Data access control method and apparatus

CN122579127APending Publication Date: 2026-08-14DATANG MOBILE COMM EQUIP CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-14
Publication Date
2026-08-14

AI Technical Summary

Technical Problem

[0004]但是,面向未来的移动通信系统,数据来源增多,大量的数据在网络侧、终端和基站侧存储流转,基于OAuth 2.0框架的网元之间的授权机制仅能防止非法用户或未授权的用户访问系统资源,并不能保证数据被合法使用,存在数据安全风险高的技术问题

Benefits of technology

[0042]第十三方面,本申请还提供一种通信设备,所述通信设备中存储有计算机程序,所述计算机程序用于使通信设备执行如上所述第一方面或第二方面或第三方面所述的数据访问控制方法。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122579127A_ABST
    Figure CN122579127A_ABST
Patent Text Reader

Abstract

This application provides a data access control method and apparatus. The method includes: sending data security policy information; the data security policy information being used to configure a data security policy for a data service provided by a network element of a data service provider; obtaining the data security policy configured for the data service provided by the network element of the data service provider; and the data security policy corresponding to a data access control algorithm for performing data access control. The data access control method and apparatus provided by this application allow a data service provider to negotiate a data security policy with the network based on the provided data service. When providing the data service, the provider can process the data according to the data access control algorithm corresponding to the data security policy, thereby achieving fine-grained access control for subsequent data requesters and improving data security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of wireless communication technology, and in particular to a data access control method and apparatus. Background Technology

[0002] The 5G system provides point-to-point forwarding of user data and network data management functions. For future mobile communication systems, the communication network will no longer be just a data transmission channel; it will also need to add a data plane to enable data services such as data collection, transmission, preprocessing, storage, analysis, and consumption.

[0003] In 5G networks, an authorization mechanism is used between core network elements. The authorization framework used in the service request process is OAuth 2.0. OAuth 2.0 is an industry-standard authorization protocol developed by the Internet Engineering Task Force (IETF). It supports a token-based framework where service users can obtain tokens from the authorization server. These tokens can be used to access specific services of Network Function Service Producers (NF-SPs). Commonly used data access control algorithms include proxy re-encryption access control algorithms and attribute-based encryption algorithms with ciphertext policies.

[0004] However, with the increasing number of data sources in future mobile communication systems, a large amount of data is stored and transferred between the network side, terminals, and base stations. The authorization mechanism between network elements based on the OAuth 2.0 framework can only prevent unauthorized users from accessing system resources, but cannot guarantee that the data is used legally, posing a high technical risk to data security. Summary of the Invention

[0005] This application provides a data access control method and apparatus to solve the technical problem of high data security risks in related technologies.

[0006] In a first aspect, this application provides a data access control method applied to a network element of a data service provider, the method comprising: Send data security policy information; the data security policy information is used to configure data security policies for the data services provided by the network element of the data service provider. Obtain the data security policy configured for the data service provided by the network element of the data service provider; the data security policy corresponds to the data access control algorithm for performing data access control.

[0007] In some embodiments, the transmission of data security policy information includes: Send data security policy information to the data access control function network element; The step of obtaining the data security policy configured for the data service provided by the network element of the data service provider includes: The data security policy configured by the data access control function network element for the data service provided by the data service provider network element is obtained; the data security policy configured for the data service provided by the data service provider network element is based on the data security policy supported by the data service provider network element and the data security policy configured locally stored by the data access control function network element.

[0008] In some embodiments, the method further includes: The data collection instruction message sent by the data management function network element is obtained; the data collection instruction message contains instruction information of the target data service, the target data security policy configured for the target data service, the target data access control algorithm corresponding to the target data security policy, and the first parameter of the target data access control algorithm. Collect target data; The target data is encrypted based on the target data access control algorithm and the first parameter of the target data access control algorithm; The encrypted target data is sent to the target data storage function network element indicated by the data acquisition instruction message.

[0009] In some embodiments, the method further includes: Access control information is generated based on the target data access control algorithm and the first parameter of the target data access control algorithm; The access control information is sent to the target data storage function network element indicated by the data acquisition instruction message.

[0010] In some embodiments, the transmission of data security policy information includes: Send data security policy information to the data management function network element; The step of obtaining the data security policy configured for the data service provided by the network element of the data service provider includes: The data security policy configured by the data management function network element for the data service provided by the data service provider network element is obtained; the data security policy configured for the data service provided by the data service provider network element is based on the data security policy supported by the data service provider network element and the data security policy locally stored by the data access control function network element.

[0011] In some embodiments, the method further includes: The data collection instruction message sent by the data management function network element is obtained; the data collection instruction message contains instruction information of the target data service, the target data security policy configured for the target data service, the target data access control algorithm corresponding to the target data security policy, and the first parameter of the target data access control algorithm. Collect target data; The target data is encrypted based on the target data access control algorithm and the first parameter of the target data access control algorithm; The encrypted target data is sent to the target data storage function network element indicated by the data acquisition instruction message.

[0012] In some embodiments, the method further includes: Access control information is generated based on the target data access control algorithm and the first parameter of the target data access control algorithm; The access control information is sent to the target data storage function network element indicated by the data acquisition instruction message.

[0013] In some embodiments, the data access control algorithm includes one or more of the following algorithms: Proxy re-encryption access control algorithm; Ciphertext policy attribute-based encryption algorithm.

[0014] In some embodiments, the data security policy information includes one or more of the following: Data security policy name; List of data security policy names; Data security policy identifier; List of data security policy identifiers.

[0015] Secondly, this application provides a data access control method applied to a data service requesting network element, the method comprising: Obtain the data security policy configured for the data service provided by the network element of the data service provider; the data security policy corresponds to the data access control algorithm for performing data access control. Send the first parameter; the first parameter is the parameter of the data access control algorithm corresponding to the data security policy configured for the data service provided by the data service provider network element; the first parameter is used for data access control.

[0016] In some embodiments, obtaining the data security policy configured for the data service provided by the data service provider network element includes: The data security policy configured by the data access control function network element for the data service provided by the data service provider network element is obtained; the data security policy configured for the data service provided by the data service provider network element is based on the data security policy supported by the data service provider network element and the data security policy configured locally stored by the data access control function network element.

[0017] In some embodiments, the method further includes: Obtain a data service response message for the data service request message targeting the target data; the data service response message contains target data security policy information. Download the encrypted target data from the target data storage function network element indicated by the data service response message; The ciphertext is decrypted using the decryption material corresponding to the target data security policy indicated by the local target data security policy information, to obtain the plaintext of the target data.

[0018] In some embodiments, the method further includes: Download access control information from the target data storage function network element indicated by the data service response message; The decryption material corresponding to the target data security policy indicated by the local target data security policy information decrypts the ciphertext, including: The ciphertext is decrypted based on the decryption material corresponding to the target data security policy indicated by the access control information and the local target data security policy information.

[0019] In some embodiments, obtaining the data security policy configured for the data service provided by the data service provider network element includes: The data security policy configured by the data management function network element for the data service provided by the data service provider network element is obtained; the data security policy configured for the data service provided by the data service provider network element is based on the data security policy supported by the data service provider network element and the data security policy locally stored by the data access control function network element.

[0020] In some embodiments, the method further includes: Obtain a data service response message for the data service request message targeting the target data; the data service response message contains target data security policy information. Download the encrypted target data from the target data storage function network element indicated by the data service response message; The ciphertext is decrypted using the decryption material corresponding to the target data security policy indicated by the local target data security policy information, to obtain the plaintext of the target data.

[0021] In some embodiments, the method further includes: Download access control information from the target data storage function network element indicated by the data service response message; The decryption material corresponding to the target data security policy indicated by the local target data security policy information decrypts the ciphertext, including: The ciphertext is decrypted based on the decryption material corresponding to the target data security policy indicated by the access control information and the local target data security policy information.

[0022] In some embodiments, the data access control algorithm includes one or more of the following algorithms: Proxy re-encryption access control algorithm; Ciphertext policy attribute-based encryption algorithm.

[0023] In some embodiments, the information used to instruct the data security policy configured for the data service provided to the data service provider network element includes one or more of the following: Data security policy name; Data security policy identifier.

[0024] Thirdly, this application provides a data access control method applied to a data management function network element, the method comprising: Obtain data security policy information sent by the network element of the data service provider; Based on the data security policy supported by the data service provider network element, a data security policy is configured for the data service provided by the data service provider network element; the data security policy corresponds to the data access control algorithm for performing data access control. Send the data security policy configured for the data service provided by the data service provider network element to the data service provider network element.

[0025] In some embodiments, configuring a data security policy for the data service provided by the data service provider network element based on the data security policy supported by the data service provider network element includes: Based on the data security policies supported by the data service provider network element and the data security policies stored locally by the data access control function network element, configure data security policies for the data services provided by the data service provider network element.

[0026] In some embodiments, configuring a data security policy for the data service provided by the data service provider network element based on the data security policy supported by the data service provider network element includes: Obtain the data security policy stored locally by the data access control function network element provided by the data access control function network element; Based on the data security policies supported by the data service provider network element and the data security policies stored locally by the data access control function network element, configure data security policies for the data services provided by the data service provider network element.

[0027] In some embodiments, the method further includes: Send the data security policy configured for the data service provided by the data service provider network element to the data service requesting network element; The first parameter sent by the network element requesting the data service is obtained; the first parameter is the parameter of the data access control algorithm corresponding to the data security policy configured for the data service provided by the network element providing the data service; the first parameter is used for data access control.

[0028] In some embodiments, the method further includes: Send the first parameter to the data access control function network element; Obtain the second parameter generated based on the first parameter sent by the data access control function network element; The second parameter is sent to the data service requester network element; the second parameter is used for data access control.

[0029] In some embodiments, the method further includes: A data collection instruction message is sent to the network element of the data service provider; the data collection instruction message contains instruction information of the target data service, the target data security policy configured for the target data service, the target data access control algorithm corresponding to the target data security policy, and the first parameter of the target data access control algorithm.

[0030] In some embodiments, the method further includes: Obtain the data service request message for the target data sent by the network element that is requesting the data service; A data service response message is sent to the network element that requests the data service; the data service response message contains target data security policy information; the target data security policy information is used to indicate the target data security policy configured for the target data service.

[0031] In some embodiments, the data access control algorithm includes one or more of the following algorithms: Proxy re-encryption access control algorithm; Ciphertext policy attribute-based encryption algorithm.

[0032] In some embodiments, the data security policy information includes one or more of the following: Data security policy name; List of data security policy names; Data security policy identifier; List of data security policy identifiers.

[0033] Fourthly, this application provides a data service provider network element, including a memory, a transceiver, and a processor; A memory for storing computer programs; a transceiver for sending and receiving data under the control of the processor; and a processor for reading the computer programs from the memory and executing the data access control method described in the first aspect.

