security policy into the second entity. For example, when the operator wants to upgrade the network to 6G, it may determine that all nodes in the network need to have 6G security capabilities (e.g., blockchain) and input the corresponding security policy into the second entity.

[0216] Scenario 2: The fourth entity is the third entity (i.e., the demander), and the third entity generates a security requirement for the third entity. The security requirement may include: security capabilities that the third entity needs to possess, and / or security capabilities that the third entity does not need to possess. For example, the security requirement may be as shown in Table 2. The third entity does not need to possess the security capability corresponding to a requirement of 0, but does need to possess the security capability corresponding to a requirement of 1. It should be understood that the numbers corresponding to the requirements in Table 2 are merely examples. In actual applications, the requirements may also correspond to other information, for example, other numbers.

[0217] Table 2

[0218] The following describes how the third entity obtains security requirements.

[0219] In some possible approaches, when the third entity's application scenario changes, the third entity can generate security requirements based on artificial intelligence technology. For example, the third entity can use the current application scenario as input data for a second AI model to obtain security requirements corresponding to the current application scenario. This second AI model can be pre-trained or trained online in real time.

[0220] In other possible approaches, the third entity may generate the security requirement based on the second expert database and the second preset rule. The second expert database may include at least one set of correspondences between application scenarios and security requirements. The second preset rule may include a correspondence between one or more conditions and security requirements. Thus, when the third entity determines that one or more of the above conditions are met, the corresponding security requirement can be generated. The following examples illustrate the correspondence between one or more conditions and security requirements in the second preset rule.

[0221] For example, the one or more conditions include at least one of the following: the third entity changes from requiring 5G security capabilities to requiring 5G and 6G security capabilities. The security requirements corresponding to the one or more conditions include the third entity requiring 6G security capabilities (e.g., blockchain).

[0222] For another example, the one or more conditions include at least one of the following: the operator has bound the first entity to the third entity, but has not yet activated the first entity; the security requirements corresponding to the one or more conditions include: the third entity needs to have at least one security capability that the first entity can provide.

[0223] In other possible approaches, the operator may set security requirements and input these requirements into the third entity. For example, when the operator wants to upgrade the third entity to 6G, it may determine that the third entity needs to have 6G security capabilities (e.g., blockchain) and input the corresponding security requirements into the third entity.

[0224] In another possible approach, the third entity may receive security requirements input by the user through a user interface (UI). For example, if the third entity is a terminal device, after the user inserts a 6G subscriber identity module (SIM) card into the third entity, the user may determine that the third entity requires 6G security capabilities (e.g., blockchain) and enter the corresponding security requirements into the third entity through a UI interface (e.g., a screen).

[0225] The following describes how the first information is used to determine the first configuration information of the first entity in conjunction with implementation methods one to four.

[0226] Implementation method 1: The first information is used to indicate a first parameter used for performing a management operation on the first entity, and the first parameter is used to determine the first configuration information.

[0227] Management operations may include, but are not limited to, one of the following: a setup operation, an update operation, a lock operation, an unlock operation, and a delete operation. Accordingly, the type of management operation may include, but is not limited to, one of the following: setup, update, lock, unlock, and delete. Optionally, each type of management operation may correspond to at least one gear state transition. For example, Table 3 shows a possible correspondence between management operation types and gear state transitions.

[0228] Table 3

[0229] Exemplarily, the first parameter may include, but is not limited to, at least one of the following:

[0230] 1. The type of management operation performed on the first entity (hereinafter referred to as management type): for example, create, update, lock, unlock, or delete.

[0231] 2. The first state may include: an expected state of the first entity (hereinafter referred to as expected state), and / or an expected state of a security capability module in the first entity to perform a management operation (hereinafter referred to as expected enabler state).

[0232] The expected state of the first entity may be the state of the first entity after the management operation is performed on the first entity. For example, if the type of the management operation is establishment, the expected state of the first entity may be configuration state. For another example, if the type of the management operation is lock, the expected state of the first entity may be lock state.

[0233] The expected state of the security capability module in the first entity on which the management operation is to be performed may be: the state of the security capability module in the first entity after the management operation is performed on the security capability module. For example, if an unlock operation is performed on security capability module #1, the expected state of security capability module #1 is a configured state. For another example, if a lock operation is performed on security capability module #1, the expected state of security capability module #1 may be a locked state.

[0234] 3. Indicative information of the security capability module on which the management operation is to be performed in the first entity: for example, the name (hereinafter referred to as enabler name) or index of the security capability module on which the management operation is to be performed in the first entity.

[0235] 4. Indicative information of the algorithm for the management operation to be performed in the security capability module of the first entity: for example, the name or ID (hereinafter referred to as algorithm ID) of the algorithm for the management operation to be performed in the security capability module of the first entity.

[0236] Optionally, when the management operation is different, the first parameter may also be different. The corresponding relationship between the management operation and the first parameter can be referred to the description of the method shown in Figures 7 to 15 below, which will not be expanded here.

[0237] Before sending the first information indicating the first parameter, the fourth entity may obtain the first parameter. The following describes how the fourth entity obtains the first parameter.

[0238] In some possible embodiments, the fourth entity is the second entity (e.g., engine). Before sending the first information, the second entity may map the security policy to the first parameter. The specific content of the security policy can be referred to Scenario 1 and will not be repeated here.

[0239] Optionally, the second entity may map the security policy to the first parameter based on the security policy and the current configuration information of the first entity. For example, the security policy is: the security capabilities that all nodes need to have include blockchain. Before sending the first information, the second entity saves the configuration information of the first entity. If the configuration information of the first entity indicates that the security capabilities provided by the first entity do not include blockchain, the second entity may determine in the first parameter that the type of management operation performed by the first entity is update, the expected state of the security capability module to be executed in the first entity is configuration, the name of the security capability module to be executed in the first entity is blockchain, and the indication information of the algorithm to be executed in the security capability module of the first entity is the ID of the algorithm related to blockchain.

[0240] In some other possible approaches, the fourth entity is the third entity (ie, the requester). Before sending the first information, the fourth entity may map the security requirement of the third entity into the first parameter.

[0241] Optionally, the third entity may map the security requirements to the first parameter based on the security requirements and the security capabilities currently provided by the first entity. The specific content of the security requirements can be referred to Scenario 2 and will not be repeated here. For example, the security requirements are: the security capabilities that the third entity needs to possess include blockchain. Before sending the first information, the third entity saves the security capabilities currently provided by the first entity. If the security capabilities currently provided by the first entity do not include blockchain, the third entity may determine in the first parameter that the type of management operation performed by the first entity is update, the expected state of the security capability module to be executed in the first entity is configuration, the name of the security capability module to be executed in the first entity is blockchain, and the indication information of the algorithm to be executed in the security capability module of the first entity is the ID of the algorithm related to blockchain.

[0242] In some possible approaches, after receiving the first information, the first entity may perform configuration according to the first parameter and generate first configuration information corresponding to the current configuration.

[0243] In some examples, the first entity may configure the first entity based on a first parameter. For example, if the first parameter indicates that the type of management operation to be performed on the first entity is establishment, the expected state of the first entity is configuration, the expected state of the security capability module on which the management operation is to be performed in the first entity is configuration, and the name of the security capability module on which the management operation is to be performed in the first entity is blockchain, the first entity may change the state of the first entity from a prepared state to a configured state, and change the state of the security capability module named blockchain to a configured state. In this case, the first configuration information may include: the state of the first entity is configuration, the name of the security capability module includes blockchain, and the state of the security capability module named blockchain is configuration.

[0244] In other examples, the first entity may configure the security capability module in the first entity according to the first parameter. For example, in the first parameter, the type of management operation performed on the first entity is update, the expected state of the security capability module in the first entity on which the management operation is to be performed is configuration, the name of the security capability module in the first entity on which the management operation is to be performed is encryption, and the ID of the algorithm for the management operation to be performed in the security capability module of the first entity is the ID of a symmetric encryption algorithm, then the first entity may change the state of the security capability module in the first entity named encryption to a configuration state, and configure a symmetric encryption algorithm in the security capability module named encryption. In this case, in the first configuration information, the name of the security capability module includes encryption, the state of the security capability module named encryption is configuration, and the indication information of the algorithm in the security capability module named encryption includes the ID of the symmetric encryption algorithm.

[0245] It should be understood that the above two examples may also be combined, that is, the first entity may configure the first entity and the security capability module in the first entity according to the first parameter.

[0246] Through this implementation method one, the first entity can obtain the first parameter from the fourth entity without the first entity having to analyze the security policy or security requirements to obtain the first parameter, thereby reducing the computing loss of the first entity and saving the computing resources and power of the first entity.

[0247] Implementation method 2: The first information is used to indicate a security policy of at least one entity, the at least one entity includes a third entity, and the security policy is used to determine the first configuration information.

[0248] In this implementation mode 2, the fourth entity may be the second entity. The specific content of the security policy can be referred to Scenario 1 and will not be described in detail here.

[0249] Optionally, the security policy is used to determine a first parameter used to perform a management operation on the first entity, and the first parameter is used to determine the first configuration information. The specific content of the first parameter and the specific process by which the first entity determines the first configuration information based on the first parameter can be referenced in Implementation Method 1. The specific process by which the first entity determines the first parameter based on the security policy can also be referenced in Implementation Method 1, where the second entity maps the security policy to the first parameter, and is not further described here.

[0250] With this second implementation, the second entity can send a security policy to the first entity, which functions as a security function. The first entity then determines the first configuration information of the first entity based on the security policy. This eliminates the need for the second entity to determine parameters for performing management operations for each security function, thereby improving the efficiency of the second entity's security function configuration, reducing the second entity's computational overhead, and conserving the second entity's computing resources and power.

[0251] Implementation method three: the first information is used to indicate a security requirement of the third entity, and the security requirement is used to determine the first configuration information.

[0252] In this implementation method 3, the fourth entity may be the third entity. The specific content of the security requirements can be referred to Scenario 2 and will not be repeated here.

[0253] Optionally, the security requirement is used to determine a first parameter used to perform a management operation on the first entity, and the first parameter is used to determine the first configuration information. The specific content of the first parameter and the specific process by which the first entity determines the first configuration information based on the first parameter can be referenced in Implementation Method 1. The specific process by which the first entity determines the first parameter based on the security requirement can also be referenced in Implementation Method 1, where the third entity maps the security requirement to the first parameter, and is not further described here.

[0254] In some embodiments, the security capabilities in the first configuration information determined by the first entity fully match the security requirements. For example, the security requirement states that the third entity must possess security capabilities that include blockchain and encryption. In the first configuration information, the security capability module named blockchain and the security capability module named encryption are both in the configured state. In other words, the security capabilities in the first configuration information include blockchain and encryption.

