Communication methods and related apparatuses
Patent Information
- Application Number
- CN202510373748.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-27
- Publication Date
- 2026-09-29
AI Technical Summary
[0003]目前,对于一个NRF而言,该NRF通常可以配置或激活一种签名算法,后续可以基于该签名算法对访问令牌进行签名,NF服务提供方可以基于该签名算法对应的验签算法对该签名进行验签,这种方式,访问令牌签发的灵活性较低
[0040]本申请实施例中,服务提供网元可以在注册时向凭证提供网元发送自身支持的算法套件,相应地,服务提供网元生成用于访问该服务提供网元的访问令牌时,可以采用该服务提供网元支持的算法套件,因此,服务提供网元接收到来自服务请求网元的服务请求之后,可以基于自身支持的算法套件对访问令牌进行校验,在校验通过的情况下,可以为该服务请求网元提供服务,反之,可以拒绝为该服务请求网元提供服务。
Smart Images

Figure CN122845121A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a communication method and related apparatus. Background Technology
[0002] To enhance network scalability and flexibility, 5G networks employ a service-based architecture (SBA). In SBA, various network functions (NFs) can interact through service interfaces. Furthermore, to improve network security, protocol 33.501 defines a service authorization mechanism based on the Open Authorization (OAuth) 2.0 protocol between NF service consumers (cNFs), network repository functions (NRFs), and NF service providers / producers.
[0003] Currently, for an NRF, it can typically be configured or activated with a signature algorithm. Subsequently, access tokens can be signed based on this signature algorithm, and the NRF service provider can verify the signature based on the verification algorithm corresponding to the signature algorithm. In this way, the flexibility of access token issuance is relatively low. Summary of the Invention
[0004] This application discloses a communication method and related apparatus, which can improve the flexibility of access token issuance and ensure that the service requesting network element can access the corresponding service based on the access token issued by the network element.
[0005] The first aspect discloses a communication method that can be applied to a credential providing network element (such as an NRF), a module within the credential providing network element (e.g., a processor or chip), or a logic module or software capable of implementing all or part of the functions of the credential providing network element. The following description, using an application to a credential providing network element as an example, includes the following steps: the credential providing network element receives a first request message from a service requesting network element, the first request message requesting authorization for the service requesting network element to access an access token for a target service; based on the first request message, the credential providing network element determines an algorithm suite supported by the service providing network element providing the target service; based on the algorithm suite, the credential providing network element generates an access token; and the credential providing network element sends a first response message to the service requesting network element, the first response message including the access token.
[0006] In this embodiment, different network elements (such as service-providing network elements, credential-providing network elements, etc.) may support different algorithm suites. For example, in the future, to improve network security, more signature algorithms and signature methods may be added to the network. In this case, different service-providing network elements, credential-providing network elements, etc., may support different algorithm suites. Therefore, after receiving the first request message from the service-requesting network element, the credential-providing network element can negotiate the algorithm suite, that is, determine the algorithm suite supported by the service-providing network element providing the target service based on the first request message. Then, it can sign the access token based on the determined algorithm suite so that the service-requesting network element can subsequently access the corresponding service based on the access token. In this method, since the credential-providing network element is a determined service-providing network element that supports the algorithm suite of the target service, it can be guaranteed that when the service-requesting network element requests the service from the corresponding service-providing network element based on the access token, the corresponding service-providing network element can support signature verification, thereby enabling the service-requesting network element to obtain the service normally. Furthermore, this method allows the credential-providing network element to flexibly determine the algorithm suite used for signing, rather than using a pre-configured or activated signature algorithm. This improves the flexibility of access token issuance and can meet the access token issuance needs of more scenarios.
[0007] In conjunction with the first aspect, in one possible implementation, the credential-providing network element determines, based on the first request message, an algorithm suite supported by the service-providing network element providing the target service, including: determining one or more candidate network elements providing the target service based on the first request message; and determining, based on the algorithm suite supported by the one or more candidate network elements, an algorithm suite supported by the service-providing network element providing the target service.
[0008] In this embodiment of the application, the credential providing network element can first determine one or more candidate network elements providing the target service, and then determine the algorithm suite supported by the service providing network element providing the target service based on the algorithm suite supported by the one or more candidate network elements, that is, the algorithm suite used for signing. In this way, it can be ensured that the signature generated based on the algorithm suite can be verified by the corresponding service providing network element providing the target service, thereby ensuring that the subsequent service requesting network element can obtain the service from the service providing network element based on the access token signed using the algorithm suite.
[0009] In conjunction with the first aspect, in one possible implementation, the first request message includes a desired algorithm suite for signing the access token; determining the algorithm suite supported by the service-providing network element providing the target service based on the algorithm suite supported by the one or more candidate network elements includes: identifying candidate network elements supporting the desired algorithm suite as service-providing network elements providing the target service; and determining the algorithm suite supported by the service-providing network element providing the target service.
[0010] Different algorithm suites may have different computational complexity, generated signature length, security, etc. In this embodiment, the credential providing network element can receive the expected algorithm suite provided by the service requesting network element. The credential providing network element can use the expected algorithm suite to sign the access token. In this way, when the service requesting network element requests an access token from the credential providing network element, it can easily indicate the corresponding expected algorithm suite to the credential providing network element according to its own storage capacity and other limitations.
[0011] In conjunction with the first aspect, in one possible implementation, the algorithm suite supported by the one or more candidate network elements is associated with at least one of the following: network element type that allows access to the candidate network element, network element instance that allows access to the candidate network element, network slice, network function, and provided service name; the first request message includes at least one of the following: network element type of the service requesting network element, network element instance identifier of the service requesting network element, network slice identifier, network function identifier, and requested authorized service name; determining the algorithm suite supported by the service providing network element providing the target service based on the algorithm suite supported by the one or more candidate network elements includes: identifying candidate network elements associated with at least one of the network element type, network element instance identifier, network slice identifier, network function identifier, and requested authorized service name as service providing network elements providing the target service; and determining the algorithm suite supported by the service providing network element providing the target service.
[0012] Different algorithm suites may have varying computational complexity, generated signature length, and security. Furthermore, different network service providers (NFs), different NF types, and different network slices have varying security requirements. In this embodiment, for a single service provider (NF), the algorithm suite supported by that NF can be configured specifically for different situations to achieve lower computational complexity and shorter generated signature lengths while still meeting security requirements. This configuration method significantly improves the flexibility of algorithm suite configuration.
[0013] In conjunction with the first aspect, in one possible implementation, determining the algorithm suite supported by the service-providing network element providing the target service based on the algorithm suite supported by the plurality of candidate network elements includes: determining the candidate network element corresponding to the algorithm suite with the largest number of supported algorithms as the service-providing network element providing the target service based on the algorithm suite supported by the plurality of candidate network elements; and determining the algorithm suite supported by the service-providing network element providing the target service.
[0014] In this embodiment of the application, the credential-providing network element can determine the algorithm suite that supports the largest number of candidate network elements as the algorithm suite for signing. In this way, by signing the access token based on the algorithm suite, the network element with the largest number of candidate network elements can be accessed.
[0015] In conjunction with the first aspect, in one possible implementation, the number of determined algorithm suites is multiple, and the number of access tokens is also multiple, which are used to access the target services of different service providing network elements.
[0016] In this embodiment of the application, since different service providing network elements may support different algorithm suites, for two service providing network elements providing the target service, these two service providing network elements may not support the same algorithm suite. In this case, in order to facilitate the service requesting network element to access the service providing network element that does not support the same algorithm suite, the credential providing network element can determine multiple algorithm suites, and then sign the corresponding access token based on the determined multiple algorithm suites respectively.
[0017] In conjunction with the first aspect, in one possible implementation, determining the algorithm suite supported by the service-providing network element providing the target service based on the algorithm suite supported by the plurality of candidate network elements includes: dividing the plurality of candidate network elements into multiple groups based on the algorithm suite supported by the plurality of candidate network elements, wherein the candidate network elements in the first group support at least one identical algorithm suite, and the first group is any one of the plurality of groups; determining the algorithm suite corresponding to each of the plurality of groups based on the algorithm suite supported by the candidate network elements in the plurality of groups; wherein the algorithm suite corresponding to the first group is an algorithm suite supported by all candidate network elements in the first group; and determining the algorithm suite corresponding to each of the plurality of groups as the algorithm suite supported by the service-providing network element providing the target service.
[0018] In this embodiment, the candidate network elements include those that do not support the same algorithm suite. To facilitate the service requesting network element's access to the target service provided by these candidate network elements, the credential providing network element can divide the candidate network elements into multiple groups. Each group of candidate network elements supports at least one of the same algorithm suites. Subsequently, the credential providing network element can generate access tokens for accessing the candidate network elements in each group based on the same algorithm suites supported by the candidate network elements in each group. In this way, for any candidate network element, the service requesting network element has a corresponding access token to request the candidate network element to provide the target service.
[0019] In conjunction with the first aspect, in one possible implementation, the method further includes: the credential providing network element receiving a second request message from the service requesting network element, the second request message being for requesting service discovery, the second request message including a desired algorithm suite; the credential providing network element sending a second response message to the service requesting network element, the second response message including information for instructing the discovered service providing network element to support the desired algorithm suite.
[0020] In this embodiment of the application, during the service discovery process, the requesting network element can discover service-providing network elements that support a specific algorithm suite (the desired algorithm suite). This facilitates the subsequent request from the credential-providing network element to request an access token from the service-providing network element that supports the specific algorithm suite, and the signing of the access token based on the specific algorithm suite. Alternatively, when the requesting network element obtains an access token signed based on a specific algorithm suite, it can request the credential-providing network element to send the access token to the service-providing network element that supports the specific algorithm suite, and then access the services provided by that service-providing network element based on the access token.
[0021] In conjunction with the first aspect, in one possible implementation, the method further includes: the credential-providing network element receiving a third request message from a target service-providing network element, the third request message being used to request network function registration, the third request message including an algorithm suite supported by the target service-providing network element; the credential-providing network element sending a third response message to the target service-providing network element, the third response message including a registration result, the registration result being determined based on the algorithm suite supported by the target service-providing network element and the algorithm suite supported by the credential-providing network element.
[0022] In this embodiment of the application, during the registration process of the service provider network element, the service provider network element can send its supported algorithm suite to the credential provider network element. The credential provider network element can determine the registration result based on the algorithm suite supported by the service provider network element and its own supported algorithm suite, and can return the registration result to the service provider network element.
[0023] In conjunction with the first aspect, in one possible implementation, if the algorithm suite supported by the target service and the algorithm suite supported by the credential include at least one identical algorithm suite, the registration result is successful; if both the algorithm suite supported by the target service and the algorithm suite supported by the credential are different, the registration result is unsuccessful.
[0024] In this embodiment, if the algorithm suite supported by the service provider network element and the algorithm suite supported by the credential provider network element include at least one identical algorithm suite, the credential provider network element can then generate an access token for accessing the service provider network element based on the at least one identical algorithm suite, and the registration result can be registration success. Conversely, if the algorithm suite supported by the service provider network element and the algorithm suite supported by the credential provider network element are both different, it indicates that the credential provider network element does not have an algorithm suite available to support signature verification by the service provider network element, and the registration result can be registration failure.
[0025] In conjunction with the first aspect, in one possible implementation, if the target service providing network element is successfully registered, the algorithm suite supported by the target service providing network element is stored, or the algorithm suite supported by both the target service providing network element and the credential providing network element is stored.
[0026] In this embodiment of the application, when the service provider network element is successfully registered, the credential provider network element can store the algorithm suite supported by the service provider network element, or store the algorithm suite supported by both the service provider network element and the credential provider network element, so that the credential provider network element can quickly negotiate the algorithm suite based on the stored information.
[0027] In conjunction with the first aspect, in one possible implementation, the algorithm suite supported by the target service-providing network element is associated with at least one of the following: the network element type that allows access to the target service-providing network element, the network element instance that allows access to the target service-providing network element, network slice, network function, and the name of the service provided.
[0028] In conjunction with the first aspect, in one possible implementation, the algorithm suite includes a signature algorithm and / or a signature method.
[0029] In this embodiment of the application, the algorithm suite may include a signature algorithm and / or a signature method, which provides high flexibility.
[0030] The second aspect discloses a communication method that can be applied to a service requesting network element (such as an NF service consumer), a module within the service requesting network element (e.g., a processor or chip), or a logic module or software capable of implementing all or part of the functions of the service requesting network element. The following description uses an application to a service requesting network element as an example. This communication method can include: the service requesting network element sending a first request message to a credential providing network element, the first request message requesting authorization for an access token to a target service, the first request message including a desired algorithm suite; and the service requesting network element receiving a first response message from the credential providing network element, the first response message including an access token, the access token being securely protected using the desired algorithm suite.
[0031] In this embodiment of the application, the computational complexity, generated signature length, security, etc. of different algorithm suites may be different. Therefore, when the service requesting network element requests an access token from the credential providing network element, it can indicate the corresponding expected algorithm suite to the credential providing network element according to actual needs (such as security requirements), so that the credential providing network element can use the expected algorithm suite to protect the access token, that is, use the expected algorithm suite to sign the access token.
[0032] In conjunction with the second aspect, in one possible implementation, the first request message includes information for instructing multiple service-providing network elements, the access tokens being multiple, the multiple access tokens being secured using different algorithm suites, and each of the multiple access tokens being used to access a target service of a portion of the multiple service-providing network elements.
[0033] In this embodiment, since different service-providing network elements may support different algorithm suites, the service requesting network element can receive access tokens from the credential-providing network element, each protected by multiple algorithm suites. Each access token can be used to access the services of some of the requested service-providing network elements. Thus, for service-providing network elements that do not support the same algorithm suite, the service requesting network element can use different access tokens to access the corresponding services.
[0034] In conjunction with the second aspect, in one possible implementation, the method further includes: the service requesting network element sending a second request message to the credential providing network element, the second request message being used to request service discovery, the second request message including a desired algorithm suite; the service requesting network element receiving a second response message from the credential providing network element, the second response message including information for indicating the discovered service providing network element that supports the desired algorithm suite; the service requesting network element sending a first request message to the credential providing network element comprising: sending the first request message to the credential providing network element based on the information of the discovered service providing network element.
[0035] In this embodiment of the application, during the service discovery process, the network element supporting the service request discovers the service-providing network element that supports a specific algorithm suite (the desired algorithm suite). Thus, the service-requesting network element can first discover the service-providing network element that supports the specific algorithm suite through the credential-providing network element, and then request an access token from the credential-providing network element to access the service-providing network element, and sign the access token based on the specific algorithm suite. In conjunction with the second aspect, in one possible implementation, the algorithm suite includes a signature algorithm and / or a signature method.
[0036] The third aspect discloses a communication method that can be applied to a service-providing network element (such as an NF service provider), a module within the service-providing network element (e.g., a processor or chip), or a logic module or software capable of implementing all or part of the functions of the service-providing network element. The following description uses an application to a service-providing network element as an example. This communication method may include: the service-providing network element sending a third request message to a credential-providing network element, the third request message requesting network function registration, the third request message including an algorithm suite supported by the service-providing network element; and the service-providing network element receiving a third response message from the credential-providing network element, the third response message including indication information of successful registration.
[0037] In this embodiment, since the service-providing network element and the credential-providing network element may support different algorithm suites, during the registration process of the service-providing network element, the service-providing network element can send its supported algorithm suite to the credential-providing network element. The credential-providing network element can then determine the registration result based on the algorithm suite supported by the service-providing network element and its own supported algorithm suite, and then return the registration result to the service-providing network element. In this approach, because the service-providing network element sends its supported algorithm suite to the credential-providing network element, it is convenient for the credential-providing network element to use the algorithm suite supported by the service-providing network element when issuing access tokens for accessing the service-providing network element. This avoids the issuance of invalid access tokens, i.e., using an algorithm suite not supported by the service-providing network element to sign the access token.