[0034] Fifthly, this application provides a data service requester network element, including a memory, a transceiver, and a processor; A memory for storing computer programs; a transceiver for sending and receiving data under the control of the processor; and a processor for reading the computer programs from the memory and executing the data access control method described in the second aspect above.

[0035] Sixthly, this application provides a data management function network element, including a memory, a transceiver, and a processor; A memory for storing computer programs; a transceiver for sending and receiving data under the control of the processor; and a processor for reading the computer programs from the memory and executing the data access control method described in the third aspect above.

[0036] In a seventh aspect, this application provides a data access control device, comprising: The first sending module is used to send data security policy information; the data security policy information is used to configure data security policies for the data services provided by the network element of the data service provider. The first acquisition module is used to acquire the data security policy configured for the data service provided by the network element of the data service provider; the data security policy corresponds to the data access control algorithm for performing data access control.

[0037] Eighthly, this application provides a data access control device, comprising: The second acquisition module is used to acquire the data security policy configured for the data service provided by the network element of the data service provider; the data security policy corresponds to the data access control algorithm for performing data access control. The second sending module is used to send a first parameter; the first parameter is a parameter of the data access control algorithm corresponding to the data security policy configured for the data service provided by the data service provider network element; the first parameter is used for data access control.

[0038] Ninthly, this application provides a data access control device, comprising: The third acquisition module is used to acquire data security policy information sent by the network element of the data service provider. The configuration module is used to configure a data security policy for the data service provided by the data service provider network element based on the data security policy supported by the data service provider network element; the data security policy corresponds to the data access control algorithm for performing data access control; The third sending module is used to send the data security policy configured for the data service provided by the data service provider network element to the data service provider network element.

[0039] In a tenth aspect, this application also provides a processor-readable storage medium storing a computer program for causing a processor to perform the data access control method described in the first, second, or third aspect as described above.

[0040] Eleventhly, this application also provides a non-transient readable storage medium storing a computer program for causing a processor to execute the data access control method described in the first, second, or third aspects above.

[0041] In a twelfth aspect, this application also provides a computer-readable storage medium storing a computer program for causing a computer to perform the data access control method described in the first, second, or third aspect as described above.

[0042] In a thirteenth aspect, this application also provides a communication device that stores a computer program for causing the communication device to perform the data access control method described in the first, second, or third aspect above.

[0043] In a fourteenth aspect, this application also provides a chip product storing a computer program for causing the chip product to perform the data access control method described in the first, second, or third aspect above.

[0044] The data access control method and apparatus provided in this application allow data service providers to negotiate data security policies with the network based on the data services they provide. When providing data services, they can process data according to the data access control algorithm corresponding to the data security policy, thereby achieving fine-grained access control for subsequent data requesters and improving data security. Attached Figure Description

[0045] To more clearly illustrate the technical solutions in the embodiments or related technologies of this application, the accompanying drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the accompanying drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0046] Figure 1 This is one of the flowcharts illustrating the data access control method provided in the embodiments of this application; Figure 2 This is a schematic diagram of the system architecture provided in the embodiments of this application; Figure 3 This is one of the data access control signaling interaction diagrams provided in the embodiments of this application; Figure 4 This is the second schematic diagram of data access control signaling interaction provided in the embodiments of this application; Figure 5 This is a schematic diagram of the proxy re-encryption access control algorithm provided in an embodiment of this application; Figure 6 This is the second schematic diagram of data access control signaling interaction provided in the embodiments of this application; Figure 7 This is a second schematic flowchart of the data access control method provided in the embodiments of this application; Figure 8 This is the third flowchart illustrating the data access control method provided in the embodiments of this application; Figure 9 This is a schematic diagram of the structure of the network element of the data service provider provided in the embodiments of this application; Figure 10 This is a schematic diagram of the structure of the data service requester network element provided in the embodiments of this application; Figure 11 This is a schematic diagram of the structure of the data management function network element provided in the embodiments of this application; Figure 12 This is one of the structural schematic diagrams of the data access control device provided in the embodiments of this application; Figure 13 This is a second schematic diagram of the structure of the data access control device provided in the embodiments of this application; Figure 14This is the third schematic diagram of the data access control device provided in the embodiments of this application. Detailed Implementation

[0047] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.

[0048] Figure 1 This is one of the flowcharts illustrating the data access control method provided in the embodiments of this application, such as... Figure 1 As shown in the figure, this application provides a data access control method, the execution subject of which is a data service provider network element, and the method includes: Step 101: The data service provider network element sends data security policy information; the data security policy information is used to configure data security policies for the data services provided by the data service provider network element.

[0049] Specifically Figure 2 This is a schematic diagram of the system architecture provided in the embodiments of this application, such as... Figure 2 As shown, the Data Processing Function (DPF) is a logical function in a data plane system that uses data plane services. It can reside in the User Equipment (UE), Radio Access Network (RAN), or core network. DPF network elements can be categorized based on their role in a data plane service: Service Requester (DPF-SR) and Service Provider (DPF-SP).

[0050] The Data Management Function (DMF) is a core function of the data plane system, located within the core network. It is responsible for registering DPF network elements / functional entities and Data Storage Function (DSF) network elements / functional entities within the data plane system, and manages the connections between DPF-SR and DPF-SP network elements. DPF network elements in the data plane system must register with the DMF network element to use the services provided by the data plane system.

[0051] The DSF (Data Flow Separator) is responsible for data storage in the data plane. The DPF-SP (Data Flow Separator-SP) network element can provide data to the DSF network element for storage, including user-related network data, sensing data, artificial intelligence (AI) data, computing power data, etc.

[0052] Data access control function network elements (e.g., data plane security module (DSM)) are used to provide data security policies to various network elements. The DSM can be embedded in the DMF network element and called by the DMF network element itself, or it can be embedded in other security network elements and called through the interface between network elements, or it can be an independent network element. Figure 2 In this system, the DSM is used as an independent network element to provide data access control policies to the DMF network element, meaning that the data access control function network element and the DMF network element are separate.

[0053] Figure 3 This is one of the data access control signaling interaction diagrams provided in the embodiments of this application, such as... Figure 3 As shown, the data access control mechanism provided in this application includes four stages: data security policy negotiation, data security parameter negotiation, data collection, and data request.

[0054] First, the DPF-SP network element negotiates data security policies with the DMF network element during the registration phase.

[0055] Then, during the registration phase, the DPF-SR network element negotiates data security parameters with the DMF network element.

[0056] During the data acquisition phase, the DPF-SP network element encrypts the data using the data access control algorithm corresponding to the data security policy when acquiring data.

[0057] The data access control algorithm in this application includes one or more of the following algorithms: Proxy re-encryption access control algorithm; Ciphertext policy attribute-based encryption algorithm.

[0058] During the data request phase, only DPF-SR network elements that meet the access control information can decrypt the ciphertext during the data request phase, thereby achieving fine-grained access control over DPF-SR network elements.

[0059] like Figure 3As shown, before the DPF-SP network element sends data security policy information to the DMF network element, the DPF-SP network element sends a service capability registration message to the DMF network element. This message may contain parameters such as the entity ID, entity type, and provided services IDs of the DPF-SP network element.

[0060] In this application embodiment, the data security policy information includes one or more of the following: Data security policy name; List of data security policy names; Data security policy identifier; List of data security policy identifiers.

[0061] like Figure 3 As shown, the data security policy information sent by the DPF-SP network element to the DMF network element mainly includes the data security capability information of the DPF-SP network element. This data security capability information may include the entity identifier, entity type, and a list of data security policy IDs it holds. The data security policy list contains one or more Data Security Policy IDs that identify the data security policies supported by the DPF-SP network element. Each Data Security Policy ID indicates a data security policy, and each data security policy corresponds to a data access control algorithm.

[0062] Step 102: The data service provider network element obtains the data security policy configured for the data service provided by the data service provider network element; the data security policy corresponds to the data access control algorithm that performs data access control.

[0063] Specifically, after the DPF-SP network element sends data security policy information, it retrieves the data security policy configured for the data services provided to the DPF-SP network element. The data security policy corresponds to the data access control algorithm. The data access control algorithm is used for data access control.

[0064] In some embodiments, such as Figure 3 As shown, when the data access control function network element and the DMF network element are separate, the data service provider network element sends data security policy information, including: Data service provider network elements send data security policy information to data management function network elements; The network element receiving the data service provides the data security policy configured for the data service provided by the network element, including: The data security policy configured by the data service provider network element for the data service provided by the data service provider network element is based on the data security policy supported by the data service provider network element and the data security policy locally stored by the data access control function network element.

[0065] DMF network elements obtain data security policy information sent by network elements from data service providers; DMF network elements configure data security policies for data services provided by data service provider network elements based on the data security policies supported by the data service provider network elements; the data security policies correspond to the data access control algorithms that perform data access control. DMF network elements send data security policies configured for the data services provided by data service providers to data service provider network elements.

[0066] DMF network elements configure data security policies for data services provided by data service provider network elements based on the data security policies supported by the data service provider network elements, including: DMF network element acquires data access control function; network element provides data access control function; network element locally stored data security policy. DMF network elements configure data security policies for data services provided by data service provider network elements based on the data security policies supported by the data service provider network elements and the data security policies stored locally by the data access control function network elements.

[0067] For example, such as Figure 3 As shown, the DMF network element can also send a request message to the DSM to query the data security policy of the DPF-SP network element. This message can carry parameters such as Entity ID, Entity type, and Provided Services IDs. The DSM returns a response message to the DMF network element containing data security policies. This message can carry parameters such as Entity ID, Entity type, Provided Services IDs, and Data Security Policy ID List. The Data Security Policy ID List carried in this message is a list of data security policies stored on the network side (DSM). Based on the data security policy list returned by the DSM and the security policy list sent by the DPF-SP network element, the DMF network element returns a Data Security Policy ID (with configured (specified) Provided Services IDs) to the DPF-SP network element.

[0068] In some embodiments, the DSM can be embedded in the DMF network element and invoked by the DMF network element itself, that is, the data access control function network element and the DMF network element are a single network element.

[0069] Data service provider network elements send data security policy information, including: Data service provider network elements send data security policy information to data access control function network elements; The network element receiving the data service provides the data security policy configured for the data service provided by the network element, including: The data service provider network element obtains the data security policy configured by the data access control function network element for the data service provided by the data service provider network element; the data security policy configured for the data service provided by the data service provider network element is based on the data security policy supported by the data service provider network element and the data security policy configured locally by the data access control function network element.

[0070] DMF network elements obtain data security policy information sent by network elements from data service providers; DMF network elements configure data security policies for data services provided by data service provider network elements based on the data security policies supported by the data service provider network elements; the data security policies correspond to the data access control algorithms that perform data access control. DMF network elements send data security policies configured for the data services provided by data service providers to data service provider network elements.