[0255] In other embodiments, the security capabilities in the first configuration information determined by the first entity do not fully match the security requirements. The first entity determines the first configuration information based on the configuration information of the first entity before receiving the first information and the first information. For example, in the configuration information before the first entity receives the first information, the status of the security capability module named encryption and the security capability module named authentication are both in the configuration state. The security requirement is: the security capabilities that the third entity needs to possess include blockchain. In this case, the security capabilities in the first configuration information determined by the first entity include blockchain, encryption, and authentication. For another example, in the configuration information before the first entity receives the first information, the status of the security capability module named encryption is in the configuration state. The security requirement is: the security capabilities that the third entity needs to possess include blockchain. If the first entity cannot obtain the blockchain, the security capabilities in the first configuration information determined by the first entity include encryption.

[0256] Through this third implementation, the third entity can send security requirements to the first entity, which functions as a security function. The first entity then determines the first configuration information of the first entity based on the security requirements. This eliminates the need for the third entity to analyze the security requirements, thereby reducing the computational overhead of the third entity and conserving its computing resources and power.

[0257] Implementation method four: the first information includes first configuration information.

[0258] In this fourth implementation, the fourth entity may be the second entity. Before sending the first information, the second entity may determine, based on the security policy, a first parameter to be used for performing a management operation on the first entity, and generate the first configuration information based on the first parameter. The specific content of the first parameter may be referenced in implementation one. The specific process by which the second entity may determine the first parameter based on the security policy may also be referenced in implementation one, where the second entity maps the security policy to the first parameter. The method by which the second entity generates the first configuration information may be referenced in implementation one, where the first entity generates the first configuration information, and will not be further described here.

[0259] Through this fourth implementation method, the first entity can obtain the first configuration information from the second entity without the first entity having to analyze the security policy or security requirements to obtain the first configuration information, thereby reducing the computing loss of the first entity and saving the computing resources and power of the first entity.

[0260] S502: The first entity sends first feedback information; correspondingly, the fourth entity receives the first feedback information, wherein the first feedback information is used to indicate whether the first entity has successfully configured the first configuration information.

[0261] In some implementations, the first information in S501 is the first information in implementation 1 or implementation 2, and the fourth entity is the second entity. In this case, the first feedback information may also include the first configuration information. In this way, the second entity can obtain and save the first configuration information, thereby effectively managing the first entity.

[0262] In some other implementations, the first information in S501 is the first information in implementation method 1 or implementation method 3, and the fourth entity is the third entity. In this case, the first feedback information may further include: indication information of the first security capability and the ID of the first entity. The first security capability is determined based on the first information and is the security capability provided by the first entity to the third entity.

[0263] In some examples, the first security capability may be a security capability adjusted based on the first information. For example, before receiving the first information, the first entity may provide the third entity with security capabilities including encryption and authentication. After receiving the first information, the first entity may provide the third entity with security capabilities including encryption, authentication, and blockchain. The first security capability may include blockchain.

[0264] In other examples, the first security capabilities may be all security capabilities provided by the first entity to the third entity after adjusting the security capabilities based on the first information. For example, before receiving the first information, the security capabilities provided by the first entity to the third entity include encryption and authentication. After receiving the first information, the security capabilities provided by the first entity to the third entity include encryption, authentication, and blockchain. The first security capabilities include encryption, authentication, and blockchain.

[0265] Exemplarily, the indication information of the first security capability may include at least one of the following: the status of the first entity, indication information of the security capability module corresponding to the first security capability in the first entity, indication information of the algorithm in the security capability module corresponding to the first security capability in the first entity, the status of the security capability module corresponding to the first security capability in the first entity, and the status of the algorithm in the security capability module corresponding to the first security capability in the first entity. For example, when the first security capability is blockchain, in the indication information of the first security capability, the status of the first entity may be configuration status, the name of the security capability module corresponding to the first security capability in the first entity may be blockchain, the indication information of the algorithm in the security capability module corresponding to the first security capability in the first entity may be the ID of algorithm #1 in blockchain, and the status of the security capability module corresponding to the first security capability in the first entity may be configuration.

[0266] In this way, the third entity can obtain and save the first security capability, so as to call the first entity to support the first security capability.

[0267] It should be understood that the first feedback information may be response information of the first information, or may be a notification message indicating whether the first entity has successfully configured the first configuration information.

[0268] Through the method shown in Figure 5, the fourth entity can configure the first entity through the first information, thereby quickly and flexibly configuring the first entity. In addition, since the fourth entity can configure the first entity through signaling, when the fourth entity perceives that the application scenario has changed, the fourth entity can promptly configure the first entity, so that the configuration of the first entity can meet the current needs and provide reliable security support for the third entity. In addition, in this method, the first entity can be an entity independent of the third entity. The first entity can serve as a security function, and the third entity can serve as a communication function. This allows for flexible configuration of security functions independent of the communication function, which is conducive to the independent evolution and update and upgrade of the security function.

[0269] In addition, in this method, the third entity, as a demander of security capabilities, can trigger the configuration of the first entity, thereby improving the third entity's control over the first entity as a security function, so that the first entity can provide security services to the third entity on demand.

[0270] In some implementations, the fourth entity is the second entity, that is, S501 includes: the first entity receives the first information from the second entity. In this case, the method shown in Figure 5 may also include:

[0271] S503: The first entity sends second information to the third entity; correspondingly, the third entity receives the second information from the first entity.

[0272] The second information indicates the first security capability provided by the first entity to the third entity. The first security capability is determined based on the first information. The details of the first security capability can be found in S502 and will not be further described here. In this way, the first entity can promptly notify the third entity of the first security capability provided by the first entity, allowing the third entity to invoke the first entity to support the first security capability.

[0273] Exemplarily, the second information includes: indication information of the first security capability and identification information of the first entity. Specific content of the indication information of the first security capability can be found in S502 and will not be described in detail here.

[0274] Optionally, after receiving the second information, the third entity may determine the first security capability provided by the first entity to the third entity and verify whether the first security capability meets its own requirements. For example, the first security capability includes blockchain. Among the third entity's security requirements, the security capability required by the third entity includes blockchain. In this case, the third entity may determine that the first security capability meets its own requirements. For another example, the first security capability includes encryption, authentication, and blockchain. Among the third entity's security requirements, the security capability required by the third entity includes situational awareness. In this case, the third entity may determine that the first security capability does not meet its own requirements.

[0275] In some possible approaches, after S503 , the method shown in FIG5 further includes:

[0276] S504: The third entity sends third information to the first entity; correspondingly, the first entity receives the third information from the third entity, wherein the third information is used to indicate whether the first security capability meets the requirements of the third entity.

[0277] Scenario 1: The third information indicates that the first security capability meets the requirements of the third entity. In this case, in S502, the first feedback information indicates that the first entity has successfully configured the first configuration information. In this way, the second entity can be informed that the configuration of the first entity has been successful.

[0278] Scenario 2: The third information is used to indicate that the first security capability does not meet the requirements of the third entity. The following example illustrates the operations of each entity in Scenario 2.

[0279] In one example, in S502, the first feedback information may indicate that the first entity failed to successfully configure the first configuration information. This allows the second entity to be notified of the unsuccessful configuration of the first entity and to further manage the first entity. For example, the third information and the first feedback information may include information indicating security capability #A, where security capability #A is a required security capability of the third entity and is not included in the first security capability. The second entity may reconfigure the first entity based on security capability #A. The configuration method may refer to S501 and will not be further described here.

[0280] In another example, the third information may include information indicating security capability #A, where security capability #A is a security capability required by the third entity and the first security capability does not include security capability #A. The first entity may reconfigure itself based on security capability #A. The configuration method is described in S501 and will not be further described here. The first entity may then perform operations from S503 to S504 until the security capabilities provided by the first entity meet the requirements of the third entity.

[0281] It should be understood that the third information may be response information to the second information, or may be a notification message indicating whether the first security capability meets the requirements of the third entity.

[0282] Through this method, the first entity can learn whether the first security capability meets the requirements of the third entity, and thus can further adjust the configuration of the first entity according to the requirements of the third entity.

[0283] In some other implementations, the fourth entity is the third entity, that is, S501 includes: the first entity receives the first information from the third entity. In this case, the method shown in Figure 5 may also include:

[0284] S505: The first entity sends fourth information to the second entity; correspondingly, the second entity receives the fourth information from the first entity, wherein the fourth information includes the first configuration information, and the fourth information is used to register the first configuration information of the first entity.

[0285] Optionally, after receiving the fourth information, the second entity may determine the first configuration information and verify whether the first configuration information satisfies the security policy. If the first configuration information satisfies the security policy, the first configuration information is successfully registered; if the first configuration information does not satisfy the security policy, the first configuration information registration fails. The specific content of the security policy can be found in Scenario 1 and is not further described here.

[0286] For example, in the first configuration information, the configured security capability module includes blockchain. In the security policy, the third entity's required security capability includes blockchain. In this case, the second entity can determine that the first configuration information satisfies the security policy and can successfully register the first configuration information.

[0287] For example, in the first configuration information, the configured security capability modules include encryption, authentication, and blockchain. In the security policy, the security capability required of the third entity includes situational awareness. In this case, the second entity may determine that the first configuration information does not meet the security policy, and the registration of the first configuration information fails.

[0288] In some possible approaches, after S505 , the method shown in FIG5 further includes:

[0289] S506: The second entity sends fifth information to the first entity; correspondingly, the first entity receives the fifth information from the second entity, wherein the fifth information is used to indicate whether the first configuration information of the first entity is successfully registered.

[0290] Scenario 1: The fifth information indicates that the first entity's first configuration information has been successfully registered. In this case, in S502, the first feedback information indicates that the first entity has successfully configured the first configuration information. This allows the third entity to learn that the first entity's first configuration information has been successfully registered and, therefore, to invoke the first entity to provide security capabilities corresponding to the first configuration information.

[0291] Scenario 2: The fifth information is used to indicate that the registration of the first configuration information of the first entity fails. The following example illustrates the operations of each entity under Scenario 2.

[0292] In one example, the fifth information may include information indicating security capability #B. Security capability #B is a security capability required by the third entity in the security policy, and the capabilities provided by the first entity based on the first configuration information do not include security capability #B. The first entity may reconfigure itself based on security capability #B. The configuration method is described in S501 and will not be further described here. The first entity may then perform operations from S503 to S504 until the first entity's configuration information is successfully registered.

[0293] In another example, in S502, the first feedback information may indicate that the registration of the first configuration information failed. This allows the third entity to learn of the registration failure of the first configuration information and to perform further operations on the first entity. For example, the fifth information and the first feedback information may include information indicating security capability #B. Security capability #B is a security capability required by the third entity in the security policy, and the capabilities provided by the first entity based on the first configuration information do not include security capability #B. The third entity may reconfigure the first entity based on security capability #B. The configuration method is described in S501 and will not be further described here.

[0294] It should be understood that the fifth information may be response information to the fourth information, or may be a notification message indicating whether the first configuration information is successfully registered.

[0295] Through this method, the first entity can promptly learn whether the first configuration information is successfully registered, and thus can provide the third entity with the security capability permitted by the second entity according to the registration result.

