User device UE role authorization method / apparatus / device and storage medium

The UE role authorization method in communication systems accurately determines UE roles and provides encryption keys to prevent unauthorized interference, ensuring secure and accurate service execution in ranging and sidelink positioning services.

JP2025532211AActive Publication Date: 2025-09-29BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025517802
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2022-09-26
Publication Date
2025-09-29
Estimated Expiration
2042-09-26

AI Technical Summary

Technical Problem

In communication systems, UEs often play inappropriate roles in ranging and sidelink positioning services, leading to accuracy issues and security risks such as information leakage.

Method used

A method for UE role authorization is implemented, where a network device determines UE roles based on capabilities and subscription information, and provides encryption keys to ensure accurate role authorization and security during service execution.

Benefits of technology

Ensures accurate role authorization and enhances information security by preventing unauthorized UEs from impersonating or interfering with UE roles, thereby improving service execution accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025532211000001_ABST
    Figure 2025532211000001_ABST
Patent Text Reader

Abstract

The present disclosure provides a method / apparatus / device for role authorization for a UE, and a storage medium, the method including: receiving a discovery request message transmitted from a first UE and / or a second UE, where the discovery request message is used to request role authorization for the first UE and / or the second UE; and transmitting a discovery response message to the first UE and / or the second UE, the discovery response message including a role determined for the first UE and / or the second UE by the network device. The present disclosure also provides a method for role authorization in a service for which a UE requests discovery, the method being used to accurately authorize a role for a UE, improving the accuracy of service execution and improving information security.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to the field of communications technology, and in particular to a UE role authorization method / apparatus / device and storage medium. [Background technology]

[0002] In a communication system, when performing ranging services and / or sidelink (SL) positioning services, multiple user equipments (UEs) are usually required to play different roles as participants to complete the services, where the UE roles may include sidelink reference UE (SL Reference UE), target UE, assistant UE, located UE, sidelink positioning server UE (SL Positioning Server UE), sidelink positioning client UE (SL Positioning Client UE), etc.

[0003] The same UE may simultaneously support multiple roles of the ranging service and / or the sidelink positioning service. For example, if a UE plays the role of transmitting a location signal, it can be used as a reference UE, and if the UE also plays the role of calculating a location, it can be used as a server UE. In a practical scenario, a UE may play an inappropriate role in a specific service, i.e., a role that is not permitted or should not be played in the service. For example, if a UE plays the role of ranging but cannot be used as an auxiliary UE in ranging service 1, and it assists an auxiliary UE in service 1, it may affect the accuracy of the ranging service and cause security issues such as information leakage. Summary of the Invention [Problem to be solved by the invention]

[0004] The UE role authorization method / apparatus / device and storage medium provided by the present disclosure accurately authorize roles for the UE in different services, thereby ensuring the accuracy of service execution and information security. [Means for solving the problem]

[0005] According to a first aspect, an embodiment of the present disclosure provides a role authorization method for a UE, the method being executed by a network device and including: receiving a discovery request message transmitted from a first UE and / or a second UE, wherein the discovery request message is used to request role authorization for the first UE and / or the second UE; and transmitting a discovery response message to the first UE and / or the second UE, the discovery response message including the role determined by the network device for the first UE and / or the second UE.

[0006] In the present disclosure, a network device receives a discovery request message sent from a first UE and / or a second UE, the discovery request message requesting role authorization for the first UE and / or the second UE, and then the network device transmits a discovery response message to the first UE and / or the second UE, the discovery response message including the role determined by the network device for the first UE and / or the second UE. As can be seen from the above, the present disclosure provides a method for authorizing a role in a service for which a UE requests discovery, where the role of the UE may be determined by the network device based on the UE's capabilities and UE subscription information, thereby ensuring accurate role authorization for the UE and ensuring accuracy when the service is executed. At the same time, encryption key information corresponding to the service that the UE requests to discover is sent to the UE, and the encryption key information provides security protection for the UE's subsequent process of discovering other UEs, thereby ensuring that irrelevant UEs cannot monitor or tamper with the UE's role when the UE transmits its role in the subsequent discovery process, thereby preventing irrelevant UEs from impersonating the UE's role and avoiding interference from other irrelevant UEs in the subsequent service execution process, thereby improving the accuracy of service execution and improving information security.