[0038] In conjunction with the third aspect, in one possible implementation, the algorithm suite supported by the service-providing network element is associated with at least one of the following: network element type that allows access to the service-providing network element, network element instance that allows access to the service-providing network element, network slice, network function, and the name of the service provided.
[0039] In conjunction with the third aspect, in one possible implementation, the method further includes: the service-providing network element receiving a service request from a service-requesting network element, the service request being used to request a target service, the service request including an access token; the service-providing network element using its own supported algorithm suite to verify the access token; if the verification passes, the service-providing network element provides services to the service-requesting network element; if the verification fails, the service-providing network element refuses to provide services to the service-requesting network element.
[0040] In this embodiment of the application, the service provider network element can send its supported algorithm suite to the credential provider network element during registration. Correspondingly, when the service provider network element generates an access token for accessing the service provider network element, it can use the algorithm suite supported by the service provider network element. Therefore, after receiving a service request from the service request network element, the service provider network element can verify the access token based on its supported algorithm suite. If the verification passes, it can provide services to the service request network element; otherwise, it can refuse to provide services to the service request network element.
[0041] In conjunction with the third aspect, in one possible implementation, the algorithm suite includes a signature algorithm and / or a signature method.
[0042] It should be noted that the technical solutions of the first aspect, the second aspect, and the third aspect of this application correspond to each other, and the relevant beneficial effects can be referred to each other.
[0043] The fourth aspect discloses a communication device that has the functions of the first aspect described above. For example, the communication device includes a module or unit that performs the methods of the first aspect or any possible implementation of the first aspect. The module or unit can be implemented by software, hardware, or a combination of software and hardware.
[0044] For example, the communication device disclosed in the fourth aspect above may be a credential providing network element or a chip in a credential providing network element.
[0045] The fifth aspect discloses a communication device that has the functions of the second aspect described above. For example, the communication device includes a module or unit that performs the methods of the second aspect or any possible implementation of the second aspect. The module or unit can be implemented by software, hardware, or a combination of software and hardware.
[0046] For example, the communication device disclosed in the fifth aspect above may be a service request network element or a chip in the service request network element.
[0047] The sixth aspect discloses a communication device that has the functions of the third aspect described above. For example, the communication device includes a module or unit that performs the methods of the third aspect or any possible implementation of the third aspect. The module or unit can be implemented by software, hardware, or a combination of software and hardware.
[0048] For example, the communication device disclosed in the sixth aspect above may be a service-providing network element or a chip in the service-providing network element.
[0049] The seventh aspect discloses a communication system comprising at least one of a credential providing network element, a service request network element, and a service providing network element. The credential providing network element is configured to implement the methods provided in the first aspect and any possible embodiments thereof. The service request network element is configured to implement the methods provided in the second aspect and any possible embodiments thereof. The service providing network element is configured to implement the methods provided in the third aspect and any possible embodiments thereof.
[0050] The eighth aspect discloses a communication device, including a processor and a communication interface; the communication interface is used to receive and / or transmit data; the processor invokes a computer program or computer instructions stored in a memory to implement the method provided in the first aspect and any possible implementation of the first aspect, or to implement the method provided in the second aspect and any possible implementation of the second aspect, or to implement the method provided in the third aspect and any possible implementation of the third aspect.
[0051] As one possible implementation, the communication device disclosed in the eighth aspect above may include one or more processors.
[0052] Optionally, the communication device disclosed in the eighth aspect above further includes one or more memories.
[0053] The ninth aspect discloses a computer-readable storage medium storing a computer program or computer instructions that, when executed, implement the methods provided in the first aspect and any possible embodiments thereof, or implement the methods provided in the second aspect and any possible embodiments thereof, or implement the methods provided in the third aspect and any possible embodiments thereof.
[0054] The tenth aspect discloses a chip including a processor for executing a program stored in a memory, wherein when the program is executed, the chip performs the methods provided in the first aspect and any possible embodiments thereof, or performs the methods provided in the second aspect and any possible embodiments thereof, or performs the methods provided in the third aspect and any possible embodiments thereof.
[0055] As one possible implementation, the memory is located outside the chip.
[0056] The eleventh aspect discloses a computer program product comprising computer program code that, when executed, causes the methods provided in the first aspect and any possible implementation thereof to be performed, or causes the methods provided in the second aspect and any possible implementation thereof to be performed, or causes the methods provided in the third aspect and any possible implementation thereof to be performed.
[0057] It should be understood that the implementation and beneficial effects of the above-mentioned aspects or any possible implementation methods of this application can be referred to each other. Attached Figure Description
[0058] The accompanying drawings are provided to more clearly illustrate the technical solutions of the embodiments of this application. The drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0059] Figure 1 This is a schematic diagram of an NF registration process disclosed in an embodiment of this application;
[0060] Figure 2 This is a schematic diagram illustrating a process for a service consumer to request an access token, as disclosed in an embodiment of this application.
[0061] Figure 3This is a schematic diagram illustrating a process disclosed in an embodiment of this application where a service consumer requests a service from a service provider using an access token;
[0062] Figure 4 This is a schematic diagram of a network architecture disclosed in an embodiment of this application;
[0063] Figure 5 This is a schematic diagram of a network architecture for multi-generational network element integration disclosed in an embodiment of this application;
[0064] Figure 6 This is a flowchart illustrating a communication method disclosed in an embodiment of this application;
[0065] Figure 7 This is a flowchart illustrating another communication method disclosed in an embodiment of this application;
[0066] Figure 8 This is a flowchart illustrating another communication method disclosed in an embodiment of this application;
[0067] Figure 9 This is a flowchart illustrating another communication method disclosed in an embodiment of this application;
[0068] Figure 10 This is a schematic diagram of the structure of a communication device disclosed in an embodiment of this application;
[0069] Figure 11 This is a schematic diagram of the hardware structure of a communication device disclosed in an embodiment of this application. Detailed Implementation
[0070] This application discloses a communication method and related apparatus, which can improve the flexibility of access token issuance. The technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings.
[0071] To better understand the embodiments of this application, the relevant content, terms or nouns involved in this application will be briefly introduced below.
[0072] I. Open Authorization (OAuth) 2.0 Protocol
[0073] The OAuth 2.0 protocol flow mainly includes 6 steps, as follows:
[0074] (A) The client requests authorization from the resource owner. For example, the client can send an authorization request to the resource owner. This authorization request can be sent directly by the client to the resource owner, or indirectly through an authorization server.
[0075] (B) The client receives an authorization grant, which can be one of four authorization methods (authorization code, implicit, resource owner password, access token). The authorization method depends on the authorization method requested by the client and the authorization methods supported by the authorization server.
[0076] (C) The client authenticates with the authorization server and submits authorization credentials to request an access token.
[0077] (D) The authorization server authenticates the client and verifies the authorization credentials. If valid, it issues an access token.
[0078] (E) The client requests services from the resource server using an access token, such as requesting protected resources.
[0079] (F) The resource server verifies the access token. If valid, it provides services, such as returning the protected resource.
[0080] For more detailed information about the OAuth 2.0 protocol, please refer to the description in the relevant protocols of the Internet Engineering Task Force (IETF), which will not be described in detail here.
[0081] II. Service Authorization Based on OAuth 2.0
[0082] Currently, to enhance network security, 3GPP 33.501 defines a service authorization mechanism based on the OAuth 2.0 protocol among network function (NF) service consumers (cNFs), network repository functions (NRFs), and NF service providers / producers. The NF service consumer corresponds to the client in OAuth 2.0, the NRF corresponds to the authorization server in OAuth 2.0, and the NF service provider corresponds to the resource server in OAuth 2.0. Specifically, when an NF needs to obtain a service from another NF, the NF requesting the service can be called the NF service consumer, and the NF requesting the service can be called the NF service provider. The NF service consumer can send a service request to the NF service provider, and the NF service provider can accept the service request from the NF service consumer and send a service response to the NF service consumer. It should be noted that in the embodiments of this application, the concepts of NF service consumer and NF service provider are relative. Any network element can act as both an NF service consumer and an NF service provider.
[0083] The overall process of NF service mainly includes three stages:
[0084] 1. NF service providers register with NRF;
[0085] 2. NF service consumption direction NRF request access token;
[0086] 3. NF service consumption direction: NF service provider requests services.
[0087] The process for the first stage (pNF registration) is as follows (see reference). Figure 1 As shown:
[0088] 101. The NF service provider sends an NF registration request to the NRF.
[0089] For example, when an NF service provider comes online, it can send an NF registration request to the NRF. The NF registration request may include the NF type of the NF service provider, the NF instance ID of the NF service provider, the services provided by the NF service provider (such as the NF service name), the scope of authorization, and information about the slice to which the NF service provider belongs (or information about the slice of the NF service provider's services). The scope of authorization may include the cNF types authorized by the NF service provider and / or the NF service consumer instances authorized by the NF service provider. Alternatively, the scope of authorization may include the services / resources authorized by the NF service provider and the operations allowed on those authorized resources (or service operations). Alternatively, the scope of authorization may include a combination of the above two methods, such as including the services / resources authorized for each cNF type and the operations allowed on those authorized resources (or service operations). The cNF types authorized by the NF service provider are the NF types of NF service consumers that are allowed to access the corresponding services provided by the NF service provider. The slice information may include network slice selection assistance information (NSSAI) and / or network slice instance identifier (NSIID). NSSAI can be single network slice selection assistance information (S-NSSAI).
[0090] It should be understood that an NF registration request may include more or less information. For example, an NF registration request may also include a public land mobile network identifier (PLMN ID), an NF set ID, and / or an NF service set ID.
[0091] 102. NRF stores the NF profile of the NF service provider.
[0092] After receiving an NF registration request from an NF service provider, the NRF can create an NF profile for the NF service provider to record relevant information, such as the information carried in the NF registration request.
[0093] 103. NRF sends an NF registration response to the NF service provider.
[0094] The NRF sends an NF register response to the NF service provider. The NF register response includes the registration result (success or failure).
[0095] The second phase of the process (CNF request access token) is referenced. Figure 2 As shown:
[0096] 201.NF service consumer sends an access token request to NRF.
[0097] For example, to obtain a desired NF service, an NF service consumer can send an access token get request to the NRF. The access token request may include the desired NF service name, the desired NF type of the NF service provider, or the desired NF instance identifier of the NF service provider. The access token request may also include the NF type of the NF service consumer, the NF service consumer's PLMNID, the NF instance identifier of the NF service consumer, the slice information of the desired NF service provider, the NF set identifier of the desired NF service provider, and / or the NF service set identifier.
[0098] Specifically, the NF service consumer can obtain all or part of the information carried in the access token request based on pre-configured NF service provider information, or through information obtained from the service discovery process. For example, regarding the service discovery process, in some possible implementations, when an NF service consumer needs to request a service, it can send a service discovery request to the NRF. This request may include the desired NF service name, the desired NF instance's NF type, and the NF type of the NF service consumer. The NRF can obtain information about one or more NF service providers that meet the corresponding conditions, such as NF instance ID and NFset ID, based on the NF profile of the registered NF. The NRF can then send a service discovery response to the NF service consumer, which may include information about the one or more NF service providers.
[0099] For example, prior to step 201, the NF service consumer can register with the NRF.
[0100] 202.NRF determines whether the NF service requested by the NF service consumer is authorized. If authorized, it generates an access token.
[0101] After receiving an access token request from an NF service consumer, the NRF can determine whether the NF service requested by the NF service consumer is authorized. If authorized, it can generate an access token; otherwise, it can send an error response to the NF service consumer.
[0102] For the specific process of NRF determining whether the NF service requested by the NF service consumer is authorized, please refer to section 13.4.1.1 of 33.501.
[0103] Access tokens may include the NRF's NF instance identifier (issuer), the NF instance identifier of the NF service consumer, the NF type or NF instance identifier of the NF service provider, and the desired service name (scope). Access tokens may also include the NF service provider's slice information, the access token's validity period, the NF set identifier of the NF service provider, and / or the NF service set identifier.
[0104] 203. NRF sends an access token get response to the NF service consumer, including the access token.
[0105] The third stage of the process (cNF requesting services from pNF via access token) is referenced below. Figure 3 As shown:
[0106] 301.NF service consumer sends a service request, including an access token, to NF service provider.
[0107] The 302.NF service provider verifies the access token; if the verification passes, the service is provided.
[0108] For example, after receiving a service request from an NF service consumer, the NF service provider can verify the integrity of the access token and the information in the access token (such as checking whether the information in the access token is consistent with the service request). After the verification is successful, the NF service provider can provide the corresponding service to the NF service consumer.
[0109] 303. The NF service provider sends a service response to the NF service consumer.
[0110] For a more detailed description of the above three stages, please refer to the relevant content in 33.501 and 23.502.
[0111] III. Access Token Format
[0112] Access token formats include single-signature and multi-signature formats.
[0113] Single signature format:
[0114] Header:{
[0115] Algorithm type (alg): hybrid
[0116] Token type (typ): JWT
[0117] }
[0118] Payload:{
[0119] Issuer: nrf
[0120] Award recipient: amf
[0121] Scope: nfm
[0122] Validity period: 232
[0123] }
[0124] Signature:{
[0125] Signature algorithm (sig_alg): HS384
[0126] Signature (sig):xxxxxx
[0127] }
[0128] Multi-signature format:
[0129] Header:{
[0130] Algorithm type (alg): hybrid
[0131] Token type (typ): JWT
[0132] }
[0133] Payload:{
[0134] Issuer: nrf
[0135] Award recipient: amf
[0136] Scope: nfm
[0137] Validity period: 232
[0138] }
[0139] Signature:{
[0140] Signature Algorithm 1 (sig1_alg): HS384
[0141] Signature 1 (sig1):xxxxxx
[0142] Signature Algorithm 2 (sig2_alg): ml-dsa
[0143] Signature 2 (sig2):xxxxxx
[0144] }
[0145] It should be understood that the access token format described above is merely an illustrative example and can be adjusted according to actual circumstances. For example, the payload portion may also include more information, such as the slice information of the NF service provider, the NF set identifier of the NF service provider, and / or the NF service set identifier.
[0146] IV. Mixed Signature Method (Hybrid Signature Mode)
[0147] Signature hybrid methods include independent signatures, protocol-level binding, algorithm-level binding, and cascading signatures.
[0148] Assuming Algorithm 1 is ed25519 and Algorithm 2 is ml-dsa, the following are examples of signatures using various signature mixing methods:
[0149] 1. Independent signature (two signatures)
[0150] sig1 = md - dsa.sign(m)
[0151] sig2 = ed25519.sign(m)
[0152] 2. Protocol-level binding (two signatures)
[0153] sig1 = ml-dsa.sign(m||“There is also an ed25519 signature”)
[0154] sig2 = ed25519.sign(m||“An ml-dsa signature also exists”)
[0155] 3. Algorithm-level binding (a signature)
[0156] Private key (private_key) = composite_key (private_key_mldsa, private_key_ed25519)
[0157] sig=composite_sig(composite_alg||message,private_key)
[0158] 4. Cascading signatures (one signature)
[0159] Sig1 = ml - dsa.sign(m)
[0160] Sig2 = ed25519.sign(m||sig1)
[0161] V. Algorithm Suite
[0162] In this embodiment, the algorithm suite (or signature algorithm suite) includes a signature method (signature mode) and / or the signature algorithm corresponding to the signature method. For an NRF, if the NRF supports an algorithm suite, it indicates that the NRF can generate signatures based on that algorithm suite. For an NF service provider, if the NF service provider supports an algorithm suite, it indicates that the NF service provider can verify signatures generated based on that algorithm suite.
[0163] For example, signature methods can include non-hybrid signature methods, independent signature methods, protocol-level binding methods, algorithm-level binding methods, and concatenated signature methods. Non-hybrid signature methods are also traditional signature methods, using a single signature algorithm to generate the signature. For example, algorithm suite 1 can be a non-hybrid signature method + HS384 signature algorithm; algorithm suite 2 can be a non-hybrid signature method + ed25519 signature algorithm; algorithm suite 3 can be an independent signature method + es256 signature algorithm and ml-dsa signature algorithm; and algorithm suite 4 can be a concatenated signature method + ed25519 signature algorithm and slh-dsa signature algorithm.