[0296] To solve the above problems, the present invention provides another communication method, which can be applied to the communication system shown in Figure 1. The flow chart shown in Figure 6 is referred to below to describe the process of this method in detail.

[0297] S601: A third entity sends a request message to a second entity; in response, the second entity receives the request message from the third entity, wherein the request message is used to request the establishment of a first entity, which is an entity that provides security capabilities for the third entity.

[0298] Optionally, when the third entity generates a security requirement for the third entity and there is no first entity currently, the third entity may send a request message to the second entity. The specific content of the third entity generating the security requirement for the third entity can be referred to Scenario 2 in S501 and will not be repeated here. The first entity may be a logical function.

[0299] In some possible implementations, the request information includes information indicating the security capability module within the first entity. In other words, the request information includes information indicating the security capability module corresponding to the security capability required by the third entity. For example, the information indicating the security capability module may be the name of the security capability module. For example, if the third entity's security requirements include the required security capabilities of blockchain and trust metrics, the name of the security capability module in the request information may include blockchain and trust metrics. This approach accurately indicates the content of the first entity, thereby accelerating the establishment of the first entity.

[0300] S602: The second entity sends second feedback information to the third entity; correspondingly, the third entity receives the second feedback information from the second entity.

[0301] The second feedback information is used to indicate information for establishing the first entity.

[0302] In some examples, the second feedback information includes a download address for the first entity. The device corresponding to the download address (e.g., the first server) may include the security capability module of the first entity. Thus, upon receiving the second feedback information, the second entity may download the security capability module from the first entity from the device corresponding to the download address. Furthermore, the second feedback information contains less information, which can reduce signaling overhead.

[0303] In other examples, the second information includes the code of the security capability module in the first entity. In this way, after receiving the second feedback information, the second entity can obtain the security capability module in the first entity, thereby quickly establishing the first entity.

[0304] It should be understood that the second feedback information may be response information to the request information, or may be a notification message indicating information for establishing the first entity.

[0305] Optionally, before sending the second feedback information, the second entity determines whether the third entity has passed the authentication, and only when the third entity has passed the authentication, the second entity sends the second feedback information. In some examples, the second entity may authenticate the third entity to determine whether the third entity has passed the authentication. In other examples, the core network device (for example, an authentication service function (AUSF) or UDM) may authenticate the third entity and send the authentication result to the second entity, and the second entity determines whether the third entity has passed the authentication based on the authentication result. This application does not limit the specific process of authentication and authorization.

[0306] S603: The third entity establishes the first entity according to the second feedback information.

[0307] In some embodiments, the third entity may obtain the security capability module in the first entity according to the second feedback information. The method of obtaining the security capability module may refer to S602 and will not be described in detail here. Then, the third entity may establish the first entity including the security capability module.

[0308] In other embodiments, the third entity may obtain the security capability module from the first entity based on the second feedback information. The method for obtaining the security capability module is described in S602 and will not be further described here. The third entity may then send the security capability module from the first entity to a fifth entity used to establish the first entity. The fifth entity may then establish the first entity containing the security capability module. The fifth entity may, for example, be the device where the first entity resides.

[0309] Optionally, after the first entity is established, the first entity may generate first configuration information. The manner in which the first entity generates the first configuration information may be referred to S501 and will not be described in detail here.

[0310] S604: The first entity sends sixth information to the second entity. In response, the second entity receives the sixth information from the first entity. The sixth information includes the first configuration information of the first entity and indicates whether the first entity has successfully configured the first configuration information. This allows the second entity to obtain and save the first configuration information, thereby managing the first entity.

[0311] Through the method shown in Figure 6, when the first entity does not exist, the third entity can request the second entity to establish the first entity based on the needs of the third entity, thereby enabling the first entity to be established quickly and flexibly. Furthermore, since the first entity can be established through signaling, when the third entity perceives a change in the application scenario, the third entity can promptly request the second entity to establish the first entity, thereby ensuring that the establishment of the first entity meets the current needs and providing reliable security support for the third entity. In addition, in this method, the third entity, as the demander of security capabilities, can trigger the establishment of the first entity, improving the third entity's control over the first entity as a security function, allowing the first entity to provide security services to the third entity on demand. In addition, in this method, the first entity can be an entity independent of the third entity. The first entity can serve as a security function, and the third entity can serve as a communication function. This allows for the flexible establishment of security functions independent of the communication function, facilitating the independent evolution and update and upgrade of the security function.

[0312] In some possible embodiments, the method shown in FIG6 further includes:

[0313] S605: The second entity sends seventh information to the third entity; correspondingly, the third entity receives the seventh information from the second entity.

[0314] The seventh information indicates the second security capability, which is the security capability of the first entity. For example, after establishing the first entity, the security capabilities provided by the first entity to the third entity include encryption and authentication. The second security capabilities also include encryption and authentication. This allows the second entity to promptly notify the third entity of the second security capability that the first entity can provide, allowing the third entity to invoke the first entity to support the second security capability.

[0315] Exemplarily, the seventh information includes: indication information of the second security capability and identification information of the first entity. The specific content of the second security capability can refer to the indication information of the first security capability in S502, which will not be repeated here.

[0316] Optionally, before S605, the second entity may verify the first configuration information, for example, to verify whether the first configuration information satisfies the security policy. The details of this verification are described in S505 and are not further described here. If the second entity verifies that the first configuration information satisfies the security policy, the second entity may execute S605. If the second entity verifies that the first configuration information does not satisfy the security policy, the first entity may be reconfigured. The configuration method is described in S501 and is not further described here.

[0317] In some possible implementations, the method shown in Figure 6 may be combined with the method shown in Figure 5. For example, after the first entity is established using the method shown in Figure 6, the first entity may be configured using the method shown in Figure 5.

[0318] The present application provides another communication method. This method is a method for establishing a first entity and is a possible implementation of the method shown in Figure 5. The following describes the process of this method in detail, taking the first entity as the gear, the second entity as the engine, and the third entity as the demander as an example.

[0319] To facilitate understanding of this method, the establishment of gear is first explained below.

[0320] Gear creation is also called gear activation. When a gear is created through local configuration, its state changes from ready to configured. Some enabler modules in the gear enter the configured state, while others enter the disabled state. When a gear is created through remote download, its state changes to configured, and its enabler modules also enter the configured state.

[0321] In this application, the gear establishment method can be a gear establishment method triggered by the engine or a gear establishment method triggered by the demander, which are described below.

[0322] FIG7 shows a method for establishing a gear triggered by an engine, in which the fourth entity is the engine. The method will be described below with reference to FIG7 .

[0323] S701: The engine sends first information to the gear, where the first information can be used to establish the gear.

[0324] For the specific content of S701, reference may be made to Implementation Method 1, Implementation Method 2, and Implementation Method 4 in S501, and the repeated parts will not be repeated here.

[0325] The following example illustrates the conditions under which the engine sends the first message.

[0326] In some examples, the engine may send the first information to the gear when it determines that the demander is in the configuration stage or the demander has newly joined the network. That is, the gear establishment process may occur in the configuration stage of the demander. The demander is, for example, a terminal device, a base station, or a NF. Exemplarily, the engine may detect that the demander has newly joined the network through the network topology. For example, if the network topology shows that a new terminal device #1 has been added to the network, the engine may determine to establish a gear bound to the terminal device #1. Alternatively, after receiving the network access request from the demander and determining that the demander has passed the authentication, the engine may determine to establish a gear for the demander.

[0327] In other examples, the engine may send the first information to the gear when it determines that at least one of the following conditions is met: the network evolves from 5G to and / or is compatible with 6G; the network is upgraded to 6G online; the operator has configured the gear but has not bound the demander to the gear; the operator has bound the gear to the demander but has not yet activated the gear.

[0328] In some other examples, the engine may send the first information to the gear after receiving an instruction from the management plane or the management network element to instruct the gear to be established. Optionally, the instruction to instruct the gear to be established includes the first information.

[0329] The first information is described below in combination with methods a1 to a3.

[0330] In mode a1, the first information includes the first parameter used to perform the establishment operation on the gear. The specific content of this mode can be referred to the implementation mode 1 in S501, and the repeated parts will not be repeated.

[0331] Exemplarily, the first parameter includes: the type of management operation to be performed on the gear, the expected state of the gear, and the name of the enabler module in the gear on which the management operation is to be performed. For example, the first parameter includes: management type = setup, expected state = configured, [enabler name = blockchain]. This indicates that the type of management operation to be performed on the gear is setup, the expected state of the gear is configured, and the gear contains an enabler module named blockchain, i.e., the expected state of the enabler module named blockchain is configured.

[0332] The first parameter may be determined by the engine based on a security policy. For example, the security policy may be that all nodes must possess security capabilities that include blockchain. If the engine does not have a gear profile for the gear, the engine may determine the first parameter to include: management type = setup, expected state = configured, [enabler name = blockchain].

[0333] In mode a2, the first information includes a security policy. The specific content of this mode can refer to the second implementation mode in S501, and the specific content of the first parameter can refer to mode a1. The repeated parts will not be repeated here.

[0334] Optionally, after receiving the security policy, the gear may determine, based on the security policy, the first parameters to use when performing a setup operation on the gear. For example, the security policy may specify that all nodes must possess security capabilities that include blockchain. The gear is bound to the demander but has not yet been activated. In this case, the gear may determine that the first parameters include: management type = setup, expected state = configured, [enabler name = blockchain].

[0335] In mode a3, the first information includes the first configuration information. The specific content of this mode can be referred to the fourth implementation mode in S501, and the repeated parts will not be repeated.

[0336] For example, the first configuration information is gear profile #1. In gear profile #1, the status of the gear is the configuration status, the ID of the node bound to the gear is the ID of the demander, and the name of the enabler module is blockchain.

[0337] The first configuration information can be determined by the engine based on a security policy. For example, the security policy may be that all nodes must possess security capabilities that include blockchain. If the engine does not have a gear profile for the gear bound to the demander, the engine may determine that the first configuration information for the gear is gear profile #1. In gear profile #1, the gear's status is configured, the node ID bound to the gear is the demander's ID, and the enabler module name is blockchain.

[0338] S702: The gear performs a gear creation operation.

[0339] In method b1, the gear can be established based on the first parameters. Exemplarily, the first parameters include: management type = setup, expected state = configured, [enabler name = blockchain]. If the gear includes an enabler module named blockchain, the gear can be established through local configuration, for example, by transferring the gear's state to the configured state and the state of the enabler module named blockchain to the configured state. If the gear does not include an enabler module named blockchain, the gear can be established through remote download, for example, by downloading the enabler module named blockchain from the first server, and transferring the gear's state to the configured state and the state of the enabler module named blockchain to the configured state.

[0340] In method b2, the gear can be established based on the first configuration information. For example, in the first configuration information, the gear's status is configured, the ID of the node bound to the gear is the ID of the demander, and the name of the enabler module is blockchain. Gear can be established in a similar manner to method b1 and will not be further described here.