[0007] According to a second aspect, an embodiment of the present disclosure provides a role authorization method for a UE, the method being executed by a first UE and including the steps of: sending a discovery request message to a network device to request an authorized role for the first UE; and receiving a discovery response message sent from the network device, the discovery response message including a role determined by the network device for the first UE.

[0008] According to a third aspect, an embodiment of the present disclosure provides a role authorization method for a UE, the method being executed by a second UE and including the steps of: sending a discovery request message to a network device requesting role authorization for the second UE; and receiving a discovery response message sent from the network device, the discovery response message including a role determined by the network device for the second UE.

[0009] According to a fourth aspect, an embodiment of the present disclosure provides a role authorization method for a UE, which is executed by a DDNMF network element of a first UE or a PKMF network element of the first UE, and includes the steps of receiving a discovery request message sent from the first UE, where the discovery request message is used to request role authorization for a service for which the first UE requests discovery; sending a first authorization request message to a server or a UDM network element based on the discovery request message; receiving a first authorization response message sent from the server or UDM network element, where the first authorization response message includes the role of the first UE determined by the server or UDM network element; and sending a discovery response message including the role of the first UE to the first UE.

[0010] According to a fifth aspect, an embodiment of the present disclosure provides a role authorization method for a UE, which is executed by a DDNMF network element of a second UE or a PKMF network element of the second UE, and includes the steps of receiving a discovery request message sent from the second UE, where the discovery request message is used to request role authorization for a service for which the second UE requests discovery; sending a first authorization request message to a server or a UDM network element based on the discovery request message; receiving a first authorization response message sent from the server or the UDM network element, where the first authorization response message includes the role of the second UE determined by the server or the UDM network element; determining encryption key information corresponding to the service for which the second UE requests discovery; and sending a discovery response message including the role of the second UE to the second UE.

[0011] According to a sixth aspect, an embodiment of the present disclosure provides a role authorization method for a UE, the method being executed by a server or a UDM network element, and including the steps of receiving a first authorization request message sent from a DDNMF network element or a PKMF network element of a first UE and / or a second UE, wherein the first authorization request message is used to request authorization of a role for a service that the first UE and / or the second UE requests discovery of; determining a role of the first UE and / or the second UE based on the first authorization request message; and sending a first authorization response message to the DDNMF network element or the PKMF network element of the first UE and / or the second UE, wherein the first authorization response message includes the role of the first UE and / or the second UE.

[0012] According to a seventh aspect, an embodiment of the present disclosure provides a communications apparatus, comprising: a transceiver module for receiving a discovery request message transmitted from a first UE and / or a second UE, the discovery request message being used to request authorization of a role for the first UE and / or the second UE, the transceiver module also being used for transmitting a discovery response message to the first UE and / or the second UE, the discovery response message including a role determined by the network device for the first UE and / or the second UE.

[0013] According to an eighth aspect, an embodiment of the present disclosure provides a communications apparatus, including a transceiver module for transmitting a discovery request message to a network device to request an authorization role for a first UE, the transceiver module also being used for receiving a discovery response message transmitted from the network device, the discovery response message including a role determined by the network device for the first UE.

[0014] According to a ninth aspect, an embodiment of the present disclosure provides a communications device, including a transceiver module for transmitting a discovery request message to a network device requesting authorization of a role for a second UE, the transceiver module also being used for receiving a discovery response message transmitted from the network device, the discovery response message including a role determined by the network device for the second UE.

[0015] According to a tenth aspect, an embodiment of the present disclosure provides a communications device, including: a transceiver module for receiving a discovery request message sent from the first UE, wherein the discovery request message is used to request authorization of a role for a service for which the first UE requests discovery; the transceiver module is also used for sending a first authorization request message to a server or a UDM network element based on the discovery request message; the transceiver module is also used for receiving a first authorization response message sent from the server or the UDM network element, wherein the first authorization response message includes the role of the first UE determined by the server or the UDM network element; and the transceiver module is also used for sending a discovery response message including the role of the first UE to the first UE.

[0016] According to an eleventh aspect, an embodiment of the present disclosure provides a communications device, comprising: a transceiver module for receiving a discovery request message sent from a second UE, wherein the discovery request message is used to request authorization of a role for a service for which the second UE requests discovery; the transceiver module is also used for sending a first authorization request message to a server or a UDM network element based on the discovery request message; the transceiver module is also used for receiving a first authorization response message sent from the server or the UDM network element, wherein the first authorization response message includes the role of the second UE determined by the server or the UDM network element; a processing block is also used for determining encryption key information corresponding to the service for which the second UE requests discovery; and the transceiver module is also used for sending a discovery response message to the second UE, including the role of the second UE.