[0164] Currently, the IETF specifies the classical signature algorithms supported by the OAuth protocol. Because these algorithms are widely used and lack significant capability differences, for service authorization mechanisms between NF service consumers, NRFs, and NF service providers, NRFs typically support multiple fixed classical signature algorithms, and NF service providers support signature verification based on these algorithms. In this scenario, an NRF can usually be configured or activated with one signature algorithm, which can then be used to sign access tokens. The NF service provider can then verify this signature using the corresponding verification algorithm. However, with the development of computer technology (such as quantum computing), signatures using a single classical algorithm may be cracked by quantum computers in the future, posing a security risk. Therefore, to improve security, access token signing may require a mixture of algorithms (such as a mixture of classical and post-quantum algorithms). The signature mixing method can also include multiple approaches. In other words, an NRF may need to support more signature algorithms and one or more hybrid signature methods. Correspondingly, an NF service provider may need to support the verification of more signature algorithms and one or more hybrid signature methods.
[0165] Based on the above description, it is clear that in the future, different NRFs in the network may support different signature algorithms and hybrid signature methods, and different NF service providers may support different signature verification algorithms and hybrid signature methods. For example, different algorithm suites require different network element capabilities and resources. In this case, limited by the network element's capabilities (such as operator computing power) and resources (such as storage resources), different network elements will support different algorithm suites. Furthermore, existing network elements may not be updated in the future, only supporting non-hybrid signature methods and classic signature algorithms, while newly added network elements may support multiple hybrid signature methods and post-quantum algorithms.
[0166] In the above scenario, in order to ensure that NF service consumers can obtain NF services and that network security is maintained during the process of NF service consumers obtaining NF services, it is necessary to redesign the overall process related to NF services.
[0167] To better understand the embodiments of this application, the system architecture of the embodiments of this application will be described below.
[0168] Please see Figure 4 , Figure 4 This is a schematic diagram of a network architecture disclosed in an embodiment of this application. Figure 4The network architecture described herein can be a serv-based architecture (SBA) for 5th generation (5G) networks, but it should be understood that the 5G network described herein is merely an example and should not constitute any limitation on this application.
[0169] like Figure 4 As shown, the network architecture may include, but is not limited to, the following network elements (or network functions, functional network elements, functional entities, nodes, devices, etc.): access and mobility management function (AMF) network elements, session management function (SMF) network elements, policy control function (PCF) network elements, unified data management (UDM) network elements, application function (AF) network elements, authentication server function (AUSF) network elements, network slice selection function (NSSF) network elements, network exposure function (NEF) network elements, and network repository function (NRF) network elements.
[0170] Among them, the NRF network element can be responsible for the registration and discovery functions of network elements, as well as the issuance of access tokens, and maintain the information of network elements, such as network element type (NFtype), Internet protocol address (IP) address, network element capabilities, supported services, etc.
[0171] In a service-oriented architecture, network elements can interact through service-oriented interfaces, such as SBA interfaces like Nnssf, Nausf, Nnef, Namf, Npcf, Nsmf, Nudm, and Naf. For example, an AMF network element can interact with an NRF network element through the Nnrf interface to use the services provided by the NEF network element. Similarly, an NRF network element can interact with a UDM network element through the Nudm interface to use the services provided by the UDM network element. (About...) Figure 4For detailed descriptions of service interfaces such as Nnssf, Nausf, Nnef, Namf, Npcf, Nsmf, Nudm, and Naf, as well as network elements such as AMF, SMF, PCF, AUSF, UDM, and AF, please refer to the relevant content in the 3GPP standard protocol.
[0172] In this embodiment, the algorithm suites supported by each network element may differ. When each network element registers with the NRF, it can include its own supported algorithm suites. Subsequently, when the NRF receives an access token request, it can select an algorithm suite based on the algorithm suites supported by the registered network elements and the relevant information carried in the access token request, and then generate a signature based on the selected algorithm suite.
[0173] Please see Figure 5 , Figure 5 This is a schematic diagram of a network architecture for multi-generational network element integration disclosed in an embodiment of this application. For example... Figure 5 As shown, this network architecture can include 5G network elements such as SMF and AMF, as well as future network elements such as access management (AM), session management (SM) / mobility management (MM), and UDM, NRF, and user plane function (UPF) shared by multiple networks (such as 5G and future networks). Network elements in each network can be connected to the SBA bus and interact through service-oriented interfaces.
[0174] For example, in the aforementioned multi-generational network element convergence network architecture, different network elements may support different algorithm suites. For instance, 5G network elements may only support non-hybrid signature methods and classic signature algorithms (or traditional signature algorithms), while network elements in future networks may only support multiple hybrid signature methods and multiple post-quantum algorithms. Shared network elements may include those supporting non-hybrid signature methods and classic signature algorithms, as well as those supporting multiple hybrid signature methods and multiple post-quantum algorithms. In this case, when the NRF generates an access token, it needs to select an appropriate signature algorithm to ensure that the NF service consumer can obtain services from the NF service provider based on the access token.
[0175] It should be understood that Figure 4 and Figure 5 The architecture shown is merely an illustrative example. Figure 4 and Figure 5 The architecture shown may also include other devices / network elements, but this application embodiment does not limit this.
[0176] It should also be understood that the aforementioned network elements or functions can be implemented in the form of hardware, computer software, or a combination of hardware and computer software. For example, the aforementioned network elements or functions can be implemented by a single device, by multiple devices working together, or by a functional module within a single device; this application embodiment does not limit this.
[0177] Furthermore, the aforementioned "network element" can also be referred to as an entity, device, or module, etc., and this application does not limit it in this way. Also, for ease of description, the term "network element" is omitted in some of the following descriptions. For example, an NRF network element may be abbreviated as NRF. In this case, "NRF" should be understood as an NRF network element or an NRF entity, and a similar understanding should be applied to other network elements or functions. That is to say, function, functional network element, and functional entity can be equivalent.
[0178] Some scenarios in this application embodiment are illustrated using a 5G communication system as an example. However, it should be understood that the solutions in this application embodiment can also be applied to other communication systems, such as networks integrating multiple systems, multi-band communication systems, future communication systems, frequency division duplex (FDD) systems, time division duplex (TDD) systems, etc. The corresponding device / network element names can also be replaced by the names of corresponding functions / devices in other communication systems.
[0179] In the embodiments of this application, the term "wireless communication" can also be abbreviated as "communication", and the term "communication" can also be described as "data transmission", "information transmission" or "transmission".
[0180] In this embodiment, NRF network elements and authorized servers can be interchanged, clients and NF service consumers can be interchanged, and resource servers can be interchanged with NF service providers.
[0181] It should be noted that the system architecture, network architecture, and business scenarios (or application scenarios) described in the embodiments of this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the evolution of communication network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.
[0182] In this embodiment of the application, in order to ensure that NF service consumers can obtain NF services and to ensure network security, the NF service-related processes have been adjusted, including the NF service provider registration process, the NF service discovery process, the NF service consumer requesting an access token process, and the NF service consumer requesting services from the NF service provider through the access token process.
[0183] The technical solution provided in this application is described below. In the following description, the first network element can be a credential-providing network element, such as an NRF network element; the second network element can be a service-requesting network element, such as an NF service consumer; and the third network element can be a service-providing network element, such as an NF service provider.
[0184] Please see Figure 6 , Figure 6 This is a flowchart illustrating a communication method disclosed in an embodiment of this application. Figure 6 The process can provide an NRF request registration process for NF services. For example... Figure 6 As shown, the method may include, but is not limited to, the following steps:
[0185] 601. The target second network element sends a third request message to the first network element. The third request message is used to request network function registration and includes the first algorithm information.
[0186] In this embodiment of the application, different second network elements may support different algorithm suites, that is, different second network elements may support different algorithm suites for signature verification. For example, for PCF network element 1 and PCF network element 2, PCF network element 1 may support 2 algorithm suites, such as algorithm suite 1 (non-hybrid signature method + ed25519) and algorithm suite 2 (non-hybrid signature method + ml-dsa), while PCF network element 2 may support 4 algorithm suites, such as algorithm suite 1, algorithm suite 2, algorithm suite 3 (independent signature method + ed25519 and ml-dsa) and algorithm suite 4 (protocol-level binding method + HS384 and slh-dsa).
[0187] To address the aforementioned scenario and facilitate subsequent signing of the access token by the first network element, when a second network element requests registration from the first network element, it can include information indicating the algorithm suite it supports in the NF registration request message. For example, the target second network element can send a third request message (NF registration request message) to the first network element. This third request message requests network function registration and includes the first algorithm information. Correspondingly, the first network element can receive the third request message from the target second network element. The target second network element can be any second network element in the network. For example, the algorithm information in this embodiment can also be referred to as an algorithm list, such as the first algorithm information being referred to as the first algorithm list.
[0188] The first algorithm information can be used to indicate the N algorithm suites supported by the target second network element, where N is a positive integer. The algorithm suite can include a signature method and the corresponding signature algorithm. It should be understood that the first algorithm information can indicate the N algorithm suites in various ways; several examples are provided below. For instance, the first algorithm information can include an algorithm list (or a signature algorithm list) and / or a signature method list. For example, the first algorithm information can include algorithm list 1 [signature algorithm 1, signature algorithm 2, signature algorithm 3, signature algorithm 4] and signature method list 1 [signature method 1, signature method 2]. In this case, it can indicate that the target second network element supports the three signature methods in signature method list 1, and each signature method can support the corresponding algorithm in algorithm list 1. Assuming signature method 1 is an independent signature method and signature method 2 is a protocol-level binding method, in this case, the target second network element supports a total of 12 algorithm suites. For example, the first algorithm information may only include Algorithm List 1 [Signature Algorithm 1, Signature Algorithm 2, Signature Algorithm 3, Signature Algorithm 4], excluding the signature method list. In this case, it can indicate that the target second network element only supports non-hybrid signature methods, or that the target second network element only supports hybrid signature methods, or that the target second network element supports all signature methods (such as non-hybrid signature methods + hybrid signature methods), or that the target second network element supports one or more specific signature methods. The specific choice can be defined by the protocol or negotiated in advance between the network elements. Similarly, the first algorithm information may only include Signature Method List 1 [Signature Method 1, Signature Method 2], excluding the algorithm list. In this case, it can indicate that the target second network element only supports classical signature algorithms, or that the target second network element only supports post-quantum signature algorithms, or that the target second network element supports all signature algorithms (such as classical signature algorithms + post-quantum signature algorithms), or that the target second network element supports one or more specific signature algorithms. The specific choice can be defined by the protocol or negotiated in advance between the network elements. It should be understood that the first algorithm information may include multiple algorithm lists and / or signature method lists, and each algorithm list may be associated with one or more signature method lists. For example, the first algorithm information may include an algorithm suite list, which may include the N algorithm suites. For instance, assuming N is 3, the first algorithm information may include algorithm suite 1 (non-hybrid signature method + ml-dsa signature algorithm), algorithm suite 2 (independent signature method + ed25519 and ml-dsa), and algorithm suite 3 (protocol-level binding method + HS384 and ml-dsa). In some possible implementations, the algorithm suite may also include a signature algorithm or a signature method. Where the algorithm suite includes a signature method, it can be assumed that each second network element supports the same signature algorithm; where the algorithm suite includes a signature algorithm, it can be assumed that each second network element supports the same signature method.
[0189] In some possible implementations, the N algorithm suites have priorities, and the target second network element can indicate the priorities of the N algorithm suites to the first network element. For example, the target second network element can indicate the priorities of the N algorithm suites by the order of the various signature algorithms and / or signature methods in the first algorithm information. For example, assuming that the first algorithm information includes algorithm list 1 [signature algorithm 1, signature algorithm 2, signature algorithm 3, signature algorithm 4] and signature method list 1 [signature method 1, signature method 2, signature method 3], the corresponding signature algorithm priorities can be: signature algorithm 1 > signature algorithm 2 > signature algorithm 3 > signature algorithm 4, and the corresponding signature method priorities can be: signature method 1 > signature method 2 > signature method 3.
[0190] It should be understood that the target second network element can indicate the corresponding signature algorithm through an algorithm identifier, which can be an algorithm name or an algorithm index, etc. The target second network element can also indicate the corresponding signature method through a signature method identifier, which can be a signature method name or a signature method index, etc. The target second network element can also indicate the corresponding algorithm suite through an algorithm suite identifier, which can be an algorithm suite name or an algorithm suite index, etc. It is understood that the implementation of the second, third, fourth, and fifth algorithm information described below is similar to that of the first algorithm information, and the description of the first algorithm information above can be referred to.
[0191] In some possible implementations, the N algorithm suites are associated with at least one of the following: the network element type (NFtype) of the third network element, the network element instance (NFinstance) of the third network element, network slices, and network function services (NF services). That is, the N algorithm suites can be associated with one or more of the following: the NF type of the third network element, the network element instance of the third network element, network slices, and network function services. The target second network element can indicate the association to the first network element, and correspondingly, the first network element can store the association. For example, suppose the NF services provided by the target second network element include service 1 (such as Nudm_UERegistration) and service 2. The N algorithm suites include algorithm suite 1, algorithm suite 2, and algorithm suite 3. Service 1 can be associated with algorithm suite 1 (such as algorithm-level binding +ml-dsa and es256), and service 2 can be associated with algorithm suite 2 and algorithm suite 3. In this case, when a subsequent third network element accesses service 1 of the target second network element, it needs to provide a valid access token based on the signature of algorithm suite 1. When accessing service 2 of the target second network element, it needs to provide a valid access token based on the signature of either algorithm suite 2 or algorithm suite 3. The NF service can be indicated by network function service identifiers, such as NF service name or NF service index. For another example, suppose the third NF type of the target second network element includes type 1 (such as UDM) and type 2, and the N algorithm suites include algorithm suite 1, algorithm suite 2 and algorithm suite 3. Type 1 can be associated with algorithm suite 1, and type 2 can be associated with algorithm suite 2 and algorithm suite 3. In this case, when the third network element of type 1 accesses the service of the target second network element, it needs to provide a valid access token based on the signature of algorithm suite 1, while when the third network element of type 2 accesses the service of the target second network element, it needs to provide a valid access token based on the signature of algorithm suite 2 or algorithm suite 3. For another example, suppose the slices served by the target second network element include slice 1 and slice 2. Slices 1 and 2 can be identified by corresponding slice information, such as S-NSSAI, network slice instance identifier (NSI ID), etc. The N algorithm suites include algorithm suite 1, algorithm suite 2, and algorithm suite 3. Slice 1 can be associated with algorithm suite 1, and slice 2 can be associated with algorithm suite 2 and algorithm suite 3. In this case, when a third network element serving slice 1 accesses the service of the target second network element, it needs to provide a valid access token based on the signature of algorithm suite 1. When a third network element serving slice 2 accesses the service of the target second network element, it needs to provide a valid access token based on the signature of algorithm suite 2 or algorithm suite 3.For another example, suppose the third network element accessing the target second network element includes third network element instance 1 and third network element instance 2, and the N algorithm suites include algorithm suite 1, algorithm suite 2, and algorithm suite 3. Third network element instance 1 can be associated with algorithm suite 1, and third network element instance 2 can be associated with algorithm suite 2 and algorithm suite 3. In this case, when third network element instance 1 accesses the service of the target second network element, it needs to provide a valid access token based on the signature of algorithm suite 1, while when third network element instance 2 accesses the service of the target second network element, it needs to provide a valid access token based on the signature of algorithm suite 2 or algorithm suite 3. The third network element instance can be indicated by an NF instance identifier.