[0071] DMF network elements configure data security policies for data services provided by data service provider network elements based on the data security policies supported by the data service provider network elements, including: The Data Access Control Function (DMF) network element configures data security policies for the data services provided by the data service provider network element based on the data security policies supported by the data service provider network element and the data security policies stored locally on the DMF network element.

[0072] For example, the DSM returns DataSecurity Policy IDs, which configure (specify) Provided Services IDs, to the DPF-SP network element based on the list of data security policies stored locally and the list of security policies sent by the DPF-SP network element.

[0073] The data access control method provided in this application allows data service providers to negotiate data security policies with the network based on the data services they provide. When providing data services, they can process data according to the data access control algorithm corresponding to the data security policy, thereby achieving fine-grained access control for subsequent data requesters and improving data security.

[0074] During the data security parameter negotiation phase, the DPF-SR network element first sends a service capability registration message to the DMF network element. This message contains parameters such as Entity ID, Entity type, Entity address, and Requested Services IDs.

[0075] In some embodiments, the data service requesting network element obtains the data security policy configured for the data service provided by the data service provider network element; the data security policy corresponds to the data access control algorithm that performs data access control.

[0076] Specifically, after receiving the service capability registration message sent by the DPF-SR network element, the DMF network element sends a data security parameter request message to the DPF-SR network element based on the Data Security Policy IDs supported by the DPF-SP network element, the Data Security Policy IDs of the Requested Services IDs stored locally by the DMF (Data Access Control Function Network Element), or the Data Security Policy IDs of the Requested Services IDs specified by the DSM. This message carries the Requested Services IDs and Data Security Policy IDs parameters.

[0077] In some embodiments, obtaining the data security policy configured for the data service provided by the data service provider network element includes: The data security policy configured by the data management function network element for the data service provided by the data service provider network element is based on the data security policy supported by the data service provider network element and the data security policy configured locally by the data access control function network element.

[0078] Specifically, such as Figure 3As shown, when the data access control function network element and the DMF network element are set up separately, the DPF-SR network element first sends a service capability registration message to the DMF network element. This message contains parameters such as Entity ID, Entity type, Entity address, and Requested Services IDs.

[0079] After receiving the service capability registration message from the DPF-SR network element, the DMF network element sends a data security policy query request message to the DSM. This message carries parameters such as Entity ID, Entity type, and Requested Services IDs.

[0080] The DSM returns a Data Security Policy Query Response Message to the DMF network element, which indicates the policy identifier of the Data Security Policy IDs that specifies the RequestedServices IDs.

[0081] Data Security Policy IDs indicate the data security policy used by Provided Services IDs. The data security policy contains (corresponding to) data access control algorithms. Different data access control algorithms require the DPF-SR network element to provide different data security parameters (Input_Security policy Parameters).

[0082] After receiving the data security policy response from the DSM, the DMF network element sends a data security parameter request message to the DPF-SR network element based on the Data Security Policy IDs of the data security policies supported by the DPF-SP network element and the Data Security Policy IDs of the data security policies specified by the DSM. This message carries the Requested Services IDs and Data Security Policy IDs parameters.

[0083] The DPF-SR network element obtains the data security policy (Data Security Policy IDs) configured by the DMF network element for the data services provided by the DPF-SP network element.

[0084] In some embodiments, where the data access control function network element and the DMF network element are co-located, the data service requesting network element obtains the data security policy configured for the data service provided by the data service provider network element, including: The data service requesting network element obtains the data security policy configured by the data access control function network element for the data service provided by the data service provider network element; the data security policy configured for the data service provided by the data service provider network element is based on the data security policy supported by the data service provider network element and the data security policy configured locally by the data access control function network element.

[0085] In some embodiments, the data service requesting network element sends a first parameter; the first parameter is a parameter of the data access control algorithm corresponding to the data security policy configured for the data service provided by the data service provider network element; the first parameter is used for data access control.

[0086] Specifically, after the DMF network element sends the data security policy configured for the data service provided by the data service provider network element to the data service requesting network element, the data service requesting network element sends the first parameter of the data access control algorithm corresponding to the data security policy configured for the data service provided by the data service provider network element to the DMF network element (data access control function network element), and the DMF network element receives the first parameter sent by the data service requesting network element.

[0087] like Figure 3 As shown, the DPF-SR network element returns a data security parameter response message to the DMF network element. This message carries the data security parameters Input_Security policy Parameters requested by the DMF network element. This message may also carry DataSecurity Policy IDs.

[0088] For example, the Input_Securitypolicy Parameters and Data Security Policy IDs included in the data security parameter response returned by the DPF-SR network element to the DMF network element correspond one-to-one.

[0089] The first parameter can be the public key of the data access control algorithm.

[0090] In some embodiments, when the data access control algorithm corresponding to the data security policy is a ciphertext policy attribute-based encryption algorithm, the first parameter provided by the data service requester network element needs to be further processed (reprocessed).

[0091] Specifically, when the data access control function network element and the DMF network element are separate, the method also includes: The DMF network element sends the first parameter to the data access control function network element; DMF network elements acquire the second parameter generated based on the first parameter sent by the network element for the data access control function; The DMF network element sends the second parameter to the data service requesting network element; the second parameter is used for data access control.

[0092] like Figure 3 As shown, the DMF network element returns a data security parameter response message to the DSM. This message contains DataSecurity Policy IDs and Input_Security policy Parameters (first parameter). The DSM further processes the Input_Security policy Parameters according to the instructions of the DataSecurity Policy IDs and feeds back the processed Input_Security policy Parameters (second parameter) to the DMF network element.

[0093] When the data access control function network element and the DMF network element are co-located, the data access control function network element generates a second parameter based on the first parameter and sends the second parameter to the data service requesting network element; the second parameter is used for data access control.

[0094] Finally, the DMF network element sends a service capability registration response message to the DPF-SR network element. This message indicates the DPF-SR network element's Entity ID, Entity type, Entity address, Requested Services IDs, and the Input_Security policy Parameters corresponding to the Requested Services IDs.

[0095] The data access control method provided in this application allows the data service requester to indicate data security parameters to the data security policy. When requesting data, the data provided by the data service provider, after being processed by the data access control algorithm corresponding to the data security policy, can be decrypted according to the data security parameters. This enables fine-grained access control for the data requester and improves data security.

[0096] During the data acquisition phase, the DPF-SP network element is responsible for data acquisition and uses the data security parameters of the data access control algorithm corresponding to the data security policy to encrypt the acquired data, and then stores the processed data in the data storage function network element.

[0097] In some embodiments, the method further includes: The data management function network element sends a data collection instruction message to the data service provider network element; the data collection instruction message contains the instruction information of the target data service, the target data security policy configured for the target data service, the target data access control algorithm corresponding to the target data security policy, and the first parameter of the target data access control algorithm.

[0098] In some embodiments, the method further includes: The data service provider network element obtains the data collection instruction message sent by the data management function network element; the data collection instruction message contains the instruction information of the target data service, the target data security policy configured for the target data service, the target data access control algorithm corresponding to the target data security policy, and the first parameter of the target data access control algorithm; Data service provider network elements collect target data; The data service provider, Network Element, encrypts the target data based on the target data access control algorithm and the first parameter of the target data access control algorithm; The data service provider network element sends the encrypted target data to the target data storage function network element indicated by the data acquisition instruction message.

[0099] Specifically, the DMF network element can initiate data collection from the DPF-SP network element.

[0100] like Figure 3 As shown, the DMF network element initiates a data acquisition task, sending a data acquisition request message to the DPF-SP network element. This message contains the Provided Services ID related to the data acquisition task, the Data Security Policy ID required for data encryption and access control, the Input_Security policyParameters, and all Entity IDs and Entity addresses contained in the data channel to be transmitted after data acquisition. The Entity ID and Entity address are used to identify the DSF network element.

[0101] The DPF-SP network element encrypts the collected data based on the received Data Security Policy ID and Input_Security policyParameters, generates ciphertext M, and sends the generated ciphertext M to the DSF network element, which stores the ciphertext M.

[0102] In this embodiment, a negotiated data access control algorithm is used to encrypt the target data collected by the network element of the data service provider, and the network element of the data service requester uses the negotiated data access control algorithm to decrypt the target data, thereby realizing fine-grained access control of the data and improving the security of data access control.

[0103] In some embodiments, the method further includes: The data service provider network element generates access control information based on the target data access control algorithm and the first parameter of the target data access control algorithm; The data service provider network element sends access control information to the target data storage function network element indicated by the data collection instruction message.

[0104] Specifically, in this embodiment of the application, when the data access control algorithm corresponding to the data security policy is the proxy re-encryption access control algorithm, the data service provider network element also needs to generate a proxy re-encryption key (access control information) based on the public key (first parameter) of the proxy re-encryption access control algorithm, and send the generated proxy re-encryption key to the DSF network element indicated by the data collection instruction message, and the DSF network element stores the proxy re-encryption key.

[0105] In this embodiment, a proxy re-encryption access control algorithm is used to encrypt the target data collected by the network element of the data service provider, and the network element of the data service requester uses the proxy re-encryption access control algorithm to decrypt the target data, thereby realizing fine-grained access control of the data and improving the security of data access control.

[0106] During the data request phase, the DPF-SR network element downloads the encrypted ciphertext and decrypts it using a negotiated data access control algorithm. The DPF-SR network element can only successfully decrypt the ciphertext using compliant key materials, thereby achieving fine-grained access control over the DPF-SR network element.

[0107] In some embodiments, the data service requesting network element initiates a data service request message to the DMF network element, the message carrying indication information of the target data.

[0108] The DMF network element obtains the data service request message for the target data sent by the data service requesting network element, and sends a data service response message to the data service requesting network element; the data service response message contains target data security policy information; the target data security policy information is used to indicate the target data security policy configured for the target data service.

[0109] The data service requesting network element obtains the data service response message for the data service request message for the target data, and downloads the ciphertext of the target data from the target data storage function network element indicated by the data service response message. Then, it decrypts the ciphertext based on the decryption material corresponding to the target data security policy indicated by the local target data security policy information to obtain the plaintext of the target data.

[0110] like Figure 3 As shown, the DPF-SR network element initiates a data service request to the DMF network element, carrying the requested service ID. The DMF network element returns a data service response, indicating the entity ID and entity address of the data storage entity, as well as the data security policy ID. The DPF-SR network element requests the corresponding entity based on the entity ID and entity address, and downloads the ciphertext M. The DPF-SR network element decrypts the ciphertext using its stored key materials; successful decryption yields the plaintext data; unsuccessful decryption results in the plaintext being unobtainable.

[0111] In this embodiment of the application, the decryption material stored locally on the network element of the data service requester can be a private key.

[0112] In some embodiments, the method further includes: The network element requesting the data service downloads access control information from the target data storage function network element indicated by the data service response message. The network element requesting the data service decrypts the ciphertext based on the decryption materials corresponding to the target data security policy indicated by the local target data security policy information, including: The network element requesting the data service decrypts the ciphertext based on the decryption materials corresponding to the target data security policy indicated by the access control information and the local target data security policy information.

