Communication method and device, equipment and storage medium
By having terminal devices request and obtain authentication and authorization results for computing services and/or computing capabilities from network devices, the problem of low computing efficiency in existing technologies is solved, and computing services and/or computing capabilities are directly provided, thereby improving computing efficiency and enhancing security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- DATANG MOBILE COMM EQUIP CO LTD
- Filing Date
- 2024-10-23
- Publication Date
- 2026-04-24
AI Technical Summary
Existing network communication technologies have low computational efficiency and cannot effectively provide computing services and capabilities, resulting in insufficient utilization of computing resources.
The terminal device sends a message to the network device requesting the authentication and authorization results of computing services and/or computing capabilities. The network device performs authentication and authorization based on the message and directly provides computing services and/or computing capabilities upon successful authentication.
It improves computing efficiency and enhances the security of computing services and/or computing capabilities, ensuring that only authenticated and authorized users can access these resources.
Smart Images

Figure CN121924461A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, specifically to a communication method, apparatus, device, and storage medium. Background Technology
[0002] The sixth generation of network communication technology will transform from a traditional connectivity infrastructure into a dual-function infrastructure of connectivity and computing power.
[0003] Currently, existing network communication technologies can only authorize users to connect to the network. These technologies provide computing services to users based on cloud computing and edge computing, which results in low computing efficiency. How to provide users with computing services and computing power is a technical problem that urgently needs to be solved. Summary of the Invention
[0004] This application provides a communication method, apparatus, device, and storage medium to solve the technical problem of low computational efficiency in the prior art.
[0005] In a first aspect, embodiments of this application provide a communication method, the communication method comprising:
[0006] Send a first message to the network device, the first message being used to request the authentication and authorization results of computing services and / or computing capabilities;
[0007] Receive a second message sent by the network device, the second message being used to indicate the authentication and authorization results of the computing service and / or computing capabilities.
[0008] In one implementation, the first message is a registration request message, a Protocol Data Unit (PDU) session establishment request message, or a request message for computing services and / or computing capabilities, and the first message includes a user identity identifier.
[0009] In one implementation, when the first message is a registration request message, the first message further includes at least one of the following:
[0010] The identifier of the node corresponding to the computing service and / or computing capability;
[0011] The demand information corresponding to the computing services and / or computing capabilities.
[0012] In one implementation, when the first message is a PDU session establishment request message, the first message further includes at least one of the following:
[0013] The identifier of the node corresponding to the computing service and / or computing capability;
[0014] The demand information corresponding to the computing services and / or computing capabilities;
[0015] Authorized data for the computing services and / or computing capabilities.
[0016] In one implementation, where the first message is a request message for the computing service and / or computing power, the first message further includes at least one of the following:
[0017] The identifier of the node corresponding to the computing service and / or computing capability;
[0018] The demand information corresponding to the computing services and / or computing capabilities;
[0019] The identifier of the computing service and / or computing capability;
[0020] The request type for computing services and / or computing capabilities.
[0021] In one implementation, the demand information corresponding to the computing service and / or computing capacity includes at least one of the following:
[0022] The requested business type;
[0023] The requested business performance requirements;
[0024] The resource types corresponding to the computing services and / or computing capabilities;
[0025] The type of computing service and / or computing capability;
[0026] The usage time of the computing services and / or computing power;
[0027] The location where the computing services and / or computing capabilities are used;
[0028] The network resource requirements corresponding to the computing services and / or computing capabilities;
[0029] The security requirements corresponding to the computing services and / or computing capabilities.
[0030] In one implementation, the second message is either a message indicating successful authentication and authorization of the computing service and / or computing capability, or a message indicating failed authentication and authorization of the computing service and / or computing capability.
[0031] In one implementation, if the second message is a message indicating successful authentication and authorization of the computing service and / or computing capabilities, the second message includes at least one of the following:
[0032] User identifiers for using computing services and / or computing capabilities;
[0033] Authorized data for the computing services and / or computing capabilities.
[0034] In one implementation, the authorized data for the computing service and / or computing power includes at least one of the following:
[0035] The duration of authorized computing services and / or computing power usage;
[0036] The type of authorized computing services and / or computing capabilities;
[0037] The amount of computing power and / or the authorized computing services and / or computing capabilities;
[0038] Authorized areas for the use of computing services and / or computing capabilities;
[0039] The node identifier corresponding to the authorized computing services and / or computing capabilities.
[0040] In one implementation, if the second message is a message indicating that the authentication and authorization of the computing service and / or computing capability has failed, the second message is further used to release network resources or computing resources, or to instruct the terminal device to re-request the authentication and authorization result of the computing service and / or computing capability, or to instruct the terminal device to send a registration request, or to instruct the terminal device to resend the registration request.
[0041] Secondly, embodiments of this application provide another communication method, which includes:
[0042] The terminal device receives a first message, which is used to request the authentication and authorization results of computing services and / or computing capabilities.
[0043] A second message is sent to the terminal device, the second message being used to indicate the authentication and authorization results of the computing service and / or computing capabilities.
[0044] In one implementation, the first message is a registration request message, a Protocol Data Unit (PDU) session establishment request message, or a request message for computing services and / or computing capabilities, and the first message includes a user identity identifier.
[0045] In one implementation, when the first message is a registration request message, the first message further includes at least one of the following:
[0046] The identifier of the node corresponding to the computing service and / or computing capability;
[0047] The demand information corresponding to the computing services and / or computing capabilities.
[0048] In one implementation, when the first message is a PDU session establishment request message, the first message further includes at least one of the following:
[0049] The identifier of the node corresponding to the computing service and / or computing capability;
[0050] The demand information corresponding to the computing services and / or computing capabilities;
[0051] Authorized data for the computing services and / or computing capabilities.
[0052] In one implementation, where the first message is a request message for the computing service and / or computing power, the first message further includes at least one of the following:
[0053] The identifier of the node corresponding to the computing service and / or computing capability;
[0054] The demand information corresponding to the computing services and / or computing capabilities;
[0055] The identifier of the computing service and / or computing capability;
[0056] The request type for computing services and / or computing capabilities.
[0057] In one implementation, the demand information corresponding to the computing service and / or computing capacity includes at least one of the following:
[0058] The requested business type;
[0059] The requested business performance requirements;
[0060] The resource types corresponding to the computing services and / or computing capabilities;
[0061] The type of computing service and / or computing capability;
[0062] The usage time of the computing services and / or computing power;
[0063] The location where the computing services and / or computing capabilities are used;
[0064] The network resource requirements corresponding to the computing services and / or computing capabilities;
[0065] The security requirements corresponding to the computing services and / or computing capabilities.
[0066] In one implementation, sending the second message to the terminal device includes:
[0067] Based on the first message, determine the authentication and authorization results of the computing service and / or computing capabilities;
[0068] Based on the authentication and authorization results, a second message is sent to the terminal device.
[0069] In one embodiment, the network device includes a first network function, a second network function, and a third network function;
[0070] The first network function is used to control the access and mobility management of terminal devices, or to control session management functions; the second network function is used for the registration of computing function nodes, the periodic maintenance and scheduling of computing resources and network resource information, and the authentication and authorization of computing services and / or computing capabilities; the third network function is used to store and manage user-related data.
[0071] In one implementation, determining the authentication and authorization result of the computing service and / or computing capability based on the first message includes:
[0072] Based on the first network function, a third message is sent to the second network function, the third message including the content of the first message;
[0073] Based on the second network function and the third message, target information is obtained at the third network function. The target information is information to verify whether the terminal device can use computing services and / or computing capabilities.
[0074] Based on the second network function, the target information is verified to obtain the authentication and authorization results of the computing service and / or computing capabilities.
[0075] In one implementation, sending a second message to the terminal device based on the authentication and authorization results includes:
[0076] Based on the second network function and the authentication and authorization results, the second message is generated and sent to the first network function;
[0077] Based on the first network function, the second message is sent to the terminal device.
[0078] In one implementation, the second message is either a message indicating successful authentication and authorization of the computing service and / or computing capability, or a message indicating failed authentication and authorization of the computing service and / or computing capability.
[0079] In one implementation, if the second message is a message indicating successful authentication and authorization of the computing service and / or computing capabilities, the second message includes at least one of the following:
[0080] User identifiers for using computing services and / or computing capabilities;
[0081] Authorized data for the computing services and / or computing capabilities.
[0082] In one implementation, the authorized data for the computing service and / or computing power includes at least one of the following:
[0083] The duration of authorized computing services and / or computing power usage;
[0084] The type of authorized computing services and / or computing capabilities;
[0085] The amount of computing power and / or the authorized computing services and / or computing capabilities;
[0086] Authorized areas for the use of computing services and / or computing capabilities;
[0087] The node identifier corresponding to the authorized computing services and / or computing capabilities.
[0088] In one implementation, if the second message is a message indicating that the authentication and authorization of the computing service and / or computing capability has failed, the second message is further used to release network resources or computing resources, or to re-request the authentication and authorization result of the computing service and / or computing capability, or to instruct the terminal device to send a registration request, or to instruct the terminal device to resend the registration request.
[0089] In one implementation, sending a third message to the second network function based on the first network function includes:
[0090] Based on the first network function, determine whether an authentication and authorization process for computing services and / or computing capabilities needs to be performed;
[0091] If an authentication and authorization process for computing services and / or computing capabilities is required, the third message is sent to the second network function based on the first network function.
[0092] In one implementation, when the first network function is used to control the access and mobility management of terminal devices, based on the first network function, determining whether an authentication and authorization process for computing services and / or computing capabilities needs to be performed includes:
[0093] If the terminal device's subscription data includes subscription data for the terminal device to use computing services and / or computing capabilities, then based on the first network function, it is determined that an authentication and authorization process for computing services and / or computing capabilities needs to be performed.
[0094] If the subscription data of the terminal device indicates that the authentication and authorization process for the computing service and / or computing capabilities needs to be executed during the registration period, then when the first message is the registration request message, it is determined based on the first network function that the authentication and authorization process for the computing service and / or computing capabilities needs to be executed.
[0095] If the first message is used to re-request the authentication and authorization results of computing services and / or computing capabilities, then it is determined based on the first network function that an authentication and authorization process for computing services and / or computing capabilities needs to be performed.
[0096] If the first message includes the demand information corresponding to the computing service and / or computing capability, then based on the first network function, it is determined that an authentication and authorization process for the computing service and / or computing capability needs to be executed.
[0097] In one implementation, when the first network function is used to control session management functions, based on the first network function, determining whether an authentication and authorization process for computing services and / or computing capabilities needs to be performed includes:
[0098] If the combination of Data Network Name (DNN) and Single Network Slice Selection Auxiliary Information (S-NSSAI) is used for computing services, then the authentication and authorization process for computing services and / or computing capabilities needs to be performed based on the first network function.
[0099] If the PDU session type indicates that the current service type is computing service, then based on the first network function, it is determined that an authentication and authorization process for computing services and / or computing capabilities needs to be performed.
[0100] If the PDU session establishment request includes the identifier of the node corresponding to the computing service and / or computing capability, then based on the first network function, it is determined that an authentication and authorization process for the computing service and / or computing capability needs to be performed.
[0101] If the PDU session establishment request includes the requirement information corresponding to the computing service and / or computing capability, then based on the first network function, it is determined that an authentication and authorization process for the computing service and / or computing capability needs to be executed.
[0102] Thirdly, embodiments of this application provide a communication device, including a transmitting module and a receiving module, wherein:
[0103] The sending module is used to send a first message to the network device, the first message being used to request the authentication and authorization results of computing services and / or computing capabilities;
[0104] The receiving module is configured to receive a second message sent by the network device, the second message being used to indicate the authentication and authorization results of the computing service and / or computing capabilities.
[0105] Fourthly, embodiments of this application provide a communication device, including a receiving module and a transmitting module, wherein:
[0106] The receiving module is used to receive a first message sent by the terminal device, the first message being used to request the authentication and authorization results of computing services and / or computing capabilities;
[0107] The sending module is used to send a second message to the terminal device, the second message being used to indicate the authentication and authorization results of the computing service and / or computing capabilities.
[0108] Fifthly, embodiments of this application provide a terminal device, including a memory, a transceiver, and a processor:
[0109] The memory is used to store computer programs;
[0110] The transceiver is used to send and receive data under the control of the processor;
[0111] The processor is configured to read the computer program from the memory and perform the following operations:
[0112] Send a first message to the network device, the first message being used to request the authentication and authorization results of computing services and / or computing capabilities;
[0113] Receive a second message sent by the network device, the second message being used to indicate the authentication and authorization results of the computing service and / or computing capabilities.
[0114] Sixthly, embodiments of this application provide a network device, including a memory, a transceiver, and a processor:
[0115] The memory is used to store computer programs;
[0116] The transceiver is used to send and receive data under the control of the processor;
[0117] The processor is configured to read the computer program from the memory and perform the following operations:
[0118] The terminal device receives a first message, which is used to request the authentication and authorization results of computing services and / or computing capabilities.
[0119] A second message is sent to the terminal device, the second message being used to indicate the authentication and authorization results of the computing service and / or computing capabilities.
[0120] In a seventh aspect, this application provides a processor-readable storage medium storing a computer program for causing a processor to perform the method described in the first aspect or the method described in the second aspect.