[0192] The above description provides an example of how an algorithm suite can be associated with one of the following: the NF type of a third network element, the network element instance of the third network element, network slices, and network function services. Furthermore, an algorithm suite can also be associated with multiple of the following: the NF type of a third network element, the network element instance of the third network element, network slices, and network function services. For example, suppose the slices served by the target second network element include slice 1 and slice 2, and the NF services provided by the target second network element include service 1 and service 2. The N algorithm suites include algorithm suite 1, algorithm suite 2, and algorithm suite 3. Slice 1 + service 1 and slice 1 + service 2 can be associated with algorithm suite 1, slice 2 + service 1 can be associated with algorithm suite 2, and slice 2 + service 2 can be associated with algorithm suite 3. In this case, when a third network element serving slice 1 accesses service 1 or service 2 of the target second network element, it needs to provide a valid access token based on the signature of algorithm suite 1. When a third network element serving slice 2 accesses service 1 of the target second network element, it needs to provide a valid access token based on the signature of algorithm suite 2. When a third network element serving slice 2 accesses service 2 of the target second network element, it needs to provide a valid access token based on the signature of algorithm suite 3. Similarly, other cases of an algorithm suite being associated with the NF type of a third network element, the network element instance of the third network element, network slices, and multiple network function services can be understood in a similar way, and will not be described in detail here. It should be understood that when an algorithm suite is associated only with the NF type of a third network element, it can be assumed that the algorithm suite has no restrictions on the network element instance, network slice, network function services, etc. of the third network element. Similarly, when an algorithm suite is associated only with a network slice, it can be assumed that the algorithm suite has no restrictions on the NF type, network element instance, network function services, etc. of the third network element.
[0193] It should be understood that, in addition to the NF type, network element instance, network slice, and network function service of the third network element mentioned above, the algorithm suite can also be associated with other information, such as service operation, PLMN identifier, network function, etc., and this application embodiment does not limit this.
[0194] The aforementioned method of associating algorithm suites with one or more of the following: the NF type of the third network element, the network element instance of the third network element, network slicing, and network function services. This facilitates the targeted configuration of algorithm suites supported by the target second network element for different situations, improving the flexibility of algorithm suite configuration. For example, different algorithm suites may have different computational complexity, generated signature length, and security requirements. Furthermore, different NF services, third network elements with different NF types, different network slices, and different third network element instances have different security requirements. Therefore, the algorithm suites supported by the target second network element can be configured specifically according to different situations to achieve lower computational complexity and shorter generated signature lengths while meeting security requirements. For example, suppose the target second network element provides NF services including service 1 and service 2, and supports algorithm suites including algorithm suite 1 and algorithm suite 2. Algorithm suite 2 has higher security than algorithm suite 1, higher computational complexity, and generates a longer signature than algorithm suite 1. In this case, if service 1 requires higher security but service 2 has lower security requirements, service 1 can be associated with algorithm suite 1 to ensure its security. Alternatively, service 2 can be associated with algorithm suite 2 to ensure its security while saving resources for signature generation and transmission. Furthermore, for different NF types, network element instances, and network slices of the third network element, the algorithm suites supported by the target second network element can be configured specifically. It should be understood that configuring one or more specific algorithm suites for different situations can also prevent degradation attacks.
[0195] In some possible implementations, the first network element may also be configured (e.g., pre-configured) with one or more of the following: algorithm suites corresponding to NF set identifiers, algorithm suites corresponding to NF types, etc. For example, for an NF set identifier, the first network element can determine the algorithm suite corresponding to that NF set identifier based on the algorithm suites supported by all currently registered second network elements associated with that NF set identifier (the second network element whose NF set identifier is that NF set identifier). For instance, NF set identifier 1 is associated with second network element instance 1 and second network element instance 2. Second network element instance 1 supports algorithm suite 1, algorithm suite 2, and algorithm suite 3, and second network element instance 2 supports algorithm suite 1, algorithm suite 2, and algorithm suite 4. The first network element can determine the algorithm suite corresponding to NF set identifier 1 as the algorithm suite supported by both second network element instance 1 and second network element instance 2. As another example, for an NF type, the first network element can determine the algorithm suite corresponding to that NF type based on the algorithm suites supported by all currently registered second network elements belonging to that NF type. For example, NF type 1 is associated with second network element instance 1 and second network element instance 2. Second network element instance 1 supports algorithm suite 1, algorithm suite 2 and algorithm suite 3. Second network element instance 2 supports algorithm suite 1, algorithm suite 2 and algorithm suite 4. The first network element can determine the algorithm suite (algorithm suite 1 and algorithm suite 2) supported by both second network element instance 1 and second network element instance 2 as the algorithm suite corresponding to NF type 1.
[0196] It should be understood that the third request message may include more information, as can be found in the description of the NF registration request in step 101 above, and in the relevant descriptions in protocols 33.501 and 23.502. For example, the third request message may also include the address of the target second network element, such as its IP address.
[0197] 602. The first network element sends a third response message to the target second network element. The third response message includes the registration result.
[0198] Accordingly, the target second network element can receive the third response message (NF registration response message) from the first network element.
[0199] In this embodiment, the first network element can obtain third algorithm information, which can be used to indicate K algorithm suites supported by the first network element, where K is a positive integer. For example, the third algorithm information can be pre-configured. For instance, the first network element can pre-store the third algorithm information (such as NRF_alg_list).
[0200] In some possible implementations, after receiving a third request message from the target second network element, the first network element can determine the registration result based on the first algorithm information and the third algorithm information carried in the third request message. For example, if the first network element determines that the N algorithm suites and the K algorithm suites include at least one identical algorithm suite, it indicates that the first network element has a usable algorithm suite (the N algorithm suites and the identical algorithm suites among the K algorithm suites) to sign the access token used to access the target second network element, and the first network element can determine that the target second network element has successfully registered, i.e., the registration result is successful registration. Conversely, if the first network element determines that the N algorithm suites and the K algorithm suites are all different, i.e., they do not include any identical algorithm suites, it indicates that the first network element does not have a usable algorithm suite to sign the access token used to access the target second network element, and the first network element can determine that the target second network element has failed to register, i.e., the registration result is failed registration. It should be understood that the above descriptions of successful and failed registration are merely illustrative and do not constitute a limitation. For example, in some other possible cases, when the N algorithm suites and the K algorithm suites include at least two identical algorithm suites, the first network element can determine that the target second network element has successfully registered; otherwise, it can determine that the target second network element has failed to register. As another example, in some further possible cases, when the N algorithm suites are a subset of the K algorithm suites, the first network element can determine that the target second network element has successfully registered; otherwise, it can determine that the target second network element has failed to register.
[0201] In some possible implementations, the K algorithm suites supported by the first network element can be associated with network slices. For example, the first network element supports algorithm suites 1-3, algorithm suite 1 is associated with slices 1 and 2, algorithm suite 2 is associated with slice 2, and algorithm suite 3 is associated with slice 3. In this case, if the N algorithm suites supported by the target second network element are also associated with network slices, the first network element needs to compare the algorithm suites associated with the first network element and the target second network element with the same slice. For example, assuming both the first network element and the target second network element serve slice 1, the first network element can determine whether the algorithm suites supported by the first network element and associated with slice 1 are the same as those supported by the target second network element and associated with slice 1. If the first network element and the target second network element have the same algorithm suite associated with a certain slice, the first network element can determine that the target second network element has successfully registered; otherwise, it can determine that the target second network element has failed to register.
[0202] When the target second network element successfully registers (the registration result is "registration successful"), the first network element can store second algorithm information and / or first algorithm information. For example, when the target second network element successfully registers, the first network element can store the NF configuration file of the target second network element, which may include second algorithm information and / or first algorithm information. The second algorithm information can be used to indicate the M algorithm suites supported by the first network element out of the N algorithm suites. These M algorithm suites are the intersection of the N algorithm suites and the K algorithm suites (the N algorithm suites and the K algorithm suites contain the same algorithm suites), where M is a positive integer less than or equal to K and N. In some possible implementations, if M equals N, meaning the K algorithm suites include the N algorithm suites, the first network element may not need to carry the second algorithm information in the third response message; it can carry the registration result instead. After receiving the third response message, the target second network element can determine that the first network element supports the N algorithm suites based on the registration result and the absence of second algorithm information.
[0203] If the target second network element successfully registers, the third response message may also include second algorithm information. Upon receiving the second algorithm information, the target second network element can perform further processing. For example, the second network element can determine whether the M algorithm suites include one or more specific algorithm suites. If not, the second network element can continue to request NF registration from other first network elements and can register with the currently registered first network element.
[0204] If the target second network element successfully registers, the third response message may also include the public keys of the M algorithm suites. The target second network element may store the public keys of the M algorithm suites. The public keys of the M algorithm suites can be used by the target second network element to verify the signature generated by the first network element based on the relevant algorithm suites. For example, if the M algorithm suites include algorithm suite 1, and the first network element subsequently signs the access token based on algorithm suite 1, the target second network element can verify the signature of the access token based on the public key corresponding to algorithm suite 1.
[0205] In some possible implementations, the first network element can support all algorithm suites that the third network element may support. In this case, after receiving the third request message from the target second network element, the first network element can directly store the first algorithm information. Furthermore, the first network element does not need to determine the registration result based on the first and third algorithm information. For example, assuming that all algorithm suites that the third network element may support include algorithm suite 1 to algorithm suite 10, and these N algorithm suites may include one or more of algorithm suites 1 to 10 (e.g., N is 3, and the N algorithm suites are algorithm suites 1 to 3), in this case, the first network element can directly store the first algorithm information.
[0206] Please see Figure 7 , Figure 7 This is a flowchart illustrating another communication method disclosed in an embodiment of this application. Figure 7 The process can be the process by which an NF service consumer requests service discovery from an NRF requester. For example... Figure 7 As shown, the method may include, but is not limited to, the following steps:
[0207] 701. The target third network element sends a second request message to the first network element. The second request message is used to request service discovery and includes fourth algorithm information.
[0208] Accordingly, the first network element can receive a second request message (service discovery request message) from the target third network element. This second request message includes fourth algorithm information, which indicates L algorithm suites, where L is a positive integer. These L algorithm suites can be algorithm suites supported by the second network element instance that the target third network element expects. For example, the second request message may include NF capacity information of the expected second network element instance, which may include the fourth algorithm information.
[0209] It should be understood that the second request message may also include more information, such as the expected NF service identifier (e.g., the expected NF service name), the NF type of the expected second network element instance, the NF type of the target third network element, the NF instance identifier of the target third network element, slice information (e.g., S-NSSAI), and other information related to NF services. These are not limited here, and for details, please refer to the description in the relevant protocol (e.g., 23.502).
[0210] 702. The first network element sends a second response message to the target third network element. The second response message includes information for instructing one or more second network elements.
[0211] After receiving the second request message from the target third network element, the first network element can identify one or more second network elements based on the information carried in the second request message. Then, it can send a second response message (service discovery response message) to the target third network element. The second response message includes information indicating the identified one or more second network elements (such as NF instance identifiers, NF addresses, etc.). Correspondingly, the target third network element can receive the second response message from the first network element.
[0212] For example, the information used to indicate one or more second network elements can be an NF instance identifier of the one or more second network elements, or it can be an NF set identifier of the one or more second network elements.
[0213] When the second request message includes fourth algorithm information, the first network element can determine one or more second network elements based on the fourth algorithm information. These one or more second network elements support at least one of the L algorithm suites indicated by the fourth algorithm information. For example, the first network element can determine one or more second network elements that match the fourth algorithm information (supporting at least one of the L algorithm suites) based on the NF profile of currently registered second network elements. The NF profile of a second network element includes its second algorithm information and / or first algorithm information. It should be understood that the one or more second network elements determined by the first network element are second network elements that support at least one of the L algorithm suites, but this application embodiment does not limit this. In some possible implementations, the one or more second network elements determined by the first network element can also be second network elements that support at least two of the L algorithm suites. In yet another possible implementation, the first network element can determine the top W second network elements that support the most of the L algorithm suites as the one or more second network elements, where W is a positive integer.
[0214] In some possible implementations, the algorithm suite is associated with at least one of the following: the NF type of the third network element, the NF instance of the third network element, network slicing, and network function service (NF service). In this case, the first network element can determine one or more second network elements that match the second request message based on the association between the algorithm suite supported by the registered second network element and one or more of the NF type, NF instance, network slicing, and network function service of the third network element, as well as the information such as the NF type of the target third network element, the NF instance identifier of the target third network element, slicing information, and the expected NF service identifier carried in the second request message. That is, it can determine one or more second network elements that match the information carried in the second request message. For example, suppose the registered second network element includes second network element instance 1, second network element instance 2, and second network element instance 3. Second network element instance 1 provides service 1, and service 1 of second network element instance 1 can be associated with algorithm suite 1 and algorithm suite 3. Second network element instance 2 provides service 1 and service 2, and service 1 of second network element instance 2 can be associated with algorithm suite 2 and service 2 of second network element instance 2 can be associated with algorithm suite 1. Second network element instance 3 provides service 1, and service 1 of second network element instance 3 can be associated with algorithm suite 1. The L algorithm suites include algorithm suite 1 and algorithm suite 3. The second request message includes the expected NF service identifier as the NF service name of service 1. In this case, the first network element can determine that second network element instance 1 and second network element instance 3 match the second request message, while second network element instance 2 does not match the second request message.
[0215] Optionally, the second response message may further include information indicating the algorithm suites among the L algorithm suites supported by each of the one or more second network elements. Further, the second response message may also include information indicating one or more of the following: the NF type, network element instance, network slice, network function service, etc., of the third network element associated with the algorithm suites among the L algorithm suites supported by each second network element. For example, if the second request message does not include fourth algorithm information, the second response message may include information about the algorithm suites supported by each of the one or more second network elements. If the one or more second network elements include the aforementioned target second network element, the second response message may include the aforementioned first algorithm information or second algorithm information.
[0216] It should be understood that the above description uses the fourth algorithm information matching as an example for illustrative purposes, but the embodiments of this application do not limit this. When the first network element determines one or more second network elements, it may also combine other information in the second request message, such as the expected NF service identifier, the NF type of the expected second network element instance, the NF type of the target third network element, the NF instance identifier of the target third network element, slice information (such as S-NSSAI), etc., which can be referred to in the description in relevant protocols (such as 23.502).
[0217] Please see Figure 8 , Figure 8 This is a flowchart illustrating another communication method disclosed in an embodiment of this application. Figure 8 The process can be the process of an NF service consumer requesting an access token from an NRF. For example... Figure 8 As shown, the method may include, but is not limited to, the following steps:
[0218] 801. The target third network element sends a first request message to the first network element. The first request message is used to request an access token and includes information for instructing one or more second network elements.
[0219] To obtain the desired NF service, the target third network element can send a first request message (access token request message) to the first network element, requesting an access token. Correspondingly, the first network element can receive the first request message from the target third network element.
[0220] For example, the information used to indicate one or more second network elements may include one or more of the following: the expected NF type of the second network element (such as the NF type of the one or more second network elements), the expected NF instance identifier of the second network element (such as the NF instance identifier of the one or more second network elements), the expected NF set identifier of the second network element (such as the NF set identifier of the one or more second network elements), the expected NF service set identifier (such as the NF service set identifier of the one or more second network elements), and the expected slice information of the second network element (such as the slice information of the one or more second network elements).
[0221] The first request message may also include a desired NF service identifier (such as a desired NF service name), that is, one or more of the following: the identifier of the requested authorized NF service, the NF type of the target third network element, the PLMN identifier of the target third network element, the NF instance identifier of the target third network element, and fifth algorithm information. The fifth algorithm information is used to indicate J algorithm suites. The J algorithm suites can be the algorithm suites desired by the target third network element, where J is a positive integer. It is hereby uniformly stated that the description of "desired" in the embodiments of this application is mainly for ease of understanding and does not constitute a limitation on the embodiments of this application. For example, the aforementioned desired NF service identifier is mainly used to represent the NF service identifier of the NF service that the target third network element expects to obtain, and the "desired NF service identifier" can also be referred to as the "NF service identifier".