[0017] According to a twelfth aspect, an embodiment of the present disclosure provides a communications device, including: a transceiver module for receiving a first authorization request message sent from a DDNMF network element or a PKMF network element of a first UE and / or a second UE, wherein the first authorization request message is used to request authorization of a role for a service for which the first UE and / or the second UE requests discovery; and a processing module for determining a role of the first UE and / or the second UE based on the first authorization request message, wherein the transceiver module is also used for sending a first authorization response message to the DDNMF network element or the PKMF network element of the first UE and / or the second UE, wherein the first authorization response message includes the role of the first UE and / or the second UE.

[0018] According to a thirteenth aspect, an embodiment of the present disclosure provides a communication device, the communication device including a processor, wherein when the processor calls a computer program stored in a memory, a method according to any one of the first to sixth aspects is executed.

[0019] According to a fourteenth aspect, an embodiment of the present disclosure provides a communication device, the communication device including a processor and a memory, wherein a computer program is stored in the memory, and the processor executes the computer program stored in the memory, thereby causing the communication device to perform a method according to any one of the first to sixth aspects.

[0020] According to a fifteenth aspect, an embodiment of the present disclosure provides a communication device, the device including a processor and an interface circuit, the interface circuit receiving and transmitting code instructions to the processor, and the processor executing the code instructions to cause the device to perform the method according to any one of the first to sixth aspects.

[0021] According to a 16th aspect, an embodiment of the present disclosure provides a communication system, the system including a communication device according to the 7th aspect to a communication device according to the 12th aspect, alternatively, the system including a communication device according to the 13th aspect, alternatively, the system including a communication device according to the 14th aspect, or alternatively, the system including a communication device according to the 15th aspect.

[0022] According to a seventeenth aspect, an embodiment of the present disclosure provides a computer-readable storage medium for storing instructions for use in the base station, the instructions, when executed, causing the terminal device to perform the method according to any one of the first to sixth aspects.

[0023] According to an eighteenth aspect, the present disclosure further provides a computer program product comprising a computer program which, when run on a computer, causes the computer to perform the method according to any one of the first to sixth aspects above.

[0024] According to a nineteenth aspect, the present disclosure provides a chip system, the chip system including at least one processor and an interface, for supporting a base station in performing functions according to the method of any one of the first to sixth aspects, for example, for determining or processing at least one of data and information according to the method. In one possible design, the chip system further includes a memory, the memory being used to store computer programs and data required by the source slave node. The chip system may be composed of a chip or may include a chip and other discrete devices.

[0025] According to a twentieth aspect, the present disclosure provides a computer program which, when executed on a computer, causes the computer to carry out the method according to any one of the first to fifth aspects above.

[0026] According to a twenty-first aspect, the present disclosure provides a communication system, characterized in that: The first UE is used to send a discovery request message, the second UE is used to send the discovery request message, the network device is used to send a discovery response message, the discovery response message includes a role determined by the network device for the first UE and / or the second UE, the first UE is used to receive the discovery response message, the discovery response message includes a role determined by the network device for the first UE, and the second UE is also used to receive the discovery response message, the discovery response message includes a role determined by the network device for the second UE. [Brief explanation of the drawings]