[0121] This application provides a communication method, apparatus, device, and storage medium. A terminal device can send a first message to a network device, wherein the first message can be used to request authentication and authorization results for computing services and / or computing capabilities. The terminal device can receive a second message sent by the network device, wherein the second message can be used to indicate the authentication and authorization results for computing services and / or computing capabilities. In the above method, since the terminal device can request authorization for computing services and / or capabilities from the network device, the network device can directly provide computing services and / or computing capabilities to the terminal device, thereby improving computing efficiency.
[0122] It should be understood that the description in the foregoing summary section is not intended to limit the key or essential features of the embodiments of this application, nor is it intended to restrict the scope of this application. Other features of this application will become readily apparent from the following description. Attached Figure Description
[0123] To more clearly illustrate the technical solutions in this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0124] Figure 1 A schematic diagram of a communication architecture provided in an embodiment of this application;
[0125] Figure 2 A schematic diagram illustrating a communication method provided in an embodiment of this application;
[0126] Figure 3 A schematic diagram illustrating another communication method provided in an embodiment of this application;
[0127] Figure 4 A schematic diagram illustrating another communication method provided in an embodiment of this application;
[0128] Figure 5 A schematic diagram illustrating another communication method provided in an embodiment of this application;
[0129] Figure 6 A schematic diagram illustrating another communication method provided in an embodiment of this application;
[0130] Figure 7 This is a schematic diagram of the structure of a communication device provided in an embodiment of this application;
[0131] Figure 8 This is a schematic diagram of the structure of a communication device provided in an embodiment of this application;
[0132] Figure 9 This is a schematic diagram of the structure of a terminal device provided in an embodiment of this application;
[0133] Figure 10 This is a schematic diagram of the structure of a network device provided in an embodiment of this application. Detailed Implementation
[0134] In the embodiments of this application, the term "and / or" describes the relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. The character " / " generally indicates that the preceding and following associated objects have an "or" relationship.
[0135] In the embodiments of this application, the term "multiple" refers to two or more, and other quantifiers are similar.
[0136] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of the embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.
[0137] This application provides a communication method, apparatus, device, and storage medium. A terminal device can send a first message to a network device to request authentication and authorization results for obtaining computing services and / or computing capabilities. Therefore, the network device can directly provide computing services and / or computing capabilities to the terminal device, thereby improving computing efficiency.
[0138] The method and apparatus are based on the same concept of the application. Since the methods and apparatus solve problems in similar ways, the implementation of the apparatus and methods can refer to each other, and the repeated parts will not be described again.
[0139] The technical solutions provided in this application can be applied to a variety of systems. For example, applicable systems may include Long Term Evolution (LTE) systems, LTE Frequency Division Duplex (FDD) systems, LTE Time Division Duplex (TDD) systems, Long Term Evolution Advanced (LTE-A) systems, Universal Mobile Telecommunications System (UMTS), Worldwide Interoperability for Microwave Access (WiMAX) systems, 5G New Radio (NR) systems and their evolved communication systems, and 6G (sixth generation mobile communication technology) systems. These systems may include terminal equipment and network equipment. The systems may also include a core network component, such as the Evolved Packet Core (EPC) and the 5G Core Network (5GC).
[0140] The terminal devices involved in the embodiments of this application can be devices that provide voice and / or data connectivity to users, handheld devices with wireless connectivity, or other processing devices connected to a wireless modem. The names of the terminal devices may differ in different systems; for example, in 5G or 6G systems, the terminal device may be called User Equipment (UE). Wireless terminal devices can be USB storage devices, other personal computer memory devices, and dongles. They can also communicate with one or more core networks (CNs) via a Radio Access Network (RAN). Wireless terminal devices can be mobile terminal devices, such as mobile phones (or "cellular" phones) and computers with mobile terminal devices. For example, they can be portable, pocket-sized, handheld, computer-embedded, or vehicle-mounted mobile devices that exchange voice and / or data with the radio access network. Examples of such devices include Personal Communication Service (PCS) phones, cordless phones, Session Initiated Protocol (SIP) phones, Wireless Local Loop (WLL) stations, Personal Digital Assistants (PDAs), personal computers, tablets, and Machine-type Communication (MTC) terminal devices. Wireless terminal devices can also be referred to as systems, subscriber units, subscriber stations, mobile stations, mobile devices, remote stations, access points, remote terminals, access terminals, user terminals, user agents, user devices, and wireless access devices and routers / modems that meet the limitations of this definition; however, this application does not limit the scope of the embodiments.
[0141] The network device involved in this application embodiment can be a base station, which may include multiple cells providing services to terminals. Depending on the specific application, the base station may also be called an access point, or a device in the access network that communicates with wireless terminal devices through one or more sectors on the air interface, or other names. The network device can be used to exchange received air frames with Internet Protocol (IP) packets, acting as a router between the wireless terminal device and the rest of the access network, where the rest of the access network may include an Internet Protocol (IP) communication network. The network device can also coordinate the attribute management of the air interface. For example, the network device involved in this application embodiment can be an evolved Node B (eNB or e-NodeB) in a long term evolution (LTE) system, a 5G base station (gNB) in a next generation system, or a Home evolved Node B (HeNB), relay node, femto, pico, network testing equipment, etc., and is not limited in this application embodiment. In some network architectures, network devices may include centralized unit (CU) nodes and distributed unit (DU) nodes, which may also be geographically separated.
[0142] In related technologies, sixth-generation network communication technology will transform from a traditional connectivity infrastructure to a dual infrastructure of connectivity and computing power. For example, in fifth-generation network communication technology, users can access network resources after connecting to network devices. However, in sixth-generation network communication technology, network devices can provide computing resources in addition to network resources. Currently, existing network communication technologies do not support providing computing services to terminal devices; therefore, they need to provide computing services to users through cloud computing centers. For instance, fifth-generation network communication technology can provide network communication services but not computing services. Therefore, in fifth-generation network communication technology, computing services can be provided by edge computing nodes or cloud computing centers. However, this results in lower computing efficiency.
[0143] To address the technical problems in related technologies, embodiments of this application provide a communication method in which a terminal device can send a first message to a network device requesting authentication and authorization results for computing services and / or computing capabilities. This first message may carry a user identity identifier. Based on the first message, the network device can determine the authentication and authorization results for the computing services and / or computing capabilities and send a second message to the terminal device indicating these results. In this way, the network device can directly provide computing services and / or computing capabilities to the terminal device, thereby improving computing efficiency. Furthermore, only authenticated and authorized users can access the computing services and / or computing capabilities provided by the network device, enhancing the security of the computing services and / or computing capabilities provided by the network device.
[0144] Below, in conjunction with Figure 1 The communication architecture of the embodiments of this application will be described.
[0145] Figure 1 This is a schematic diagram of a communication architecture provided for an embodiment of this application. Please refer to [link / reference]. Figure 1 This includes terminal devices and network devices. The terminal devices can send messages to the network devices requesting computing services and / or computing capabilities. The network devices can include a first network function, a second network function, and a third network function. The first network function can be used to control the access and mobility management of the terminal devices, or to control session management functions. The second network function is used for the registration of computing function nodes, the periodic maintenance and scheduling of computing resource and network resource information, and the authentication and authorization of computing services and / or computing capabilities. The third network function is used to store and manage user-related data (including user subscription data as a computing capability user).
[0146] Please see Figure 1 The second network function can determine the authentication and authorization results of the computing service and / or computing capability based on the message requesting computing service and / or computing capability, and send the authentication and authorization results to the terminal device. If the authentication and authorization results of the computing service and / or computing capability indicate successful authentication and authorization, the terminal device can use the computing service for data processing. In this way, the network device can directly provide computing services to the terminal device, improving the computing efficiency of the terminal device.
[0147] The communication method provided in this application will now be described in conjunction with specific embodiments.
[0148] Figure 2 This diagram illustrates a communication method provided in an embodiment of this application. For application to terminal devices, please refer to [link / reference needed]. Figure 2 The communication method includes:
[0149] S201, The terminal device sends the first message to the network device.
[0150] The first message can be used to request authentication and authorization for computing services and / or computing capabilities. Computing services and / or computing capabilities can refer to services and / or capabilities that provide computing resources via a network. For example, computing services and / or computing capabilities can provide the computing resources required for training artificial intelligence (AI) models.
[0151] The first message may include a user identity identifier. For example, the user identity identifier can be any unique identifier such as a hidden user identifier, a temporary user identifier, or a permanent device identifier; this embodiment of the application does not limit this. For example, since the first message may include a user identity identifier, the network device can determine whether the user can obtain the authentication and authorization results for computing services and / or computing capabilities based on the user identity identifier.
[0152] Optionally, the first message can be a registration request message. For example, a registration request message can be used to register a terminal device in a network. For instance, when a terminal device joins a new network, it can request registration as a new user in that network. The terminal device can send a registration request message to the network device, which can then register the terminal device in the corresponding network based on this message. This registration request message can also be used to request authentication and authorization results for computing services and / or computing capabilities. For example, the authentication and authorization process for computing services and / or computing capabilities is optional. If the default policy is to execute this process during user registration, the terminal device can request authentication and authorization results for computing services and / or computing capabilities during the registration process.
[0153] Optionally, the first message can be a Protocol Data Unit (PDU) session establishment request message. For example, when a terminal device requests to establish a PDU session connection, it can send a PDU session establishment request message to the network device. During PDU session establishment, computing services and / or computing capabilities may be required; therefore, this PDU session establishment request message can be used to request authentication and authorization results for computing services and / or computing capabilities. For example, if the terminal device did not request authentication and authorization results for computing services and / or computing capabilities during the registration process, it can request these results when requesting to establish a PDU session connection.
[0154] Optionally, the first message may be a request message for computing services and / or computing capabilities. For example, when a terminal device needs computing services and / or computing capabilities, it may send a request message for computing services and / or computing capabilities to the network device. This request message may indicate the computing services and / or computing capabilities requested by the terminal device (e.g., for AI model training). Optionally, if the first message is a request message for computing services and / or computing capabilities, the network device may further determine the authentication and authorization results of the computing services and / or computing capabilities already obtained by the terminal device. If the authentication and authorization results indicate authentication and authorization failure, the request message for computing services and / or computing capabilities may be used to request the re-obtaining of the authentication and authorization results for the computing services and / or computing capabilities. If the authentication and authorization results indicate successful authentication and authorization, the network device may provide computing services and / or computing capabilities to the terminal device.
[0155] Optionally, the terminal device may send the first message at any time, and this embodiment of the application does not limit this. For example, the terminal device may send the first message (registration request message) during registration, the terminal device may send the first message (PDU session establishment request message) when a PDU session is established, or the terminal device may send the first message (computing service and / or computing power request message) when computing services and / or computing power are needed.
[0156] Optionally, the terminal device may send the first message to the network device based on any feasible implementation method, and the embodiments of this application do not limit this. For example, the terminal device may send the first message to the network device based on Non-Access Stratum (NAS) signaling, etc.
[0157] S202, The terminal device receives the second message sent by the network device.
[0158] The second message indicates the authentication and authorization result of the computing service and / or computing capability. For example, the second message could be a message indicating successful authentication and authorization of the computing service and / or computing capability, or a message indicating failed authentication and authorization of the computing service and / or computing capability. For instance, if the network device determines, based on the first message, that it can provide computing services and / or computing capability to the terminal device, then the authentication and authorization result of the computing service and / or computing capability could indicate successful authentication and authorization, and the second message sent by the network device to the terminal device could be a message indicating successful authentication and authorization of the computing service and / or computing capability. Conversely, if the network device determines, based on the first message, that it cannot provide computing services and / or computing capability to the terminal device, then the authentication and authorization result of the computing service and / or computing capability could indicate failed authentication and authorization, and the second message sent by the network device to the terminal device could be a message indicating failed authentication and authorization of the computing service and / or computing capability.
[0159] Optionally, the second message may include an indicator indicating the authentication and authorization result. For example, the second message may include 0 or 1. If the second message includes 0, it indicates that the authentication and authorization of the computing service and / or computing capability has failed. If the second message includes 1, it indicates that the authentication and authorization of the computing service and / or computing capability has succeeded. It should be noted that the indicator may also be any other feasible indicator, and this embodiment of the application does not limit it.
[0160] This application provides a communication method in which a terminal device can send a first message to a network device requesting authentication and authorization results for computing services and / or computing capabilities, and the terminal device can receive a second message from the network device indicating the authentication and authorization results for the computing services and / or computing capabilities. In this method, since the terminal device can request authentication and authorization results for computing services and / or computing capabilities from the network device, the network device can directly provide computing services and / or computing capabilities to the terminal device, thereby improving computing efficiency. Furthermore, only authenticated and authorized users can access the computing services and / or computing capabilities provided by the network device, enhancing the security of the computing services and / or computing capabilities provided by the network device.
[0161] exist Figure 2 Based on the embodiments shown, the following, in conjunction with Figure 3 This section describes another communication method.
[0162] Figure 3 This is a schematic diagram illustrating another communication method provided in an embodiment of this application. Please refer to... Figure 3 The method process includes:
[0163] S301, The terminal device sends the first message to the network device.
[0164] The first message may include a user identification identifier. Furthermore, since the first message can be a registration request message, a PDU session establishment request message, or a request message for computing services and / or computing capabilities, the content of the first message will differ depending on the type of message. There are three possible scenarios:
[0165] Scenario 1: The first message is a registration request message.