[0222] In some possible implementations, the target third network element can first pass through Figure 7 The service discovery process shown discovers one or more second network elements, and then can send a first request message to the first network element. The first request message may include information indicating the discovered one or more second network elements. Optionally, when the target third network element passes through... Figure 7 When the service discovery process shown discovers multiple second network elements, the first request message may also include information indicating some of the multiple second network elements. For example, the second response message received by the target third network element from the first network element may include information indicating the algorithm suites among the L algorithm suites supported by each of the multiple second network elements. In this case, the target third network element can determine the second network element for which it needs to obtain an access token based on the algorithm suites among the L algorithm suites supported by each of the multiple second network elements. For example, assuming the discovered second network elements include second network element instance 1 and second network element instance 2, and second network element instance 1 supports algorithm suites 1 and 2, and second network element instance 2 supports algorithm suite 3, if the target third network element expects to sign the access token using algorithm suite 3, in this case, the target third network element can carry information indicating second network element instance 2 in the first request message.
[0223] 802. The first network element determines X algorithm suites based on the algorithm suites supported by the one or more second network elements.
[0224] For example, after receiving a first request message from a target third network element, the first network element can obtain the algorithm suites supported by the one or more second network elements based on the information carried in the first request message that indicates one or more second network elements. Then, it can determine X algorithm suites based on the algorithm suites supported by the one or more second network elements, where X is a positive integer. In some possible implementations, the value of X can be pre-configured, such as X being 1. It should be understood that since the first network element needs to generate a signature for the access token later, the algorithm suites supported by the one or more second network elements can be algorithm suites that the first network element also supports. In this embodiment, determining the algorithm suite can also be referred to as selecting the algorithm suite.
[0225] When the information used to indicate one or more second network elements includes the NF instance identifier of the desired second network element, the NF instance identifier of the desired second network element is the same as the NF instance identifier of the one or more second network elements. In this case, for multiple second network elements, the algorithm suite supported by the multiple second network elements can include the algorithm suite supported by each of the multiple second network elements. For example, the first network element can obtain first algorithm information or second algorithm information from the stored NF configuration file of the one or more second network elements. Alternatively, the algorithm suite supported by the multiple second network elements can include algorithm suites supported by all of the multiple second network elements.
[0226] When the information used to indicate one or more second network elements includes the expected NF type of the second network element, the first network element can determine the second network elements among the registered second network elements that are associated with that NF type (the second network element whose NF type is that NF type). These second network elements associated with that NF type are the one or more second network elements. In this case, for multiple second network elements, the algorithm suite supported by the multiple second network elements can include the algorithm suite supported by each of the multiple second network elements. Alternatively, the algorithm suite supported by the multiple second network elements can include the algorithm suite corresponding to the NF type, such as the algorithm suite supported by all of the multiple second network elements.
[0227] When the information used to indicate one or more second network elements includes the NF set identifier of the desired second network element, the first network element can determine the second network elements among the registered second network elements that are associated with the NF set identifier (the second network element whose NF set identifier is the NF set identifier). These second network elements associated with the NF set identifier are the one or more second network elements. In this case, for multiple second network elements, the algorithm suite supported by the multiple second network elements can include the algorithm suite supported by each of the multiple second network elements. Alternatively, the algorithm suite supported by the multiple second network elements can include the algorithm suite corresponding to the NF set identifier, such as the algorithm suite supported by all the multiple second network elements.
[0228] When the information used to indicate one or more second network elements includes a desired NF service set identifier, the first network element can determine the second network elements among the registered second network elements that are associated with the NF service set identifier (the second network elements that support the service corresponding to the NF service set identifier). These second network elements associated with the NF service set identifier are the one or more second network elements. In this case, for multiple second network elements, the algorithm suite supported by the multiple second network elements can include the algorithm suite supported by each of the multiple second network elements. Alternatively, the algorithm suite supported by the multiple second network elements can include the algorithm suite corresponding to the NF service set identifier, such as the algorithm suite supported by all the multiple second network elements.
[0229] When the information used to indicate one or more second network elements includes the slice information of the desired second network element, the first network element can determine the second network elements among the registered second network elements that are associated with the slice information (the second network elements serving the network slice corresponding to the slice information). These second network elements associated with the slice information are the one or more second network elements. In this case, for multiple second network elements, the algorithm suite supported by the multiple second network elements can include the algorithm suite supported by each of the multiple second network elements. Alternatively, the algorithm suite supported by the multiple second network elements can include the algorithm suite corresponding to the slice information, such as the algorithm suite supported by all the multiple second network elements.
[0230] It is understood that when the information used to indicate one or more second network elements includes multiple items such as the expected second network element's NF instance identifier, expected second network element's NF type, expected second network element's NF set identifier, expected NF service set identifier, and expected second network element's slice information, the first network element can determine the second network elements among the registered second network elements associated with these multiple items. These second network elements associated with these multiple items are the one or more second network elements. For example, taking the expected second network element's NF type and expected second network element's NF set identifier as an example, the first network element can determine the second network elements among the registered second network elements associated with both the NF type and the NF set identifier (the second network element whose NF type is the NF type and whose NF set identifier is the NF set identifier). These second network elements associated with the NF type and the NF set identifier are the one or more second network elements. Other cases can be understood similarly and will not be described in detail here.
[0231] It should be understood that when the first request message includes the desired NF service identifier and other information related to the NF service, the one or more network elements should also be associated with the desired NF service identifier and other information related to the NF service, such as supporting the service corresponding to the desired NF service identifier.
[0232] In some possible implementations, the algorithm suite is associated with at least one of the following: the NF type of the third network element, the network element instance of the third network element, network slicing, and network function services. In this case, the algorithm suite supported by the one or more second network elements may include an algorithm suite supported by the one or more second network elements that is associated with at least one of the following: the network element type of the target third network element, the network element instance identifier of the target third network element, the slice information of the desired second network element, and the desired NF service identifier. For example, each of the one or more second network elements supports an algorithm suite that is associated with at least one of the following: the network element type of the target third network element, the network element instance identifier of the target third network element, the slice information of the desired second network element, and the desired NF service identifier. For example, suppose the plurality of second network elements includes second network element instance 1 and second network element instance 2. Second network element instance 1 provides service 1 and service 2. Service 1 of second network element instance 1 can be associated with algorithm suite 1, and service 2 of second network element instance 1 can be associated with algorithm suite 2. Second network element instance 2 provides service 1, and service 1 of second network element instance 2 can be associated with algorithm suite 1 and algorithm suite 3. The desired NF service identifier includes the NF service identifier of service 1. In this case, the algorithm suites supported by the plurality of second network elements may include algorithm suite 1 supported by second network element instance 1 and associated with the NF service identifier of service 1, and algorithm suite 1 and algorithm suite 3 supported by second network element instance 2 and associated with the NF service identifier of service 1. It should be understood that in the above case, the X algorithm suites determined by the first network element are associated with at least one of the following: the network element type of the target third network element, the network element instance identifier of the target third network element, the slice information of the desired second network element, and the desired NF service identifier. It should also be understood that for an algorithm suite supported by a second network element, whether the algorithm suite is associated with the network element type of the target third network element, the network element instance identifier of the target third network element, the slice information of the expected second network element, and the expected NF service identifier, and, if associated, how many of these four items are specifically associated, is indicated by the second network element when registering NF with the first network element.
[0233] The following example illustrates how, when the first request message includes information indicating a second network element, the first network element determines the implementation of X algorithm suites based on the algorithm suites supported by the second network element.
[0234] If the first request message includes information indicating a second network element, suggesting that only one second network element is desired, then X can be 1 (e.g., pre-configured as 1). That is, the first network element can determine an algorithm suite based on the algorithm suites supported by that second network element (hereinafter referred to as the target second network element). For example, the first network element can arbitrarily select an algorithm suite from those supported by the target second network element. As another example, if the target second network element indicates the priority of the algorithm suite when registering with the first network element, the first network element can select the algorithm suite with the highest priority among those supported by the target second network element. As yet another example, if the first network element configures the priority of the algorithm suite, the first network element can select the algorithm suite with the highest priority among those supported by the target second network element.
[0235] The following example illustrates how, when the first request message includes information indicating multiple second network elements, the first network element determines the implementation of X algorithm suites based on the algorithm suites supported by the multiple second network elements.
[0236] When the first request message includes information indicating multiple second network elements, indicating that the desired second network elements include multiple elements, X can be an integer greater than or equal to 1. That is, the first network element can determine one algorithm suite or multiple algorithm suites based on the algorithm suites supported by the multiple second network elements. Further, when the first request message includes information indicating multiple second network elements, the algorithm suites supported by the multiple second network elements may fall into two categories: one, the algorithm suites supported by the multiple second network elements include algorithm suites supported by each of the multiple second network elements individually; and two, the algorithm suites supported by the multiple second network elements include algorithm suites supported by all of the multiple second network elements. These will be explained separately below.
[0237] In some possible implementations, the algorithm suites supported by the plurality of second network elements include the algorithm suites supported by each of the plurality of second network elements, and the case where X is pre-configured to 1. In this case, the first network element can determine an algorithm suite (hereinafter referred to as the target algorithm suite) based on the algorithm suites supported by each of the plurality of second network elements. In one possible implementation, the first network element can determine the algorithm suite with the largest number of supported algorithms among the plurality of second network elements as the target algorithm suite (first algorithm suite). For example, assuming that the plurality of second network elements includes second network element instance 1, second network element instance 2, and second network element instance 3, the algorithm suites supported by second network element instance 1 include algorithm suite 1, algorithm suite 2, and algorithm suite 3, the algorithm suites supported by second network element instance 2 include algorithm suite 2 and algorithm suite 4, and the algorithm suites supported by second network element instance 3 include algorithm suite 1, the first network element can determine that the algorithm suites with the largest number of supported algorithms are algorithm suite 1 and algorithm suite 2, and can determine algorithm suite 1 or algorithm suite 2 as the target algorithm suite. For example, when the multiple second network elements support a maximum number of algorithm suites (such as algorithm suite 1 and algorithm suite 2 in the example above), the first network element can select the algorithm suite with the highest priority among the multiple algorithm suites. For example, the second network element indicates the priority of the algorithm suite when registering with the first network element, or the first network element configures the priority of the algorithm suite.
[0238] In other possible implementations, where the algorithm suites supported by the plurality of second network elements include algorithm suites supported by each of the plurality of second network elements, the first network element can divide the plurality of second network elements into X groups based on the algorithm suites supported by each of the plurality of second network elements. Then, it can determine the algorithm suites corresponding to each of the X groups based on the algorithm suites supported by the second network elements in the X groups, that is, determine X algorithm suites. Here, the X algorithm suites correspond one-to-one with the X groups, the second network elements in the first group support at least one identical algorithm suite, the algorithm suites corresponding to the first group are algorithm suites supported by all the second network elements in the first group, and the first group is any one of the X groups. In this embodiment, dividing the network into X groups is mainly because two of the multiple second network elements may support different algorithm suites. In this case, to facilitate the subsequent access of the target third network element to these two second network elements via access tokens, the first network element may need to sign using two different algorithm suites for these two second network elements. In addition, other second network elements may support the same algorithm suite as one of these two second network elements. Therefore, network elements supporting the same algorithm suite can be grouped together to reduce the number of access tokens that need to be generated. It should be noted that the implementation of the X-group division in this embodiment is not limited. Several examples are given below. First, the first network element determines the algorithm suite that is supported by the largest number of second network elements currently not grouped, and then groups those supporting that algorithm suite together. The above two steps are repeated until there are no more ungrouped second network elements. For example, initially, the second network elements supporting the algorithm suite with the most supported algorithms among the multiple second network elements can be grouped together. Then, for the remaining ungrouped second network elements, the algorithm suite with the most supported algorithms among the remaining ungrouped second network elements can be determined, and the second network elements supporting that algorithm suite can be grouped together. If there are still ungrouped second network elements, they can be grouped further. Alternatively, the first network element can determine X algorithm suites with the minimum number of groups based on the algorithm suites supported by the multiple second network elements, that is, X algorithm suites that minimize the number of groups. Then, groups can be formed based on these X algorithm suites to minimize the number of groups.For example, suppose the multiple second network elements include second network element instances 1 to 6. The algorithm suites supported by second network element instances 1 and 2 include algorithm suite 1 and algorithm suite 2. The algorithm suites supported by second network element instances 3 and 4 include algorithm suite 1 and algorithm suite 3. The algorithm suites supported by second network element instance 5 include algorithm suite 2 and algorithm suite 4. The algorithm suites supported by second network element instance 6 include algorithm suite 3 and algorithm suite 5. In this case, the first network element can determine the minimum number of algorithm suites X as algorithm suite 2 and algorithm suite 3. It only needs to be divided into two groups. The second network element supporting algorithm suite 2 belongs to one group, and the second network element supporting algorithm suite 3 belongs to another group.
[0239] When the algorithm suites supported by the multiple second network elements include algorithm suites supported by all of the multiple second network elements, X can be 1. In this case, the first network element can determine one algorithm suite from the algorithm suites supported by all of the multiple second network elements. For example, the first network element can arbitrarily select one algorithm suite from the algorithm suites supported by all of the multiple second network elements. Another example is that the first network element can select the algorithm suite with the highest priority among the algorithm suites supported by all of the multiple second network elements. For example, the second network element indicated the priority of the algorithm suite when registering with the first network element, or the first network element configured the priority of the algorithm suite.
[0240] If the first request message includes fifth algorithm information, the first network element can determine X algorithm suites based on the algorithm suites supported by the one or more second network elements and the J algorithm suites indicated by the fifth algorithm information. These X algorithm suites belong to the J algorithm suites. In other words, the X algorithm suites determined by the first network element need to be algorithm suites from the J algorithm suites.
[0241] 803. The first network element sends a first response message to the target third network element. The first response message includes X access tokens and information about one or more second network elements corresponding to the X access tokens. The X access tokens are signed based on the X algorithm suites.
[0242] Accordingly, the target third network element can receive the first response message (access token response message) from the first network element.
[0243] After determining X algorithm suites, the first network element can use these X algorithm suites to sign X access tokens respectively. For example, the first network element can generate X access tokens based on the determined X algorithm suites, and can sign each of the X access tokens based on the X algorithm suites respectively.
[0244] For example, one or more second network elements corresponding to an access token can be second network elements that the access token can access, that is, second network elements that can access NF services. The information of one or more second network elements corresponding to an access token can be used to indicate one or more second network elements that the access token can access. The information of one or more second network elements corresponding to an access token may include one or more of the following: the NF type of the second network element (that the access token can access), the NF instance identifier of the second network element (that the access token can access), the NF set identifier of the second network element (that the access token can access), the NF service set identifier (such as the NF subset ID), and slice information associated with the second network element that the access token can access. In some possible implementations, the information of one or more second network elements corresponding to an access token may be carried in the access token itself.
[0245] For example, suppose the X access tokens include access token 1 and access token 2. Access token 1 corresponds to algorithm suite 1, and access token 2 corresponds to algorithm suite 2. The second network element corresponding to access token 1 includes second network element instance 1, second network element instance 2, and second network element instance 5. The second network element corresponding to access token 2 includes second network element instance 3, second network element instance 4, and second network element instance 6. In this case, access token 1 can include information corresponding to second network element instance 1, second network element instance 2, and second network element instance 5, such as the NF instance identifier of second network element instance 1, second network element instance 2, and second network element instance 5, or the NF subset identifier corresponding to second network element instance 1, second network element instance 2, and second network element instance 5. Access token 2 can include information corresponding to second network element instance 3, second network element instance 4, and second network element instance 6, such as the NF instance identifier of second network element instance 3, second network element instance 4, and second network element instance 6, or the NF subset identifier corresponding to second network element instance 3, second network element instance 4, and second network element instance 6.
[0246] It should be understood that when the first network element uses an algorithm suite to sign an access token, it can use the private key corresponding to that algorithm suite, or other keys.
[0247] Understandably, the access token may also include one or more of the following: the NF instance identifier of the first network element, the desired NF service identifier, the NF instance identifier of the target third network element, additional scope information (such as the resources that are allowed to be accessed and the operations that are run on those resources), the validity period of the access token, and information indicating the algorithm suite corresponding to the access token.