[0113] Specifically, in this embodiment of the application, when the data access control algorithm corresponding to the data security policy is the proxy re-encryption access control algorithm, the data service requesting network element also needs to download the proxy re-encryption key (access control information) from the target data storage function network element indicated by the data service response message. When decrypting the ciphertext, it uses its own private key and the proxy re-encryption key to decrypt the ciphertext and obtain the plaintext.

[0114] In this embodiment, a proxy re-encryption access control algorithm is used to encrypt the target data collected by the network element of the data service provider, and the network element of the data service requester uses the proxy re-encryption access control algorithm to decrypt the target data, thereby realizing fine-grained access control of the data and improving the security of data access control.

[0115] The following example, using a terminal requesting data encrypted using a proxy re-encryption access control algorithm, further illustrates the above method: Figure 4 This is the second schematic diagram of data access control signaling interaction provided in the embodiments of this application. Figure 5 This is a schematic diagram of the proxy re-encryption access control algorithm provided in an embodiment of this application, as shown below. Figure 4 and 5 As shown, data access control includes the following steps: The data security policy negotiation phase between the UE and the DMF network element (omitted in the diagram): Step 00a: The UE sends a service capability registration message to the DMF network element. The message includes the DPF-SP network element's Entity ID, Entity type, and Provided ServicesIDs.

[0116] Step 00b: The UE sends its data security capabilities to the DMF network element, which includes the parameter Data SecurityPolicy ID List. The Data Security Policy ID List is a list of data security policies held by the UE. Each Data Security Policy ID indicates a data security policy, and each data security policy corresponds to a data access control algorithm.

[0117] Step 00c: Based on the security policy list sent by the UE, the DMF network element returns the Data Security Policy IDs (specifying Provided ServicesIDs) to the UE.

[0118] Data security parameter negotiation phase between UE and DMF network element: Step 0a: The UE sends a service capability registration message to the DMF network element, which carries parameters such as Subscription Concealed Identifier (SUCI), Entity type, UE address, and RequestedServices IDs. The Access and Mobility Management Function (AMF) network element forwards the message with parameters such as Subscription Permanent Identifier (SUPI), Entity type, UE address, and RequestedServices IDs.

[0119] Step 0b: After receiving the service capability registration message sent by the UE, the DMF network element sends a data security policy query request to the DSM, carrying the parameters SUPI, Entity type, and Requested Services IDs.

[0120] Step 0c: The DSM returns a data security policy query response to the DMF network element. The response indicates the Data Security Policy ID of the data security policy specified in the RequestedServices IDs, and the ID indicates the proxy re-encryption access control algorithm.

[0121] Step 0d: After receiving the data security policy response sent by the DSM, the DMF network element sends a data security parameter request to the UE according to the Data SecurityPolicy ID, carrying the parameters Requested Services IDs and Data Security Policy ID, where the Data Security Policy ID indicates the proxy re-encryption access control algorithm.

[0122] Step 0e: The UE returns data security parameters to the DMF network element, carrying the data security parameters provided by the DMF network element, namely Provided Services IDs and Input_Security policy Parameters. The Data SecurityPolicy ID indicates the proxy re-encryption access control algorithm, and the Input_Security policy Parameters indicates the UE's public key.

[0123] Data collection phase: Step 1a: The UE initiates a data collection request to the DMF network element, carrying the parameter Requested Services IDs.

[0124] Step 1b: The DMF network element initiates a data collection request to the DPF-SP network element, carrying the parameters Provided ServicesID, Data Security Policy ID, Input_Security policy Parameters, DSF ID, and DSFaddress. The Data Security Policy ID indicates the proxy re-encryption access control algorithm, and the Input_Security policy Parameters indicate the UE's public key.

[0125] Step 1c: Generate a proxy re-encryption key based on the UE public key, and encrypt the data based on the public key of the DSF-SP network element to form ciphertext M.

[0126] Step 1d: The DSF-SP network element sends the encrypted ciphertext M and the agent re-encryption key to the DSF network element.

[0127] Step 1e: The DSF network element stores the ciphertext M and the agent's re-encryption key.

[0128] Data request phase: Step 2a: The DMF network element returns a data acquisition service request response to the UE, carrying the parameters DSF ID and DSFaddress, as well as the Data Security Policy ID, where the Data Security Policy ID indicates the proxy re-encryption access control algorithm.

[0129] Step 2b: The UE downloads the ciphertext M and the proxy re-encryption key stored in the DSF network element based on the DSF ID and DSF address.

[0130] Step 2c: The UE decrypts the ciphertext M using its own private key k and the proxy re-encryption key. Only if the access control information in the ciphertext is correct can the ciphertext be decrypted, thereby realizing access control over the UE.

[0131] The following example, using a core network element / RAN requesting data encrypted using a ciphertext policy attribute-based encryption algorithm, further illustrates the above method: Figure 6 This is the second schematic diagram of data access control signaling interaction provided in the embodiments of this application, such as... Figure 6 As shown, data access control includes the following steps: Data security policy negotiation between DPF-SP network element and DMF network element: Step 0a: The DPF-SP network element sends a service capability registration message to the DMF network element. The message includes the DPF-SP network element's Entity ID, Entity type, and ProvidedServices IDs.

[0132] Step 0b: The DPF-SP network element sends its data security capabilities to the DMF network element, carrying the parameter Data Security Policy ID List. The Data Security Policy ID List is a list of data security policies held by the DPF-SP network element. Each Data Security Policy ID indicates a data security policy, and each data security policy corresponds to a data access control algorithm.

[0133] Step 0c: The DMF network element sends a request to the DSM to query the data security policy of the DPF-SP network element, carrying the parameters Entity ID, Entity type, and Provided Services IDs.

[0134] Step 0d: DSM returns the security policy list of DPF-SP network elements, carrying the parameters Entity ID, Entity type, Provided Services IDs, and Data Security Policy ID List. The Data Security Policy ID List carried in this message is the list of data security policies stored on the network side.

[0135] Step 0e: Based on the data security policy list returned by the DSM and the security policy list sent by the DPF-SP network element, the DMF network element returns a Data Security Policy ID (specifying Provided Services IDs) to the DPF-SP network element. In this embodiment, the Data Security Policy ID indicates the encryption algorithm and access policy of the encrypted policy attribute.

[0136] Data security parameter negotiation between Core Network (CN) Network Function (NF) / RAN and DMF network elements: Step 0f: The CN NF / RAN sends a service capability registration message to the DMF network element, which includes the parameters Entity ID, Entity type, Entity address, and Requested Services IDs.

[0137] Step 0g: After receiving the service capability registration message sent by CN NF / RAN, the DMF network element sends a data security policy query request to DSM, carrying the parameters Entity ID, Entity type, and Requested Services IDs.

[0138] Step 0h: The DSM returns a data security policy query response to the DMF network element. The response indicates the policy identifier (Data Security Policy ID) of the data security policy specified in the RequestedServices IDs, where the Data SecurityPolicy ID indicates the encryption algorithm for the encrypted policy attribute.

[0139] Step 0i: After receiving the data security policy response sent by the DSM, the DMF network element sends a data security parameter request to the DPF-SR network element according to the Data SecurityPolicy ID, carrying the parameters Requested ServicesIDs and Data Security Policy ID, where Data Security Policy ID indicates the encryption algorithm of the encrypted policy attribute.

[0140] Step 0j: The CN NF / RAN returns data security parameters to the DMF network element, carrying the data security parameters requested by the DMF network element, namely Data Security Policy IDs and Input_Security policy Parameters, where Input_Security policy Parameters indicates the CN NF / RAN attribute set.

[0141] Step 0k: The DMF network element returns a data security parameter response to the DSM and forwards (Data Security Policy ID, Input_Security policy Parameters). The DSM generates a CN NF / RAN private key based on the ciphertext policy attribute encryption algorithm, the CN NF / RAN attribute set, and the system public key, and feeds back the generated CN NF / RAN private key, i.e., Input_Securitypolicy Parameters, to the DMF network element.

[0142] Step 01: The DMF network element sends a service capability registration response message to the CN NF / RAN. The message carries all parameters (Entity ID, Entity type, Entity address, Requested Services IDs, Input_Security policy Parameters), where Input_Security policy Parameters indicates the CN NF / RAN private key.

[0143] Data acquisition phase initiated by DMF network element to DPF-SP network element: Step 1a: The CN NF / RAN initiates a data collection request to the DMF network element, carrying the parameter Requested ServicesIDs.

[0144] Step 1b: The DMF network element initiates a data collection request to the DPF-SP network element, carrying the parameters Provided ServicesID, Data Security Policy ID, Input_Security policy Parameters, DSF ID, and DSF address. The Data Security Policy ID indicates the encryption algorithm for the encrypted policy attribute, and the Input_Securitypolicy Parameters indicates the system public key.

[0145] Step 1c: The DPF-SP network element encrypts the data to form ciphertext M based on the access policy system public key received in step 0d.

[0146] Step 1d: The DSF-SP network element sends the encrypted ciphertext M to the DSF network element.

[0147] Step 1e: The DSF network element stores the ciphertext M.

[0148] Data request phase initiated by CN NF / RAN: Step 2a: The DMF network element returns a data acquisition service request response to the CN NF / RAN, carrying the parameters DSF ID and DSFaddress, as well as the Data Security Policy ID, where the Data Security Policy ID indicates the encryption algorithm of the encrypted policy attribute.

[0149] Step 2b: The UE downloads the ciphertext M stored in the DSF network element based on the DSF ID and DSF address.

[0150] Step 2c: CN NF / RAN decrypts ciphertext M based on the CN NF / RAN private key obtained in step 0l. Only ciphertext that matches the access control information in the ciphertext can be decrypted, thereby realizing access control over CN NF / RAN.

[0151] The access control mechanism provided in this application ensures data security. Even if the data storage terminal is untrusted, the data is encrypted by the data provider, preventing the data storage segment from abusing the data and thus guaranteeing data security.

[0152] Figure 7 This is a second flowchart illustrating the data access control method provided in the embodiments of this application, as shown below. Figure 7 As shown in the figure, this application provides a data access control method, the execution subject of which is a data service requesting network element, and the method includes: Step 701: Obtain the data security policy configured for the data service provided by the network element of the data service provider; the data security policy corresponds to the data access control algorithm for performing data access control; Step 702: Send the first parameter; the first parameter is the parameter of the data access control algorithm corresponding to the data security policy configured for the data service provided by the data service provider network element; the first parameter is used for data access control.

[0153] In some embodiments, obtaining the data security policy configured for the data service provided by the data service provider network element includes: The data security policy configured by the data access control function network element for the data service provided by the data service provider network element is obtained; the data security policy configured for the data service provided by the data service provider network element is based on the data security policy supported by the data service provider network element and the data security policy configured locally stored by the data access control function network element.