[0166] If the first message is a registration request message, the first message may also include at least one of the following:
[0167] The identifier of the node corresponding to the computing service and / or computing capacity;
[0168] Information on the demand for computing services and / or computing capabilities.
[0169] The node corresponding to the computing service and / or computing capability can be a node that provides the computing service and / or computing capability. For example, the first message sent by the terminal device to the network device may include the identifier of the node corresponding to the computing service and / or computing capability, and the network device can determine the network node that the user requested to provide the computing service and / or computing capability based on the identifier of the node corresponding to the computing service and / or computing capability.
[0170] The demand information corresponding to computing services and / or computing capabilities may include at least one of the following:
[0171] The requested business type;
[0172] The requested business performance requirements;
[0173] The resource type corresponding to computing services and / or computing capabilities;
[0174] Type of computing services and / or computing capabilities;
[0175] The duration of use of computing services and / or computing power;
[0176] Location of computing services and / or computing power usage;
[0177] Network resource requirements corresponding to computing services and / or computing capabilities;
[0178] Security requirements for computing services and / or computing capabilities.
[0179] The requested service type can be used to indicate the service requested by the terminal device. For example, the requested service type can be any service type related to computing, such as AI service types (e.g., AI model training, AI model updating, and AI model inference), Extended Reality (XR) service types, Vehicle to Everything (V2X) service types, etc. This application embodiment does not limit this. For example, the requested service type can be indicated based on an indicator, where if the indicator is 1, it indicates that the requested service type is an AI service type; if the indicator is 2, it indicates that the requested service type is a V2X service type, and so on.
[0180] The requested service performance requirements can be used to indicate the computing resources required by the requested service. For example, the requested service performance requirements may include data processing performance requirements (e.g., throughput, latency), concurrent processing capability requirements (session processing capability, etc.), and quality of service requirements (e.g., reliability, availability, etc.), which are not limited in this embodiment.
[0181] The requested business performance requirements can be indicated based on an indicator or any other feasible implementation method, and this application embodiment does not limit this.
[0182] The resource type corresponding to the computing service and / or computing power can be used to indicate the type of computing resources required by the computing service and / or computing power. For example, the resource type may include the Central Processing Unit (CPU) type and the Graphics Processing Unit (GPU) type, etc., which are not limited in this embodiment.
[0183] The type of computing service and / or computing capability can be used to indicate the computing service and / or computing capability. For example, the type of computing service and / or computing capability may include AI-related types, which may include computing services and / or computing capabilities corresponding to AI model training, AI model updates, and AI model inference, etc. The embodiments of this application do not limit this.
[0184] The usage time of computing services and / or computing capabilities can be used to indicate the time period during which computing services and / or computing capabilities are used. For example, if the usage time of computing services and / or computing capabilities is time 1 and time 2, then the time period during which the computing services and / or computing capabilities need to be used is the period from time 1 to time 2.
[0185] The location where computing services and / or computing capabilities are used can be used to indicate the geographical location where computing services and / or computing capabilities are required. For example, if the location where computing services and / or computing capabilities are used is Region 1, it means that the computing services and / or computing capabilities need to be used in Region 1; if the location where computing services and / or computing capabilities are used is Region 2, it means that the computing services and / or computing capabilities need to be used in Region 2.
[0186] The network resource requirements corresponding to computing services and / or computing capabilities can be used to indicate the network resources required for computing services and / or computing capabilities. For example, the network resource requirements corresponding to computing services and / or computing capabilities can be bandwidth requirements, latency requirements, and jitter requirements, etc., which are not limited in this embodiment.
[0187] The security requirements corresponding to computing services and / or computing capabilities can be used to indicate the security requirements for using computing services and / or computing capabilities. For example, security requirements may include network security measures, which may include encryption, authentication, and firewalls, etc., and this application embodiment does not limit this. For example, security requirements may include encryption requirements, and security requirements may also include encryption requirements, authentication requirements, and firewall requirements.
[0188] Optionally, the terminal device may send all information in a single first message or based on multiple first messages; this embodiment of the application does not limit this.
[0189] Scenario 2: The first message is a PDU session establishment request message.
[0190] If the first message is a PDU session establishment request message, the first message also includes at least one of the following:
[0191] The identifier of the node corresponding to the computing service and / or computing capacity;
[0192] Information on the demand for computing services and / or computing capabilities;
[0193] Authorized data for computing services and / or computing power
[0194] The authorization data for computing services and / or computing capabilities can serve as credentials for computing service authentication and authorization. The authorization data may include at least one of the following:
[0195] The duration of authorized computing services and / or computing power usage;
[0196] The type of authorized computing services and / or computing capabilities;
[0197] The amount of computing power corresponding to the authorized computing services and / or computing capabilities;
[0198] The location where authorized computing services and / or computing power are used;
[0199] The identifier of the node corresponding to the authorized computing services and / or computing capabilities.
[0200] The term "computational capacity" can be used to indicate the amount of computational resources available for computing services and / or computing power. For example, computational capacity can indicate the amount of data that a computing service can process.
[0201] Optionally, the authorization data for computing services and / or computing capabilities can be provided by the terminal device. For example, when establishing a PDU session, the terminal device can request the authentication and authorization results of computing services and / or computing capabilities, wherein the authorized data can be carried in the PDU session establishment request message.
[0202] Scenario 3: The first message is a request message for computing services and / or computing capabilities.
[0203] In the case that the first message is a request message for computing services and / or computing capabilities, the first message may also include at least one of the following:
[0204] The identifier of the node corresponding to the computing service and / or computing capacity;
[0205] Information on the demand for computing services and / or computing capabilities;
[0206] Identification of computing services and / or computing capabilities;
[0207] The type of request for computing services and / or computing power.
[0208] The identifier for computing services and / or computing capabilities can indicate the requested computing services and / or computing capabilities. For example, if the identifier for computing services and / or computing capabilities is for AI model training, it means that the computing services and / or computing capabilities requested by the terminal device are for AI model training; if the identifier for computing services and / or computing capabilities is for AI model inference, it means that the computing services and / or computing capabilities requested by the terminal device are for AI model inference.
[0209] The request type can include initial request, emergency request, and update request. For example, when a terminal device requests the authentication and authorization results of computing services and / or computing capabilities for the first time, the request type can be an initial request. When a terminal device requests the authentication and authorization results of computing services and / or computing capabilities urgently (e.g., due to a sudden failure requiring immediate response and handling), the request type can be an emergency request. When a terminal device requests an update to the computing services and / or computing capabilities already provided by the network device, the request type can be an update request.
[0210] S302. Based on the first message, determine the certification and authorization results of the computing service and / or computing capabilities.
[0211] The network device may include a first network function, a second network function, and a third network function.
[0212] The first network function can be used to control the access and mobility management of terminal devices, or to control the session management function. For example, the first network function can be an Access and Mobility Management Function (AMF), or it can be a Session Management Function (SMF), and this application embodiment does not limit this.
[0213] The second network function can be used for the registration of computing function nodes, the periodic maintenance and scheduling of computing and network resource information, and the authentication and authorization of computing services and / or computing capabilities. For example, the second network function can be a Computing Control Function (CCF), which can register computing function nodes, periodically maintain and schedule computing and network resource information, and authenticate and authorize computing services and / or computing capabilities.
[0214] The third network function can be used to store and manage user-related data. For example, the third network function can be a unified data management (UDM) function, in which the UDM can store the subscription data of the terminal device as a user of computing power.
[0215] Optionally, the UDM may store at least one of the following pieces of information:
[0216] Access to and mobile contract data;
[0217] SMF's selected contract data;
[0218] The context of the terminal device in SMF data;
[0219] SMS-managed contract data;
[0220] SMS signing data;
[0221] The context of the terminal device in SMSF data;
[0222] Session management and contract data;
[0223] Identifier translation;
[0224] The contract data selected by the slice;
[0225] Inter-system continuity context;
[0226] Contractual data as a user of computing power.
[0227] The contracted data used by the user of computing power may include at least one of the following:
[0228] A list of user identifiers;
[0229] List of internal group IDs (used to distinguish and manage different groups);
[0230] The upper limit of the computational load for the contract;
[0231] A list of contracted computing services and / or computing capabilities;
[0232] Permitted types of computing services and / or computing capabilities;
[0233] The default type of computing service and / or computing power;
[0234] List of contracted computing power nodes;
[0235] Default computing node ID;
[0236] The ID of the contracted computing power node group;
[0237] Default computing power node group ID;
[0238] The area where the contracted computing is used;
[0239] The default calculation area is used;
[0240] Prohibited computing areas;
[0241] The contracted computing node region;
[0242] The default compute node region;
[0243] Forbidden computing node regions;
[0244] Billing method;
[0245] Instructions for secondary authentication;
[0246] Computational security policy;
[0247] Calculation continuity indicator (whether calculation interruption is allowed).
[0248] Specifically, the network device determines the authentication and authorization results of the computing service and / or computing capability based on the first message. This can be achieved by: sending a third message to a second network function based on the first network function; obtaining target information at the third network function based on the second network function and the third message; verifying the target information based on the second network function; and obtaining the authentication and authorization results of the computing service and / or computing capability.
[0249] The third message may include the content of the first message. For example, the third message may include all the content of the first message, or it may include only a portion of the content of the first message; this embodiment of the application does not limit this. For example, the third message may include the user identification identifier from the first message. Optionally, the third message may also include the identifier of the computing power node, computing service and / or computing power demand information, and the location information of the terminal device, etc.; this embodiment of the application does not limit this.
[0250] Optionally, the terminal device may generate a third message based on any feasible implementation method, and this application embodiment does not limit this. For example, after receiving the registration request message, the AMF may generate a third message and send the third message to the CCF.
[0251] Optionally, the terminal device may send a third message to the second network function based on the first network function. Specifically, it may be: based on the first network function, determine whether it is necessary to perform the authentication and authorization process for computing services and / or computing capabilities. If it is necessary to perform the authentication and authorization process for computing services and / or computing capabilities, then send a third message to the second network function based on the first network function.
[0252] Optionally, when the first network function is used to control the access and mobility management of the terminal device, if the terminal device's subscription data includes subscription data indicating that the terminal device can use computing services and / or computing capabilities, the network device can determine, based on the first network function, that an authentication and authorization process for computing services and / or computing capabilities needs to be executed; if the terminal device's subscription data indicates that the authentication and authorization process for computing services and / or computing capabilities needs to be executed during registration, the network device can determine, based on the first network function, that an authentication and authorization process for computing services and / or computing capabilities needs to be executed when the first message is a registration request message; if the first message is used to re-request the authentication and authorization result for computing services and / or computing capabilities, the network device can determine, based on the first network function, that an authentication and authorization process for computing services and / or computing capabilities needs to be executed; if the first message includes demand information corresponding to computing services and / or computing capabilities, the network device can determine, based on the first network function, that an authentication and authorization process for computing services and / or computing capabilities needs to be executed.
[0253] Optionally, the AMF can send an authentication request (which may include the user's identity) to the Authentication Server Function (AUSF). The AMF can obtain the terminal device's subscription data from the UDM, and the AMF can obtain the terminal device's subscription data from the AMF.
[0254] For example, if the contract data of a terminal device includes contract data for the terminal device to use computing services and / or computing capabilities, it means that the terminal device has the right to use computing services and / or computing capabilities. However, whether the terminal device can use computing services and / or computing capabilities at that time still needs to be determined by the CCF (e.g., if the contracted location for the use of computing services and / or computing capabilities is Region 1, and the terminal device is located in Region 2, the terminal device cannot use computing services and / or computing capabilities). Therefore, the AMF can determine that the authentication and authorization process for computing services and / or computing capabilities needs to be executed.
[0255] For example, if the terminal device's subscription data indicates that the authorization process for computing services and / or computing capabilities needs to be executed during registration, it means that when the terminal device sends a registration request message to the network device, the AMF also needs to execute the authentication and authorization process for computing services and / or computing capabilities.
[0256] For example, if the first message is used to re-request authentication and authorization for computing services and / or computing capabilities, it indicates that the terminal device failed to obtain authentication and authorization for computing services and / or computing capabilities in the previous attempt. That is, the terminal device has the permission to use computing services and / or computing capabilities, but whether the terminal device can currently use computing services and / or computing capabilities still needs to be determined by the CCF. Therefore, the AMF can determine that the authentication and authorization process for computing services and / or computing capabilities needs to be executed.
[0257] For example, if the first message includes the demand information corresponding to computing services and / or computing capabilities, it means that the terminal device has the permission to use computing services and / or computing capabilities. However, whether the terminal device can currently use computing services and / or computing capabilities still needs to be determined by the CCF. Therefore, the AMF can determine that the authentication and authorization process for computing services and / or computing capabilities needs to be executed.
[0258] Optionally, when the first network function is used to control session management functions, if the combination of Data Network Name (DNN) and Single Network Slice Selection Assistance Information (S-NSSAI) is used for computing services, the network device can determine, based on the first network function, that authentication and authorization procedures for computing services and / or computing capabilities need to be performed; if the PDU session type indicates that the current service type is computing services, the network device can determine, based on the first network function, that authentication and authorization procedures for computing services and / or computing capabilities need to be performed; if the PDU session establishment request includes the identifier of the node corresponding to the computing service and / or computing capability, the network device can determine, based on the first network function, that authentication and authorization procedures for the computing service and / or computing capability need to be performed; if the PDU session establishment request includes the requirement information corresponding to the computing service and / or computing capability, the network device can determine, based on the first network function, that authentication and authorization procedures for the computing service and / or computing capability need to be performed.