[0341] S703: The gear generates first configuration information corresponding to the current configuration. The specific content of the first configuration information can be referred to method a3 in S701 and will not be repeated here.

[0342] S703 is an optional step. For example, when the first information includes first configuration information, the method shown in FIG7 may not include S703.

[0343] S704: The gear sends second information to the demander, wherein the second information is used to indicate the first security capability provided by the gear to the demander, and the first security capability is determined according to the first information.

[0344] The specific content of S704 can be referred to S503, and the repeated parts will not be repeated.

[0345] Optionally, since Gear is newly established, the first security capability is all security capabilities that Gear provides to the demander. For example, if the security capabilities that Gear can provide include blockchain, then the first security capability includes blockchain.

[0346] S705: The demander verifies whether the first security capability meets the demander's needs. If the first capability meets the demander's needs, the demander may save the first security capability.

[0347] The specific content of the demander verifying whether the first security capability meets the demander's needs can be referred to the description of the third entity verifying whether the first security capability meets its own needs in S503, which will not be repeated here.

[0348] S706: The demander sends third information to the gear, wherein the third information is used to indicate whether the first security capability meets the demander's requirements.

[0349] The specific content of S706 can be found in S504 and will not be repeated here.

[0350] S707: The gear sends first feedback information to the engine, wherein the first feedback information is used to indicate whether the gear has successfully configured the first configuration information; in other words, the first feedback information is used to indicate whether the gear has been successfully established.

[0351] The specific content of S707 can be referred to S502, and the repeated parts will be omitted.

[0352] S708: The engine saves the first configuration information.

[0353] Optionally, in the method shown in FIG7 , S701 may be replaced by: the engine sends a first message to the node where the gear is located. The first message may be the first message in method a1 or method a2. S702 may be replaced by: the node where the gear is located performs a gear establishment operation. The specific content of the gear node performing the gear establishment operation can be referred to the remote download method in the gear performing the gear establishment operation, and will not be repeated here.

[0354] Through the method shown in Figure 7, the engine can trigger the establishment of the gear through the first information, thereby enabling rapid and flexible gear establishment. Furthermore, because the engine can trigger the establishment of the gear through signaling, when the engine detects a change in the application scenario, it can promptly trigger the establishment of the gear, enabling the gear to meet current needs and provide reliable security support for the demander. Furthermore, in this method, the gear can be an entity independent of the demander, with the gear serving as a security function and the demander serving as a communication function. This allows for the flexible establishment of security functions independent of the communication function, facilitating the independent evolution and update and upgrade of the security function.

[0355] Figure 8 shows a method for establishing a gear triggered by a demander. In this method, the fourth entity is the demander; the demander has bound a default gear, but the gear is not activated. The method is described below with reference to Figure 8.

[0356] S801: The demand direction sends the first information to the gear.

[0357] For the specific content of S801, please refer to the implementation method 1 and implementation method 3 in S501, and the repeated parts will be omitted.

[0358] The following examples illustrate the conditions for the demander to send the first information.

[0359] In some examples, when the demander determines that the demander is in the configuration phase, the first information may be sent to the gear. In other words, the gear establishment process may occur during the demander's configuration phase. The demander may be, for example, a terminal device, a base station, or a network function.

[0360] In other examples, the demander may send the first information to the gear when it determines that at least one of the following conditions is met: the demander changes from requiring 5G security capabilities to requiring 5G and 6G security capabilities; the operator binds the first entity to the third entity, but has not yet activated the first entity.

[0361] In some other examples, the engine may send the first information to the gear after receiving an instruction for establishing the gear from the management plane or the management network element. Optionally, the instruction for establishing the gear may include the first information.

[0362] The first information will be described below.

[0363] In one possible manner, the first information includes a first parameter used to perform the establishment operation on the gear. The specific content of this manner can refer to the implementation manner 1 in S501, and the specific content of the first parameter can refer to the manner a1 in S701. The repeated parts will not be repeated here.

[0364] The first parameter can be determined by the demander based on their security requirements. For example, a security requirement might include: The demander's security capabilities must include blockchain. If the demander is already bound to a device but lacks the device's security capabilities, the demander can determine the first parameter to include: management type = setup, expected state = configured, [enabler name = blockchain].

[0365] In another possible manner, the first information includes the security requirements of the demander. The specific content of this manner can be referred to the third implementation manner in S501, and the repeated parts will not be repeated here.

[0366] Optionally, after receiving the security requirement, the gear may determine, based on the security requirement, the first parameters used to perform the setup operation on the gear. For example, the security requirement may be: The security capabilities required by the requester include blockchain. If the gear is bound to the requester but not yet activated, the requester may determine that the first parameters include: management type = setup, expected state = configured, [enabler name = blockchain].

[0367] S802: The gear performs a gear creation operation.

[0368] The specific content of S802 can be referred to S702 and will not be repeated here.

[0369] S803: The gear generates first configuration information corresponding to the current configuration. The specific content of the first configuration information can be referred to method a3 in S701 and will not be repeated here.

[0370] S804: The gear sends fourth information to the engine, wherein the fourth information includes the first configuration information and is used to register the first configuration information.

[0371] The specific content of S804 can be found in S505 and will not be repeated here.

[0372] S805: The engine verifies whether the first configuration information satisfies the security policy. If the first configuration information satisfies the security policy, the engine may save the first configuration information.

[0373] The specific content of S805 can be found in S505 and will not be repeated here.

[0374] S806: The engine sends fifth information to the gear, wherein the fifth information is used to indicate whether the first configuration information is successfully registered.

[0375] The specific content of S806 can be found in S506 and will not be repeated here.

[0376] S807: The gear sends first feedback information to the demander, wherein the first feedback information may include indication information of the first security capability and the gear ID.

[0377] The specific content of S807 can be found in S502 and will not be repeated here.

[0378] S808: The demander saves the first security capability.

[0379] Through the method shown in Figure 8, the demander can trigger the establishment of the gear through the first information, thereby enabling the gear to be established quickly and flexibly. Furthermore, since the demander can trigger the establishment of the gear through signaling, when the demander perceives a change in the application scenario, the demander can promptly trigger the establishment of the gear so that the gear can meet the current needs. In addition, in this method, the demander can trigger the establishment of the gear, which improves the demander's control over the gear as a security function, allowing the gear to provide security services to the demander on demand. In addition, in this method, the gear can be an entity independent of the demander, the gear can serve as a security function, and the demander can serve as a communication function, thereby enabling the flexible establishment of a security function independent of the communication function, which is conducive to the independent evolution and update and upgrade of the security function.

[0380] The present application provides another communication method. This method is an update method for a first entity and is another possible implementation of the method shown in Figure 5. The following describes the process of this method in detail, taking the first entity as a gear, the second entity as an engine, and the third entity as a demander as an example.

[0381] To facilitate understanding of the method, the following first describes a scenario of gear updating. FIG9 shows two scenarios of gear updating, which will be described below in conjunction with FIG9.

[0382] Scenario 1: The entire network's gears are upgraded or undergoing version evolution. For example, as shown in Figure 9, before the update, the network's enabler modules may include E1 through E5. After the update, E6 and E7 are added. The Engine can trigger updates for each gear, for example, adding E6 and E7 to gear1 and E7 to gear2.

[0383] Scenario 2: Changes in the network's security policy or the customer's security requirements necessitate a gear update. The details of the security policy and requirements are described in S501 and are omitted here. For example, as shown in Figure 9, the enabler modules in the full gear remain unchanged, E1 through E5, before and after the update. Before the update, the enabler module in gear 1 was E1; after the update, the enabler modules in gear 1 have been expanded to include E2 and E5.

[0384] In this application, the gear update method can be an engine-triggered gear update method or a demand-side triggered gear update method. Among them, the engine-triggered gear update method can be applied to the above-mentioned scenarios 1 and 2, and the demand-side triggered gear update method can be applied to the above-mentioned scenario 2.

[0385] FIG10 shows a gear update method triggered by an engine, in which the fourth entity is the engine. The method will be described below with reference to FIG10.

[0386] In the first embodiment, the method shown in FIG10 includes S1001 to S1002:

[0387] S1001: The engine sends a first message including a security policy to the gear, and the gear receives the first message accordingly.

[0388] S1002: The gear determines a first parameter used for performing an update operation on the gear according to the security policy.

[0389] For the specific contents of S1001 to S1002, please refer to the second implementation method in S501, and the repeated parts will not be repeated.

[0390] In this application, gear updates may include at least one of the following: gear state transitions between configured and disabled states, enabler module state transitions, adding or removing enabler modules, modifying the demander associated with the gear, and activating, deactivating, adding, or removing algorithms within enabler modules. Regarding enabler state transitions, please refer to the terminology explanation section and will not be further described here. Accordingly, gear update objects may include at least one of the following: gear, enabler modules within the gear, and algorithms within the enabler modules. The first parameters corresponding to each update object are described below.

[0391] 1. The update object is gear.

[0392] If gear determines that it needs to transition between the configured state and the disabled state, it needs to modify the state of the gear in the gear profile. For example, the first parameter includes: manage type = update, expected state = disable. This means: the type of management operation performed on the gear is update, and the expected state of the gear is disabled. For another example, the first parameter includes: manage type = update, expected state = configured. This means: the type of management operation performed on the gear is update, and the expected state of the gear is configured.

[0393] The gear determines whether to modify the demander bound to the gear. For example, if the node bound to the gear is deleted or restarted, but the gear is not deleted synchronously and can still be bound to other nodes. In this case, the gear can determine the ID of the demander to modify in the gear profile. For example, the first parameter may include: manage type = update, node ID = ID#A. This indicates that the type of management operation performed on the gear is update, and the node bound to the gear will be changed to the node with ID ID#A.

[0394] In this application, the gear can be updated by means of local configuration.

[0395] 2. The update object is the enabler module.

[0396] If the gear determines that it needs to perform a state transition on an enabler module, or add or delete an enabler module in the gear, it must modify one or more of the enabler module name in the gear profile, the algorithm identifier in the enabler corresponding to the enabler module, and the enabler module state. For example, the first parameter includes: manage type = update, [enabler names = blockchain, expected enabler state = terminated]. This indicates that the type of management operation being performed on the gear is update, and that the enabler module named blockchain is expected to be deleted. The square brackets may contain one or more enabler module names and their corresponding information (e.g., the expected enabler module state).

[0397] In this application, the gear can update the enabler module by local configuration or remote download.

[0398] 3. The update object is the algorithm in the enabler module.

[0399] If the gear determines that it wants to activate, deactivate, add, or delete an algorithm in an enabler module, it must modify the algorithm's ID and / or state in the gear profile. For example, the first parameter includes: management type = update, [enabler name = blockchain, algorithm ID = ID#B, expected algorithm state = configured]. This indicates that the management operation being performed on the gear is update, and that the algorithm identified by ID#B in the enabler module named blockchain is expected to be activated.

[0400] In this application, the gear can update the algorithm through local configuration or remote download.