[0154] In some embodiments, the method further includes: Obtain a data service response message for the data service request message targeting the target data; the data service response message contains target data security policy information. Download the encrypted target data from the target data storage function network element indicated by the data service response message; The ciphertext is decrypted using the decryption material corresponding to the target data security policy indicated by the local target data security policy information, to obtain the plaintext of the target data.

[0155] In some embodiments, the method further includes: Download access control information from the target data storage function network element indicated by the data service response message; The decryption material corresponding to the target data security policy indicated by the local target data security policy information decrypts the ciphertext, including: The ciphertext is decrypted based on the decryption material corresponding to the target data security policy indicated by the access control information and the local target data security policy information.

[0156] In some embodiments, obtaining the data security policy configured for the data service provided by the data service provider network element includes: The data security policy configured by the data management function network element for the data service provided by the data service provider network element is obtained; the data security policy configured for the data service provided by the data service provider network element is based on the data security policy supported by the data service provider network element and the data security policy locally stored by the data access control function network element.

[0157] In some embodiments, the method further includes: Obtain a data service response message for the data service request message targeting the target data; the data service response message contains target data security policy information. Download the encrypted target data from the target data storage function network element indicated by the data service response message; The ciphertext is decrypted using the decryption material corresponding to the target data security policy indicated by the local target data security policy information, to obtain the plaintext of the target data.

[0158] In some embodiments, the method further includes: Download access control information from the target data storage function network element indicated by the data service response message; The decryption material corresponding to the target data security policy indicated by the local target data security policy information decrypts the ciphertext, including: The ciphertext is decrypted based on the decryption material corresponding to the target data security policy indicated by the access control information and the local target data security policy information.

[0159] In some embodiments, the data access control algorithm includes one or more of the following algorithms: Proxy re-encryption access control algorithm; Ciphertext policy attribute-based encryption algorithm.

[0160] In some embodiments, the information used to instruct the data security policy configured for the data service provided to the data service provider network element includes one or more of the following: Data security policy name; Data security policy identifier.

[0161] Specifically, the data access control method provided in this application embodiment can refer to the above-described data access control method embodiment where the execution subject is a data service requesting network element, and can achieve the same technical effect. Here, the parts and beneficial effects that are the same as those in the corresponding method embodiments described above will not be described in detail.

[0162] Figure 8 This is the third flowchart illustrating the data access control method provided in this application embodiment. Figure 8 As shown in the figure, this application provides a data access control method, the execution subject of which is a data management function network element, and the method includes: Step 801: Obtain data security policy information sent by the network element of the data service provider; Step 802: Based on the data security policy supported by the data service provider network element, configure a data security policy for the data service provided by the data service provider network element; the data security policy corresponds to the data access control algorithm for performing data access control; Step 803: Send the data security policy configured for the data service provided by the data service provider network element to the data service provider network element.

[0163] In some embodiments, configuring a data security policy for the data service provided by the data service provider network element based on the data security policy supported by the data service provider network element includes: Based on the data security policies supported by the data service provider network element and the data security policies stored locally by the data access control function network element, configure data security policies for the data services provided by the data service provider network element.

[0164] In some embodiments, configuring a data security policy for the data service provided by the data service provider network element based on the data security policy supported by the data service provider network element includes: Obtain the data security policy stored locally by the data access control function network element provided by the data access control function network element; Based on the data security policies supported by the data service provider network element and the data security policies stored locally by the data access control function network element, configure data security policies for the data services provided by the data service provider network element.

[0165] In some embodiments, the method further includes: Send the data security policy configured for the data service provided by the data service provider network element to the data service requesting network element; The first parameter sent by the network element requesting the data service is obtained; the first parameter is the parameter of the data access control algorithm corresponding to the data security policy configured for the data service provided by the network element providing the data service; the first parameter is used for data access control.

[0166] In some embodiments, the method further includes: Send the first parameter to the data access control function network element; Obtain the second parameter generated based on the first parameter sent by the data access control function network element; The second parameter is sent to the data service requester network element; the second parameter is used for data access control.

[0167] In some embodiments, the method further includes: A data collection instruction message is sent to the network element of the data service provider; the data collection instruction message contains instruction information of the target data service, the target data security policy configured for the target data service, the target data access control algorithm corresponding to the target data security policy, and the first parameter of the target data access control algorithm.

[0168] In some embodiments, the method further includes: Obtain the data service request message for the target data sent by the network element that is requesting the data service; A data service response message is sent to the network element that requests the data service; the data service response message contains target data security policy information; the target data security policy information is used to indicate the target data security policy configured for the target data service.

[0169] In some embodiments, the data access control algorithm includes one or more of the following algorithms: Proxy re-encryption access control algorithm; Ciphertext policy attribute-based encryption algorithm.

[0170] In some embodiments, the data security policy information includes one or more of the following: Data security policy name; List of data security policy names; Data security policy identifier; List of data security policy identifiers.

[0171] Specifically, the data access control method provided in this application embodiment can refer to the above-described data access control method embodiment where the execution subject is a data service requesting network element, and can achieve the same technical effect. Here, the parts and beneficial effects that are the same as those in the corresponding method embodiments described above will not be described in detail.

[0172] Figure 9 This is a schematic diagram of the structure of the data service provider network element provided in the embodiments of this application, such as... Figure 9 As shown, it includes a memory 920, a transceiver 900, and a processor 910, wherein: The memory 920 is used to store computer programs; the transceiver 900 is used to send and receive data under the control of the processor 910; the processor 910 is used to read the computer program in the memory 920 and perform the following operations: Send data security policy information; the data security policy information is used to configure data security policies for the data services provided by the network element of the data service provider. Obtain the data security policy configured for the data service provided by the network element of the data service provider; the data security policy corresponds to the data access control algorithm for performing data access control.

[0173] Among them, Figure 9 In this context, the bus architecture can include any number of interconnected buses and bridges, specifically linking various circuits together, represented by one or more processors (processor 910) and memory (memory 920). The bus architecture can also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface. The transceiver 900 can be multiple elements, including transmitters and receivers, providing units for communicating with various other devices over transmission media, including wireless channels, wired channels, optical fibers, etc. The processor 910 is responsible for managing the bus architecture and general processing, and the memory 920 can store data used by the processor 910 during operation.

[0174] The processor 910 can be a central processing unit (CPU), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or a complex programmable logic device (CPLD). The processor can also adopt a multi-core architecture.

[0175] In some embodiments, the transmission of data security policy information includes: Send data security policy information to the data access control function network element; The step of obtaining the data security policy configured for the data service provided by the network element of the data service provider includes: The data security policy configured by the data access control function network element for the data service provided by the data service provider network element is obtained; the data security policy configured for the data service provided by the data service provider network element is based on the data security policy supported by the data service provider network element and the data security policy configured locally stored by the data access control function network element.

[0176] In some embodiments, the processor is further configured to read a computer program from the memory and perform the following operations: The data collection instruction message sent by the data management function network element is obtained; the data collection instruction message contains instruction information of the target data service, the target data security policy configured for the target data service, the target data access control algorithm corresponding to the target data security policy, and the first parameter of the target data access control algorithm. Collect target data; The target data is encrypted based on the target data access control algorithm and the first parameter of the target data access control algorithm; The encrypted target data is sent to the target data storage function network element indicated by the data acquisition instruction message.

[0177] In some embodiments, the processor is further configured to read a computer program from the memory and perform the following operations: Access control information is generated based on the target data access control algorithm and the first parameter of the target data access control algorithm; The access control information is sent to the target data storage function network element indicated by the data acquisition instruction message.

[0178] In some embodiments, the transmission of data security policy information includes: Send data security policy information to the data management function network element; The step of obtaining the data security policy configured for the data service provided by the network element of the data service provider includes: The data security policy configured by the data management function network element for the data service provided by the data service provider network element is obtained; the data security policy configured for the data service provided by the data service provider network element is based on the data security policy supported by the data service provider network element and the data security policy locally stored by the data access control function network element.

[0179] In some embodiments, the processor is further configured to read a computer program from the memory and perform the following operations: The data collection instruction message sent by the data management function network element is obtained; the data collection instruction message contains instruction information of the target data service, the target data security policy configured for the target data service, the target data access control algorithm corresponding to the target data security policy, and the first parameter of the target data access control algorithm. Collect target data; The target data is encrypted based on the target data access control algorithm and the first parameter of the target data access control algorithm; The encrypted target data is sent to the target data storage function network element indicated by the data acquisition instruction message.

[0180] In some embodiments, the processor is further configured to read a computer program from the memory and perform the following operations: Access control information is generated based on the target data access control algorithm and the first parameter of the target data access control algorithm; The access control information is sent to the target data storage function network element indicated by the data acquisition instruction message.

[0181] In some embodiments, the data access control algorithm includes one or more of the following algorithms: Proxy re-encryption access control algorithm; Ciphertext policy attribute-based encryption algorithm.

[0182] In some embodiments, the data security policy information includes one or more of the following: Data security policy name; List of data security policy names; Data security policy identifier; List of data security policy identifiers.

[0183] Specifically, the data service provider network element provided in this application embodiment can implement all the method steps implemented by the method embodiment where the execution subject is the data service provider network element, and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.

[0184] Figure 10 This is a schematic diagram of the structure of the data service requester network element provided in the embodiments of this application, such as... Figure 10 As shown, it includes a memory 1020, a transceiver 1000, and a processor 1010, wherein: The memory 1020 is used to store computer programs; the transceiver 1000 is used to send and receive data under the control of the processor 1010; the processor 1010 is used to read the computer program in the memory 1020 and perform the following operations: Obtain the data security policy configured for the data service provided by the network element of the data service provider; the data security policy corresponds to the data access control algorithm for performing data access control. Send the first parameter; the first parameter is the parameter of the data access control algorithm corresponding to the data security policy configured for the data service provided by the data service provider network element; the first parameter is used for data access control.

[0185] Among them, Figure 10 In this context, the bus architecture can include any number of interconnected buses and bridges, specifically linking various circuits together, represented by one or more processors (processor 1010) and memory (memory 1020). The bus architecture can also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface. The transceiver 1000 can be multiple elements, including transmitters and receivers, providing units for communicating with various other devices over transmission media, including wireless channels, wired channels, optical fibers, etc. The processor 1010 is responsible for managing the bus architecture and general processing, and the memory 1020 can store data used by the processor 1010 during operation.

[0186] The processor 1010 can be a central processing unit (CPU), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or a complex programmable logic device (CPLD). The processor can also adopt a multi-core architecture.

[0187] In some embodiments, obtaining the data security policy configured for the data service provided by the data service provider network element includes: The data security policy configured by the data access control function network element for the data service provided by the data service provider network element is obtained; the data security policy configured for the data service provided by the data service provider network element is based on the data security policy supported by the data service provider network element and the data security policy configured locally stored by the data access control function network element.