[0027] The above and / or additional aspects and advantages of the present disclosure will become apparent and easier to understand from the following description of the embodiments taken in conjunction with the drawings. [Figure 1a] 1 is a schematic diagram of the architecture of several communication systems provided by embodiments of the present disclosure. [Figure 1b] 1 is a schematic diagram of the architecture of several communication systems provided by embodiments of the present disclosure. [Figure 2a] 4 is a schematic flowchart of a role authorization method for a UE provided by another embodiment of the present disclosure; [Figure 2b] 4 is a schematic flowchart of a role authorization method for a UE provided by another embodiment of the present disclosure; [Figure 2c] 4 is a schematic flowchart of a role authorization method for a UE provided by another embodiment of the present disclosure; [Figure 2d] 4 is a schematic flowchart of a role authorization method for a UE provided by another embodiment of the present disclosure; [Figure 2e] 4 is a schematic flowchart of a role authorization method for a UE provided by another embodiment of the present disclosure; [Figure 2f] 4 is a schematic flowchart of a role authorization method for a UE provided by another embodiment of the present disclosure; [Figure 2g] 4 is a schematic flowchart of a role authorization method for a UE provided by another embodiment of the present disclosure; [Figure 2h] 4 is a schematic flowchart of a role authorization method for a UE provided by another embodiment of the present disclosure; [Figure 2i] 4 is a schematic flowchart of a role authorization method for a UE provided by another embodiment of the present disclosure; [Figure 2j] 4 is a schematic flowchart of a role authorization method for a UE provided by another embodiment of the present disclosure; [Figure 2k] 4 is a schematic flowchart of a role authorization method for a UE provided by another embodiment of the present disclosure; [Figure 2L] 4 is a schematic flowchart of a role authorization method for a UE provided by another embodiment of the present disclosure; [Figure 3] 10 is a schematic flowchart of a role authorization method for a UE provided by a further embodiment of the present disclosure; [Figure 4] 4 is a schematic flowchart of a role authorization method for a UE provided by another embodiment of the present disclosure; [Figure 5] 4 is a schematic flowchart of a role authorization method for a UE provided by another embodiment of the present disclosure; [Figure 6] 10 is a schematic flowchart of a role authorization method for a UE provided by a further embodiment of the present disclosure; [Figure 7] 4 is a schematic flowchart of a role authorization method for a UE provided by another embodiment of the present disclosure; [Figure 8] 1 is a schematic flowchart of a role authorization method for a UE provided by an embodiment of the present disclosure; [Figure 9] 4 is a schematic flowchart of a role authorization method for a UE provided by another embodiment of the present disclosure; [Figure 10] 4 is a schematic flowchart of a role authorization method for a UE provided by another embodiment of the present disclosure; [Figure 11] 4 is a schematic flowchart of a role authorization method for a UE provided by another embodiment of the present disclosure; [Figure 12] 4 is a schematic flowchart of a role authorization method for a UE provided by another embodiment of the present disclosure; [Figure 13] 4 is a schematic flowchart of a role authorization method for a UE provided by another embodiment of the present disclosure; [Figure 14] 4 is a schematic flowchart of a role authorization method for a UE provided by another embodiment of the present disclosure; [Figure 15] 4 is a schematic flowchart of a role authorization method for a UE provided by another embodiment of the present disclosure; [Figure 16] 4 is a schematic flowchart of a role authorization method for a UE provided by another embodiment of the present disclosure; [Figure 17] FIG. 10 is a structural schematic diagram of a communication device provided by another embodiment of the present disclosure. [Figure 18] FIG. 10 is a structural schematic diagram of a communication device provided by another embodiment of the present disclosure. [Figure 19] FIG. 10 is a structural schematic diagram of a communication device provided by another embodiment of the present disclosure. [Figure 20] FIG. 10 is a structural schematic diagram of a communication device provided by another embodiment of the present disclosure. [Figure 21a] FIG. 10 is a structural schematic diagram of a communication device provided by another embodiment of the present disclosure. [Figure 21b] FIG. 10 is a structural schematic diagram of a communication device provided by another embodiment of the present disclosure. [Figure 22] FIG. 2 is a structural schematic diagram of a communication system provided by another embodiment of the present disclosure. [Figure 23] FIG. 1 is a block diagram of a communication device provided by one embodiment of the present disclosure. [Figure 24] 1 is a structural schematic diagram of a chip provided by an embodiment of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0028] Reference will now be made in detail to illustrative embodiments, examples of which are illustrated in the drawings. Where the following description refers to the drawings, like numerals in different drawings represent the same or similar elements unless otherwise indicated. The embodiments described in the following illustrative examples do not represent all embodiments consistent with embodiments of the present disclosure. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present disclosure, as set forth in the appended claims.

[0029] The terms used in the embodiments of the present disclosure are used to describe particular embodiments and are not intended to limit the embodiments of the present disclosure. Unless the context clearly indicates otherwise, the singular forms "a," "an," and "the" used in the embodiments of the present disclosure and the appended claims are intended to include the plural forms. Furthermore, the term "and / or" as used herein refers to and includes any and all possible combinations of one or more of the associated listed items.