[0248] In some possible implementations, information about one or more second network elements corresponding to an access token may also be carried in the first response message.
[0249] Optionally, after receiving an access token request from the NF service consumer, the NRF can determine whether the NF service requested by the NF service consumer is authorized. If authorized, an access token can be generated; otherwise, an error response can be sent to the NF service consumer. The error response may include information indicating an error. For example, the authorization determination can be performed before or after step 802; this embodiment of the application does not limit this.
[0250] For example, if a first network element does not support the J algorithm suites indicated by the fifth algorithm information, the first network element can identify other first network elements that support one or more of the J algorithm suites. Then, it can send information (such as address information) of these first network elements to the target third network element, so that the target third network element can re-request algorithm tokens from these first network elements. For instance, if a first network element is configured with information indicating one or more algorithm suites supported by other first network elements, in this case, the first network element can determine whether other first network elements support one or more of the J algorithm suites. The implementation of the information indicating one or more algorithm suites supported by other first network elements can include various methods, and this application embodiment does not limit this. For example, the information indicating one or more algorithm suites supported by other first network elements can each include information corresponding to each first network element indicating the one or more algorithm suites supported by that first network element. For example, the information used to indicate one or more algorithm suites supported by other first network elements may include multiple algorithm suites and the NF instance identifier of the first network element corresponding to each algorithm suite. For example, it may include algorithm suite 1 and algorithm suite 2, ["Algorithm suite 1": NF instance identifier of first network element instance 2, NF instance identifier of first network element instance 3], that is, first network element instance 2 and first network element instance 3 support algorithm suite 1, ["Algorithm suite 2": NF instance identifier of first network element instance 2, NF instance identifier of first network element instance 4], that is, first network element instance 2 and first network element instance 4 support algorithm suite 2.
[0251] Understandably, after the target third network element receives the first response message from the first network element, it can use the X access tokens carried in the first response message to request the corresponding service. For example, the target third network element can select an access token and send a service request to the second network element (such as the target second network element) corresponding to that access token. This service request includes the access token. After receiving the service request from the target third network element, the target second network element can verify the access token. If the verification passes, it provides the service and sends a service response to the target third network element. The public key corresponding to the access token can be used when verifying it, such as the public key corresponding to the algorithm suite obtained during the registration of the target second network element.
[0252] In the above processing flow, when the first network element receives a first request message (access token request message) from the target third network element, the first network element can first determine X algorithm suites based on its own supported algorithm suites, the algorithm suites supported by the registered second network element, and the information carried in the first request message. Then, it can sign X access tokens based on these X algorithm suites. This method can avoid problems such as service request failure or service interruption caused by algorithm suite mismatch (e.g., the requesting second network element does not support the algorithm suite corresponding to the access token) when the target third network element obtains services, ensuring that the target third network element can obtain services based on the access tokens issued by the first network element.
[0253] The following example illustrates the specific implementation of how the first network element determines X algorithm suites based on the algorithm suites supported by one or more second network elements.
[0254] In the first implementation, the first network element can be pre-configured with one or more supported algorithm suites. The first network element can sequentially query whether the following conditions are met according to the order of the one or more algorithm suites (e.g., in descending order of priority):
[0255] Condition 1: If the first request message includes an NF set identifier, and the first network element possesses algorithm information (such as an algorithm list) corresponding to that NF set identifier, the first network element can determine whether the algorithm suite belongs to the algorithm suite corresponding to that NF set identifier. If the algorithm suite belongs to the algorithm suite corresponding to that NF set identifier, then Condition 1 is satisfied; otherwise, Condition 1 is not satisfied. If there is no algorithm information corresponding to that NF set identifier, Condition 1 can be skipped. The algorithm information corresponding to that NF set identifier can be used to indicate the algorithm suite corresponding to that NF set identifier. The algorithm information corresponding to that NF set identifier can be pre-configured, or it can be generated by the first network element based on statistics of the algorithm suites supported by each second network element corresponding to that NF set identifier.
[0256] Condition 2: If the first request message includes an NF set identifier, the first network element can obtain the algorithm information of each registered NF corresponding to the NF set identifier, such as from the NF configuration files of each registered NF. Then, the first network element can determine whether the algorithm suite belongs to the algorithm suite supported by all registered NFs corresponding to the NF set identifier. If the algorithm suite belongs to the algorithm suite supported by all registered NFs corresponding to the NF set identifier, then Condition 2 is satisfied; otherwise, Condition 2 is not satisfied. If the algorithm suite supported by the registered NFs corresponding to the NF set identifier cannot be obtained (e.g., there is no registered NF corresponding to the NF set identifier), Condition 2 can be skipped. The algorithm information of an NF can be used to indicate the algorithm suite supported by that NF.
[0257] Condition 3: If the first request message includes an NF instance identifier, the first network element can obtain the algorithm information corresponding to that NF instance identifier and determine whether the algorithm suite belongs to the algorithm suite corresponding to that NF instance identifier (carried during NF registration and can be stored in the NF configuration file). If the algorithm suite belongs to the algorithm suite corresponding to that NF instance identifier, then condition 3 is satisfied; otherwise, condition 3 is not satisfied. If the algorithm suite corresponding to that NF instance identifier cannot be obtained, condition 3 can be skipped. The algorithm information corresponding to the NF instance identifier can be used to indicate the algorithm suite corresponding to that NF instance identifier.
[0258] Condition 4: If the first request message includes an NF service identifier, and the second network element provides algorithm information corresponding to that NF service identifier during registration (i.e., algorithm information associated with that NF service identifier), the first network element can determine whether the algorithm suite belongs to the algorithm suite corresponding to that NF service identifier. If the algorithm suite belongs to the algorithm suite corresponding to that NF service identifier, then condition 4 is satisfied; otherwise, condition 4 is not satisfied. If there is no algorithm information corresponding to that NF service identifier, condition 4 can be skipped. The algorithm information corresponding to that NF service identifier can be used to indicate the algorithm suite corresponding to that NF service identifier.
[0259] Condition 5: If the first request message includes slice information, and the first network element has pre-configured the algorithm information corresponding to the slice information, the first network element can determine whether the algorithm suite belongs to the algorithm suite corresponding to the slice information. If the algorithm suite belongs to the algorithm suite corresponding to the slice information, then condition 5 is satisfied; otherwise, condition 5 is not satisfied. If there is no algorithm information corresponding to the slice information, condition 5 can be skipped. The algorithm information corresponding to the slice information pre-configured by the first network element can be used to indicate the algorithm suite corresponding to the slice information supported by the first network element.
[0260] Condition 6: If the first request message includes slice information, and the second network element submits algorithm information corresponding to that slice information during registration, the first network element can determine whether the algorithm suite belongs to the algorithm suite corresponding to that slice information. If the algorithm suite belongs to the algorithm suite corresponding to that slice information, then condition 6 is satisfied; otherwise, condition 6 is not satisfied. If no algorithm information corresponding to that slice information exists, condition 6 can be skipped. The algorithm information corresponding to that slice information submitted by the second network element during registration can be used to indicate the algorithm suite corresponding to that slice information supported by the second network element.
[0261] Condition 7: If the first request message includes desired algorithm information, the first network element can determine whether the algorithm suite belongs to the desired algorithm suite. If the algorithm suite belongs to the desired algorithm suite, then condition 7 is satisfied; otherwise, condition 7 is not satisfied. If the desired algorithm suite does not exist, condition 7 can be skipped. The desired algorithm information can be used to indicate the desired algorithm suite of the target third network element.
[0262] If all conditions in conditions 1-7 that were not skipped are met, the first network element can use the algorithm suite to sign the access token. If any condition in conditions 1-7 is not met, the first network element can continue to select the next algorithm suite it supports for querying. If, after traversing all algorithm suites supported by the first network element, no algorithm suite suitable for signing is found, the first network element can send an error response to the target third network element.
[0263] In the second implementation, the first network element can obtain multiple algorithm information (such as an algorithm list). For example, it can obtain multiple algorithm information based on the information carried in the first request message (such as one or more of the following: NF set identifier, NF instance identifier, NF service identifier, slice information, and expected algorithm information). The multiple algorithm information includes one or more of the following: algorithm information corresponding to the NF set identifier, algorithm information of each registered NF corresponding to the NF set identifier, algorithm information corresponding to the NF instance identifier, algorithm information corresponding to the NF service identifier, algorithm information corresponding to the slice information associated with the first network element, algorithm information corresponding to the slice information associated with the registered second network element, and expected algorithm information.
[0264] The first network element can determine one or more algorithm suites by finding the intersection of the multiple algorithm information. For example, when the multiple algorithm information includes the desired algorithm information and the algorithm information corresponding to the NF instance identifier, the first network element can find the intersection of the desired algorithm suite and the algorithm suite corresponding to the NF instance identifier, and can determine that both the desired algorithm suite and the algorithm suite corresponding to the NF instance identifier include one or more algorithm suites.
[0265] The first network element can select one algorithm suite (such as randomly or according to priority) from one or more defined algorithm suites to sign the access token.
[0266] The following is an exemplary description of an OAuth protocol flow provided in an embodiment of this application:
[0267] (A) The client requests authorization from the resource owner. For example, the client can send an authorization request to the resource owner. This authorization request can be sent directly by the client to the resource owner, or indirectly through an authorization server.
[0268] (B) The client receives an authorization credential, which can be authorized using one of four methods: authorization code, implicit authorization, resource owner password, or access token. The authorization method depends on the authorization method requested by the client and the authorization methods supported by the authorization server.
[0269] Optionally, the client may also receive information indicating the algorithm suite supported by the resource server. The algorithm suite supported by the resource server can be an algorithm suite authorized by the resource owner.
[0270] (C) The client authenticates with the authorization server and submits authorization credentials to request an access token.
[0271] Optionally, the client can also send desired algorithm information, such as the desired algorithm information based on the information received in step B indicating the algorithm suite supported by the resource server. This desired algorithm information can be carried in a field of the authorization code, a field of the password credential, or an access token.
[0272] (D) The authorization server authenticates the client and verifies the authorization credentials. If valid, it issues an access token.
[0273] For example, the authorization server can select an algorithm suite for issuing access tokens based on the algorithm suite supported by the resource server, and the specific implementation can be referred to step 802 above.
[0274] As another example, if the licensee server's local policy pre-configures an algorithm suite, the licensee server can select an algorithm suite based on the local policy. Alternatively, the licensee server can select the algorithm suite indicated by the desired algorithm information carried in step C. If the licensee server has a default algorithm suite configured locally, the default algorithm suite can be used.
[0275] (E) The client requests services from the resource server using an access token, such as requesting protected resources.
[0276] (F) The resource server verifies the access token. If valid, it provides services, such as returning the protected resource.
[0277] Please see Figure 9 , Figure 9 This is a flowchart illustrating another communication method disclosed in an embodiment of this application. Figure 9 The relevant steps can be referred to above. Figures 6-8 The relevant description in [the text]. For example... Figure 9 As shown, the method may include, but is not limited to, the following steps:
[0278] 901. The service-providing network element sends a third request message to the credential-providing network element. The third request message is used to request network function registration and includes the algorithm suite supported by the service-providing network element.
[0279] In this embodiment, different service-providing network elements may support different algorithm suites, meaning different service-providing network elements may support different signature verification algorithm suites. In this case, to facilitate the generation of access tokens by the credential-providing network element, the service-providing network element can send its supported algorithm suite to the credential-providing network element when registering. Correspondingly, the credential-providing network element can receive third-party request messages from service-providing network elements (such as the target service-providing network element). In this embodiment, the access token can also be referred to as a credential.
[0280] The service-providing network element may support one or more algorithm suites. The algorithm suite may include signature methods and / or signature algorithms.
[0281] In some possible implementations, the algorithm suite supported by the service-providing network element is associated with at least one of the following: the network element type that allows access to the service-providing network element, the network element instance that allows access to the service-providing network element, network slices, network functions, and the name of the service provided.
[0282] Step 901 is similar to step 601 above, and you can also refer to the relevant description in step 601 above.
[0283] 902. The credential-providing network element sends a third response message to the service-providing network element. The third response message includes the registration result.
[0284] Accordingly, the service-providing network element can receive third-party response messages from the credential-providing network element.
[0285] In some possible implementations, after receiving a third request message from a service provider network element, the credential provider network element can determine the registration result of the service provider network element based on the algorithm suites supported by both the service provider network element and the credential provider network element, and then send a third response message to the service provider network element. For example, if the algorithm suites supported by the service provider network element and the credential provider network element include at least one identical algorithm suite, the registration result can be registration success; if both the algorithm suites supported by the service provider network element and the credential provider network element are different, the registration result can be registration failure. If the registration result is registration success, the third response message can include registration success indication information; if the registration result is registration failure, the third response message can include registration failure indication information.
[0286] If the service provider network element is successfully registered, the credential provider network element can store the algorithm suite supported by the service provider network element, or store the algorithm suite supported by both the service provider network element and the credential provider network element.
[0287] Step 902 is similar to step 602 above, and you can also refer to the relevant description in step 602 above.
[0288] Steps 901-902 are optional.
[0289] 903. The service requesting network element sends a second request message to the credential providing network element. The second request message is used to request service discovery and includes the desired algorithm suite.
[0290] Accordingly, the credential-providing network element can receive a second request message from the service-requesting network element.
[0291] It should be understood that the desired algorithm suite can be one or more.
[0292] Step 903 is similar to step 701 above, and you can also refer to the relevant description in step 701 above.
[0293] 904. The credential-providing network element sends a second response message to the service-requesting network element, the second response message including information for instructing the discovered service-providing network element to support the desired algorithm suite.
[0294] After receiving the second request message from the service requesting network element, the credential providing network element can identify one or more service providing network elements based on the information carried in the second request message. Then, it can send a second response message to the service requesting network element. The second response message may include information indicating the identified one or more service providing network elements (such as NF instance identifier, NF address, etc.), that is, information indicating the discovered service providing network elements. Correspondingly, the service requesting network element can receive the second response message from the credential providing network element.
[0295] It should be understood that when there are multiple desired algorithm suites, the discovered service-providing network element supporting the desired algorithm suite may be at least one, at least two, or at least three of the multiple desired algorithm suites, etc.
[0296] In some possible implementations, the algorithm suite supported by the service-providing network element is associated with at least one of the following: the network element type (NFtype) of the service-requesting network element, the network element instance (NFinstance) of the service-requesting network element, network slice, network function, and the name of the service provided. In this case, the credential-providing network element can determine one or more service-providing network elements matching the second request message based on the association between the algorithm suite supported by the registered service-providing network element and one or more of the network element type, network element instance, network slice, network function, and name of the service-requesting network element, as well as the information carried in the second request message, such as the network element type, NF instance identifier, slice information, network function identifier, and expected NF service identifier of the service-requesting network element. That is, it determines one or more service-providing network elements matching the information carried in the second request message.
[0297] Step 904 is similar to step 702 above, and you can also refer to the relevant description in step 702 above.
[0298] Steps 903-904 are optional.
[0299] 905. Service requesting network element sends a first request message to the credential providing network element. The first request message is used to request authorization from the service requesting network element to access the access token of the target service.
[0300] To obtain the target service (the desired NF service), the service requesting network element can send a first request message to the credential providing network element, requesting authorization for the service requesting network element to access the target service with an access token. Correspondingly, the credential providing network element can receive the first request message from the service requesting network element.
[0301] The first request message may include information for instructing one or more service-providing network elements, which may be referred to as candidate network elements.
[0302] The first request message may also include a desired algorithm suite for signing the access token. This desired algorithm suite may consist of one or more algorithms.
[0303] In some possible implementations, the service requesting network element may send a first request message to the credential providing network element based on the information of the discovered service providing network element (step 703).
[0304] Step 905 is similar to step 801 above, and you can also refer to the relevant description in step 801 above.