[0188] In some embodiments, the processor is further configured to read a computer program from the memory and perform the following operations: Obtain a data service response message for the data service request message targeting the target data; the data service response message contains target data security policy information. Download the encrypted target data from the target data storage function network element indicated by the data service response message; The ciphertext is decrypted using the decryption material corresponding to the target data security policy indicated by the local target data security policy information, to obtain the plaintext of the target data.

[0189] In some embodiments, the processor is further configured to read a computer program from the memory and perform the following operations: Download access control information from the target data storage function network element indicated by the data service response message; The decryption material corresponding to the target data security policy indicated by the local target data security policy information decrypts the ciphertext, including: The ciphertext is decrypted based on the decryption material corresponding to the target data security policy indicated by the access control information and the local target data security policy information.

[0190] In some embodiments, obtaining the data security policy configured for the data service provided by the data service provider network element includes: The data security policy configured by the data management function network element for the data service provided by the data service provider network element is obtained; the data security policy configured for the data service provided by the data service provider network element is based on the data security policy supported by the data service provider network element and the data security policy locally stored by the data access control function network element.

[0191] In some embodiments, the processor is further configured to read a computer program from the memory and perform the following operations: Obtain a data service response message for the data service request message targeting the target data; the data service response message contains target data security policy information. Download the encrypted target data from the target data storage function network element indicated by the data service response message; The ciphertext is decrypted using the decryption material corresponding to the target data security policy indicated by the local target data security policy information, to obtain the plaintext of the target data.

[0192] In some embodiments, the processor is further configured to read a computer program from the memory and perform the following operations: Download access control information from the target data storage function network element indicated by the data service response message; The decryption material corresponding to the target data security policy indicated by the local target data security policy information decrypts the ciphertext, including: The ciphertext is decrypted based on the decryption material corresponding to the target data security policy indicated by the access control information and the local target data security policy information.

[0193] In some embodiments, the data access control algorithm includes one or more of the following algorithms: Proxy re-encryption access control algorithm; Ciphertext policy attribute-based encryption algorithm.

[0194] In some embodiments, the information used to instruct the data security policy configured for the data service provided to the data service provider network element includes one or more of the following: Data security policy name; Data security policy identifier.

[0195] Specifically, the data service requester network element provided in this application embodiment can implement all the method steps implemented by the method embodiment where the execution subject is the data service requester network element, and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.

[0196] Figure 11 This is a schematic diagram of the structure of the data management function network element provided in the embodiments of this application, such as... Figure 11 As shown, it includes a memory 1120, a transceiver 1100, and a processor 1110, wherein: The memory 1120 is used to store computer programs; the transceiver 1100 is used to send and receive data under the control of the processor 1110; the processor 1110 is used to read the computer program in the memory 1120 and perform the following operations: Obtain data security policy information sent by the network element of the data service provider; Based on the data security policy supported by the data service provider network element, a data security policy is configured for the data service provided by the data service provider network element; the data security policy corresponds to the data access control algorithm for performing data access control. Send the data security policy configured for the data service provided by the data service provider network element to the data service provider network element.

[0197] Among them, Figure 11 In this context, the bus architecture can include any number of interconnected buses and bridges, specifically linking various circuits together, represented by one or more processors (processor 1110) and memory (memory 1120). The bus architecture can also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface. The transceiver 1100 can be multiple elements, including transmitters and receivers, providing units for communicating with various other devices over transmission media, including wireless channels, wired channels, optical fibers, etc. The processor 1110 is responsible for managing the bus architecture and general processing, and the memory 1120 can store data used by the processor 1110 during operation.

[0198] The processor 1110 can be a central processing unit (CPU), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or a complex programmable logic device (CPLD). The processor can also adopt a multi-core architecture.

[0199] In some embodiments, configuring a data security policy for the data service provided by the data service provider network element based on the data security policy supported by the data service provider network element includes: Based on the data security policies supported by the data service provider network element and the data security policies stored locally by the data access control function network element, configure data security policies for the data services provided by the data service provider network element.

[0200] In some embodiments, configuring a data security policy for the data service provided by the data service provider network element based on the data security policy supported by the data service provider network element includes: Obtain the data security policy stored locally by the data access control function network element provided by the data access control function network element; Based on the data security policies supported by the data service provider network element and the data security policies stored locally by the data access control function network element, configure data security policies for the data services provided by the data service provider network element.

[0201] In some embodiments, the processor is further configured to read a computer program from the memory and perform the following operations: Send the data security policy configured for the data service provided by the data service provider network element to the data service requesting network element; The first parameter sent by the network element requesting the data service is obtained; the first parameter is the parameter of the data access control algorithm corresponding to the data security policy configured for the data service provided by the network element providing the data service; the first parameter is used for data access control.

[0202] In some embodiments, the processor is further configured to read a computer program from the memory and perform the following operations: Send the first parameter to the data access control function network element; Obtain the second parameter generated based on the first parameter sent by the data access control function network element; The second parameter is sent to the data service requester network element; the second parameter is used for data access control.

[0203] In some embodiments, the processor is further configured to read a computer program from the memory and perform the following operations: A data collection instruction message is sent to the network element of the data service provider; the data collection instruction message contains instruction information of the target data service, the target data security policy configured for the target data service, the target data access control algorithm corresponding to the target data security policy, and the first parameter of the target data access control algorithm.

[0204] In some embodiments, the processor is further configured to read a computer program from the memory and perform the following operations: Obtain the data service request message for the target data sent by the network element that is requesting the data service; A data service response message is sent to the network element that requests the data service; the data service response message contains target data security policy information; the target data security policy information is used to indicate the target data security policy configured for the target data service.

[0205] In some embodiments, the data access control algorithm includes one or more of the following algorithms: Proxy re-encryption access control algorithm; Ciphertext policy attribute-based encryption algorithm.

[0206] In some embodiments, the data security policy information includes one or more of the following: Data security policy name; List of data security policy names; Data security policy identifier; List of data security policy identifiers.

[0207] Specifically, the data management function network element provided in this application embodiment can implement all the method steps implemented by the method embodiment with the data management function network element as the execution subject, and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.

[0208] Figure 12 This is one of the structural schematic diagrams of the data access control device provided in the embodiments of this application, such as... Figure 12 As shown, it includes: The first sending module 1201 is used to send data security policy information; the data security policy information is used to configure data security policies for the data services provided by the data service provider network element. The first acquisition module 1202 is used to acquire the data security policy configured for the data service provided by the data service provider network element; the data security policy corresponds to the data access control algorithm for performing data access control.

[0209] In some embodiments, the transmission of data security policy information includes: Send data security policy information to the data access control function network element; The step of obtaining the data security policy configured for the data service provided by the network element of the data service provider includes: The data security policy configured by the data access control function network element for the data service provided by the data service provider network element is obtained; the data security policy configured for the data service provided by the data service provider network element is based on the data security policy supported by the data service provider network element and the data security policy configured locally stored by the data access control function network element.

[0210] In some embodiments, it also includes: The data acquisition instruction acquisition module is used to acquire data acquisition instruction messages sent by the data management function network element; the data acquisition instruction message includes instruction information of the target data service, the target data security policy configured for the target data service, the target data access control algorithm corresponding to the target data security policy, and the first parameter of the target data access control algorithm. The data acquisition module is used to collect target data; A data encryption module is used to encrypt the target data based on the target data access control algorithm and a first parameter of the target data access control algorithm; The encrypted data transmission module is used to send the encrypted target data to the target data storage function network element indicated by the data acquisition instruction message.

[0211] In some embodiments, it also includes: An access control information generation module is used to generate access control information based on the target data access control algorithm and the first parameter of the target data access control algorithm; The access control information transmission module is used to send the access control information to the target data storage function network element indicated by the data acquisition instruction message.

[0212] In some embodiments, the transmission of data security policy information includes: Send data security policy information to the data management function network element; The step of obtaining the data security policy configured for the data service provided by the network element of the data service provider includes: The data security policy configured by the data management function network element for the data service provided by the data service provider network element is obtained; the data security policy configured for the data service provided by the data service provider network element is based on the data security policy supported by the data service provider network element and the data security policy locally stored by the data access control function network element.

[0213] In some embodiments, the data access control algorithm includes one or more of the following algorithms: Proxy re-encryption access control algorithm; Ciphertext policy attribute-based encryption algorithm.

[0214] In some embodiments, the data security policy information includes one or more of the following: Data security policy name; List of data security policy names; Data security policy identifier; List of data security policy identifiers.

[0215] Specifically, the data access control device provided in this application embodiment can implement all the method steps implemented by the method embodiment where the execution subject is a data service provider network element, and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.

[0216] Figure 13 This is a second schematic diagram of the structure of the data access control device provided in the embodiments of this application, as shown below. Figure 13 As shown, it includes: The second acquisition module 1301 is used to acquire the data security policy configured for the data service provided by the network element of the data service provider; the data security policy corresponds to the data access control algorithm for performing data access control. The second sending module 1302 is used to send a first parameter; the first parameter is the parameter of the data access control algorithm corresponding to the data security policy configured for the data service provided by the data service provider network element; the first parameter is used to perform data access control.

[0217] In some embodiments, obtaining the data security policy configured for the data service provided by the data service provider network element includes: The data security policy configured by the data access control function network element for the data service provided by the data service provider network element is obtained; the data security policy configured for the data service provided by the data service provider network element is based on the data security policy supported by the data service provider network element and the data security policy configured locally stored by the data access control function network element.

[0218] In some embodiments, it also includes: The data service response acquisition module is used to acquire a data service response message for a data service request message targeting target data; the data service response message contains target data security policy information. The data download module is used to download the encrypted target data from the target data storage function network element indicated by the data service response message; The data decryption module is used to decrypt the ciphertext based on the decryption material corresponding to the target data security policy indicated by the local target data security policy information, so as to obtain the plaintext of the target data.

[0219] In some embodiments, it also includes: The access control information download module is used to download access control information from the target data storage function network element indicated by the data service response message; The decryption material corresponding to the target data security policy indicated by the local target data security policy information decrypts the ciphertext, including: The ciphertext is decrypted based on the decryption material corresponding to the target data security policy indicated by the access control information and the local target data security policy information.

[0220] In some embodiments, obtaining the data security policy configured for the data service provided by the data service provider network element includes: The data security policy configured by the data management function network element for the data service provided by the data service provider network element is obtained; the data security policy configured for the data service provided by the data service provider network element is based on the data security policy supported by the data service provider network element and the data security policy locally stored by the data access control function network element.

[0221] In some embodiments, the data access control algorithm includes one or more of the following algorithms: Proxy re-encryption access control algorithm; Ciphertext policy attribute-based encryption algorithm.

[0222] In some embodiments, the information used to instruct the data security policy configured for the data service provided to the data service provider network element includes one or more of the following: Data security policy name; Data security policy identifier.

[0223] Specifically, the data access control device provided in this application embodiment can implement all the method steps implemented by the method embodiment where the execution subject is a data service requester network element, and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.