[0259] For example, based on the provided DNN and / or S-NSSAI combination, the SMF can determine whether it needs to invoke the CCF's service operations to establish a PDU session and request the authentication and authorization results for computing services and / or computing capabilities. For instance, if the DNN and / or S-NSSAI combination is dedicated to computing services, the SMF can determine whether it needs to perform the authentication and authorization process for computing services and / or computing capabilities.
[0260] For example, if the PDU session type indicates that the current business type is computing business, it means that the SMF needs to call the CCF's service operation to establish the PDU session and request the authentication and authorization results of computing services and / or computing capabilities. Therefore, the SMF can determine that the authentication and authorization process of computing services and / or computing capabilities needs to be executed.
[0261] For example, if the PDU session establishment request includes the identifier of the node corresponding to the computing service and / or computing capability, it means that the SMF needs to establish a path to the computing node through the PDU session establishment process. Therefore, the SMF can determine that the authentication and authorization process for the computing service and / or computing capability needs to be executed.
[0262] For example, if the PDU session establishment request includes the requirement information corresponding to computing services and / or computing capabilities, it means that the SMF needs to call the CCF's service operation to establish the PDU session and request to obtain the authentication and authorization results of the computing services and / or computing capabilities. Therefore, the SMF can determine that the authentication and authorization process of computing services and / or computing capabilities needs to be executed.
[0263] The target information can be information used to verify whether a terminal device can use computing services and / or computing capabilities. For example, the UDM can store subscription data for users of computing capabilities, and the CCF can retrieve the subscription data for the terminal device as a user of computing capabilities from the UDM based on the user's identity.
[0264] After obtaining the target information from the UDM, the CCF can verify the target information and then obtain the certification and authorization results of the computing service and / or computing capabilities.
[0265] The target information may include contract data stored in the UDM that represents users of computing power. For example, the target information may include one or more contract data.
[0266] If the parameters carried in the third message sent by the AMF or SMF to the CCF (such as the demand information corresponding to computing services and / or computing capabilities) satisfy every item of the contract data in the target information, the authentication and authorization result can be successful. If the parameters carried in the third message sent by the AMF or SMF to the CCF do not satisfy any item of the contract data in the target information, the authentication and authorization result can be unsuccessful.
[0267] For example, if the list of computing services and / or computing capabilities subscribed to by the terminal device includes the identifier of the requested computing service and / or computing capability, the CCF can determine that the authentication and authorization result of the computing service and / or computing capability is successful; if the list of computing services and / or computing capabilities subscribed to by the terminal device does not include the identifier of the requested computing service and / or computing capability, the CCF can determine that the authentication and authorization result of the computing service and / or computing capability is unsuccessful.
[0268] For example, if a terminal device requests computing service 1 during the registration process, and the list of computing services subscribed to by the terminal device stored in the UDM includes the identifiers of computing service 1 and computing service 2, then the CCF can determine that the authentication and authorization result of computing service 1 is successful (all other parameters meet the subscription data). If the list of computing services subscribed to by the terminal device stored in the UDM includes the identifiers of computing service 2 and computing service 3, then the CCF can determine that the authentication and authorization result of computing service 1 is unsuccessful.
[0269] For example, if the computing service and / or computing capability requested by the terminal device is located in region 1, and the terminal device has subscribed to computing usage regions including both region 1 and region 2, then the CCF can determine that the authentication and authorization result corresponding to the computing service and / or computing capability is successful (all other parameters meet the subscription data); if the terminal device has subscribed to computing usage regions including both region 2 and region 3, then the CCF can determine that the authentication and authorization result corresponding to the computing service and / or computing capability is unsuccessful.
[0270] For example, if the computing power requested by the terminal device exceeds the computing power subscribed to by the terminal device, the CCF can determine that the authentication and authorization result corresponding to the computing service and / or computing power is authentication and authorization failure. If the computing power requested by the terminal device is less than or equal to the computing power subscribed to by the terminal device, the CCF can determine that the authentication and authorization result corresponding to the computing service and / or computing power is authentication and authorization success (all other parameters meet the subscribed data).
[0271] For example, when a terminal device requests a computing service, the requested computing volume is computing volume 1, and the computing volume subscribed by the terminal device and stored in the UDM is computing volume 2. If computing volume 1 is greater than computing volume 2, the CCF can determine that the authentication and authorization result corresponding to the computing service and / or computing capability is authentication and authorization failure. If computing volume 1 is less than or equal to computing volume 2, the CCF can determine that the authentication and authorization result corresponding to the computing service and / or computing capability is authentication and authorization success (all other parameters meet the subscription data).
[0272] S303. Based on the authentication and authorization results, send a second message to the terminal device.
[0273] Optionally, when performing the authentication and authorization process for computing services and / or computing capabilities, CCF and SMF may store the authorization context of computing services and / or computing capabilities locally, or they may store the authorization context of computing services and / or computing capabilities based on the Unstructured Data Storage Function (UDSF). This application embodiment does not limit this.
[0274] The terminal device can send a second message to the terminal device based on the following feasible implementation methods: generating a second message based on the second network function and the authentication and authorization results, and sending the second message to the first network function; or sending the second message to the terminal device based on the first network function.
[0275] The second message can be either a message indicating successful authentication and authorization of the computing service and / or computing capabilities, or a message indicating failed authentication and authorization of the computing service and / or computing capabilities. For example, if the authentication and authorization result is successful, the CCF can generate a second message indicating successful authentication and authorization for the computing service and / or computing capabilities and send it to the AMF. The AMF can then forward the second message to the terminal device. Conversely, if the authentication and authorization result is failed, the CCF can generate a second message indicating failed authentication and authorization for the computing service and / or computing capabilities and send it to the AMF. The AMF can then forward the second message to the terminal device.
[0276] Optionally, if the second message is a message indicating successful authentication and authorization of computing services and / or computing capabilities, the second message may include at least one of the following:
[0277] User identifiers for using computing services and / or computing capabilities;
[0278] Authorized data for computing services and / or computing capabilities.
[0279] For example, if the authentication and authorization of the computing service and / or computing power are successful, the CCF can add a unique computing user identifier and authorization data assigned to the terminal device to the response message (second message). This allows the terminal device to determine the data related to the successfully authenticated and authorized computing service and / or computing power based on the response message. For instance, if the authentication and authorization of the computing service and / or computing power are successful, the CCF can generate a second message that may include a unique identifier (based on which the terminal device can use the computing service and computing power), the authorized usage time of the computing service and / or computing power, the type of authorized computing service and / or computing power, the computing load corresponding to the authorized computing service and / or computing power, the location of use of the authorized computing service and / or computing power, and the identifier of the node corresponding to the authorized computing service and / or computing power.
[0280] Optionally, if the second message is a message indicating that the authentication and authorization of computing services and / or computing capabilities has failed, the second message may also be used to release network resources or computing resources, or to re-request the authentication and authorization results of computing services and / or computing capabilities, or to instruct the terminal device to send a registration request, or to instruct the terminal device to resend the registration request.
[0281] For example, if the authentication and authorization of computing services and / or computing capabilities fails, the CCF can instruct the terminal device to take the next step in the second message. In the second message, the CCF can instruct the terminal device to release network resources or computing resources (e.g., instruct the terminal device to request the release of reserved network resources or computing resources). The CCF can also instruct the terminal device to re-request the authentication and authorization results of computing services and / or computing capabilities in the second message. After receiving the second message, the terminal device can resend the message to the network device to request the authentication and authorization results of computing services and / or computing capabilities (it can resend the first message or generate and send a new first message).
[0282] For example, if the authentication and authorization of computing services and / or computing capabilities fail, the CCF can instruct the terminal device to send a registration request message in the second message. After receiving the second message, the terminal device can send a registration request message to the network device, and then re-request the authentication and authorization results of computing services and / or computing capabilities.
[0283] For example, when a terminal device sends a registration request message, it can request the authentication and authorization results of computing services and / or computing capabilities. If the authentication and authorization of computing services and / or computing capabilities fails, the CCF can instruct the terminal device to resend the registration request message in a second message. After receiving the second message, the terminal device can resend the registration request message to the network device, and thus re-request the authentication and authorization results of computing services and / or computing capabilities.
[0284] Optionally, the CCF can be implemented in any feasible way, based on the second message to instruct the terminal device to take the next action (e.g., adding an indicator to the CCF to indicate the next action), and this application embodiment does not limit this.
[0285] This application provides a communication method in which a terminal device sends a first message to a network device, sends a third message to a second network function based on a first network function, obtains target information at the third network function based on the second network function and the third message, verifies the target information based on the second network function to obtain authentication and authorization results for computing services and / or computing capabilities, generates a second message based on the second network function and the authentication and authorization results, sends the second message to the first network function, and finally sends the second message to the terminal device based on the first network function. In this way, the network device can obtain the authentication and authorization results for computing services and / or computing capabilities based on the second network function, thus enabling the terminal device to quickly acquire computing resources and improve computing efficiency.
[0286] Based on any of the above embodiments, when the first message is a registration request message, the following, in conjunction with... Figure 4 This section describes another communication method.
[0287] Figure 4 This is a schematic diagram illustrating another communication method provided in an embodiment of this application. Figure 4 In the illustrated embodiment, the first message can be a registration request message, the first network function is AMF, the second network function is CCF, and the third network function is UDM. Please refer to [link to relevant documentation]. Figure 4 The method process includes:
[0288] S401, The terminal device sends a registration request message to the AMF.
[0289] Optionally, the registration request message may include a user identifier, and may also include at least one of the following:
[0290] The identifier of the node corresponding to the computing service and / or computing capacity;
[0291] Information on the demand for computing services and / or computing capabilities.
[0292] The requirement information corresponding to computing services and / or computing capabilities includes at least one of the following:
[0293] The requested business type;
[0294] The requested business performance requirements;
[0295] The resource types corresponding to the computing services and / or computing capabilities;
[0296] The type of computing service and / or computing capability;
[0297] The usage time of the computing services and / or computing power;
[0298] The location where the computing services and / or computing capabilities are used;
[0299] The network resource requirements corresponding to the computing services and / or computing capabilities;
[0300] The security requirements corresponding to the computing services and / or computing capabilities.
[0301] S402, AMF determines whether a certification and authorization process for computing services and / or computing capabilities is required.
[0302] If the terminal device's subscription data includes subscription data for the terminal device to use computing services and / or computing capabilities, then the AMF determines that an authentication and authorization process for the computing services and / or computing capabilities needs to be performed.
[0303] If the terminal device’s subscription data indicates that the authentication and authorization process for computing services and / or computing capabilities needs to be performed during registration, then when the first message is a registration request message, the AMF determines that the authentication and authorization process for computing services and / or computing capabilities needs to be performed.
[0304] If the first message is used to re-request authentication and authorization for computing services and / or computing capabilities, then the AMF determines that the authentication and authorization process for computing services and / or computing capabilities needs to be performed.
[0305] If the first message includes requirement information for computing services and / or computing capabilities, then the AMF determines that an authentication and authorization process for the computing services and / or computing capabilities needs to be performed.
[0306] Optionally, the AMF can request authentication from the AUSF based on the user identity identifier in the registration request message. The AUSF can obtain the terminal device's subscription data from the UDM and send the terminal device's subscription data to the AMF.
[0307] Optionally, if the terminal device requests re-authentication, or if re-authentication is triggered by the computing capability node, the AMF may determine to execute the authentication and authorization process for the computing service and / or computing capability.
[0308] Optionally, if the subscription data of the terminal device retrieved by the AMF from the UDM does not include the subscription data of the terminal device as a user of computing power, the AMF will not trigger the authentication and authorization process for computing services and / or computing power.
[0309] S403 and AMF send a message to the terminal device indicating whether the registration was successful or failed.
[0310] Optionally, the AMF can determine whether to send a registration acceptance or registration failure message to the terminal device based on any feasible implementation. For example, if the AMF determines that the terminal device can register in the network based on the terminal device's subscription data, the AMF can send a registration success message to the terminal device; if the AMF determines that the terminal device cannot register in the network based on the terminal device's subscription data, the AMF can send a registration failure message to the network device.
[0311] Optionally, when the AMF sends a registration success message to the terminal device, if the AMF determines to execute the authentication and authorization process for computing services and / or computing capabilities, the registration success message sent by the AMF may include an indication to wait for the authentication and authorization results of the computing services and / or computing capabilities. For example, if the AMF determines that it can send a registration success message to the terminal device, and the AMF determines to execute the authentication and authorization process for computing services and / or computing capabilities, the AMF may add an indicator to the registration success message, which may instruct the terminal device to wait for the authentication and authorization results of the computing services and / or computing capabilities.
[0312] Optionally, when the AMF sends a registration success message to the terminal device, if the AMF determines that it does not need to perform the authentication and authorization process for computing services and / or computing capabilities, the AMF may determine whether to perform the authentication and authorization process for computing services and / or computing capabilities during the PDU session establishment process or during the request for computing services and / or computing capabilities.
[0313] Optionally, if the AMF sends a registration failure message to the terminal device, the message may include the reason for the registration failure. For example, if the AMF sends a registration failure message to the terminal device, the message may include information about the terminal device's subscription data, specifically that the terminal device's subscription data does not include subscription data for computing services and / or computing power.