[0030] Although various pieces of information may be described using terms such as first, second, and third in the embodiments of the present disclosure, these pieces of information should not be limited to these terms. These terms are used only to distinguish between pieces of information of the same type. For example, first information may be referred to as second information without departing from the scope of the embodiments of the present disclosure. Similarly, second information may be referred to as first information. Depending on the context, the terms "when" and "in response to" used herein may be understood as "at the time of" or "on the occasion of" or "in response to determining."

[0031] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0021] The following detailed description of the preferred embodiments of the present disclosure is provided in the accompanying drawings, in which like or similar reference numerals refer to like or similar elements throughout. The preferred embodiments described below with reference to the accompanying drawings are illustrative and are intended to explain the present disclosure but are not intended to limit the present disclosure.

[0032] To facilitate understanding, we first explain the terminology associated with this application.

[0033] 1. Unified Data Management (UDM) network elements It is used to manage user identification, subscription data, authentication data, and to manage the user's service network element registration (e.g., the Access and Mobility Management Function (AMF) network element, network element, and Session Management Function (SMF) network element currently providing services to the terminal. For example, when a user switches access AMF, the UDM sends a logout message to the old AMF, requesting the old AMF to delete information related to the user).

[0034] To better understand the UE role authorization method disclosed in the embodiments of the present disclosure, the following will first describe a communication system to which the embodiments of the present disclosure are applied.

[0035] 1a, 1a is an architecture schematic diagram of a communication system provided by an embodiment of the present disclosure. As shown in FIG. 1a, the communication system may include, but is not limited to, one network device 13 and at least two UEs (e.g., a first UE 11 and a second UE 12).

[0036] It should be noted that the technical solutions of the embodiments of the present disclosure can be applied to various communication systems, such as a long term evolution (LTE) system, a fifth generation (5G) mobile communication system, a 5G new radio (NR) system, or other future new mobile communication systems.

[0037] The network devices 13 may include, for example, access network devices (e.g., base stations) and core network devices, where a core network device is a device located within a core network and a core network element is a network element located in a core network, the functions of both being to provide user connectivity, user management and execute services, and providing interfaces to external networks as bearer networks.

[0038] In the embodiment of the present disclosure, the first UE 11 and the second UE 12 are entities for transmitting and receiving signals on the user side, such as mobile phones. The terminal devices may also be called terminals, user equipment (UE), mobile stations (MS), mobile terminals (MT), etc. The terminal devices may also be automobiles with communication capabilities, smart cars, mobile phones, wearable devices, tablets, computers with wireless transmission and reception capabilities, virtual reality (VR) terminal devices, augmented reality (AR) terminal devices, wireless terminal devices in industrial control, wireless terminal devices in self-driving, wireless terminal devices in remote medical surgery, wireless terminal devices in smart grids, wireless terminal devices in transportation safety, wireless terminal devices in smart cities, wireless terminal devices in smart homes, etc. The embodiments of the present disclosure do not limit the specific technology used by the terminal device or the specific device configuration.

[0039] As shown in FIG. 1b, the core network devices in the communication system may include, for example, a direct discovery name management function (DDNMF) / Proximity Service key management function (ProSe key management function) network element of the first UE, a DDNMF / PKMF network element of the second UE, and a server / UDM network element.

[0040] Here, the DDNMF / PKMF network element of the first UE and the DDNMF / PKMF network element of the second UE may be the same or different.

[0041] It should be noted that the communication systems described in the embodiments of the present disclosure are technical solutions for more clearly explaining the embodiments of the present disclosure, and do not limit the technical solutions provided by the embodiments of the present disclosure. As those skilled in the art will appreciate, with the evolution of system architecture and the emergence of new service scenarios, the technical solutions provided by the embodiments of the present disclosure can also be applied to similar technical problems.

[0042] The following describes in detail the UE role authorization method / apparatus / device and storage medium provided by the embodiments of the present disclosure in combination with the drawings.

[0043] The names of the following messages (including request messages, response messages, etc.) are given for convenience, and the names themselves do not limit the functions of the messages.

[0044] FIG. 2a is a schematic flowchart of a UE role authorization method provided by an embodiment of the present disclosure, which is performed by a network device. As shown in FIG. 2a, the UE role authorization method may include the following steps 201a to 202a:

[0045] Step 201a: receiving a discovery request message sent from a first UE and / or a second UE, the discovery request message being used to request authorization of a role for the first UE and / or the second UE;

[0046] In one embodiment of the present disclosure, the discovery request message sent from the first UE may include at least one of a ranging or sidelink positioning application user ID (RAUID) corresponding to the first UE, an identifier of a service for which the first UE requests discovery, and a capability of the first UE.