[0305] 906. Based on the first request message, the credential-providing network element determines the algorithm suite supported by the service-providing network element that provides the target service.
[0306] In some possible implementations, the credential providing network element can determine one or more candidate network elements to provide the target service based on the first request message, and then determine the algorithm suite supported by the service providing network element to provide the target service based on the algorithm suite supported by the one or more candidate network elements. For example, the credential providing network element can determine one or more candidate network elements to provide the target service based on information carried in the first request message that indicates the one or more candidate network elements.
[0307] When the first request message includes a desired algorithm suite, the credential-providing network element determines, based on the algorithm suites supported by the one or more candidate network elements, the algorithm suite supported by the service-providing network element providing the target service. This may include: identifying candidate network elements supporting the desired algorithm suite as the service-providing network element providing the target service, and determining the algorithm suite supported by the service-providing network element providing the target service. When there are multiple desired algorithm suites, the candidate network element supporting the desired algorithm suite may support at least one, at least two, or at least three of the multiple desired algorithm suites, etc. The algorithm suite supported by the service-providing network element providing the target service, determined by the credential-providing network element, must be the desired algorithm suite.
[0308] In some possible implementations, the algorithm suite supported by the service-providing network element (such as the one or more candidate network elements) is associated with at least one of the following: the network element type (NFtype) that allows access to the service-providing network element, i.e., the network element type of the service-requesting network element; the network element instance (NFinstance) that allows access to the service-providing network element, i.e., the network element instance of the service-requesting network element, network slice, network function, and the name of the service provided. The first request message includes at least one of the following: the network element type of the service-requesting network element, the network element instance identifier of the service-requesting network element, the network slice identifier, the network function identifier, and the name of the service to be authorized. In this case, the credential-providing network element, based on the algorithm suite supported by the one or more candidate network elements, determines that the algorithm suite supported by the service-providing network element providing the target service may include: identifying candidate network elements associated with at least one of the network element type, the network element instance identifier, the network slice identifier, the network function identifier, and the name of the service to be authorized as the service-providing network element providing the target service, and determining the algorithm suite supported by the service-providing network element providing the target service. For example, suppose the multiple candidate network elements include service provider network element instance 1 and service provider network element instance 2. The slices served by service provider network element instance 1 include slice 1 and slice 2. Slice 1 can be associated with algorithm suite 1, slice 2 can be associated with algorithm suite 2 and algorithm suite 3, and the slices served by service provider network element instance 2 include slice 3. Slice 3 can be associated with algorithm suite 1 and algorithm suite 2. The network slice identifier includes the identifier of slice 1. In this case, the candidate network element (service provider network element instance 1) associated with slice 1 can be identified as the service provider network element providing the target service. Then, the algorithm suites supported by service provider network element instance 1, such as algorithm suite 1, can be determined.
[0309] When there are multiple candidate network elements, the credential providing network element determines the algorithm suite supported by the service providing network element providing the target service based on the algorithm suites supported by the multiple candidate network elements. This can include: determining the candidate network element corresponding to the algorithm suite with the most supported algorithm suites as the service providing network element providing the target service, and determining the algorithm suite supported by the service providing network element providing the target service. For example, assuming that the multiple candidate network elements include candidate network element 1, candidate network element 2, and candidate network element 3, and the algorithm suites supported by candidate network element 1 include algorithm suite 1, algorithm suite 2, and algorithm suite 3, the algorithm suites supported by candidate network element 2 include algorithm suite 4, and the algorithm suites supported by candidate network element 3 include algorithm suite 1, the credential providing network element can determine that the algorithm suite with the most supported algorithm suite is algorithm suite 1, and can use the candidate network elements corresponding to algorithm suite 1 (candidate network element 1 and candidate network element 3) as the service providing network element providing the target service. Then, the algorithm suites supported by candidate network element 1 and candidate network element 3, i.e., algorithm suite 1, can be determined.
[0310] When the first request message includes information for instructing multiple service-providing network elements, the number of algorithm suites determined by the credential-providing network element can be multiple. For example, the credential-providing network element determining the algorithm suite supported by the service-providing network element providing the target service based on the algorithm suites supported by multiple candidate network elements may include: dividing the multiple candidate network elements into multiple groups based on the algorithm suites supported by the multiple candidate network elements; the candidate network elements in the first group supporting at least one of the same algorithm suites; the first group being any one of the multiple groups; determining the algorithm suites corresponding to each of the multiple groups based on the algorithm suites supported by the candidate network elements in the multiple groups; the algorithm suites corresponding to the first group being the algorithm suites supported by all candidate network elements in the first group; and determining the algorithm suites corresponding to each of the multiple groups as the algorithm suites supported by the service-providing network element providing the target service. Thus, for a candidate network element, the candidate network element can support at least one of the determined algorithm suites, thereby ensuring that the access token generated by the credential-providing network element based on the determined algorithm suites can be used to access the target service of all candidate network elements.
[0311] It should be understood that the above descriptions address situations where the first request message includes the desired algorithm suite, the algorithm suite supported by the service-providing network element (such as the one or more candidate network elements) is associated with at least one of the following: network element type, network element instance, network slice, network function, service name, etc., and when multiple candidate network elements are included. However, it should be understood that the above situations can be combined, and correspondingly, the algorithm suites supported by the service-providing network element for determining the target service under various situations can be combined, which will not be elaborated further here.
[0312] Step 906 is similar to step 802 above, and you can also refer to the relevant description in step 802 above.
[0313] 907. The credential provider generates access tokens based on this algorithm suite.
[0314] After the credential-providing network element determines the algorithm suite supported by the service-providing network element providing the target service, it can generate an access token based on the determined algorithm suite. In other words, the access token can be secured using the determined algorithm suite, which means it is signed using the determined algorithm suite.
[0315] When there are multiple defined algorithm suites, there can be multiple corresponding access tokens. These multiple access tokens can be secured using different algorithm suites, and each of these multiple access tokens is used to access the target service of a portion of the service-providing network elements. For example, these multiple access tokens can be used to access the target services of different service-providing network elements.
[0316] 908. The credential-providing network element sends a first response message to the service-requesting network element, the first response message including the access token.
[0317] Accordingly, the service requesting network element can receive the first response message from the credential providing network element.
[0318] After receiving the first response message from the credential-providing network element, the requesting network element obtains an access token and can then send a service request to the providing network element. This service request, which includes the access token, is used to request the target service. Correspondingly, the providing network element can receive the service request from the requesting network element. The providing network element can use its supported algorithm suite to verify the access token carried in the service request. If the verification passes, the providing network element can provide the service to the requesting network element; if the verification fails, the providing network element can refuse to provide the service to the requesting network element.
[0319] It should be noted that the relevant information and descriptions in the different embodiments described above can be referenced interchangeably. For example, the above... Figures 6-9 The explanations or adaptations in the illustrated method embodiments can be referenced interchangeably. Furthermore, technical features from different method embodiments can be combined to form new embodiments based on their inherent logical relationships. Additionally, different implementations or examples within the same method embodiment can also be referenced or consulted.
[0320] It should be understood that the above Figures 6-9 The above processing flow is illustrated primarily using the credential-providing network element, the service-requesting network element, and the service-providing network element as the executing entities in the interaction illustration. However, this application does not limit the executing entities of this interaction illustration. For example, Figures 6-9 The credential provisioning network element can also be a chip, chip system, or processor that supports the implementation of this method, or it can be a logic module or software that can implement all or part of the credential provisioning network element. For example, Figures 6-9 The service request network element can also be a chip, chip system, or processor that supports the implementation of the method by the service request network element, or it can be a logic module or software that can implement all or part of the service request network element functions. For example, Figures 6-9 The service-providing network element can also be a chip, chip system, or processor that supports the implementation of the method by the service-providing network element, or it can be a logic module or software that can implement all or part of the functions of the service-providing network element.
[0321] The foregoing mainly describes the communication method provided in the embodiments of this application. It is understood that the aforementioned credential providing network element, service request network element, and service providing network element, in order to achieve the corresponding functions, may include hardware structures and / or software modules for executing each function. Based on the units and steps of the various examples described in the embodiments disclosed herein, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed by hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the embodiments of this application.
[0322] This application embodiment can divide the credential providing network element, service request network element, and service providing network element into functional modules according to the above method example. For example, each function can be divided into a separate functional module, or two or more functions can be integrated into one module. The integrated module can be implemented in hardware or as a software functional module. It should be noted that the module division in this application embodiment is illustrative and only represents one logical functional division; other division methods may be used in actual implementation.
[0323] When dividing each function into modules according to its corresponding function. Figure 10 A possible structural schematic diagram of a communication device 1000 is shown. The communication device 1000 includes a communication unit 1001. The communication device may also include a processing unit 1002 and a storage unit 1403. Optionally, the communication unit 1001 may also be referred to as a transceiver unit, an output unit, or an interface unit, etc. In one possible implementation, the communication unit 1001 includes at least one of a transmitting unit or a receiving unit. The transmitting unit and the receiving unit may be integrated together, or they may be two independent units, etc. In one possible design, the communication device 1000 may be the aforementioned credential providing network element, or it may be a component within the credential providing network element (e.g., a processor, chip, chip system, circuit, or functional module), or it may be a processing system within the credential providing network element, etc.
[0324] When the communication device 1000 is used for the above Figures 6-9 In the embodiments shown, when the credentials provide the functionality of the network element, for example:
[0325] Communication unit 1001 is used to receive a first request message from a service requesting network element, the first request message being used to request authorization for the service requesting network element to access the target service with an access token;
[0326] Processing unit 1002 is used to determine, based on the first request message, an algorithm suite supported by the service providing network element that provides the target service;
[0327] Processing unit 1002 is also used to generate access tokens based on the algorithm suite;
[0328] The communication unit 1001 is also used to send a first response message to the service requesting network element, the first response message including the access token.
[0329] In one possible implementation, the processing unit 1002 determines an algorithm suite supported by the service-providing network element providing the target service based on the first request message, including: determining one or more candidate network elements providing the target service based on the first request message; and determining an algorithm suite supported by the service-providing network element providing the target service based on the algorithm suite supported by the one or more candidate network elements.
[0330] In one possible implementation, the first request message includes a desired algorithm suite used to sign the access token; the processing unit 1002 determines the algorithm suite supported by the service-providing network element providing the target service based on the algorithm suite supported by the one or more candidate network elements, including: identifying candidate network elements supporting the desired algorithm suite as service-providing network elements providing the target service; and determining the algorithm suite supported by the service-providing network element providing the target service.
[0331] In one possible implementation, the algorithm suite supported by the one or more candidate network elements is associated with at least one of the following: network element type that allows access to the candidate network element, network element instance that allows access to the candidate network element, network slice, network function, and the name of the service provided; the first request message includes at least one of the following: network element type of the service requesting network element, network element instance identifier of the service requesting network element, network slice identifier, network function identifier, and the name of the service requested for authorization; the processing unit 1002 determines the algorithm suite supported by the service providing network element that provides the target service based on the algorithm suite supported by the one or more candidate network elements, including: determining the candidate network element associated with at least one of the network element type, network element instance identifier, network slice identifier, network function identifier, and the name of the service requested for authorization as the service providing network element that provides the target service; and determining the algorithm suite supported by the service providing network element that provides the target service.
[0332] In one possible implementation, the processing unit 1002 determines the algorithm suite supported by the service-providing network element providing the target service based on the algorithm suites supported by the multiple candidate network elements, including: determining the candidate network element corresponding to the algorithm suite with the largest number of supported algorithms as the service-providing network element providing the target service; and determining the algorithm suite supported by the service-providing network element providing the target service.
[0333] In one possible implementation, there are multiple algorithm suites and multiple access tokens, which are used to access the target services of different service-providing network elements.
[0334] In one possible implementation, the processing unit 1002 determines the algorithm suite supported by the service-providing network element providing the target service based on the algorithm suite supported by the plurality of candidate network elements, including: dividing the plurality of candidate network elements into multiple groups based on the algorithm suite supported by the plurality of candidate network elements, wherein the candidate network elements in the first group support at least one identical algorithm suite, and the first group is any one of the multiple groups; determining the algorithm suite corresponding to each of the multiple groups based on the algorithm suite supported by the candidate network elements in the multiple groups; the algorithm suite corresponding to the first group is an algorithm suite supported by all candidate network elements in the first group; and determining the algorithm suite corresponding to each of the multiple groups as the algorithm suite supported by the service-providing network element providing the target service.
[0335] In one possible implementation, the communication unit 1001 is further configured to receive a second request message from the service requesting network element, the second request message being used to request service discovery, the second request message including a desired algorithm suite; the communication unit 1001 is further configured to send a second response message to the service requesting network element, the second response message including information for instructing the discovered service providing network element to support the desired algorithm suite.
[0336] In one possible implementation, the communication unit 1001 is further configured to receive a third request message from a target service-providing network element, the third request message being used to request network function registration, the third request message including an algorithm suite supported by the target service-providing network element; the communication unit 1001 is further configured to send a third response message to the target service-providing network element, the third response message including a registration result, the registration result being determined based on the algorithm suite supported by the target service-providing network element and the algorithm suite supported by the credential-providing network element.
[0337] In one possible implementation, if the algorithm suite supported by the target service and the algorithm suite supported by the credential include at least one of the same algorithm suites, the registration result is successful; if the algorithm suite supported by the target service and the algorithm suite supported by the credential are both different, the registration result is unsuccessful.
[0338] In one possible implementation, storage unit 1003 is used to store, upon successful registration of the target service providing network element, an algorithm suite supported by the target service providing network element, or an algorithm suite supported by both the target service providing network element and the credential providing network element.
[0339] In one possible implementation, the algorithm suite supported by the target service network element is associated with at least one of the following: network element type that allows access to the target service network element, network element instance that allows access to the target service network element, network slice, network function, and the name of the service provided.
[0340] In one possible implementation, the algorithm suite includes a signature algorithm and / or a signature method.
[0341] For specific operation details of each unit in the aforementioned communication device 1000, please refer to the above. Figures 6-9 The embodiments shown provide a description of the network element corresponding to the certificate, which will not be repeated here.
[0342] In another possible design, the communication device 1000 may be the aforementioned service request network element, or a component within the service request network element (e.g., a processor, chip, chip system, circuit, or functional module), or a processing system within the service request network element, etc.
[0343] When the communication device 1000 is used for the above Figures 6-9 In the embodiments shown, when requesting the function of a network element, the following is an example:
[0344] The communication unit 1001 is used to send a first request message to the credential providing network element. The first request message is used to request authorization for the service requesting network element to access the target service with an access token. The first request message includes the expected algorithm suite.
[0345] The communication unit 1001 is also configured to receive a first response message from the credential-providing network element, the first response message including an access token that is securely protected using the desired algorithm suite.
[0346] In one possible implementation, the first request message includes information for instructing multiple service-providing network elements, and there are multiple access tokens, which are secured using different algorithm suites. Each of the multiple access tokens is used to access a target service of a portion of the multiple service-providing network elements.
[0347] In one possible implementation, the communication unit 1001 is further configured to send a second request message to the credential providing network element, the second request message being used to request service discovery, the second request message including a desired algorithm suite; the communication unit 1001 is further configured to receive a second response message from the credential providing network element, the second response message including information for indicating the discovered service providing network element that supports the desired algorithm suite; the communication unit 1001 sending the first request message to the credential providing network element includes: sending the first request message to the credential providing network element based on the information of the discovered service providing network element.
[0348] In one possible implementation, the algorithm suite includes a signature algorithm and / or a signature method.
[0349] For specific operation details of each unit in the aforementioned communication device 1000, please refer to the above. Figures 6-9 The descriptions of the service request network elements in the illustrated embodiments are not repeated here.
[0350] In another possible design, the communication device 1000 may be the aforementioned service-providing network element, or a component within the service-providing network element (e.g., a processor, chip, chip system, circuit, or functional module), or a processing system within the service-providing network element, etc.