[0401] In the second embodiment, the method shown in FIG10 includes S1003:

[0402] S1003: The engine sends first information including first parameters to the gear.

[0403] The specific content of S1003 can refer to the implementation method 1 in S501, and the content of the first parameter can refer to S1002. The repeated parts will not be repeated here.

[0404] Optionally, after the engine obtains the security policy, or after the engine receives an instruction from the management plane or other network element to instruct the gear to be updated, the engine may send the first information to the gear. The instruction to instruct the gear to be updated may include the first information.

[0405] In the third embodiment, the method shown in FIG10 includes S1004:

[0406] S1004: The engine sends first information including first configuration information to the gear.

[0407] The specific content of S1004 can be referred to the fourth implementation method in S501, and will not be repeated here.

[0408] After S1002, S1003 or S1004, the method shown in FIG10 further includes:

[0409] S1005: The gear performs a gear update operation.

[0410] In method C1, the gear can update the gear according to the first parameter. Exemplarily, the first parameter includes: manage type = update, [enabler names = blockchain, expected enabler state = configured]. If the gear includes an enabler module named blockchain, the gear can update the gear through local configuration, for example, by transferring the state of the enabler module named blockchain from another state to the configured state. If the gear does not include an enabler module named blockchain, the gear can update the gear through remote download, for example, by downloading the enabler module named blockchain from the first server and transferring the state of the enabler module named blockchain to the configured state.

[0411] In method c2, the gear may be updated according to the first configuration information.

[0412] For example, the first configuration information is gear profile #2. In gear profile #2, the gear state is configured. If the current state of the gear is closed, the gear state is transferred to the configured state.

[0413] For another example, the first configuration information is gear profile #3. In gear profile #3, the gear is in the configured state, the enabler module is named blockchain, and the state of the enabler module named blockchain is in the configured state. If the gear includes an enabler module named blockchain, the gear can be updated through local configuration, for example, by transferring the state of the enabler module named blockchain from another state to the configured state. If the gear does not include an enabler module named blockchain, the gear can be updated through remote download, for example, by downloading the enabler module named blockchain from the first server and transferring the state of the enabler module named blockchain to the configured state.

[0414] S1006: The gear generates first configuration information corresponding to the current configuration. The specific content of the first configuration information can be found in S1005 and will not be described in detail here.

[0415] S1006 is an optional step. For example, when the first information includes first configuration information, the method shown in FIG10 may not include S1006.

[0416] S1007: The gear sends second information to the demander, wherein the second information is used to indicate the first security capability provided by the gear to the demander, and the first security capability is determined according to the first information.

[0417] S1008: The demander verifies whether the first security capability meets the demander's needs. If the first security capability meets the demander's needs, the demander may save the first security capability.

[0418] The specific contents of S1007 to S1008 can be referred to S503 and will not be repeated here.

[0419] S1009: The demander sends third information to the gear, wherein the third information is used to indicate whether the first security capability meets the demander's requirements.

[0420] The specific content of S1009 can be found in S504 and will not be repeated here.

[0421] S1010: The gear sends first feedback information to the engine, wherein the first feedback information is used to indicate whether the gear has successfully configured the first configuration information; in other words, the first feedback information is used to indicate whether the gear has been successfully updated.

[0422] The specific content of S1010 can be referred to S502, and the repeated parts will be omitted.

[0423] S1011: The engine saves the first configuration information.

[0424] Through the method shown in Figure 10, the engine can trigger a gear update via the first information, enabling fast and flexible gear updates. Furthermore, because the engine can trigger gear updates via signaling, when the engine detects a change in the application scenario, it can promptly trigger a gear update, ensuring that the gear meets current needs and provides reliable security support for the demander. Furthermore, in this method, the gear can be an entity independent of the demander, with the gear serving as a security function and the demander serving as a communication function. This allows for flexible updates to security functions independent of the communication function, facilitating the independent evolution and upgrade of security functions.

[0425] FIG11 shows a gear update method triggered by a demander, in which the fourth entity is the demander. The method will be described below with reference to FIG11.

[0426] In embodiment 1, the method shown in FIG11 further includes S1101 to S1102.

[0427] S1101: The demander sends a first message including a security requirement to the gear.

[0428] S1102: The gear determines a first parameter used for performing an update operation on the gear according to security requirements.

[0429] The specific contents of S1101 to S1102 may refer to the third implementation method in S501, and the specific contents of the first parameter may refer to S1002, which will not be repeated here.

[0430] In embodiment 2, the method shown in FIG11 includes S1103.

[0431] S1103: The demander sends first information including first parameters to the gear.

[0432] The specific content of S1103 can refer to the implementation method 1 in S501, and the specific content of the first parameter can refer to S1002, which will not be repeated here.

[0433] After S1102 or S1103, the method shown in FIG11 further includes:

[0434] S1104: The gear performs a gear update operation.

[0435] The gear may be updated according to the first parameter. For details, please refer to S1005 and will not be described again here.

[0436] S1105: The gear generates first configuration information corresponding to the current configuration. The specific content of the first configuration information can be found in S1005 and will not be described in detail here.

[0437] S1106: The gear sends fourth information to the engine, wherein the fourth information includes the first configuration information, and the fourth information is used to register the first configuration information.

[0438] S1107: The engine verifies whether the first configuration information satisfies the security policy. If the first configuration information satisfies the security policy, the engine may save the first configuration information.

[0439] The specific contents of S1106 to S1107 can be referred to S505 and will not be repeated here.

[0440] S1108: The engine sends fifth information to the gear, wherein the fifth information is used to indicate whether the first configuration information is successfully registered.

[0441] The specific content of S1108 can be found in S506 and will not be repeated here.

[0442] S1109: The gear sends first feedback information to the demander, wherein the first feedback information may include indication information of the first security capability and the gear ID.

[0443] The specific content of S1109 can be found in S502 and will not be repeated here.

[0444] S1110: The demander preserves the first security capability.

[0445] Through the method shown in Figure 11, the demander can trigger a gear update through the first information, allowing for quick and flexible gear updates. Furthermore, because the demander can trigger a gear update through signaling, when the demander perceives a change in the application scenario, it can promptly trigger a gear update to ensure that the gear meets current needs. Furthermore, in this method, the demander can trigger a gear update, improving the demander's control over the gear as a security function, allowing the gear to provide security services to the demander on demand. Furthermore, in this method, the gear can be an entity independent of the demander, with the gear acting as a security function and the demander acting as a communication function. This allows for flexible updates to security functions independent of the communication function, facilitating the independent evolution and upgrade of security functions.

[0446] The present application provides another communication method. This method is a method for locking or unlocking a first entity and is another possible implementation of the method shown in Figure 5. The following describes the process of this method in detail, taking the first entity as the gear, the second entity as the engine, and the third entity as the demander as an example.

[0447] In this application, the gear locking or unlocking method can be a gear locking or unlocking method triggered by the engine, or a gear locking or unlocking method triggered by the demander, which are described below.

[0448] FIG12 shows a method for locking or unlocking a gear triggered by an engine, in which the fourth entity is the engine.

[0449] In embodiment a1, the method shown in FIG12 includes S1201 to S1202:

[0450] S1201: The engine sends first information including a security policy to the gear.

[0451] S1202: The gear determines a first parameter used to perform a locking or unlocking operation on the gear according to the security policy.

[0452] For the specific contents of S1201 to S1202, reference may be made to the second implementation method in S501, and the repeated parts will not be repeated.

[0453] In this application, locking or unlocking a gear may include at least one of the following: a gear state transition between a configured state and a locked state; or a state transition between a configured state and a locked state of an enabler module. Accordingly, the objects to be locked or unlocked by a gear may include at least one of the following: the gear itself; or an enabler module within the gear itself. The following describes the first parameters corresponding to each locked or unlocked object.

[0454] 1. The object to be locked or unlocked is gear.

[0455] If the gear determines to transfer the gear state between the configured state and the locked state, the gear state in the gear profile needs to be modified.

[0456] In some examples, the gear determines that it wants to transition from a configured state to a locked state. In this case, the first parameter may include manage type = lock, and / or expected state = locked. This indicates that the type of management operation being performed on the gear is locked, and / or the expected state of the gear is locked.

[0457] In other examples, the gear determines that it wants to move from a locked state to a configured state. In this case, the first parameter may include: manage type = unlock, and / or expected state = configured. This indicates that the type of management operation being performed on the gear is unlock, and / or the expected state of the gear is configured.

[0458] In this application, the gear can be locked or unlocked by local configuration.

[0459] 2. The object to be locked or unlocked is the enabler module.

[0460] If the gear determines that the enabler module needs to be transferred between the configured state and the locked state, the state of the enabler module in the gear profile needs to be modified.

[0461] In some examples, the gear determines that an enabler module in the gear needs to be moved from a configured state to a locked state. In this case, the first parameter may include: manage type = lock, [enabler names = blockchain]; or [enabler names = blockchain, expect enabler state = locked]. This indicates that a lock operation is performed on the enabler module named blockchain in the gear.

[0462] In other examples, the management operation on the gear is to transfer the enabler module in the gear from a locked state to a configured state. In this case, the first parameter may include: manage type = unlock, [enabler names = blockchain]; or [enabler names = blockchain, expect enabler state = configured]. This indicates that the unlock operation is performed on the enabler module named blockchain in the gear.

[0463] In this application, the gear can lock or unlock the enabler module through local configuration or remote download.

[0464] In embodiment a2, the method shown in FIG12 includes S1203:

[0465] S1203: The engine sends first information including first parameters to the gear.

[0466] The specific content of S1203 can refer to the implementation method 1 in S501, and the content of the first parameter can refer to S1202. The repeated parts will not be repeated here.

[0467] Optionally, after the engine obtains the security policy, or after the engine receives an instruction from the management plane or other network element to instruct the gear to be locked or unlocked, the engine may send a first message to the gear. The instruction to instruct the gear to be locked or unlocked may include the first message.

[0468] In embodiment a3, the method shown in FIG12 includes S1204:

[0469] S1204: The engine sends first information including first configuration information to the gear.

[0470] The specific content of S1204 can be referred to the fourth implementation method in S501 and will not be repeated here.

[0471] After S1202, S1203 or S1204, the method shown in FIG12 further includes:

[0472] S1205: The gear performs a gear locking or unlocking operation.

[0473] In mode d1, the gear can perform a gear locking or unlocking operation according to the first parameter.

[0474] For example, the first parameter includes: manage type=lock, [enabler names=blockchain]; or [enabler names=blockchain, expect enabler state=locked]. Gear can lock the enabler module named blockchain, that is, transfer the state of the enabler module named blockchain to a locked state.

[0475] For another example, the first parameter includes: manage type=lock, and / or expected state=locked. gear may perform a locking operation on the gear, that is, transfer the state of the gear to a locked state.

[0476] For another example, if the first parameter includes: manage type=unlock, and / or expected state=configured, gear may perform an unlock operation on the gear, that is, transfer the state of the gear to the configured state.