[0047] In another embodiment of the present disclosure, the discovery request message sent from the second UE may include at least one of a RAUID corresponding to the second UE, a service for which the second UE requests discovery, and a capability of the second UE.

[0048] The RAUID is used to identify the UE so that the network device knows from which UE the discovery request message was sent.

[0049] The service for which the UE requests discovery may be, for example, a ranging service and / or a sidelink positioning service.

[0050] The UE capability may be, for example, a ranging service capability supported by the UE and / or a sidelink positioning service capability supported by the UE. Different UE capabilities may support different UE roles. UE roles may include, for example, a reference UE (e.g., a sidelink reference UE (SL Reference UE)), a target UE, an assistant UE, a located UE, a UE as a server (e.g., a sidelink positioning server UE (SL Positioning Server UE)), a client UE (e.g., a sidelink positioning client UE (SL Positioning Client UE)), a ranging UE, etc. The target UE may be a UE to be positioned or ranged. The positioning UE may be a UE that acquires the positioning location of the target UE. The ranging UE may be a UE that acquires the ranging distance of the target UE, the reference UE may be a UE that can determine the positioning location or ranging distance of the target UE based on the location of the reference UE or the distance between the reference UE and the target UE, the assisting UE may be a UE that assists in forwarding messages in the ranging service or sidelink positioning service, the server UE may be a UE with positioning calculation capability or ranging calculation capability, and the client UE may be a UE that can be used as a client in the ranging service or sidelink positioning service.

[0051] Based on this, for example, if a UE supports data processing capabilities (i.e., data calculation capabilities), the UE role that the UE can support may be a UE as a server, etc., and if a UE does not support data processing capabilities but supports the ability to send and receive positioning information and / or ranging information, the UE role that the UE can support may be a reference UE or a target UE, etc.

[0052] Step 202a: The network device sends a discovery response message to the first UE and / or the second UE, the discovery response message including the role determined for the first UE and / or the second UE.

[0053] The UE role is the role authorized by the network device for the UE. The UE role may be determined by the network device based on the UE capabilities and UE subscription information, where the subscription information may be a service protocol and / or UE subscription, and the subscription information registers the roles authorized for each UE in the ranging service and / or sidelink positioning service. Based on this, when the network device determines the role based on the UE subscription information, it ensures that the role authorized for the UE is an authorized role, thereby ensuring accurate authorization corresponding to the UE role and therefore ensuring accuracy when the UE subsequently performs services based on the UE role.

[0054] Furthermore, in one embodiment of the present disclosure, the discovery response message may include encryption key information generated by the network device for the service requested by the first UE to be discovered and / or encryption key information generated corresponding to the service requested by the second UE to be discovered, where the encryption key information corresponding to the service requested by the first UE to be discovered is the same as the encryption key information corresponding to the service requested by the second UE to be discovered. The encryption key information provides security protection for the subsequent discovery process of the first UE to the second UE, thereby ensuring that unrelated UEs cannot monitor or tamper with the role of the first UE when the first UE transmits the role of the first UE in the subsequent discovery process. This prevents unrelated UEs from impersonating the role of the first UE to deceive the counterpart UE of the first UE (i.e., the second UE), avoiding interference from other unrelated UEs in the subsequent service execution process, improving the accuracy of service execution, and improving information security. Here, unrelated UEs include, for example, UEs whose service discovery is requested is different from the service that the first UE and the second UE request discovery of, UEs that have not requested a service, UEs whose role has not been authorized by the network device, and UEs that have not obtained the encryption key information from the network device.

[0055]

[0013] As described above, in a UE role authorization method provided by an embodiment of the present disclosure, a network device receives a discovery request message sent from a first UE and / or a second UE, where the discovery request message requests role authorization for the first UE and / or the second UE, and then the network device sends a discovery response message to the first UE and / or the second UE, the discovery response message including the role determined by the network device for the first UE and / or the second UE. As can be seen from the above, the present disclosure provides a method for role authorization in a service for which a UE requests discovery, where the role of the UE may be determined by the network device based on UE capabilities and UE subscription information, thereby ensuring accurate role authorization for the UE and accuracy during service execution. At the same time, encryption key information corresponding to the service that the UE requests to discover is sent to the UE, and the encryption key information provides security protection for the UE's subsequent process of discovering other UEs, thereby ensuring that irrelevant UEs cannot monitor or tamper with the UE's role when the UE transmits its role in the subsequent discovery process, thereby preventing irrelevant UEs from impersonating the UE's role and avoiding interference from other irrelevant UEs in the subsequent service execution process, thereby improving the accuracy of service execution and improving information security.