[0314] Optionally, when the terminal device sends a registration request message, the terminal device may also request S-NSSAI authentication. If the requested S-NSSAI authentication has not yet been successful, the terminal device may perform the network slice authentication and authorization process.
[0315] S404, AMF sends a third message to CCF.
[0316] The AMF can generate a third message based on the first message and send the third message to the CCF. For example, the AMF can generate a third message that may include the user's identity identifier, the identifier of the computing power node, and the location information of the terminal device, etc., and the AMF can send the third message to the CCF.
[0317] S405 and CCF obtain target information at UDM based on the third message.
[0318] Specifically, the CCF can obtain target information from the UDM, based on the user identity identifier in the third message, to verify whether the terminal device can use computing services and / or computing capabilities. For example, after receiving the third message from the AMF, the CCF can send the user identity identifier to the UDM, and the UDM can determine the target information based on the user identity identifier and send the target information to the CCF.
[0319] S406 and CCF verify the target information to obtain certification and authorization results for computing services and / or computing capabilities.
[0320] Optionally, the terminal device can be a single terminal device or a group of terminal devices. That is, a group of terminal devices can register as a user with the network to obtain authentication and authorization results for computing services and / or computing capabilities. For example, when a group of terminal devices initiates the registration process, the CCF needs to ensure that all terminal devices in the group are successfully authenticated before sending an authentication and authorization success message. Otherwise, it sends an authentication and authorization failure message, carrying the identifiers of the terminal devices that failed authentication and authorization and the terminal devices that succeeded in authentication and authorization within the authentication and authorization failure message.
[0321] Optionally, a verified terminal device identifier only indicates that the terminal device is entitled to use computing services and / or computing capabilities, and does not indicate that authorization has been successfully granted. If the terminal device wants to use computing services and / or computing capabilities, it needs to initiate the authentication and authorization process for computing services and / or computing capabilities separately as a computing user.
[0322] Optionally, the method by which CCF verifies the target information to obtain the certification and authorization results of computing services and / or computing capabilities can refer to the method in the above embodiments, and will not be repeated here in the embodiments of this application.
[0323] S407 and CCF determine the second message based on the results of authentication and authorization.
[0324] The CCF can determine the content of the second message based on the authentication and authorization results. For example, the CCF can send a second message to the AMF, which may include the user's identity, the authentication and authorization results of computing services and / or computing capabilities.
[0325] For example, if the second message is a message indicating successful authentication and authorization of computing services and / or computing capabilities, then the second message may include a unique computing user identifier and authorization data assigned to the terminal device, wherein the authorization data may include authorized computing service time, authorized computing service type, authorized computing volume, authorized computing usage area, and authorized computing capability node identifier.
[0326] For example, if the second message is a message indicating that the authentication and authorization of computing services and / or computing capabilities has failed, the second message may include the CCF instructing the terminal device to take the next action, wherein the next action may include releasing network resources or computing resources, or re-requesting authentication and authorization of computing services and / or computing capabilities, or sending a registration request, or resending the registration request.
[0327] S408, CCF sends a second message to AMF.
[0328] Once the CCF determines the second message, it can send the second message to the AMF.
[0329] S409, AMF sends a second message to the terminal device.
[0330] After receiving the second message, the AMF can send a second message to the terminal device. For example, the AMF can receive the second message sent by the CCF and forward it to the terminal device.
[0331] Optionally, if the authentication and authorization of the computing service and / or computing capabilities are successful, the second message can trigger a configuration update on the terminal device. For example, if the second message received by the terminal device is a message indicating successful authentication and authorization of the computing service and / or computing capabilities, the terminal device can update the obtained computing service and / or computing capabilities based on the authorization data in the second message.
[0332] Optionally, if the authentication and authorization of computing services and / or computing capabilities fail, the terminal device may trigger a process of deregistering, releasing computing resources, or releasing network resources based on the CCF's instructions.
[0333] This application provides a communication method in which a terminal device sends a registration request message to the AMF (Application Management Function). The AMF determines whether an authentication and authorization process for computing services and / or computing capabilities is required. The AMF sends a registration success or failure message to the terminal device. The AMF then sends a third message to the CCF (Computer Communication Function). Based on the third message, the CCF obtains target information from the UDM (User Device Management Function). The CCF verifies the target information to obtain the authentication and authorization result for the computing services and / or computing capabilities. Based on the authentication and authorization result, the CCF sends a second message to the AMF, which then sends the second message to the terminal device. In this way, the network device can provide computing services and / or computing capabilities to the terminal device, thereby improving computing efficiency.
[0334] Based on any of the above embodiments, when the first message is a PDU session establishment request message, the following, in conjunction with Figure 5 This section describes another communication method.
[0335] Figure 5 This is a schematic diagram illustrating another communication method provided in an embodiment of this application. Figure 5 In the illustrated embodiment, the first message can be a PDU session establishment request message, the first network function is SMF, the second network function is CCF, and the third network function is UDM. Please refer to [link to relevant documentation]. Figure 5 The method process includes:
[0336] S501, The terminal device sends a PDU session establishment request message to the SMF.
[0337] Optionally, if the terminal device provides information such as user identity identifier, computing demand information, computing capability node identifier, and authorization data (i.e., computing service authentication credentials) during the PDU session establishment process, the authentication and authorization process of computing services and / or computing capabilities can be triggered during the PDU session establishment.
[0338] When a terminal device requests to establish a PDU session connection, it may require authentication and authorization processes for computing services and / or computing capabilities. During the authentication and authorization process for computing services and / or computing capabilities, the CCF can either store the authorization context of the computing services and / or computing capabilities locally or store it in the UDSF.
[0339] The SMF can subscribe to notifications from the CCF. When the SMF receives a request from a group that includes the current terminal device, it can perform operations such as re-authentication, updating authorization data, or revoking authorization for the current terminal device based on the notification from the CCF.
[0340] Optionally, the PDU session establishment request message may include a user identity identifier, and may also include at least one of the following:
[0341] The identifier of the node corresponding to the computing service and / or computing capability;
[0342] The demand information corresponding to the computing services and / or computing capabilities;
[0343] Authorized data for the computing services and / or computing capabilities.
[0344] The requirement information corresponding to computing services and / or computing capabilities includes at least one of the following:
[0345] The requested business type;
[0346] The requested business performance requirements;
[0347] The resource types corresponding to the computing services and / or computing capabilities;
[0348] The type of computing service and / or computing capability;
[0349] The usage time of the computing services and / or computing power;
[0350] The location where the computing services and / or computing capabilities are used;
[0351] The network resource requirements corresponding to the computing services and / or computing capabilities;
[0352] The security requirements corresponding to the computing services and / or computing capabilities.
[0353] The authorized data for computing services and / or computing capabilities may include at least one of the following:
[0354] The duration of authorized computing services and / or computing power usage;
[0355] The type of authorized computing services and / or computing capabilities;
[0356] The amount of computing power and / or the authorized computing services and / or computing capabilities;
[0357] Authorized areas for the use of computing services and / or computing capabilities;
[0358] The node identifier corresponding to the authorized computing services and / or computing capabilities.
[0359] S502, SMF determines whether a certification and authorization process for computing services and / or computing capabilities is required.
[0360] If the combination of Data Network Name (DNN) and Single Network Slice Selection Auxiliary Information (S-NSSAI) is used for computing services, then the SMF determines that an authentication and authorization process for computing services and / or computing capabilities needs to be performed.
[0361] If the PDU session type indicates that the current service type is computing service, then the SMF determines that an authentication and authorization process for computing services and / or computing capabilities needs to be performed.
[0362] If the PDU session establishment request includes the identifier of the node corresponding to the computing service and / or computing capability, then the SMF determines that the authentication and authorization process for the computing service and / or computing capability needs to be executed.
[0363] If the PDU session establishment request includes the requirement information corresponding to the computing service and / or computing capability, then the SMF determines that the authentication and authorization process for the computing service and / or computing capability needs to be executed.
[0364] S503, SMF sends a third message to CCF.
[0365] If the SMF determines that an authentication and authorization process for computing services and / or computing capabilities is required, the SMF can generate a third message based on the first message and send the third message to the CCF. For example, the SMF can generate a third message that may include user identification, computing requirement information, identifiers of computing capability nodes, location information of the terminal device, authorization data (if provided by the UE), and the IP address of the terminal device (if available), etc., and the AMF can send the third message to the CCF.
[0366] S504 and CCF obtain target information at UDM based on the third message.
[0367] Specifically, the CCF can obtain target information from the UDM, based on the user identity identifier in the third message, to verify whether the terminal device can use computing services and / or computing capabilities. For example, after receiving the third message from the AMF, the CCF can send the user identity identifier to the UDM, and the UDM can determine the target information based on the user identity identifier and send the target information to the CCF.
[0368] S505 and CCF verify the target information to obtain the certification and authorization results for computing services and / or computing capabilities.
[0369] Optionally, the method by which CCF verifies the target information to obtain the certification and authorization results of computing services and / or computing capabilities can refer to the method in the above embodiments, and will not be described again in the embodiments of this application.
[0370] S506 and CCF determine the second message based on the results of authentication and authorization.
[0371] Optionally, the method by which CCF determines the second message based on the authentication and authorization results can refer to the method in the above embodiments, and will not be repeated here.
[0372] S507, CCF sends a second message to SMF.
[0373] Once the CCF determines the second message, it can send the second message to the SMF.
[0374] Optionally, if the second message is a message indicating successful authentication and authorization of computing services and / or computing capabilities, the CCF may subscribe to PDU session status notifications from the SMF, which may include DNN, S-NSSAI, and PDU session ID.
[0375] S508 and SMF send a second message to the terminal device.
[0376] Optionally, if the second message is a message indicating successful authentication and authorization of computing services and / or computing capabilities, the SMF may send computing service policies (e.g., the identifier of the computing capability node used) to the Policy Control Function (PCF).
[0377] Optionally, if the CCF subscribes to PDU session status events in the SMF, the SMF can send a PDU session establishment event report to the CCF. In addition, the SMF can also subscribe to event notifications related to the computing services and / or computing capabilities of the current terminal device from the CCF.
[0378] This application provides a communication method in which a terminal device sends a PDU session establishment request message to the SMF (Service Provider Function). The SMF determines whether an authentication and authorization process for computing services and / or computing capabilities is required. The SMF sends a third message to the CCF (Computer Provider Function). Based on the third message, the CCF obtains target information from the UDM (User Device Provider Function). The CCF verifies the target information to obtain the authentication and authorization result for computing services and / or computing capabilities. Based on the authentication and authorization result, the CCF determines a second message and sends it to the SMF. The SMF then sends the second message to the terminal device. In this way, the network device can provide computing services and / or computing capabilities to the terminal device, thereby improving computing efficiency.
[0379] Based on any of the above embodiments, when the first message is a request message for computing services and / or computing power, the following, in conjunction with... Figure 6 This section describes another communication method.
[0380] Figure 6 This is a schematic diagram illustrating another communication method provided in an embodiment of this application. Figure 6 In the illustrated embodiment, the first message may be a request message for computing services and / or computing power; the first network function is AMF; the second network function is CCF; and the third network function is UDM. Please refer to [link to relevant documentation]. Figure 6 The method process includes:
[0381] S601, The terminal device sends a request message for computing services and / or computing capabilities to the AMF.
[0382] Optionally, during the process of a terminal device initiating a request for computing services and / or computing capabilities, the network device needs to verify the identity of the terminal device based on the subscription data of the terminal device as a user of computing capabilities stored in the UDM. Only after successful authorization can the network device provide computing services and / or computing capabilities to the user.
[0383] Optionally, the terminal device may send a request message for computing services and / or computing capabilities to the Radio Access Network (RAN), and the RAN may send the request message to the AMF. For example, the terminal device may add a request message for computing services and / or computing capabilities to a NAS message, and the terminal device may send the NAS message to the RAN, which may then send the NAS message to the AMF.
[0384] Optionally, the request message for computing services and / or computing power may include a user identifier, and may also include at least one of the following:
[0385] The identifier of the node corresponding to the computing service and / or computing capacity;
[0386] Information on the demand for computing services and / or computing capabilities;
[0387] Identification of computing services and / or computing capabilities;
[0388] The type of request for computing services and / or computing power.
[0389] The requirement information corresponding to computing services and / or computing capabilities includes at least one of the following:
[0390] The requested business type;
[0391] The requested business performance requirements;
[0392] The resource type corresponding to computing services and / or computing capabilities;
[0393] Type of computing services and / or computing capabilities;
[0394] The duration of use of computing services and / or computing power;
[0395] Location of computing services and / or computing power usage;
[0396] Network resource requirements corresponding to computing services and / or computing capabilities;
[0397] Security requirements for computing services and / or computing capabilities.
[0398] Optionally, if the terminal device uses new computing services and / or computing capabilities, the terminal device may generate an identifier for the new computing services and / or computing capabilities.
[0399] S602, AMF selects CCF based on the request message for computing services and / or computing capabilities.
[0400] Among them, AMF can parse the received NAS messages, create computing services and / or computing capabilities, and select CCF.
[0401] Optionally, if the request type is an update request type, the AMF can select the CCF that last served the terminal device.
[0402] S603, AMF determines whether a certification and authorization process for computing services and / or computing capabilities is required.