[0224] Figure 14 This is the third schematic diagram of the data access control device provided in the embodiments of this application, as shown below. Figure 14 As shown, it includes: The third acquisition module 1401 is used to acquire data security policy information sent by the network element of the data service provider; Configuration module 1402 is used to configure a data security policy for the data service provided by the data service provider network element based on the data security policy supported by the data service provider network element; the data security policy corresponds to the data access control algorithm for performing data access control; The third sending module 1403 is used to send a data security policy configured for the data service provided by the data service provider network element to the data service provider network element.

[0225] In some embodiments, configuring a data security policy for the data service provided by the data service provider network element based on the data security policy supported by the data service provider network element includes: Based on the data security policies supported by the data service provider network element and the data security policies stored locally by the data access control function network element, configure data security policies for the data services provided by the data service provider network element.

[0226] In some embodiments, configuring a data security policy for the data service provided by the data service provider network element based on the data security policy supported by the data service provider network element includes: Obtain the data security policy stored locally by the data access control function network element provided by the data access control function network element; Based on the data security policies supported by the data service provider network element and the data security policies stored locally by the data access control function network element, configure data security policies for the data services provided by the data service provider network element.

[0227] In some embodiments, the method further includes: Send the data security policy configured for the data service provided by the data service provider network element to the data service requesting network element; The first parameter sent by the network element requesting the data service is obtained; the first parameter is the parameter of the data access control algorithm corresponding to the data security policy configured for the data service provided by the network element providing the data service; the first parameter is used for data access control.

[0228] In some embodiments, it also includes: The first parameter sending module is used to send the first parameter to the data access control function network element; The second parameter acquisition module is used to acquire the second parameter generated based on the first parameter sent by the data access control function network element; The second parameter sending module is used to send the second parameter to the data service requester network element; the second parameter is used for data access control.

[0229] In some embodiments, it also includes: The data acquisition instruction sending module is used to send a data acquisition instruction message to the network element of the data service provider; the data acquisition instruction message includes instruction information of the target data service, the target data security policy configured for the target data service, the target data access control algorithm corresponding to the target data security policy, and the first parameter of the target data access control algorithm.

[0230] In some embodiments, it also includes: The data service request acquisition module is used to acquire data service request messages for target data sent by the network element of the data service requesting party; A data service response sending module is used to send a data service response message to the network element that requests the data service; the data service response message contains target data security policy information; the target data security policy information is used to indicate the target data security policy configured for the target data service.

[0231] In some embodiments, the data access control algorithm includes one or more of the following algorithms: Proxy re-encryption access control algorithm; Ciphertext policy attribute-based encryption algorithm.

[0232] In some embodiments, the data security policy information includes one or more of the following: Data security policy name; List of data security policy names; Data security policy identifier; List of data security policy identifiers.

[0233] Specifically, the data access control device provided in this application embodiment can implement all the method steps implemented by the method embodiment where the execution subject is a data management function network element, and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.

[0234] It should be noted that the division of units / modules in the above embodiments of this application is illustrative and only represents one logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated units described above can be implemented in hardware or as software functional units.

[0235] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a processor-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to related technologies, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0236] In some embodiments, a processor-readable storage medium is also provided, the processor-readable storage medium storing a computer program, the computer program being configured to cause a processor to execute the data access control method provided in the various method embodiments where the execution subject is a data service provider network element, or the data access control method provided in the various method embodiments where the execution subject is a data service requester network element, or the data access control method provided in the various method embodiments where the execution subject is a data management function network element.

[0237] Specifically, the processor-readable storage medium provided in this application embodiment can implement all the method steps implemented in the above method embodiments and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiments and the beneficial effects will not be described in detail.

[0238] It should be noted that the processor-readable storage medium can be any available medium or data storage device that the processor can access, including but not limited to magnetic memory (e.g., floppy disk, hard disk, magnetic tape, magneto-optical disk (MO)), optical memory (e.g., CD, DVD, BD, HVD), and semiconductor memory (e.g., ROM, EPROM, EEPROM, non-volatile memory (NAND FLASH), solid-state drive (SSD)).

[0239] In some embodiments, a non-transient readable storage medium is also provided, which stores a computer program for causing a processor to execute the data access control method provided in the various method embodiments where the execution subject is a data service provider network element, or the data access control method provided in the various method embodiments where the execution subject is a data service requester network element, or the data access control method provided in the various method embodiments where the execution subject is a data management function network element.

[0240] Specifically, the non-transiently readable storage medium provided in this application embodiment can implement all the method steps implemented in the above method embodiments and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiments and the beneficial effects will not be described in detail.

[0241] In some embodiments, a computer-readable storage medium is also provided, the computer-readable storage medium storing a computer program, the computer program being used to cause a computer to execute the data access control method provided in the various method embodiments where the execution subject is a data service provider network element, or the data access control method provided in the various method embodiments where the execution subject is a data service requester network element, or the data access control method provided in the various method embodiments where the execution subject is a data management function network element.

[0242] Specifically, the computer-readable storage medium provided in the embodiments of this application can implement all the method steps implemented in the above method embodiments and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiments and the beneficial effects will not be described in detail.

[0243] In some embodiments, a communication device is also provided, wherein the communication device stores a computer program, the computer program being used to cause the communication device to execute the data access control method provided in the various method embodiments where the execution subject is a data service provider network element, or the data access control method provided in the various method embodiments where the execution subject is a data service requester network element, or the data access control method provided in the various method embodiments where the execution subject is a data management function network element.

[0244] Specifically, the communication device provided in this application embodiment can implement all the method steps implemented in the above method embodiments and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiments and the beneficial effects will not be described in detail.

[0245] In some embodiments, a chip product is also provided, wherein the chip product stores a computer program, the computer program being used to cause the chip product to execute the data access control method provided in the various method embodiments where the execution subject is a data service provider network element, or the data access control method provided in the various method embodiments where the execution subject is a data service requester network element, or the data access control method provided in the various method embodiments where the execution subject is a data management function network element.

[0246] Specifically, the chip product provided in this application embodiment can implement all the method steps implemented in the above method embodiments and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiments and the beneficial effects will not be described in detail.

[0247] Additionally, it should be noted that the term "and / or" in the embodiments of this application describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. The character " / " generally indicates that the preceding and following related objects have an "or" relationship.

[0248] In this application's embodiments, "determine B based on A" means that factor A must be considered when determining B. It is not limited to "B can be determined based solely on A," but should also include: "determine B based on A and C," "determine B based on A, C, and E," "determine C based on A, and further determine B based on C," etc. Additionally, it can include using A as a condition for determining B, for example, "when A meets the first condition, determine B using the first method"; another example, "when A meets the second condition, determine B," etc.; another example, "when A meets the third condition, determine B based on the first parameter," etc. Of course, it can also be a condition where A is a factor in determining B, for example, "when A meets the first condition, determine C using the first method, and further determine B based on C," etc.

[0249] In the embodiments of this application, the term "multiple" refers to two or more, and other quantifiers are similar.

[0250] In the embodiments of this application, the terms "target," "first," "second," etc., are used to distinguish similar objects, and not to describe a specific order or sequence. It should be understood that such terms can be used interchangeably where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first" and "second" are generally of the same class, and the number of objects is not limited; for example, the first object can be one or more.

[0251] The technical solutions provided in this application can be applied to a variety of systems. For example, applicable systems may include Long Term Evolution (LTE) systems, LTE Frequency Division Duplex (FDD) systems, LTE Time Division Duplex (TDD) systems, Long Term Evolution Advanced (LTE-A) systems, Universal Mobile Telecommunications System (UMTS), Worldwide Interoperability for Microwave Access (WiMAX) systems, 5G New Radio (NR) systems and their evolved communication systems, and 6G (sixth generation mobile communication technology) systems. These systems may include terminal equipment and network equipment. The systems may also include a core network component, such as an Evolved Packet Core (EPC), a 5G core network (5GC), or a 6G core network (6GC).

[0252] The terminal devices involved in the embodiments of this application can be devices that provide voice and / or data connectivity to users, handheld devices with wireless connectivity, or other processing devices connected to a wireless modem. The names of the terminal devices may differ in different systems; for example, in 5G or 6G systems, the terminal device may be called User Equipment (UE). Wireless terminal devices can be USB storage devices, other personal computer memory devices, and dongles. They can also communicate with one or more core networks (CNs) via a Radio Access Network (RAN). Wireless terminal devices can be mobile terminal devices, such as mobile phones (or "cellular" phones) and computers with mobile terminal devices. For example, they can be portable, pocket-sized, handheld, computer-embedded, or vehicle-mounted mobile devices that exchange voice and / or data with the radio access network. Examples of such devices include Personal Communication Service (PCS) phones, cordless phones, Session Initiated Protocol (SIP) phones, Wireless Local Loop (WLL) stations, Personal Digital Assistants (PDAs), personal computers, tablets, and Machine-type Communication (MTC) terminal devices. Wireless terminal devices can also be referred to as systems, subscriber units, subscriber stations, mobile stations, mobile terminals, remote stations, access points, remote terminals, access terminals, user terminals, user agents, user devices, and wireless access devices and routers / modems that meet the limitations of this definition; however, this application does not limit the scope of the embodiments described.

[0253] The network device involved in the embodiments of this application can be a base station, which may include multiple cells providing services to terminals. Depending on the specific application, the base station may also be called an access point, or a device in the access network that communicates with wireless terminal devices through one or more sectors on the air interface, or other names. The network device can be used to exchange received air frames with Internet Protocol (IP) packets, acting as a router between the wireless terminal device and the rest of the access network, where the rest of the access network may include an Internet Protocol (IP) communication network. The network device can also coordinate the attribute management of the air interface. For example, the network device involved in the embodiments of this application may be an evolved Node B (eNB or e-NodeB) in a long term evolution (LTE) system, a 5G base station (gNB) in a next generation system, or a Home evolved Node B (HeNB), relay node, femto, pico, network testing equipment, etc., and is not limited in the embodiments of this application. In some network architectures, network devices may include centralized unit (CU) nodes and distributed unit (DU) nodes, which may also be geographically separated.

[0254] Network devices and terminal devices can each use one or more antennas to perform multiple-input multiple-output (MIMO) transmission. MIMO transmission can be single-user MIMO or multi-user MIMO. Depending on the configuration and number of antenna combinations, MIMO transmission can be 2D-MIMO, 3D-MIMO, FD-MIMO, or massive-MIMO, and can also be diversity transmission, precoding transmission, or beamforming transmission, etc.

[0255] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage and optical storage) containing computer-usable program code.

[0256] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-executable instructions. These computer-executable instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0257] These processor-executable instructions may also be stored in a processor-readable memory that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the processor-readable memory produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0258] These processors can execute instructions that can also be loaded onto a computer or other programmable data processing device, causing a series of operational steps to be performed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable device for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0259] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.