[0056] FIG. 2b is a schematic flowchart of a UE role authorization method provided by an embodiment of the present disclosure, which is performed by a network device. As shown in FIG. 2b, the UE role authorization method may include the following step 201b:

[0057] Step 201b: determining a role of the first UE and / or the second UE based on the capabilities of the first UE and / or the second UE and subscription information of the first UE and / or the second UE stored in the network device;

[0058] As can be seen from the above, the subscription information registers the roles that each UE is permitted to play in the ranging service and / or sidelink positioning service. Based on this, the network device can search the subscription information to determine the roles that a specific UE is permitted to play in the ranging service and / or sidelink positioning service, and then, in combination with the UE's capabilities, determine the roles that the UE's permitted roles support as the roles of the UE.

[0059] On this basis, the first UE is taken as an example to describe how the network device determines the role of the first UE, and similarly for the second UE.

[0060] Specifically, for example, if the service that two UEs request to discover is a ranging service, the network device may search a service protocol based on the identifier of the first UE to find that the roles of the first UE authorized in the ranging service are target UE and serving UE, and / or may determine a subscription of the first UE based on the identifier of the first UE and search the subscription of the first UE to find that the roles of the first UE authorized in the sidelink positioning service are target UE and serving UE. If the network device determines based on the capabilities of the first UE that the first UE supports in the ranging service are target UE and positioning UE, the network device may authorize the first UE to play the role of target UE.

[0061] In addition, in one embodiment of the present disclosure, if the first UE is allowed to have multiple roles supported by its capabilities, the network device determines all of the multiple roles as the first UE's roles, that is, the first UE may have multiple roles.

[0062]

[0013] As described above, in a UE role authorization method provided by an embodiment of the present disclosure, a network device receives a discovery request message sent from a first UE and / or a second UE, where the discovery request message requests role authorization for the first UE and / or the second UE, and then the network device sends a discovery response message to the first UE and / or the second UE, the discovery response message including the role determined by the network device for the first UE and / or the second UE. As can be seen from the above, the present disclosure provides a method for role authorization in a service for which a UE requests discovery, where the role of the UE may be determined by the network device based on UE capabilities and UE subscription information, thereby ensuring accurate role authorization for the UE and accuracy during service execution. At the same time, encryption key information corresponding to the service that the UE requests to discover is sent to the UE, and the encryption key information provides security protection for the UE's subsequent process of discovering other UEs, thereby ensuring that irrelevant UEs cannot monitor or tamper with the UE's role when the UE transmits its role in the subsequent discovery process, thereby preventing irrelevant UEs from impersonating the UE's role and avoiding interference from other irrelevant UEs in the subsequent service execution process, thereby improving the accuracy of service execution and improving information security.

[0063] FIG. 2c is a schematic flowchart of a UE role authorization method provided by an embodiment of the present disclosure, which is performed by a first UE. As shown in FIG. 2c, the UE role authorization method includes the following steps 201c to 202c:

[0064] Step 201c: sending a discovery request message to the network device requesting authorization of a role for the first UE;

[0065] Step 202c: receiving a discovery response message sent from a network device, where the discovery response message includes a role determined by the network device for the first UE;

[0066] For a detailed explanation of steps 201c to 202c, please refer to the explanation of the above embodiment.

[0067]

[0013] In accordance with the above, in a UE role authorization method provided by an embodiment of the present disclosure, a first UE sends a discovery request message to a network device, requesting role authorization for the first UE. The first UE then receives a discovery response message sent from the network device, where the discovery response message includes the role determined by the network device for the first UE.

[0014] As can be seen from the above, the present disclosure provides a method for role authorization in a service for which a UE requests discovery, where the role of the UE may be determined by the network device based on UE capabilities and UE subscription information, thereby ensuring accurate role authorization for the UE and accuracy during service execution. At the same time, encryption key information corresponding to the service that the UE requests to discover is sent to the UE, and the encryption key information provides security protection for the UE's subsequent process of discovering other UEs, thereby ensuring that irrelevant UEs cannot monitor or tamper with the UE's role when the UE transmits its role in the subsequent discovery process, thereby preventing irrelevant UEs from impersonating the UE's role and avoiding interference from other irrelevant UEs in the subsequent service execution process, thereby improving the accuracy of service execution and improving information security.