[0351] When the communication device 1000 is used for the above Figures 6-9 In the embodiments shown, when the service provides the functionality of a network element, for example:
[0352] The communication unit 1001 is used to send a third request message to the credential providing network element. The third request message is used to request network function registration. The third request message includes an algorithm suite supported by the service providing network element.
[0353] The communication unit 1001 is also configured to receive a third response message from the credential-providing network element, the third response message including indication information of successful registration.
[0354] In one possible implementation, the algorithm suite supported by the network element provided by the service is associated with at least one of the following: the network element type that allows access to the network element provided by the service, the network element instance that allows access to the network element provided by the service, network slice, network function, and the name of the service provided.
[0355] In one possible implementation, the communication unit 1001 is further configured to receive a service request from a service requesting network element, the service request being for requesting a target service and including an access token; the processing unit 1002 is configured to verify the access token using its own supported algorithm suite; the processing unit 1002 is further configured to provide services to the service requesting network element if the verification passes; the processing unit 1002 is further configured to refuse to provide services to the service requesting network element if the verification fails.
[0356] In one possible implementation, the algorithm suite includes a signature algorithm and / or a signature method.
[0357] For specific operation details of each unit in the aforementioned communication device 1000, please refer to the above. Figures 6-9 The descriptions of the service-providing network elements in the illustrated embodiments are not repeated here.
[0358] Figure 11 The diagram shows a possible hardware structure of a communication device 1100 provided in an embodiment of this application. The communication device 1100 may include a communication interface 1104 and at least one processor 1102. Optionally, it may also include a bus 1103. Further optionally, it may also include at least one memory 1101, wherein the memory 1101, the processor 1102, and the communication interface 1104 can be connected via the bus 1103.
[0359] The memory 1101 provides storage space, which can store data such as the operating system and computer programs. The memory 1101 can be one or a combination of several of the following: random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), or compact disc read-only memory (CD-ROM).
[0360] Processor 1102 is a module that performs arithmetic and / or logical operations. Specifically, it can be one or a combination of processing modules such as a central processing unit (CPU), graphics processing unit (GPU), microprocessor unit (MPU), application-specific integrated circuit (ASIC), field-programmable gate array (FPGA), complex programmable logic device (CPLD), coprocessor (assisting the CPU in completing corresponding processing and applications), and microcontroller unit (MCU). For example, processor 1102 can be used to process communication protocols and communication data.
[0361] The communication interface 1104 is used to receive and / or transmit data to external sources. Optionally, the communication interface 1104 may also include a transmitter (such as an RF transmitter, antenna, etc.) and / or a receiver coupled to the interface. For example, the communication interface 1104 may include a control circuit and an antenna. The control circuit is mainly used for converting baseband signals to RF signals and processing RF signals. The antenna is mainly used for transmitting and receiving RF signals in the form of electromagnetic waves. When data needs to be transmitted wirelessly, the processor 1102 performs baseband processing on the data to be transmitted and outputs a baseband signal to the control circuit. The control circuit then performs RF processing on the baseband signal and transmits the RF signal outward in the form of electromagnetic waves through the antenna. When data is sent to the communication device, the control circuit receives the RF signal through the antenna, converts the RF signal into a baseband signal, and outputs the baseband signal to the processor 1102. The processor 1102 converts the baseband signal back into data and processes the data.
[0362] In one possible implementation, the control circuitry and antenna can be set up independently of the processor performing baseband processing. For example, in a distributed scenario, the control circuitry and antenna can be arranged in a remote manner, independent of the communication device.
[0363] In one design, the communication device 1100 can be used to perform the aforementioned... Figures 6-9 The illustrated embodiment provides the functionality of the network element through credentials. For details, please refer to the above. Figures 6-9 The relevant descriptions of network elements provided by the certificate will not be elaborated here.
[0364] In another design, the communication device 1100 can be used to perform the aforementioned... Figures 6-9 The illustrated embodiment demonstrates the function of the service request network element. For details, please refer to the above. Figures 6-9 The relevant descriptions of the network elements requesting services will not be elaborated here.
[0365] In another design, the communication device 1100 can be used to perform the aforementioned... Figures 6-9 The illustrated embodiment provides the functionality of the network element. For details, please refer to the above. Figures 6-9 The relevant descriptions of the network elements provided by the service provider will not be elaborated here.
[0366] In one possible design, memory 1101 may store instructions, which may be computer programs. These computer programs run on processor 1102 and cause communication device 1100 to perform operations performed by the credential-providing network element, the service-requesting network element, or the service-providing network element in any of the above method embodiments. For details, please refer to the above description. Figures 6-9 The relevant descriptions in the document will not be repeated here.
[0367] It should be noted that, Figure 11 The communication device 1100 shown is merely one implementation of the embodiments of this application. In actual applications, the communication device 1100 may include more or fewer components, which is not limited here.
[0368] This application also discloses a communication system, which includes at least one of a credential providing network element, a service request network element, and a service providing network element. The credential providing network element is used to perform the operation performed by the credential providing network element in any of the above method embodiments. The service request network element is used to perform the operation performed by the service request network element in any of the above method embodiments. The service providing network element is used to perform the operation performed by the service providing network element in any of the above method embodiments.
[0369] This application also discloses a chip, which includes a processor, wherein the processor is configured to execute a computer program or computer instructions stored in a memory, causing the chip to perform the operations performed by the credential providing network element in the above method embodiments, or to perform the operations performed by the service request network element in the above method embodiments, or to perform the operations performed by the service providing network element in the above method embodiments.
[0370] As one possible implementation, the memory is located outside the chip.
[0371] This application also discloses a computer-readable storage medium storing instructions that, when executed, perform operations performed by the credential-providing network element, the service-requesting network element, or the service-providing network element in the above method embodiments.
[0372] This application also discloses a computer program product including instructions, which, when executed, perform the operations performed by the credential providing network element in the above method embodiments, or the operations performed by the service request network element in the above method embodiments, or the operations performed by the service providing network element in the above method embodiments.
[0373] It should be understood that the transmission in the embodiments of this application can be direct or indirect. Direct transmission means that one device or module directly sends information / data to the corresponding device or module, while indirect transmission means that one device or module sends information / data to the corresponding device or module through other devices or modules.
[0374] Obviously, the embodiments described above are only some embodiments of this application, and not all embodiments. The term "embodiment" as used herein means that a specific feature, structure, or characteristic described in connection with an embodiment can be included in at least one embodiment of this application. The appearance of this phrase in various places in the specification does not necessarily indicate the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art will understand, explicitly and implicitly, that the embodiments described herein can be combined with other embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without inventive effort are within the scope of protection of this application. The terms "first," "second," "third," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish different objects and are not used to describe a specific order. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion. For example, it may include a series of steps or units, or optionally, steps or units not listed, or optionally other steps or units inherent to these processes, methods, products, or devices. It is also understandable that, for an architecture with multiple devices or modules, if one device or module generates a piece of information and another device or module uses that information, there are multiple ways for the other device to obtain that information. For example, the device or module that generated the information may send the information directly to the device or module that used the information (equivalent to direct sending), or the device or module that generated the information may send the information to the device or module that used the information through other devices or modules (equivalent to indirect sending).
[0375] It is understood that the accompanying drawings show only the parts relevant to this application and not all of them. It should be understood that some exemplary embodiments are described as processes or methods depicted as flowcharts. Although the flowcharts describe operations (or steps) as sequential processes, many of these operations can be performed in parallel, concurrently, or simultaneously. Furthermore, the order of the operations can be rearranged. The process can be terminated when its operation is completed, but may also have additional steps not included in the drawings. The process can correspond to a method, function, procedure, subroutine, subroutine, etc.
[0376] The terms “component,” “module,” “system,” “unit,” etc., used in this specification are used to refer to computer-related entities, hardware, firmware, combinations of hardware and software, software, or software in execution. For example, a unit can be, but is not limited to, a process running on a processor, a processor, an object, an executable file, a thread of execution, a program, and / or distributed between two or more computers. Furthermore, these units can be executed from various computer-readable media on which various data structures are stored. For example, a unit can communicate via local and / or remote processes based on signals having one or more data packets (e.g., data from a second unit interacting with another unit between a local system, a distributed system, and / or a network; for example, the Internet interacting with other systems via signals).
[0377] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of this application. It should be understood that the above description is only a specific embodiment of this application and is not intended to limit the scope of protection of this application. Any modifications, equivalent substitutions, improvements, etc., made on the basis of the technical solution of this application should be included within the scope of protection of this application.
Claims
1. A communication method, characterized in that, The method includes: The credential-providing network element receives a first request message from the service requesting network element, the first request message being used to request authorization for the service requesting network element to access the target service with an access token. Based on the first request message, the credential providing network element determines the algorithm suite supported by the service providing network element that provides the target service; The credential provides the network element with an access token generated based on the algorithm suite; The credential-providing network element sends a first response message to the service-requesting network element, the first response message including the access token.
2. The method according to claim 1, characterized in that, The credential-providing network element determines, based on the first request message, a suite of algorithms supported by the service-providing network element providing the target service, including: Based on the first request message, one or more candidate network elements are determined to provide the target service; Based on the algorithm suites supported by the one or more candidate network elements, determine the algorithm suites supported by the service-providing network element that provides the target service.
3. The method according to claim 2, characterized in that, The first request message includes a desired algorithm suite, which is used to sign the access token; the step of determining the algorithm suite supported by the service-providing network element providing the target service based on the algorithm suites supported by the one or more candidate network elements includes: Candidate network elements that support the desired algorithm suite are identified as service-providing network elements that provide the target service; Determine the algorithm suite supported by the service-providing network elements that provide the target service.
4. The method according to claim 2, characterized in that, The algorithm suite supported by the one or more candidate network elements is associated with at least one of the following: network element type that allows access to the candidate network element, network element instance that allows access to the candidate network element, network slice, network function, and the name of the service provided; the first request message includes at least one of the following: network element type of the service requesting network element, network element instance identifier of the service requesting network element, network slice identifier, network function identifier, and the name of the service requested for authorization; The algorithm suite for determining the service-providing network element support for the target service based on the algorithm suite supported by the one or more candidate network elements includes: Candidate network elements associated with at least one of the following: network element type of the service requesting network element, network element instance identifier of the service requesting network element, network slice identifier, network function identifier, and service name requested for authorization, are identified as service providing network elements that provide the target service. Determine the algorithm suite supported by the service-providing network elements that provide the target service.
5. The method according to claim 2, characterized in that, The algorithm suite for determining the service-providing network element supporting the target service, based on the algorithm suite supported by the multiple candidate network elements, includes: Based on the algorithm suites supported by the multiple candidate network elements, the candidate network element corresponding to the algorithm suite that supports the most algorithms is determined as the service providing network element that provides the target service; Determine the algorithm suite supported by the service-providing network elements that provide the target service.
6. The method according to any one of claims 1-5, characterized in that, The number of determined algorithm suites is multiple, and the number of access tokens is also multiple. The multiple access tokens are used to access the target services of different service providing network elements.
7. The method according to claim 6, characterized in that, The algorithm suite for determining the service-providing network element supporting the target service, based on the algorithm suite supported by the multiple candidate network elements, includes: Based on the algorithm suites supported by the multiple candidate network elements, the multiple candidate network elements are divided into multiple groups. The candidate network elements in the first group support at least one of the same algorithm suites. The first group is any one of the multiple groups. The algorithm suites corresponding to each of the multiple groups are determined based on the algorithm suites supported by the candidate network elements in the multiple groups; the algorithm suite corresponding to the first group is the algorithm suite supported by all candidate network elements in the first group. The algorithm suites corresponding to the multiple groups are determined as the algorithm suites that provide network element support for the target service.
8. The method according to any one of claims 1-7, characterized in that, The method further includes: The credential-providing network element receives a second request message from the service requesting network element. The second request message is used to request service discovery and includes a desired suite of algorithms. The credential-providing network element sends a second response message to the service-requesting network element. The second response message includes information indicating the discovered service-providing network element that supports the desired algorithm suite.
9. The method according to any one of claims 1-8, characterized in that, The method further includes: The credential providing network element receives a third request message from the target service providing network element. The third request message is used to request network function registration and includes an algorithm suite supported by the target service providing network element. The credential providing network element sends a third response message to the target service providing network element. The third response message includes a registration result, which is determined based on the algorithm suite supported by the target service providing network element and the algorithm suite supported by the credential providing network element.
10. The method according to claim 9, characterized in that, If the algorithm suite supported by the target service and the algorithm suite supported by the credential include at least one of the same algorithm suites, the registration result is successful registration; If the algorithm suite supported by the target service network element is different from the algorithm suite supported by the credential network element, the registration result is registration failure.
11. The method according to claim 9 or 10, characterized in that, If the target service provider network element is successfully registered, store the algorithm suite supported by the target service provider network element, or store the algorithm suite supported by both the target service provider network element and the credential provider network element.
12. The method according to any one of claims 9-11, characterized in that, The algorithm suite supported by the target service network element is associated with at least one of the following: network element type that allows access to the target service network element, network element instance that allows access to the target service network element, network slice, network function, and the name of the service provided.
13. The method according to any one of claims 1-12, characterized in that, The algorithm suite includes signature algorithms and / or signature methods.
14. A communication method, characterized in that, The method includes: The service requesting network element sends a first request message to the credential providing network element. The first request message is used to request authorization for the service requesting network element to access the target service with an access token. The first request message includes the desired algorithm suite. The service requesting network element receives a first response message from the credential providing network element. The first response message includes an access token, which is protected by the desired algorithm suite.
15. The method according to claim 14, characterized in that, The first request message includes information for instructing multiple service-providing network elements. There are multiple access tokens, which are protected by different algorithm suites. Each of the multiple access tokens is used to access a target service of a portion of the multiple service-providing network elements.
16. The method according to claim 14 or 15, characterized in that, The method further includes: The service requesting network element sends a second request message to the credential providing network element. The second request message is used to request service discovery and includes the desired algorithm suite. The service requesting network element receives a second response message from the credential providing network element, the second response message including information for indicating the discovered service providing network element that supports the desired algorithm suite; The service requesting network element sends a first request message to the credential providing network element, including: Based on the discovered information of the service-providing network element, a first request message is sent to the credential-providing network element.
17. The method according to any one of claims 14-16, characterized in that, The algorithm suite includes signature algorithms and / or signature methods.
18. A communication method, characterized in that, The method includes: The service-providing network element sends a third request message to the credential-providing network element. The third request message is used to request network function registration and includes an algorithm suite supported by the service-providing network element. The service-providing network element receives a third response message from the credential-providing network element, the third response message including indication information of successful registration.
19. The method according to claim 18, characterized in that, The algorithm suite supported by the service-providing network element is associated with at least one of the following: network element type that allows access to the service-providing network element, network element instance that allows access to the service-providing network element, network slice, network function, and the name of the service provided.
20. The method according to claim 18 or 19, characterized in that, The method further includes: The service providing network element receives a service request from the service requesting network element. The service request is used to request a target service and includes an access token. The service provides network elements to verify the access token using their own supported algorithm suite; If the verification passes, the service-providing network element provides services to the service-requesting network element; If the verification fails, the service-providing network element refuses to provide services to the service-requesting network element.
21. The method according to any one of claims 18-20, characterized in that, The algorithm suite includes signature algorithms and / or signature methods.
22. A communication system, characterized in that, It includes at least one of a credential providing network element, a service requesting network element, and a service providing network element, wherein the credential providing network element is used to implement the method of any one of claims 1-13, the service requesting network element is used to implement the method of any one of claims 14-17, and the service providing network element is used to implement the method of any one of claims 18-21.
23. A communication device, characterized in that, Includes modules for implementing the method as described in any one of claims 1-21.
24. A communication device, characterized in that, Includes a processor for executing instructions stored in a memory, causing the communication device to perform the method as described in any one of claims 1-21.
25. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program or computer instructions that are executed by a processor to implement the method as described in any one of claims 1-21.
26. A computer program product, characterized in that, The computer program product includes computer program code or computer instructions, which, when executed, implement the method described in any one of claims 1-21.