[0477] In mode d2, the gear may perform a gear locking or unlocking operation according to the first configuration information.

[0478] For example, the first configuration information is gear profile #4. In gear profile #4, the gear status is configured. The current gear status is locked. The gear can then perform an unlock operation on the gear, that is, transfer the gear status to configured.

[0479] For another example, the first configuration information is gear profile #5. In gear profile #5, the gear status is locked. The current gear status is configured. The gear can perform a lock operation on the gear, that is, transfer the gear status to locked.

[0480] S1206: The gear generates first configuration information corresponding to the current configuration. The specific content of the first configuration information can be found in S1205 and will not be repeated here.

[0481] S1207: The gear sends second information to the demander, wherein the second information is used to indicate the first security capability provided by the gear to the demander, and the first security capability is determined based on the first information.

[0482] S1208: The demander verifies whether the first security capability meets the demander's needs. If the first security capability meets the demander's needs, the demander may save the first security capability.

[0483] S1209: The demander sends third information to the gear, wherein the third information is used to indicate whether the first security capability meets the demander's requirements.

[0484] S1210: The gear sends first feedback information to the engine, wherein the first feedback information is used to indicate whether the gear has successfully configured the first configuration information; in other words, the first feedback information is used to indicate whether the gear has been successfully locked or unlocked.

[0485] S1211: The engine saves the first configuration information.

[0486] For the specific contents of S1206 to S1211, please refer to S1006 to S1011, and the repeated parts will not be repeated.

[0487] Through the method shown in Figure 12, the engine can trigger the locking or unlocking of the gear through the first information, thereby quickly and flexibly locking or unlocking the gear. In addition, since the engine can trigger the locking or unlocking of the gear through signaling, when the engine senses that the application scenario has changed, the engine can promptly trigger the locking or unlocking of the gear, so that the gear can meet the current needs and provide reliable security support for the demander. In addition, in this method, the gear can be an entity independent of the demander, the gear can be used as a security function, and the demander can be used as a communication function, so that the security function independent of the communication function can be flexibly locked or unlocked, which is conducive to the independent evolution and update and upgrade of the security function.

[0488] FIG13 shows a method for locking or unlocking a gear triggered by a demander, in which the fourth entity is the demander.

[0489] In implementation b1, the method shown in FIG13 includes S1301 to S1302.

[0490] S1301: The demander sends a first message including a security requirement to the gear.

[0491] For the specific content of S1301, please refer to the third implementation method in S501, and the repeated parts will be omitted.

[0492] In some examples, the security requirement indicates that the requester needs to have the security capabilities that the gear can provide, and the requester can trigger the locking of the gear to send the first message. When the security requirement indicates that the requester needs to have the security capabilities that the gear can provide, the requester can be calling the gear or calling the gear during a subsequent communication process.

[0493] In other examples, the security requirement indicates that the requester needs to have the security capabilities that can be provided by the enabler module in the gear. The requester can trigger the lock of the enabler module to send the first information. When the security requirement indicates that the requester needs to have the security capabilities that can be provided by the enabler module, the requester can call the enabler module or call the enabler module in a subsequent communication process.

[0494] In some other examples, the security requirement indicates that the security capabilities required by the requester do not include those provided by the gear, and the requester may trigger unlocking of the gear, thereby sending the first message. When the security requirement indicates that the security capabilities required by the requester do not include those provided by the gear, the requester has already terminated the call for the gear or does not need to call the gear.

[0495] In some further examples, if the security requirement indicates that the security capabilities required by the requester do not include those provided by the enabler module in the gear, the requester may trigger unlocking of the enabler module, thereby sending the first information. When the security requirement indicates that the security capabilities required by the requester do not include those provided by the enabler module, the requester has terminated invoking the enabler module or no longer needs to invoke the enabler module.

[0496] S1302: The gear determines a first parameter used to perform a locking or unlocking operation on the gear according to security requirements.

[0497] The specific content of S1302 can refer to the implementation method three in S501, and the specific content of the first parameter can refer to S1202, which will not be repeated here.

[0498] In implementation b2, the method shown in FIG13 includes S1303.

[0499] S1303: The demander sends first information including first parameters to the gear.

[0500] The specific content of S1303 can refer to the implementation method 1 in S501, and the specific content of the first parameter can refer to S1202, which will not be repeated here.

[0501] After S1302 or S1303, the method shown in FIG13 further includes:

[0502] S1304: The gear performs a gear locking or unlocking operation.

[0503] The gear may be locked or unlocked according to the first parameter. For details, please refer to S1205 and will not be described again here.

[0504] S1305: The gear generates first configuration information corresponding to the current configuration. The specific content of the first configuration information can be found in S1205 and will not be described in detail here.

[0505] S1306: The gear sends fourth information to the engine, wherein the fourth information includes the first configuration information, and the fourth information is used to register the first configuration information.

[0506] S1307: The engine verifies whether the first configuration information satisfies the security policy. If the first configuration information satisfies the security policy, the engine may save the first configuration information.

[0507] S1308: The engine sends fifth information to the gear, wherein the fifth information is used to indicate whether the first configuration information is successfully registered.

[0508] S1309: The gear sends first feedback information to the demander, wherein the first feedback information may include indication information of the first security capability and the gear ID.

[0509] S1310: Gear saves the first security capability.

[0510] The specific contents of S1305 to S1310 can be referred to S1105 to S1110 and will not be repeated here.

[0511] Through the process shown in Figure 13, the demander can trigger the locking or unlocking of the gear through the first information, thereby quickly and flexibly locking or unlocking the gear. Moreover, since the demander can trigger the locking or unlocking of the gear through signaling, when the demander perceives that the application scenario has changed, the demander can trigger the locking or unlocking of the gear in a timely manner so that the gear can meet the current needs. In addition, in this method, the demander can trigger the locking or unlocking of the gear, which improves the demander's control over the gear as a security function, allowing the gear to provide security services to the demander on demand. In addition, in this method, the gear can be an entity independent of the demander, the gear can serve as a security function, and the demander can serve as a communication function, so that the security function independent of the communication function can be flexibly locked or unlocked, which is conducive to the independent evolution and update and upgrade of the security function.

[0512] To address the above issues, embodiments of the present application provide yet another communication method. This method is a method for deleting a first entity and is another possible implementation of the method shown in Figure 5. The following describes the method flow in detail, taking the first entity as gear, the second entity as engine, and the third entity as the demander as an example.

[0513] In this application, the gear deletion method can be an engine-triggered gear deletion method, a demander-triggered gear deletion method, or a gear-triggered gear deletion method. These are described below.

[0514] FIG14 shows a gear deletion method triggered by an engine, in which the fourth entity is an engine. The method will be described below with reference to FIG14.

[0515] In embodiment c1, the method shown in FIG14 includes S1401 to S1402:

[0516] S1401: The engine sends first information including a security policy to the gear.

[0517] S1402: The gear determines, according to the security policy, a first parameter used to perform a deletion operation on the gear.

[0518] For the specific contents of S1401 to S1402, reference may be made to the second implementation method in S501, and the repeated parts will not be repeated here.

[0519] For example, the first parameter may include: manage type=delete, and / or expected state=terminated, which means that the type of management operation performed on the gear is delete, and the expected state of the gear is terminated.

[0520] In embodiment c2, the method shown in FIG14 includes S1403:

[0521] S1403: The engine sends first information including first parameters to the gear.

[0522] The specific content of S1403 can refer to the implementation method 1 in S501, and the content of the first parameter can refer to S1402. The repeated parts will not be repeated here.

[0523] Optionally, after the engine obtains the security policy, or after the engine receives an instruction from the management plane or other network element to instruct the gear to be deleted, the engine may send the first information to the gear. The instruction to instruct the gear to be deleted may include the first information.

[0524] In implementation c3, the method shown in FIG14 includes S1404:

[0525] S1404: The engine sends first information including first configuration information to the gear.

[0526] For the specific content of S1404, please refer to the fourth implementation method in S501, and the repeated parts will be omitted.

[0527] Optionally, in the first configuration information, the state of the gear is a terminated state.

[0528] After S1402, S1403 or S1404, the method shown in FIG14 further includes:

[0529] S1405: After finishing running the currently running program, the gear deletes all node-related data stored in the gear.

[0530] S1406: The gear sends a request message #A to the demander. The request message #A is used to trigger the demander to delete the security capability and the gear ID of the gear stored in the demander.

[0531] In some possible implementations, the request message #A is a message requesting the deletion of the security capabilities and ID of the gear, and the request message #A includes the gear ID. Thus, upon receiving the request message #A, the demander can determine that the security capabilities and ID of the gear stored in the demander's database need to be deleted.

[0532] In other possible implementations, the request message #A may be the second message in S503, indicating that the first security capability provided by the gear to the demander is an empty set. Thus, upon receiving the request message #A, the demander may determine that the security capabilities and ID of the gear stored in the demander's database need to be deleted.

[0533] S1407: The demander deletes the security capability of the gear and the gear ID stored locally.

[0534] S1406 to S1407 are optional. For example, when the demander has deregistered or has withdrawn from the network, the method shown in FIG14 may not include S1406 to S1407.

[0535] S1408: The gear sends a request message #B to the engine. The request message #B is used to trigger the engine to delete the gear profile of the gear stored in the engine.

[0536] In some possible implementations, the request message #B is a message for requesting the gear profile to be deleted, and the request message #B includes the gear ID. Thus, upon receiving the request message #B, the engine can determine that the gear profile of the gear stored in the engine needs to be deleted.

[0537] In other possible implementations, request message #B may be the first feedback message in S502. This first feedback message indicates that the gear has been successfully deleted. For example, this first feedback message includes gear profile #6 for the gear, where the gear status in gear profile #6 is terminated. Thus, upon receiving request message #B, the engine can determine that the gear has been deleted and, therefore, needs to delete the gear profile stored in the engine.

[0538] S1409: The engine deletes the configuration information (gear profile) of the gear stored locally.

[0539] The present application does not limit the execution order of S1406 to S1407 and S1408 to S1409. The present application does not limit the execution order of S1405 and S1406 to S1409.

[0540] The method shown in FIG14 further includes:

[0541] S1410: The gear performs a network exit operation.

[0542] Optionally, S1410 occurs after S1405, S1406, and S1408.

[0543] Through the method shown in Figure 14, the engine can trigger gear deletion via the first message, enabling quick and flexible gear deletion. Furthermore, because the engine can trigger gear deletion via signaling, when the engine detects a change in the application scenario, it can promptly trigger gear deletion, ensuring that the gear meets current needs and provides reliable security support for the demander. Furthermore, in this method, the gear can be an entity independent of the demander, with the gear serving as a security function and the demander serving as a communication function. This allows for flexible removal of security functions independent of the communication function.

[0544] FIG15 shows a gear deletion method triggered by a demander, in which the fourth entity is the demander. The method will be described below with reference to FIG15.