Claims

1. A data access control method, characterized in that, Applied to network elements of data service providers, the method includes: Send data security policy information; the data security policy information is used to configure data security policies for the data services provided by the network element of the data service provider. Obtain the data security policy configured for the data service provided by the network element of the data service provider; the data security policy corresponds to the data access control algorithm for performing data access control.

2. The data access control method according to claim 1, characterized in that, The data transmission security policy information includes: Send data security policy information to the data access control function network element; The step of obtaining the data security policy configured for the data service provided by the network element of the data service provider includes: The data security policy configured by the data access control function network element for the data service provided by the data service provider network element is obtained; the data security policy configured for the data service provided by the data service provider network element is based on the data security policy supported by the data service provider network element and the data security policy configured locally stored by the data access control function network element.

3. The data access control method according to claim 2, characterized in that, The method further includes: The data collection instruction message sent by the data management function network element is obtained; the data collection instruction message contains instruction information of the target data service, the target data security policy configured for the target data service, the target data access control algorithm corresponding to the target data security policy, and the first parameter of the target data access control algorithm. Collect target data; The target data is encrypted based on the target data access control algorithm and the first parameter of the target data access control algorithm; The encrypted target data is sent to the target data storage function network element indicated by the data acquisition instruction message.

4. The data access control method according to claim 3, characterized in that, The method further includes: Access control information is generated based on the target data access control algorithm and the first parameter of the target data access control algorithm; The access control information is sent to the target data storage function network element indicated by the data acquisition instruction message.

5. The data access control method according to claim 1, characterized in that, The data transmission security policy information includes: Send data security policy information to the data management function network element; The step of obtaining the data security policy configured for the data service provided by the network element of the data service provider includes: The data security policy configured by the data management function network element for the data service provided by the data service provider network element is obtained; the data security policy configured for the data service provided by the data service provider network element is based on the data security policy supported by the data service provider network element and the data security policy locally stored by the data access control function network element.

6. The data access control method according to claim 5, characterized in that, The method further includes: The data collection instruction message sent by the data management function network element is obtained; the data collection instruction message contains instruction information of the target data service, the target data security policy configured for the target data service, the target data access control algorithm corresponding to the target data security policy, and the first parameter of the target data access control algorithm. Collect target data; The target data is encrypted based on the target data access control algorithm and the first parameter of the target data access control algorithm; The encrypted target data is sent to the target data storage function network element indicated by the data acquisition instruction message.

7. The data access control method according to claim 6, characterized in that, The method further includes: Access control information is generated based on the target data access control algorithm and the first parameter of the target data access control algorithm; The access control information is sent to the target data storage function network element indicated by the data acquisition instruction message.

8. The data access control method according to any one of claims 1 to 7, characterized in that, The data access control algorithm includes one or more of the following algorithms: Proxy re-encryption access control algorithm; Ciphertext policy attribute-based encryption algorithm.

9. The data access control method according to any one of claims 1 to 7, characterized in that, The data security policy information includes one or more of the following: Data security policy name; List of data security policy names; Data security policy identifier; List of data security policy identifiers.

10. A data access control method, characterized in that, Applied to network elements that request data services, the method includes: Obtain the data security policy configured for the data service provided by the network element of the data service provider; the data security policy corresponds to the data access control algorithm for performing data access control. Send the first parameter; the first parameter is the parameter of the data access control algorithm corresponding to the data security policy configured for the data service provided by the data service provider network element; the first parameter is used for data access control.

11. The data access control method according to claim 10, characterized in that, The acquisition of the data security policy configured for the data service provided by the network element of the data service provider includes: The data security policy configured by the data access control function network element for the data service provided by the data service provider network element is obtained; the data security policy configured for the data service provided by the data service provider network element is based on the data security policy supported by the data service provider network element and the data security policy configured locally stored by the data access control function network element.

12. The data access control method according to claim 11, characterized in that, The method further includes: Obtain a data service response message for the data service request message targeting the target data; the data service response message contains target data security policy information. Download the encrypted target data from the target data storage function network element indicated by the data service response message; The ciphertext is decrypted using the decryption material corresponding to the target data security policy indicated by the local target data security policy information, to obtain the plaintext of the target data.

13. The data access control method according to claim 12, characterized in that, The method further includes: Download access control information from the target data storage function network element indicated by the data service response message; The decryption material corresponding to the target data security policy indicated by the local target data security policy information decrypts the ciphertext, including: The ciphertext is decrypted based on the decryption material corresponding to the target data security policy indicated by the access control information and the local target data security policy information.

14. The data access control method according to claim 10, characterized in that, The step of obtaining the data security policy configured for the data service provided by the network element of the data service provider includes: The data security policy configured by the data management function network element for the data service provided by the data service provider network element is obtained; the data security policy configured for the data service provided by the data service provider network element is based on the data security policy supported by the data service provider network element and the data security policy locally stored by the data access control function network element.

15. The data access control method according to claim 14, characterized in that, The method further includes: Obtain a data service response message for the data service request message targeting the target data; the data service response message contains target data security policy information. Download the encrypted target data from the target data storage function network element indicated by the data service response message; The ciphertext is decrypted using the decryption material corresponding to the target data security policy indicated by the local target data security policy information, to obtain the plaintext of the target data.

16. The data access control method according to claim 15, characterized in that, The method further includes: Download access control information from the target data storage function network element indicated by the data service response message; The decryption material corresponding to the target data security policy indicated by the local target data security policy information decrypts the ciphertext, including: The ciphertext is decrypted based on the decryption material corresponding to the target data security policy indicated by the access control information and the local target data security policy information.

17. The data access control method according to any one of claims 10 to 16, characterized in that, The data access control algorithm includes one or more of the following algorithms: Proxy re-encryption access control algorithm; Ciphertext policy attribute-based encryption algorithm.

18. The data access control method according to any one of claims 10 to 16, characterized in that, Information used to instruct the data security policy configured for the data service provided to the data service provider network element includes one or more of the following: Data security policy name; Data security policy identifier.

19. A data access control method, characterized in that, The method, applied to a data management function network element, includes: Obtain data security policy information sent by the network element of the data service provider; Based on the data security policy supported by the data service provider network element, a data security policy is configured for the data service provided by the data service provider network element; the data security policy corresponds to the data access control algorithm for performing data access control. Send the data security policy configured for the data service provided by the data service provider network element to the data service provider network element.

20. The data access control method according to claim 19, characterized in that, The process of configuring data security policies for data services provided by the data service provider's network element based on the data security policies supported by the data service provider's network element includes: Based on the data security policies supported by the data service provider network element and the data security policies stored locally by the data access control function network element, configure data security policies for the data services provided by the data service provider network element.

21. The data access control method according to claim 19, characterized in that, The process of configuring data security policies for data services provided by the data service provider's network element based on the data security policies supported by the data service provider's network element includes: Obtain the data security policy locally stored by the data access control function network element provided by the data access control function network element; Based on the data security policies supported by the data service provider network element and the data security policies stored locally by the data access control function network element, configure data security policies for the data services provided by the data service provider network element.

22. The data access control method according to claim 19, characterized in that, The method further includes: Send the data security policy configured for the data service provided by the data service provider network element to the data service requesting network element; The first parameter sent by the network element requesting the data service is obtained; the first parameter is the parameter of the data access control algorithm corresponding to the data security policy configured for the data service provided by the network element providing the data service; the first parameter is used for data access control.

23. The data access control method according to claim 22, characterized in that, The method further includes: Send the first parameter to the data access control function network element; Obtain the second parameter generated based on the first parameter sent by the data access control function network element; The second parameter is sent to the data service requester network element; the second parameter is used for data access control.

24. The data access control method according to claim 19, characterized in that, The method further includes: A data collection instruction message is sent to the network element of the data service provider; the data collection instruction message contains instruction information of the target data service, the target data security policy configured for the target data service, the target data access control algorithm corresponding to the target data security policy, and the first parameter of the target data access control algorithm.

25. The data access control method according to claim 19, characterized in that, The method further includes: Obtain the data service request message for the target data sent by the network element that is requesting the data service; A data service response message is sent to the network element that requests the data service; the data service response message contains target data security policy information; the target data security policy information is used to indicate the target data security policy configured for the target data service.

26. The data access control method according to any one of claims 19 to 25, characterized in that, The data access control algorithm includes one or more of the following algorithms: Proxy re-encryption access control algorithm; Ciphertext policy attribute-based encryption algorithm.

27. The data access control method according to any one of claims 19 to 25, characterized in that, The data security policy information includes one or more of the following: Data security policy name; List of data security policy names; Data security policy identifier; List of data security policy identifiers.

28. A data service provider network element, characterized in that, Includes memory, transceiver, and processor; Memory, used to store computer programs; Transceiver, used to send and receive data under the control of the processor; A processor for reading a computer program from the memory and executing the data access control method according to any one of claims 1 to 9.

29. A data service requester network element, characterized in that, Includes memory, transceiver, and processor; Memory, used to store computer programs; Transceiver, used to send and receive data under the control of the processor; A processor for reading a computer program from the memory and executing the data access control method according to any one of claims 10 to 18.

30. A data management function network element, characterized in that, Includes memory, transceiver, and processor; Memory, used to store computer programs; Transceiver, used to send and receive data under the control of the processor; A processor for reading a computer program from the memory and executing the data access control method according to any one of claims 19 to 27.

31. A data access control device, characterized in that, include: The first sending module is used to send data security policy information; The data security policy information is used to configure data security policies for the data services provided by the data service provider network element; The first acquisition module is used to acquire the data security policy configured for the data service provided by the network element of the data service provider; The data security policy corresponds to the data access control algorithm that performs data access control.

32. A data access control device, characterized in that, include: The second acquisition module is used to acquire the data security policy configured for the data service provided by the network element of the data service provider; The data security policy corresponds to the data access control algorithm that performs data access control. The second sending module is used to send a first parameter; the first parameter is a parameter of the data access control algorithm corresponding to the data security policy configured for the data service provided by the data service provider network element; the first parameter is used for data access control.

33. A data access control device, characterized in that, include: The third acquisition module is used to acquire data security policy information sent by the network element of the data service provider. The configuration module is used to configure data security policies for the data services provided by the data service provider network element based on the data security policies supported by the data service provider network element. The data security policy corresponds to the data access control algorithm that performs data access control. The third sending module is used to send the data security policy configured for the data service provided by the data service provider network element to the data service provider network element.

34. A processor-readable storage medium, characterized in that, The processor-readable storage medium stores a computer program that causes the processor to execute the data access control method according to any one of claims 1 to 9.

35. A processor-readable storage medium, characterized in that, The processor-readable storage medium stores a computer program for causing the processor to execute the data access control method according to any one of claims 10 to 18.

36. A processor-readable storage medium, characterized in that, The processor-readable storage medium stores a computer program for causing the processor to execute the data access control method according to any one of claims 19 to 27.