[0403] The method by which the AMF determines whether an authentication and authorization process for computing services and / or computing capabilities is required can refer to the method in the above embodiments, and will not be repeated here in the embodiments of this application.
[0404] S604, AMF sends a context request to CCF to create computing services and / or computing capabilities.
[0405] Optionally, the context request for computing services and / or computing capabilities may include a request message for computing services and / or computing capabilities. For example, the context request for computing services and / or computing capabilities may include a Subscription Permanent Identifier (SUPI), DNN, S-NSSAI, the identifier of the computing service and / or computing capability, the ID of the AMF, the request type, the ID of the PCF, the priority, the container (including the request message for computing services and / or computing capabilities), the location information of the terminal device, the access type, and the user identity identifier.
[0406] S605 and CCF obtain target information from UDM based on context requests.
[0407] Specifically, the CCF can obtain target information from the UDM (User Device Manager) regarding whether the terminal device can use computing services and / or computing capabilities, based on the user identity identifier in the context request. For example, the CCF can send a request message to the UDM, which may include the user identity identifier. The UDM can then determine the target information based on the user identity identifier and send the target information to the CCF.
[0408] S606 and CCF verify the target information to obtain certification and authorization results for computing services and / or computing capabilities.
[0409] Optionally, the method by which CCF verifies the target information can refer to the method in the above embodiments, and will not be described again in this application embodiment.
[0410] The CCF can also check the validity of computing services and / or computing capabilities requested by terminal devices. For example, the CCF can determine whether the computing services and / or computing capabilities requested by the terminal device comply with the terminal device's local policies. For example, the CCF can determine whether the terminal device's subscription data includes subscription data indicating that the terminal device is a user of computing capabilities. For example, the CCF can determine whether the subscription data indicating that the terminal device is a user of computing capabilities satisfies the current computing services and / or computing capabilities (e.g., whether the type of computing services and / or computing capabilities included in the subscription data, the location where the computing services and / or computing capabilities are used, etc., satisfy the current computing services and / or computing capabilities).
[0411] Optionally, if the computing service and / or computing power requested by the terminal device is invalid, the CCF may refuse the computing service and / or computing power currently requested by the terminal device.
[0412] S607 and CCF determine the response to the context request based on the authentication and authorization results.
[0413] Optionally, the response to the context request can be a second message. The CCF determines the method for responding to the context request for creating computing services and / or computing capabilities based on the authentication and authorization results. This method can be referred to in the above embodiments, and will not be described again in this application embodiment.
[0414] S608, CCF sends a response to the AMF that sends a context request.
[0415] Optionally, the CCF may send a response to the AMF regarding a context request. The response to the context request may include the context ID of the computing service and / or computing capability, the authentication and authorization results, and if the CCF refuses authentication and authorization, the response to the context request may also include the reason for refusal.
[0416] Optionally, if the request type is an urgent request or an update request, the CCF does not need to perform secondary authentication and authorization. Optionally, the CCF may perform secondary authentication and authorization based on any feasible implementation method, and this application embodiment does not limit this.
[0417] S609, CCF selects nodes for computing services and / or computing capabilities.
[0418] Optionally, the CCF can parse the computing services and / or computing capabilities requested by the terminal device and select nodes that meet the terminal device's requirements. For example, if the terminal device requests computing service 1, the CCF can select nodes that meet computing service 1; if the terminal device requests computing service 2, the CCF can select nodes that meet computing service 2.
[0419] Optionally, CCF may also select nodes for computing services and / or computing capabilities based on any feasible implementation method (e.g., selecting default nodes, etc.), and this application embodiment does not limit this.
[0420] S610 and CCF send computing tasks and computing strategies to nodes providing computing services and / or computing capabilities.
[0421] Optionally, the computing tasks and computing strategies may include the identifier of the computing task and / or computing capability, priority, type of computing resources to be provided, type of computing services and / or computing capability to be provided, size of computing resources to be provided, usage time of computing resources to be provided, computing routing strategy, etc.
[0422] Optionally, the network can establish paths from terminal devices to nodes providing computing services and / or computing capabilities, so that terminal devices can utilize the computing capabilities of the nodes providing computing services and / or computing capabilities.
[0423] S611, AMF determines the response to the request for computing services and / or computing capabilities based on the response to the context request.
[0424] Optionally, the AMF can determine the request response for computing services and / or computing capabilities based on the information carried in the response to the context request. For example, the AMF can obtain the authentication and authorization results of the computing services and / or computing capabilities from the response to the context request, and determine the request response for the computing services and / or computing capabilities based on the authentication and authorization results.
[0425] S612, AMF sends a request response to the terminal device for computing services and / or computing capabilities.
[0426] Optionally, the AMF can send a request response for computing services and / or computing capabilities to the terminal device via the RAN.
[0427] This application provides a communication method in which a terminal device sends a request message for computing services and / or computing capabilities to an AMF (Advanced Component Provider). Based on the request message, the AMF selects a CCF (Computer Computing Provider). The AMF determines whether an authentication and authorization process for the computing services and / or computing capabilities is required. The AMF then sends a context request to the CCF to create the computing services and / or computing capabilities. Based on the context request, the CCF obtains target information from the UDM (User Device Manager). The CCF verifies the target information to obtain the authentication and authorization results for the computing services and / or computing capabilities. Based on the authentication and authorization results, the CCF determines the response to the context request and sends the response to the AMF. The CCF selects a node for the computing services and / or computing capabilities and sends computing tasks and strategies to the node. Finally, the AMF sends the context request response to the terminal device. In this way, the CCF can provide the requested computing services and / or computing capabilities to the terminal device, thereby improving computing efficiency.
[0428] Figure 7 This is a schematic diagram of a communication device provided in an embodiment of this application. Please refer to [link / reference]. Figure 7 The communication device 700 includes a transmitting module 701 and a receiving module 702, wherein:
[0429] The sending module 701 is used to send a first message to the network device, the first message being used to request the authentication and authorization results of computing services and / or computing capabilities;
[0430] The receiving module 702 is used to receive a second message sent by the network device, the second message being used to indicate the authentication and authorization results of the computing service and / or computing capabilities.
[0431] In one implementation, the first message is a registration request message, a Protocol Data Unit (PDU) session establishment request message, or a request message for computing services and / or computing capabilities, and the first message includes a user identity identifier.
[0432] In one implementation, when the first message is a registration request message, the first message further includes at least one of the following:
[0433] The identifier of the node corresponding to the computing service and / or computing capability;
[0434] The demand information corresponding to the computing services and / or computing capabilities.
[0435] In one implementation, when the first message is a PDU session establishment request message, the first message further includes at least one of the following:
[0436] The identifier of the node corresponding to the computing service and / or computing capability;
[0437] The demand information corresponding to the computing services and / or computing capabilities;
[0438] Authorized data for the computing services and / or computing capabilities.
[0439] In one implementation, where the first message is a request message for the computing service and / or computing power, the first message further includes at least one of the following:
[0440] The identifier of the node corresponding to the computing service and / or computing capability;
[0441] The demand information corresponding to the computing services and / or computing capabilities;
[0442] The identifier of the computing service and / or computing capability;
[0443] The request type for computing services and / or computing capabilities.
[0444] In one implementation, the demand information corresponding to the computing service and / or computing capacity includes at least one of the following:
[0445] The requested business type;
[0446] The requested business performance requirements;
[0447] The resource types corresponding to the computing services and / or computing capabilities;
[0448] The type of computing service and / or computing capability;
[0449] The usage time of the computing services and / or computing power;
[0450] The location where the computing services and / or computing capabilities are used;
[0451] The network resource requirements corresponding to the computing services and / or computing capabilities;
[0452] The security requirements corresponding to the computing services and / or computing capabilities.
[0453] In one implementation, the second message is either a message indicating successful authentication and authorization of the computing service and / or computing capability, or a message indicating failed authentication and authorization of the computing service and / or computing capability.
[0454] In one implementation, if the second message is a message indicating successful authentication and authorization of the computing service and / or computing capabilities, the second message includes at least one of the following:
[0455] User identifiers for using computing services and / or computing capabilities;
[0456] Authorized data for the computing services and / or computing capabilities.
[0457] In one implementation, the authorized data for the computing service and / or computing power includes at least one of the following:
[0458] The duration of authorized computing services and / or computing power usage;
[0459] The type of authorized computing services and / or computing capabilities;
[0460] The amount of computing power and / or the authorized computing services and / or computing capabilities;
[0461] Authorized areas for the use of computing services and / or computing capabilities;
[0462] The node identifier corresponding to the authorized computing services and / or computing capabilities.
[0463] In one implementation, if the second message is a message indicating that the authentication and authorization of the computing service and / or computing capability has failed, the second message is further used to release network resources or computing resources, or to instruct the terminal device to re-request the authentication and authorization result of the computing service and / or computing capability, or to instruct the terminal device to send a registration request, or to instruct the terminal device to resend the registration request.
[0464] Figure 8 This is a schematic diagram of a communication device provided in an embodiment of this application. Please refer to [link / reference]. Figure 8 The communication device 800 includes a receiving module 801 and a transmitting module 802, wherein:
[0465] The receiving module 801 is used to receive a first message sent by the terminal device, the first message being used to request the authentication and authorization results of computing services and / or computing capabilities;
[0466] The sending module 802 is used to send a second message to the terminal device, the second message being used to indicate the authentication and authorization results of the computing service and / or computing capabilities.
[0467] In one implementation, the first message is a registration request message, a Protocol Data Unit (PDU) session establishment request message, or a request message for computing services and / or computing capabilities, and the first message includes a user identity identifier.
[0468] In one implementation, when the first message is a registration request message, the first message further includes at least one of the following:
[0469] The identifier of the node corresponding to the computing service and / or computing capability;
[0470] The demand information corresponding to the computing services and / or computing capabilities.
[0471] In one implementation, when the first message is a PDU session establishment request message, the first message further includes at least one of the following:
[0472] The identifier of the node corresponding to the computing service and / or computing capability;
[0473] The demand information corresponding to the computing services and / or computing capabilities;
[0474] Authorized data for the computing services and / or computing capabilities.
[0475] In one implementation, where the first message is a request message for the computing service and / or computing power, the first message further includes at least one of the following:
[0476] The identifier of the node corresponding to the computing service and / or computing capability;
[0477] The demand information corresponding to the computing services and / or computing capabilities;
[0478] The identifier of the computing service and / or computing capability;
[0479] The request type for computing services and / or computing capabilities.
[0480] In one implementation, the demand information corresponding to the computing service and / or computing capacity includes at least one of the following:
[0481] The requested business type;
[0482] The requested business performance requirements;
[0483] The resource types corresponding to the computing services and / or computing capabilities;
[0484] The type of computing service and / or computing capability;
[0485] The usage time of the computing services and / or computing power;
[0486] The location where the computing services and / or computing capabilities are used;
[0487] The network resource requirements corresponding to the computing services and / or computing capabilities;
[0488] The security requirements corresponding to the computing services and / or computing capabilities.
[0489] In one implementation, sending the second message to the terminal device includes:
[0490] Based on the first message, determine the authentication and authorization results of the computing service and / or computing capabilities;
[0491] Based on the authentication and authorization results, a second message is sent to the terminal device.
[0492] In one embodiment, the network device includes a first network function, a second network function, and a third network function;
[0493] The first network function is used to control the access and mobility management of terminal devices, or to control session management functions; the second network function is used for the registration of computing function nodes, the periodic maintenance and scheduling of computing resources and network resource information, and the authentication and authorization of computing services and / or computing capabilities; the third network function is used to store and manage user-related data.
[0494] In one implementation, determining the authentication and authorization result of the computing service and / or computing capability based on the first message includes:
[0495] Based on the first network function, a third message is sent to the second network function, the third message including the content of the first message;
[0496] Based on the second network function and the third message, target information is obtained at the third network function. The target information is information to verify whether the terminal device can use computing services and / or computing capabilities.
[0497] Based on the second network function, the target information is verified to obtain the authentication and authorization results of the computing service and / or computing capabilities.
[0498] In one implementation, sending a second message to the terminal device based on the authentication and authorization results includes:
[0499] Based on the second network function and the authentication and authorization results, the second message is generated and sent to the first network function;
[0500] Based on the first network function, the second message is sent to the terminal device.
[0501] In one implementation, the second message is either a message indicating successful authentication and authorization of the computing service and / or computing capability, or a message indicating failed authentication and authorization of the computing service and / or computing capability.
[0502] In one implementation, if the second message is a message indicating successful authentication and authorization of the computing service and / or computing capabilities, the second message includes at least one of the following:
[0503] User identifiers for using computing services and / or computing capabilities;
[0504] Authorized data for the computing services and / or computing capabilities.
[0505] In one implementation, the authorized data for the computing service and / or computing power includes at least one of the following:
[0506] The duration of authorized computing services and / or computing power usage;
[0507] The type of authorized computing services and / or computing capabilities;
[0508] The amount of computing power and / or the authorized computing services and / or computing capabilities;
[0509] Authorized areas for the use of computing services and / or computing capabilities;
[0510] The node identifier corresponding to the authorized computing services and / or computing capabilities.
[0511] In one implementation, if the second message is a message indicating that the authentication and authorization of the computing service and / or computing capability has failed, the second message is further used to release network resources or computing resources, or to re-request the authentication and authorization result of the computing service and / or computing capability, or to instruct the terminal device to send a registration request, or to instruct the terminal device to resend the registration request.