[0545] In implementation d1, the method shown in FIG15 includes S1501 to S1503.

[0546] S1501: The demander sends a first message including a security requirement to the gear.

[0547] For the specific content of S1501, please refer to the implementation method three in S501, and the repeated parts will be omitted.

[0548] For example, when the demander wants to perform operations such as logout or network withdrawal, or the demander needs to use other security authorizations besides gear, the demander determines that the security requirements include: no need for the security capabilities provided by gear, thereby triggering the deletion of gear and sending the first information to the gear.

[0549] S1502: The gear determines a first parameter used to perform a deletion operation on the gear according to security requirements.

[0550] The specific content of S1502 can refer to the implementation method three in S501, and the specific content of the first parameter can refer to S1402, which will not be repeated here.

[0551] In implementation d2, the method shown in FIG15 includes S1503.

[0552] S1503: The demander sends first information including first parameters to the gear.

[0553] The specific content of S1503 can refer to the implementation method 1 in S501, and the specific content of the first parameter can refer to S1402, which will not be repeated here.

[0554] After S1502 or S1503, the method shown in FIG15 further includes:

[0555] S1504: After the gear finishes running the currently running program, it deletes all node-related data stored in the gear.

[0556] S1505: The gear requests information #B from the engine. The request information #B is used to trigger the engine to delete the gear profile of the gear stored in the engine.

[0557] In some possible implementations, the request message #B is a message for requesting the gear profile to be deleted, and the request message #B includes the gear ID. Thus, upon receiving the request message #B, the engine can determine that the gear profile of the gear stored in the engine needs to be deleted.

[0558] In other possible implementations, request message #B may be the fourth message in S505. For example, the fourth message includes gear profile #6 for the gear. In gear profile #6, the gear's status is terminated. Thus, upon receiving request message #B, the engine can determine that the gear has been deleted and, therefore, needs to delete the gear profile stored in the engine.

[0559] S1506: The engine deletes the configuration information (gear profile) of the gear stored locally.

[0560] S1507: The gear sends a request message #A to the demander. The request message #A is used to trigger the demander to delete the security capability and the gear ID of the gear stored in the demander.

[0561] In some possible implementations, the request message #A is a message requesting the deletion of the security capabilities and ID of the gear, and the request message #A includes the gear ID. Thus, upon receiving the request message #A, the demander can determine that the security capabilities and ID of the gear stored in the demander's database need to be deleted.

[0562] In other possible implementations, the request message #A may be the first feedback message in S502, indicating that the first security capability provided by the gear to the demander is an empty set. Thus, upon receiving the request message #A, the demander may determine that the security capabilities and ID of the gear stored in the demander's database need to be deleted.

[0563] S1508: The demander deletes the security capability of the gear and the gear ID stored locally.

[0564] S1507 to S1508 are optional. For example, when the demander has deregistered or has withdrawn from the network, the method shown in FIG15 may not include S1507 to S1508.

[0565] The present application does not impose any restrictions on the execution order of S1505 to S1506 and S1507 to S1508. The present application does not impose any restrictions on the execution order of S1504 and S1505 to S1508.

[0566] The method shown in FIG15 further includes:

[0567] S1509: The gear performs a network exit operation.

[0568] Optionally, S1509 occurs after S1504, S1505, and S1507.

[0569] In some possible implementations, if the demander detects that a bound gear has been disconnected from the network, the demander can trigger gear deletion. For example, upon detecting that a bound gear has been disconnected from the network, the demander can delete the locally stored security capabilities and gear ID of the gear and send a request message #C to the engine, requesting the engine to delete the gear profile. Upon receiving the request message #C, the engine can delete the locally stored gear profile for the gear. Optionally, the request message #C can include the gear ID.

[0570] Through the process shown in Figure 15, the demander can trigger the deletion of the gear through the first message, thereby deleting the gear quickly and flexibly. Moreover, because the demander can trigger the deletion of the gear through signaling, when the demander perceives a change in the application scenario, the demander can promptly trigger the deletion of the gear so that the gear can meet the current needs. In addition, in this method, the demander can trigger the deletion of the gear, which improves the demander's control over the gear that serves as a security function, allowing the gear to provide security services to the demander on demand. In addition, in this method, the gear can be an entity independent of the demander, the gear can serve as a security function, and the demander can serve as a communication function, thus allowing the flexible deletion of security functions independent of the communication function.

[0571] FIG16 shows a gear deletion method triggered by a gear, and the method is described below with reference to FIG16 .

[0572] S1601: The gear sends a request message #B to the engine. The request message #B is used to trigger the engine to delete the gear profile of the gear saved in the engine.

[0573] Optionally, when a program error occurs in the gear and the gear cannot work, or the life cycle in the gear profile of the gear expires, the gear can send a request message #B to the engine.

[0574] The specific content of the request information #B can be found in S1408 and S1505 and will not be repeated here.

[0575] S1602: The engine deletes the configuration information (gear profile) of the gear stored locally.

[0576] S1603: The gear sends a request message #A to the demander. The request message #A is used to trigger the demander to delete the security capability and the gear ID of the gear stored in the demander.

[0577] Optionally, when a gear operation error causes it to shut down, or when the life cycle in the gear profile of the gear expires, the gear may send a request message #A to the requester.

[0578] The specific content of the request information #A can be found in S1406 and S1507 and will not be repeated here.

[0579] S1604: The demander deletes the security capability of the gear and the gear ID stored locally.

[0580] S1603 to S1604 are optional. For example, when the demander has deregistered or has withdrawn from the network, the method shown in FIG16 may not include S1603 to S1604.

[0581] This application does not limit the execution order of S1601 to S1602 and S1603 to S1604.

[0582] S1605: The gear deletes all data related to the node stored in the gear.

[0583] This application does not limit the execution order of S1601 to S1604 and S1605.

[0584] The method shown in FIG16 further includes:

[0585] S1606: The gear performs a network exit operation.

[0586] Optionally, S1606 occurs after S1601, S1603, and S1605.

[0587] Through the process shown in Figure 16, the gear can trigger the gear deletion, allowing for quick and flexible gear deletion. Furthermore, in this method, the gear can be an entity independent of the demander. The gear can serve as a security function, and the demander can serve as a communication function, allowing for flexible deletion of the security function independent of the communication function.

[0588] Based on the same technical concept as the method embodiments of Figures 5 to 16, the embodiment of the present application provides a communication device through Figure 17, which can be used to perform the functions of the relevant steps in the above method embodiments. The functions can be implemented by hardware, or by software or hardware executing corresponding software implementations. The hardware or software includes one or more modules corresponding to the above functions. The structure of the communication device is shown in Figure 17, including a communication unit 1701 and a processing unit 1702. The communication device 1700 can be applied to a terminal device, AN device, CN device, engine or gear in the communication system shown in Figure 1, and can implement the communication method provided in the above embodiments of the present application and the examples. The functions of each unit in the communication device 1700 are introduced below.

[0589] The communication unit 1701 is used to receive and send data. In some embodiments, the communication unit 1701 can be implemented through a physical interface, a communication module, a communication interface, and an input / output interface. The communication device 1700 can be connected to a network cable or a cable through the communication unit to establish a physical connection with other devices. In other embodiments, the communication unit 1701 can be implemented by a transceiver, for example, a mobile communication module. The mobile communication module may include at least one antenna, at least one filter, a switch, a power amplifier, a low noise amplifier (LNA), etc.

[0590] The processing unit 1702 can be used to support the communication device 1700 in performing the processing actions in the above method embodiment. The processing unit 1702 can be implemented by a processor. For example, the processor can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor can be a microprocessor or any conventional processor.

[0591] The specific functions of the processing unit 1702 can be referred to the description of the communication method provided in the above embodiments and examples of the present application, and will not be repeated here.

[0592] It should be noted that the division of modules in the above embodiments of the present application is illustrative and is only a logical functional division. In actual implementation, there may be other division methods. In addition, the functional units in the various embodiments of the present application may be integrated into a processing unit, or may exist separately physically, or two or more units may be integrated into a single unit. The above-mentioned integrated units may be implemented in the form of hardware or in the form of software functional units.

[0593] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0594] Based on the same technical concept, an embodiment of the present application provides a communication device as shown in Figure 18, which can be used to execute the relevant steps in the above method embodiment. The communication device can be applied to the terminal equipment, AN equipment, CN equipment, engine or gear in the communication system shown in Figure 1, and can implement the communication method provided in the above embodiments and examples of the present application, and has the functions of the communication device shown in Figure 17. Referring to Figure 18, the communication device 1800 includes: a processor 1802. Optionally, the communication device 1800 also includes: a transceiver 1801 and a memory 1803. Among them, the transceiver 1801, the processor 1802 and the memory 1803 are interconnected.

[0595] Optionally, the transceiver 1801, the processor 1802, and the memory 1803 are interconnected via a bus 1804. The bus 1804 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus. The bus may be classified as an address bus, a data bus, a control bus, etc. For ease of illustration, FIG18 shows only one thick line, but this does not mean that there is only one bus or only one type of bus.

[0596] The transceiver 1801 is used to receive and send data to implement communication interaction with other devices. For example, the transceiver 1801 can be implemented through a physical interface, a communication module, a communication interface, and an input / output interface.

[0597] [Corrected 20.04.2023 in accordance with Rule 91] The processor 1802 may be used to support the communication device 1800 in executing the processing actions in the above-mentioned method embodiments. When the communication device 1800 is used to implement the above-mentioned method embodiments, the processor 1802 may also be used to implement the functions of the processing unit 1702. The processor 1802 may be a CPU, other general-purpose processors, DSPs, ASICs, FPGAs, other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. A general-purpose processor may be a microprocessor or any conventional processor.

[0598] The specific functions of the processor 1802 can be referred to the description of the communication method provided in the above embodiments and examples of the present application, and will not be repeated here.

[0599] The memory 1803 is used to store program instructions and / or data, etc. Specifically, the program instructions may include program code, which includes computer operation instructions. The memory 1803 may include RAM, and may also include non-volatile memory (non-volatile memory), such as at least one disk storage. The processor 1802 executes the program instructions stored in the memory 1803, and uses the data stored in the memory 1803 to implement the above functions, thereby realizing the communication method provided in the above embodiment of the present application. The memory 1803 can be integrated with the processor 1802, or it can be a memory outside the communication device.

[0600] It is understood that the memory 1803 in FIG. 18 of the present application can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be ROM, programmable read-only memory (Programmable ROM, PROM), erasable programmable read-only memory (Erasable PROM, EPROM), electrically erasable programmable read-only memory (Electrically EPROM, EEPROM) or flash memory. The volatile memory can be RAM, which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct RAM bus random access memory (DR RAM). It should be noted that the memory of the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0601] Based on the above embodiments, an embodiment of the present application further provides a computer program, which, when executed on a computer, enables the computer to execute the method provided in the above embodiments.

[0602] Based on the above embodiments, an embodiment of the present application further provides a computer program product including computer-executable instructions. When the computer program product is run, the method provided in the above embodiments is executed.

[0603] Based on the above embodiments, an embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a computer, the computer executes the method provided in the above embodiments.

[0604] The storage medium may be any available medium that can be accessed by a computer. By way of example and not limitation, computer-readable media may include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage media or other magnetic storage devices, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer.

[0605] Based on the above embodiments, an embodiment of the present application further provides a chip, which is used to read a computer program stored in a memory to implement the method provided in the above embodiments.

[0606] Based on the above embodiments, embodiments of the present application provide a chip system, which includes a processor for supporting a computer device to implement the functions involved in each device in the above embodiments. In one possible design, the chip system also includes a memory for storing the necessary programs and data for the computer device. The chip system can be composed of a chip or can include a chip and other discrete devices.

[0607] In the various embodiments of the present application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.

[0608] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0609] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the present application. It should be understood that each flow and / or box in the flow chart and / or block diagram, as well as the combination of the flow chart and / or box in the flow chart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device for implementing the functions specified in one or more flow charts and / or one or more boxes in the block diagram.

[0610] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.

[0611] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.

[0612] Obviously, those skilled in the art may make various changes and modifications to the present application without departing from the scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is intended to include these modifications and variations.

Claims

1. A communication method, characterized in that: include: The first entity receives first information, where the first information is used to determine first configuration information of the first entity, where the first configuration information is configuration information used by the first entity to provide security capabilities for a third entity; The first entity sends first feedback information, where the first feedback information is used to indicate whether the first entity successfully configures the first configuration information.

2. The method according to claim 1, characterized in that The first information is used to indicate a first parameter used to perform a management operation on the first entity, and the first parameter is used to determine the first configuration information.

3. The method according to claim 1, characterized in that The first information is used to indicate a security policy of at least one entity, the at least one entity includes the third entity, and the security policy is used to determine the first configuration information.

4. The method according to claim 3, characterized in that The security policy includes: security capabilities that the at least one entity needs to have, and / or security capabilities that the at least one entity does not need to have.

5. The method according to claim 3 or 4, characterized in that The security policy is used to determine a first parameter used to perform a management operation on the first entity, and the first parameter is used to determine the first configuration information.

6. The method according to claim 1, characterized in that The first information is used to indicate a security requirement of the third entity, and the security requirement is used to determine the first configuration information.

7. The method according to claim 6, characterized in that The security requirements include: security capabilities that the third entity needs to have, and / or security capabilities that the third entity does not need to have.

8. The method according to claim 6 or 7, characterized in that The security requirement is used to determine a first parameter used to perform a management operation on the first entity, and the first parameter is used to determine the first configuration information.

9. The method according to claim 2, 5 or 8, characterized in that The management operation includes one of the following: a creation operation, an update operation, a lock operation, an unlock operation, and a delete operation.

10. The method according to any one of claims 2, 5, 8 to 9, characterized in that: The first parameter includes at least one of the following: a type of management operation performed on the first entity; a first state, the first state comprising: an expected state of the first entity, and / or an expected state of a security capability module in the first entity on which a management operation is to be performed; Indicative information of a security capability module in the first entity on which a management operation is to be performed; Indicative information of an algorithm for a management operation to be performed in a security capability module of the first entity.

11. The method according to any one of claims 2 to 5, characterized in that: The first feedback information also includes the first configuration information.

12. The method according to claim 1, characterized in that The first information includes the first configuration information.

13. The method according to any one of claims 1 to 5, 11 to 12, characterized in that: The first entity receiving the first information includes: the first entity receiving the first information from a second entity, where the second entity is an entity that manages the first entity; The method further includes: the first entity sending second information to the third entity, where the second information is used to indicate a first security capability provided by the first entity for the third entity, and the first security capability is determined according to the first information.

14. The method according to claim 13, characterized in that Also includes: The first entity receives third information from the third entity, where the third information is used to indicate whether the first security capability meets the requirements of the third entity; When the third information is used to indicate that the first security capability meets the requirement of the third entity, the first feedback information is used to indicate that the first entity successfully configures the first configuration information.

15. The method according to claim 13 or 14, characterized in that The second information includes: indication information of the first security capability and identification information of the first entity.

16. The method according to any one of claims 1 to 3, 6 to 8, 11 to 12, characterized in that: The first entity receiving the first information includes: the first entity receiving the first information from the third entity; The method also includes: the first entity sending fourth information to a second entity, the fourth information including the first configuration information, the fourth information being used to register the first configuration information of the first entity, and the second entity being an entity that manages the first entity.

17. The method according to claim 16, characterized in that Also includes: The first entity receives fifth information from the second entity, where the fifth information is used to indicate whether the first configuration information of the first entity is successfully registered; When the fifth information is used to indicate that the first configuration information of the first entity is successfully registered, the first feedback information is used to indicate that the first entity successfully configures the first configuration information.

18. A communication method, characterized in that: include: The fourth entity sends first information, where the first information is used to determine first configuration information of the first entity, where the first configuration information is configuration information used by the first entity to provide security capabilities for the third entity, and the fourth entity is the third entity or a second entity that manages the first entity; The fourth entity receives first feedback information, where the first feedback information is used to indicate whether the first entity successfully configures the first configuration information.

19. The method according to claim 18, characterized in that The first information is used to indicate a first parameter used to perform a management operation on the first entity, and the first parameter is used to determine the first configuration information.

20. The method of claim 18, wherein: The first information is used to indicate a security policy of at least one entity, the at least one entity includes the third entity, and the security policy is used to determine the first configuration information.

21. The method of claim 20, wherein: The security policy includes: security capabilities that the at least one entity needs to have, and / or security capabilities that the at least one entity does not need to have.

22. The method according to claim 20 or 21, characterized in that The security policy is used to determine a first parameter used to perform a management operation on the first entity, and the first parameter is used to determine the first configuration information.

23. The method of claim 18, wherein: The first information is used to indicate a security requirement of the third entity, and the security requirement is used to determine the first configuration information.

24. The method of claim 23, wherein: The security requirements include: security capabilities that the third entity needs to have, and / or security capabilities that the third entity does not need to have.

25. The method according to claim 23 or 24, characterized in that The security requirement is used to determine a first parameter used to perform a management operation on the first entity, and the first parameter is used to determine the first configuration information.

26. The method of claim 19, 22 or 25, wherein: The management operation includes one of the following: a creation operation, an update operation, a lock operation, an unlock operation, and a delete operation.

27. The method according to any one of claims 19, 22, 25 to 26, characterized in that The first parameter includes at least one of the following: a type of management operation performed on the first entity; a first state, the first state comprising: an expected state of the first entity, and / or an expected state of a security capability module in the first entity on which a management operation is to be performed; Indicative information of a security capability module in the first entity on which a management operation is to be performed; Indicative information of an algorithm for a management operation to be performed in a security capability module of the first entity.

28. The method according to any one of claims 19 to 22, characterized in that The first feedback information also includes the first configuration information.

29. The method of claim 18, wherein: The first information includes the first configuration information.

30. A communication method, characterized in that: include: The second entity receives request information from the third entity, where the request information is used to request to establish a first entity, where the first entity is an entity that provides security capabilities for the third entity; The second entity sends second feedback information to the third entity, where the second feedback information is used to indicate information for establishing the first entity; The second entity receives sixth information from the first entity, where the sixth information includes first configuration information of the first entity, and the sixth information is used to indicate whether the first entity successfully configures the first configuration information.

31. The method of claim 30, wherein: The second feedback information includes a download address of the first entity.

32. The method according to claim 30 or 31, characterized in that The request information includes indication information of a security capability module in the first entity.

33. The method according to any one of claims 30 to 32, characterized in that Also includes: The second entity sends seventh information to the third entity, where the seventh information is used to indicate a second security capability, and the second security capability is the security capability of the first entity.

34. The method of claim 33, wherein: The seventh information includes: indication information of the second security capability and identification information of the first entity.

35. A communication method, characterized in that: include: The third entity sends a request message to the second entity, where the request message is used to request to establish a first entity, where the first entity is an entity that provides security capabilities for the third entity; The third entity receives second feedback information from the second entity, where the second feedback information is used to indicate information for establishing the first entity; The third entity establishes the first entity according to the second feedback information.

36. The method of claim 35, wherein: The second feedback information includes a download address of the first entity.

37. The method according to claim 35 or 36, characterized in that The request information includes indication information of a security capability module in the first entity.

38. The method according to any one of claims 35 to 37, characterized in that Also includes: The third entity receives seventh information from the second entity, where the seventh information is used to indicate second security capabilities, and the second security capabilities are security capabilities of the first entity.

39. The method of claim 38, wherein: The seventh information includes: indication information of the second security capability and identification information of the first entity.

40. A communication device, characterized in that: include: A communication unit for receiving and / or sending information; A processing unit, configured to execute the method according to any one of claims 1 to 17 through the communication unit.

41. A communication device, characterized in that: include: A communication unit for receiving and / or sending information; A processing unit, configured to execute the method according to any one of claims 18 to 29 through the communication unit.

42. A communication device, characterized in that: include: A communication unit for receiving and / or sending information; A processing unit, configured to execute the method according to any one of claims 30 to 34 through the communication unit.

43. A communication device, characterized in that: include: A communication unit for receiving and / or sending information; A processing unit, configured to execute the method according to any one of claims 35 to 39 through the communication unit.

44. A communication device, characterized in that: include: A processor, the processor being coupled to a memory storing instructions, wherein when the instructions are executed by the processor, the communication device executes the method according to any one of claims 1 to 17.

45. A communication device, characterized in that: include: A processor, the processor being coupled to a memory storing instructions, wherein when the instructions are executed by the processor, the communication device executes the method according to any one of claims 18 to 29.

46. ​​A communication device, characterized in that: include: A processor, the processor being coupled to a memory storing instructions, wherein when the instructions are executed by the processor, the communication device performs the method according to any one of claims 30 to 34.

47. A communication device, characterized in that: include: A processor, the processor being coupled to a memory storing instructions, wherein when the instructions are executed by the processor, the communication device performs the method according to any one of claims 35 to 39.

48. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is run on a computer, the method according to any one of claims 1 to 39 is executed.

49. A chip, characterized in that: The chip is coupled to a memory, and the chip reads a computer program stored in the memory so that the method according to any one of claims 1 to 39 is executed.

50. A communication system, characterized in that: include: Communication means for performing the operations of a first entity in the method of any one of claims 1 to 29, and communication means for performing the operations of a second entity in the method of any one of claims 1 to 29.

51. The system of claim 50, wherein: Also includes: Communication means for operation of a third entity in the method according to any one of claims 1 to 29.

52. A communication system, characterized in that: include: Communication means for performing the operations of the first entity in the method of any one of claims 30 to 39, and communication means for performing the operations of the second entity in the method of any one of claims 30 to 39.

53. The system of claim 52, wherein: Also includes: Communication means for operation of a third entity in a method as claimed in any one of claims 30 to 39.