[0512] In one implementation, sending a third message to the second network function based on the first network function includes:
[0513] Based on the first network function, determine whether an authentication and authorization process for computing services and / or computing capabilities needs to be performed;
[0514] If an authentication and authorization process for computing services and / or computing capabilities is required, the third message is sent to the second network function based on the first network function.
[0515] In one implementation, when the first network function is used to control the access and mobility management of terminal devices, based on the first network function, determining whether an authentication and authorization process for computing services and / or computing capabilities needs to be performed includes:
[0516] If the terminal device's subscription data includes subscription data for the terminal device to use computing services and / or computing capabilities, then based on the first network function, it is determined that an authentication and authorization process for computing services and / or computing capabilities needs to be performed.
[0517] If the subscription data of the terminal device indicates that the authentication and authorization process for the computing service and / or computing capabilities needs to be executed during the registration period, then when the first message is the registration request message, it is determined based on the first network function that the authentication and authorization process for the computing service and / or computing capabilities needs to be executed.
[0518] If the first message is used to re-request the authentication and authorization results of computing services and / or computing capabilities, then it is determined based on the first network function that an authentication and authorization process for computing services and / or computing capabilities needs to be performed.
[0519] If the first message includes the demand information corresponding to the computing service and / or computing capability, then based on the first network function, it is determined that an authentication and authorization process for the computing service and / or computing capability needs to be executed.
[0520] In one implementation, when the first network function is used to control session management functions, based on the first network function, determining whether an authentication and authorization process for computing services and / or computing capabilities needs to be performed includes:
[0521] If the combination of Data Network Name (DNN) and Single Network Slice Selection Auxiliary Information (S-NSSAI) is used for computing services, then the authentication and authorization process for computing services and / or computing capabilities needs to be performed based on the first network function.
[0522] If the PDU session type indicates that the current service type is computing service, then based on the first network function, it is determined that an authentication and authorization process for computing services and / or computing capabilities needs to be performed.
[0523] If the PDU session establishment request includes the identifier of the node corresponding to the computing service and / or computing capability, then based on the first network function, it is determined that an authentication and authorization process for the computing service and / or computing capability needs to be performed.
[0524] If the PDU session establishment request includes the requirement information corresponding to the computing service and / or computing capability, then based on the first network function, it is determined that an authentication and authorization process for the computing service and / or computing capability needs to be executed.
[0525] It should be noted that the division of units in the embodiments of this application is illustrative and only represents one logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated units described above can be implemented in hardware or as software functional units.
[0526] If the aforementioned integrated units are implemented as software functional units and sold or used as independent products, they can be stored in a processor-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0527] It should be noted that the apparatus provided in this application can implement all the method steps implemented in the above method embodiments and can achieve the same technical effect. Therefore, the parts and beneficial effects that are the same as those in the method embodiments will not be described in detail here.
[0528] Figure 9 This is a schematic diagram of the structure of a terminal device provided in an embodiment of this application. Please refer to... Figure 9 The terminal device includes a memory 910, a transceiver 920, and a processor 930.
[0529] The memory 910 is used to store computer programs;
[0530] The transceiver 920 is used to send and receive data under the control of the processor;
[0531] The processor 930 is configured to read the computer program in the memory and perform the following operations:
[0532] The terminal device receives a first message, which is used to request the authentication and authorization results of computing services and / or computing capabilities.
[0533] A second message is sent to the terminal device, the second message being used to indicate the authentication and authorization results of the computing service and / or computing capabilities.
[0534] In one implementation, the first message is a registration request message, a Protocol Data Unit (PDU) session establishment request message, or a request message for computing services and / or computing capabilities, and the first message includes a user identity identifier.
[0535] In one implementation, when the first message is a registration request message, the first message further includes at least one of the following:
[0536] The identifier of the node corresponding to the computing service and / or computing capability;
[0537] The demand information corresponding to the computing services and / or computing capabilities.
[0538] In one implementation, when the first message is a PDU session establishment request message, the first message further includes at least one of the following:
[0539] The identifier of the node corresponding to the computing service and / or computing capability;
[0540] The demand information corresponding to the computing services and / or computing capabilities;
[0541] Authorized data for the computing services and / or computing capabilities.
[0542] In one implementation, where the first message is a request message for the computing service and / or computing power, the first message further includes at least one of the following:
[0543] The identifier of the node corresponding to the computing service and / or computing capability;
[0544] The demand information corresponding to the computing services and / or computing capabilities;
[0545] The identifier of the computing service and / or computing capability;
[0546] The request type for computing services and / or computing capabilities.
[0547] In one implementation, the demand information corresponding to the computing service and / or computing capacity includes at least one of the following:
[0548] The requested business type;
[0549] The requested business performance requirements;
[0550] The resource types corresponding to the computing services and / or computing capabilities;
[0551] The type of computing service and / or computing capability;
[0552] The usage time of the computing services and / or computing power;
[0553] The location where the computing services and / or computing capabilities are used;
[0554] The network resource requirements corresponding to the computing services and / or computing capabilities;
[0555] The security requirements corresponding to the computing services and / or computing capabilities.
[0556] In one implementation, the second message is either a message indicating successful authentication and authorization of the computing service and / or computing capability, or a message indicating failed authentication and authorization of the computing service and / or computing capability.
[0557] In one implementation, if the second message is a message indicating successful authentication and authorization of the computing service and / or computing capabilities, the second message includes at least one of the following:
[0558] User identifiers for using computing services and / or computing capabilities;
[0559] Authorized data for the computing services and / or computing capabilities.
[0560] In one implementation, the authorized data for the computing service and / or computing power includes at least one of the following:
[0561] The duration of authorized computing services and / or computing power usage;
[0562] The type of authorized computing services and / or computing capabilities;
[0563] The amount of computing power and / or the authorized computing services and / or computing capabilities;
[0564] Authorized areas for the use of computing services and / or computing capabilities;
[0565] The node identifier corresponding to the authorized computing services and / or computing capabilities.
[0566] In one implementation, if the second message is a message indicating that the authentication and authorization of the computing service and / or computing capability has failed, the second message is further used to release network resources or computing resources, or to instruct the terminal device to re-request the authentication and authorization result of the computing service and / or computing capability, or to instruct the terminal device to send a registration request, or to instruct the terminal device to resend the registration request.
[0567] In one embodiment, the terminal device may further include a user interface 940. For different terminal devices, the user interface 940 may also be an interface that can connect to external or internal devices, including but not limited to keypad, display, speaker, microphone, joystick, etc.
[0568] Among them, Figure 9 In this context, the bus architecture can include any number of interconnected buses and bridges, specifically linking various circuits together, represented by one or more processors (processor 903) and memory (memory 910). The bus architecture can also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface. The transceiver 920 can be multiple elements, including transmitters and receivers, providing units for communicating with various other devices over transmission media, including wireless channels, wired channels, optical fibers, etc. The processor 930 is responsible for managing the bus architecture and general processing, and the memory 901 can store data used by the processor 930 during operation.
[0569] Optionally, the processor 930 can be a central processing unit (CPU), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or a complex programmable logic device (CPLD). The processor can also adopt a multi-core architecture.
[0570] The processor 930 executes any of the methods described in the embodiments of this application by calling a computer program stored in the memory 910, according to the obtained executable instructions. The processor 930 and the memory 910 may also be physically separated.
[0571] It should be noted that the physical device provided in this application can implement all the method steps implemented by the physical device in the above method embodiment and can achieve the same technical effect. Therefore, the parts and beneficial effects that are the same as those in the method embodiment will not be described in detail here.
[0572] Figure 10 This is a schematic diagram of the structure of a network device provided in an embodiment of this application. Please refer to [link / reference]. Figure 10 The network device includes a memory 1010, a transceiver 1020, and a processor 1030.
[0573] The memory 1010 is used to store computer programs;
[0574] The transceiver 1020 is used to send and receive data under the control of the processor;
[0575] The processor 1030 is configured to read the computer program in the memory and perform the following operations:
[0576] The terminal device receives a first message, which is used to request the authentication and authorization results of computing services and / or computing capabilities.
[0577] A second message is sent to the terminal device, the second message being used to indicate the authentication and authorization results of the computing service and / or computing capabilities.
[0578] In one implementation, the first message is a registration request message, a Protocol Data Unit (PDU) session establishment request message, or a request message for computing services and / or computing capabilities, and the first message includes a user identity identifier.
[0579] In one implementation, when the first message is a registration request message, the first message further includes at least one of the following:
[0580] The identifier of the node corresponding to the computing service and / or computing capability;
[0581] The demand information corresponding to the computing services and / or computing capabilities.
[0582] In one implementation, when the first message is a PDU session establishment request message, the first message further includes at least one of the following:
[0583] The identifier of the node corresponding to the computing service and / or computing capability;
[0584] The demand information corresponding to the computing services and / or computing capabilities;
[0585] Authorized data for the computing services and / or computing capabilities.
[0586] In one implementation, where the first message is a request message for the computing service and / or computing power, the first message further includes at least one of the following:
[0587] The identifier of the node corresponding to the computing service and / or computing capability;
[0588] The demand information corresponding to the computing services and / or computing capabilities;
[0589] The identifier of the computing service and / or computing capability;
[0590] The request type for computing services and / or computing capabilities.
[0591] In one implementation, the demand information corresponding to the computing service and / or computing capacity includes at least one of the following:
[0592] The requested business type;
[0593] The requested business performance requirements;
[0594] The resource types corresponding to the computing services and / or computing capabilities;
[0595] The type of computing service and / or computing capability;
[0596] The usage time of the computing services and / or computing power;
[0597] The location where the computing services and / or computing capabilities are used;
[0598] The network resource requirements corresponding to the computing services and / or computing capabilities;
[0599] The security requirements corresponding to the computing services and / or computing capabilities.
[0600] In one implementation, sending the second message to the terminal device includes:
[0601] Based on the first message, determine the authentication and authorization results of the computing service and / or computing capabilities;
[0602] Based on the authentication and authorization results, a second message is sent to the terminal device.
[0603] In one embodiment, the network device includes a first network function, a second network function, and a third network function;
[0604] The first network function is used to control the access and mobility management of terminal devices, or to control session management functions; the second network function is used for the registration of computing function nodes, the periodic maintenance and scheduling of computing resources and network resource information, and the authentication and authorization of computing services and / or computing capabilities; the third network function is used to store and manage user-related data.
[0605] In one implementation, determining the authentication and authorization result of the computing service and / or computing capability based on the first message includes:
[0606] Based on the first network function, a third message is sent to the second network function, the third message including the content of the first message;
[0607] Based on the second network function and the third message, target information is obtained at the third network function. The target information is information to verify whether the terminal device can use computing services and / or computing capabilities.
[0608] Based on the second network function, the target information is verified to obtain the authentication and authorization results of the computing service and / or computing capabilities.
[0609] In one implementation, sending a second message to the terminal device based on the authentication and authorization results includes:
[0610] Based on the second network function and the authentication and authorization results, the second message is generated and sent to the first network function;
[0611] Based on the first network function, the second message is sent to the terminal device.
[0612] In one implementation, the second message is either a message indicating successful authentication and authorization of the computing service and / or computing capability, or a message indicating failed authentication and authorization of the computing service and / or computing capability.
[0613] In one implementation, if the second message is a message indicating successful authentication and authorization of the computing service and / or computing capabilities, the second message includes at least one of the following:
[0614] User identifiers for using computing services and / or computing capabilities;
[0615] Authorized data for the computing services and / or computing capabilities.
[0616] In one implementation, the authorized data for the computing service and / or computing power includes at least one of the following:
[0617] The duration of authorized computing services and / or computing power usage;
[0618] The type of authorized computing services and / or computing capabilities;
[0619] The amount of computing power and / or the authorized computing services and / or computing capabilities;
[0620] Authorized areas for the use of computing services and / or computing capabilities;
[0621] The node identifier corresponding to the authorized computing services and / or computing capabilities.
[0622] In one implementation, if the second message is a message indicating that the authentication and authorization of the computing service and / or computing capability has failed, the second message is further used to release network resources or computing resources, or to re-request the authentication and authorization result of the computing service and / or computing capability, or to instruct the terminal device to send a registration request, or to instruct the terminal device to resend the registration request.
[0623] In one implementation, sending a third message to the second network function based on the first network function includes:
[0624] Based on the first network function, determine whether an authentication and authorization process for computing services and / or computing capabilities needs to be performed;
[0625] If an authentication and authorization process for computing services and / or computing capabilities is required, the third message is sent to the second network function based on the first network function.
[0626] In one implementation, when the first network function is used to control the access and mobility management of terminal devices, based on the first network function, determining whether an authentication and authorization process for computing services and / or computing capabilities needs to be performed includes:
[0627] If the terminal device's subscription data includes subscription data for the terminal device to use computing services and / or computing capabilities, then based on the first network function, it is determined that an authentication and authorization process for computing services and / or computing capabilities needs to be performed.
[0628] If the subscription data of the terminal device indicates that the authentication and authorization process for the computing service and / or computing capabilities needs to be executed during the registration period, then when the first message is the registration request message, it is determined based on the first network function that the authentication and authorization process for the computing service and / or computing capabilities needs to be executed.
[0629] If the first message is used to re-request the authentication and authorization results of computing services and / or computing capabilities, then it is determined based on the first network function that an authentication and authorization process for computing services and / or computing capabilities needs to be performed.
[0630] If the first message includes the demand information corresponding to the computing service and / or computing capability, then based on the first network function, it is determined that an authentication and authorization process for the computing service and / or computing capability needs to be executed.
[0631] In one implementation, when the first network function is used to control session management functions, based on the first network function, determining whether an authentication and authorization process for computing services and / or computing capabilities needs to be performed includes:
[0632] If the combination of Data Network Name (DNN) and Single Network Slice Selection Auxiliary Information (S-NSSAI) is used for computing services, then the authentication and authorization process for computing services and / or computing capabilities needs to be performed based on the first network function.
[0633] If the PDU session type indicates that the current service type is computing service, then based on the first network function, it is determined that an authentication and authorization process for computing services and / or computing capabilities needs to be performed.
[0634] If the PDU session establishment request includes the identifier of the node corresponding to the computing service and / or computing capability, then based on the first network function, it is determined that an authentication and authorization process for the computing service and / or computing capability needs to be performed.
[0635] If the PDU session establishment request includes the requirement information corresponding to the computing service and / or computing capability, then based on the first network function, it is determined that an authentication and authorization process for the computing service and / or computing capability needs to be executed.
[0636] This application also provides a processor-readable storage medium storing a computer program for causing the processor to execute the method described in any of the above method embodiments.
[0637] Processor-readable storage media can be any available medium or data storage device that a computer can access, including but not limited to magnetic storage (such as floppy disks, hard disks, magnetic tapes, magneto-optical disks (MOs), etc.), optical storage (such as CDs, DVDs, BDs, HVDs, etc.), and semiconductor storage (such as ROMs, EPROMs, EEPROMs, non-volatile memory (NAND flash), solid-state drives (SSDs)).
[0638] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the method described in any of the above method embodiments.
[0639] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage and optical storage) containing computer-usable program code.
[0640] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-executable instructions. These computer-executable instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0641] These processor-executable instructions may also be stored in a processor-readable memory that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the processor-readable memory produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0642] These processors can execute instructions that can also be loaded onto a computer or other programmable data processing device, causing a series of operational steps to be performed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable device for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0643] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. A communication method, characterized in that, Applied to terminal devices, including: Send a first message to the network device, the first message being used to request the authentication and authorization results of computing services and / or computing capabilities; Receive a second message sent by the network device, the second message being used to indicate the authentication and authorization results of the computing service and / or computing capabilities.
2. The method according to claim 1, characterized in that, The first message is a registration request message, a Protocol Data Unit (PDU) session establishment request message, or a request message for computing services and / or computing capabilities, and the first message includes a user identity identifier.
3. The method according to claim 2, characterized in that, If the first message is a registration request message, the first message also includes at least one of the following: The identifier of the node corresponding to the computing service and / or computing capability; The demand information corresponding to the computing services and / or computing capabilities.
4. The method according to claim 2, characterized in that, If the first message is a PDU session establishment request message, the first message further includes at least one of the following: The identifier of the node corresponding to the computing service and / or computing capability; The demand information corresponding to the computing services and / or computing capabilities; Authorized data for the computing services and / or computing capabilities.
5. The method according to claim 2, characterized in that, In the case where the first message is a request message for the computing service and / or computing power, the first message further includes at least one of the following: The identifier of the node corresponding to the computing service and / or computing capability; The demand information corresponding to the computing services and / or computing capabilities; The identifier of the computing service and / or computing capability; The request type for computing services and / or computing capabilities.
6. The method according to any one of claims 3-5, characterized in that, The demand information corresponding to the computing services and / or computing capabilities includes at least one of the following: The requested business type; The requested business performance requirements; The resource types corresponding to the computing services and / or computing capabilities; The type of computing service and / or computing capability; The usage time of the computing services and / or computing power; The location where the computing services and / or computing capabilities are used; The network resource requirements corresponding to the computing services and / or computing capabilities; The security requirements corresponding to the computing services and / or computing capabilities.
7. The method according to any one of claims 1-5, characterized in that, The second message is either a message indicating successful authentication and authorization of the computing service and / or computing capabilities, or a message indicating failed authentication and authorization of the computing service and / or computing capabilities.
8. The method according to claim 7, characterized in that, In the case where the second message is a message indicating successful authentication and authorization of the computing service and / or computing capabilities, the second message includes at least one of the following: User identifiers for using computing services and / or computing capabilities; Authorized data for the computing services and / or computing capabilities.
9. The method according to claim 4 or 8, characterized in that, The authorized data for the computing services and / or computing capabilities includes at least one of the following: The duration of authorized computing services and / or computing power usage; The type of authorized computing services and / or computing capabilities; The amount of computing power and / or the authorized computing services and / or computing capabilities; Authorized areas for the use of computing services and / or computing capabilities; The node identifier corresponding to the authorized computing services and / or computing capabilities.
10. The method according to claim 7, characterized in that, In the event that the second message is a message indicating a failure in the authentication and authorization of the computing service and / or computing capabilities, the second message may also be used to release network resources or computing resources, or to instruct the terminal device to re-request the authentication and authorization results of the computing service and / or computing capabilities, or to instruct the terminal device to send a registration request, or to instruct the terminal device to resend the registration request.
11. A communication method, characterized in that, Applied to network devices, including: The terminal device receives a first message, which is used to request the authentication and authorization results of computing services and / or computing capabilities. A second message is sent to the terminal device, the second message being used to indicate the authentication and authorization results of the computing service and / or computing capabilities.
12. The method according to claim 11, characterized in that, The first message is a registration request message, a Protocol Data Unit (PDU) session establishment request message, or a request message for computing services and / or computing capabilities, and the first message includes a user identity identifier.
13. The method according to claim 12, characterized in that, If the first message is a registration request message, the first message also includes at least one of the following: The identifier of the node corresponding to the computing service and / or computing capability; The demand information corresponding to the computing services and / or computing capabilities.
14. The method according to claim 12, characterized in that, If the first message is a PDU session establishment request message, the first message further includes at least one of the following: The identifier of the node corresponding to the computing service and / or computing capability; The demand information corresponding to the computing services and / or computing capabilities; Authorized data for the computing services and / or computing capabilities.
15. The method according to claim 12, characterized in that, In the case where the first message is a request message for the computing service and / or computing power, the first message further includes at least one of the following: The identifier of the node corresponding to the computing service and / or computing capability; The demand information corresponding to the computing services and / or computing capabilities; The identifier of the computing service and / or computing capability; The request type for computing services and / or computing capabilities.
16. The method according to any one of claims 13-15, characterized in that, The demand information corresponding to the computing services and / or computing capabilities includes at least one of the following: The requested business type; The requested business performance requirements; The resource types corresponding to the computing services and / or computing capabilities; The type of computing service and / or computing capability; The usage time of the computing services and / or computing power; The location where the computing services and / or computing capabilities are used; The network resource requirements corresponding to the computing services and / or computing capabilities; The security requirements corresponding to the computing services and / or computing capabilities.
17. The method according to any one of claims 12-15, characterized in that, Sending the second message to the terminal device includes: Based on the first message, determine the authentication and authorization results of the computing service and / or computing capabilities; Based on the authentication and authorization results, a second message is sent to the terminal device.
18. The method according to claim 17, characterized in that, The network device includes a first network function, a second network function, and a third network function; The first network function is used to control the access and mobility management of terminal devices, or to control session management functions; the second network function is used for the registration of computing function nodes, the periodic maintenance and scheduling of computing resources and network resource information, and the authentication and authorization of computing services and / or computing capabilities; the third network function is used to store and manage user-related data.
19. The method according to claim 18, characterized in that, Based on the first message, determine the authentication and authorization results of the computing service and / or computing capabilities, including: Based on the first network function, a third message is sent to the second network function, the third message including the content of the first message; Based on the second network function and the third message, target information is obtained at the third network function. The target information is information to verify whether the terminal device can use computing services and / or computing capabilities. Based on the second network function, the target information is verified to obtain the authentication and authorization results of the computing service and / or computing capabilities.
20. The method according to claim 18, characterized in that, The step of sending a second message to the terminal device based on the authentication and authorization results includes: Based on the second network function and the authentication and authorization results, the second message is generated and sent to the first network function; Based on the first network function, the second message is sent to the terminal device.
21. The method according to claim 20, characterized in that, The second message is either a message indicating successful authentication and authorization of the computing service and / or computing capabilities, or a message indicating failed authentication and authorization of the computing service and / or computing capabilities.
22. The method according to claim 21, characterized in that, In the case where the second message is a message indicating successful authentication and authorization of the computing service and / or computing capabilities, the second message includes at least one of the following: User identifiers for using computing services and / or computing capabilities; Authorized data for the computing services and / or computing capabilities.
23. The method according to claim 14 or 22, characterized in that, The authorized data for the computing services and / or computing capabilities includes at least one of the following: The duration of authorized computing services and / or computing power usage; The type of authorized computing services and / or computing capabilities; The amount of computing power and / or the authorized computing services and / or computing capabilities; Authorized areas for the use of computing services and / or computing capabilities; The node identifier corresponding to the authorized computing services and / or computing capabilities.
24. The method according to claim 21, characterized in that, In the event that the second message is a message indicating that the authentication and authorization of the computing service and / or computing capabilities has failed, the second message may also be used to release network resources or computing resources, or to re-request the authentication and authorization results of the computing service and / or computing capabilities, or to instruct the terminal device to send a registration request, or to instruct the terminal device to resend the registration request.
25. The method according to any one of claims 19-24, characterized in that, The step of sending a third message to the second network function based on the first network function includes: Based on the first network function, determine whether an authentication and authorization process for computing services and / or computing capabilities needs to be performed; If an authentication and authorization process for computing services and / or computing capabilities is required, the third message is sent to the second network function based on the first network function.
26. The method according to claim 25, characterized in that, When the first network function is used to control the access and mobility management of terminal devices, based on the first network function, it is determined whether an authentication and authorization process for computing services and / or computing capabilities needs to be executed, including: If the terminal device's subscription data includes subscription data for the terminal device to use computing services and / or computing capabilities, then based on the first network function, it is determined that an authentication and authorization process for computing services and / or computing capabilities needs to be performed. If the subscription data of the terminal device indicates that the authentication and authorization process for the computing service and / or computing capabilities needs to be executed during the registration period, then when the first message is the registration request message, it is determined based on the first network function that the authentication and authorization process for the computing service and / or computing capabilities needs to be executed. If the first message is used to re-request the authentication and authorization results of computing services and / or computing capabilities, then it is determined based on the first network function that an authentication and authorization process for computing services and / or computing capabilities needs to be performed. If the first message includes the demand information corresponding to the computing service and / or computing capability, then based on the first network function, it is determined that an authentication and authorization process for the computing service and / or computing capability needs to be executed.
27. The method according to claim 25, characterized in that, When the first network function is used to control session management functions, based on the first network function, it is determined whether an authentication and authorization process for computing services and / or computing capabilities needs to be performed, including: If the combination of Data Network Name (DNN) and Single Network Slice Selection Auxiliary Information (S-NSSAI) is used for computing services, then the authentication and authorization process for computing services and / or computing capabilities needs to be performed based on the first network function. If the PDU session type indicates that the current service type is computing service, then based on the first network function, it is determined that an authentication and authorization process for computing services and / or computing capabilities needs to be performed. If the PDU session establishment request includes the identifier of the node corresponding to the computing service and / or computing capability, then based on the first network function, it is determined that an authentication and authorization process for the computing service and / or computing capability needs to be performed. If the PDU session establishment request includes the requirement information corresponding to the computing service and / or computing capability, then based on the first network function, it is determined that an authentication and authorization process for the computing service and / or computing capability needs to be executed.
28. A communication device, characterized in that, Applied to terminal devices, including a transmitting module and a receiving module, wherein: The sending module is used to send a first message to the network device, the first message being used to request the authentication and authorization results of computing services and / or computing capabilities; The receiving module is configured to receive a second message sent by the network device, the second message being used to indicate the authentication and authorization results of the computing service and / or computing capabilities.
29. A communication device, characterized in that, Applied to network devices, including receiving and transmitting modules, wherein: The receiving module is used to receive a first message sent by the terminal device, the first message being used to request the authentication and authorization results of computing services and / or computing capabilities; The sending module is used to send a second message to the terminal device, the second message being used to indicate the authentication and authorization results of the computing service and / or computing capabilities.
30. A terminal device, characterized in that, Includes memory, transceiver, and processor: The memory is used to store computer programs; The transceiver is used to send and receive data under the control of the processor; The processor is configured to read the computer program from the memory and perform the following operations: Send a first message to the network device, the first message being used to request the authentication and authorization results of computing services and / or computing capabilities; Receive a second message sent by the network device, the second message being used to indicate the authentication and authorization results of the computing service and / or computing capabilities.
31. A network device, characterized in that, Includes memory, transceiver, and processor: The memory is used to store computer programs; The transceiver is used to send and receive data under the control of the processor; The processor is configured to read the computer program from the memory and perform the following operations: The terminal device receives a first message, which is used to request the authentication and authorization results of computing services and / or computing capabilities. A second message is sent to the terminal device, the second message being used to indicate the authentication and authorization results of the computing service and / or computing capabilities.
32. A processor-readable storage medium, characterized in that, The processor-readable storage medium stores a computer program that causes the processor to perform the method as described in any one of claims 1-10, or the method as described in any one of claims 11-27.