[0068] Figure 2d is a schematic flowchart of a UE role authorization method provided by an embodiment of the present disclosure, where the method is performed by a first UE. As shown in Figure 2d, the UE role authorization method may include the following step 201d:

[0069] Step 201d: broadcasting a first discovery message, where the first discovery message is protected by encryption key information corresponding to a service for which the first UE requests discovery, and the first discovery message includes a role of the first UE.

[0070] In one embodiment of the present disclosure, the first UE broadcasts a first discovery message protected by encryption key information corresponding to a service for which the first UE requests discovery; based on the encryption key information corresponding to the service for which the second UE requests discovery being the same as the security encryption key corresponding to the service for which the first UE requests discovery, the second UE successfully verifies the first discovery message broadcast by the first UE using the same encryption key information, achieving successful discovery with the first UE; and then the second UE verifies whether the role of the second UE is consistent with the role of the first UE, so as to confirm whether to subsequently establish a connection with the first UE.

[0071]

[0013] As described above, in a UE role authorization method provided by an embodiment of the present disclosure, a first UE sends a discovery request message to a network device, requesting role authorization for the first UE. The first UE then receives a discovery response message sent from the network device, where the discovery response message includes the role determined by the network device for the first UE. As can be seen from the above, the present disclosure provides a method for role authorization in a service for which a UE requests discovery, where the role of the UE may be determined by the network device based on UE capabilities and UE subscription information, thereby ensuring accurate role authorization for the UE and accuracy during service execution. At the same time, encryption key information corresponding to the service that the UE requests to discover is sent to the UE, and the encryption key information provides security protection for the UE's subsequent process of discovering other UEs, thereby ensuring that irrelevant UEs cannot monitor or tamper with the UE's role when the UE transmits its role in the subsequent discovery process, thereby preventing irrelevant UEs from impersonating the UE's role and avoiding interference from other irrelevant UEs in the subsequent service execution process, thereby improving the accuracy of service execution and improving information security.

[0072] FIG. 2e is a schematic flowchart of a UE role authorization method provided by an embodiment of the present disclosure, which is performed by a first UE. As shown in FIG. 11, the UE role authorization method includes the following steps 201e to 203e.

[0073] Step 201e: receiving a second discovery message broadcasted by a second UE, the second discovery message being protected by encryption key information corresponding to a service for which the second UE requests discovery, and the second discovery message including the role of the second UE;

[0074] Step 202e: decrypting and verifying the second discovery message, and determining whether the role of the second UE and the role of the first UE match in response to successful verification.

[0075] The second discovery message may be verified using the encryption key information, and the principle of this aspect is explained in the above embodiment.

[0076] Furthermore, if the service that the second UE requests to discover is the same as the service that the first UE requests to discover, the matching of the roles of the first UE and the second UE proves that the first UE and the second UE can complete the service that the two UEs request to discover. Based on this, after the first UE decodes and verifies the second discovery message, it further determines whether the roles of the first UE and the second UE match, thereby understanding whether the first UE and the second UE can complete the services that the two UEs request. If they can be completed, the two UEs can then perform a discovery process to establish connection; if they cannot be completed, it is ignored.

[0077] Furthermore, in one embodiment of the present disclosure, the above-mentioned matching of the role of the first UE and the role of the second UE in the service for which the two UEs request discovery may be understood as the combination of the role of the first UE and the role of the second UE being able to complete the service for which the two UEs request discovery. Here, for a ranging service, the two roles that can be combined to complete the ranging service are typically a target UE and a reference UE. For a sidelink positioning service, the two roles that can be combined to complete the sidelink positioning service are typically a positioning UE and a target UE. Based on this, if the service for which the two UEs request discovery is a ranging service 1, when the role of the first UE is a target UE and the role of the second UE is a reference UE, this represents the matching of the role of the first UE and the role of the second UE in the service for which the two UEs request discovery.

[0078] In another embodiment of the present disclosure, a mismatch between the role of the first UE and the role of the second UE in the service for which the two UEs request discovery may be understood as a combination of the role of the first UE and the role of the second UE that cannot complete the service for which the two UEs request discovery. For example, when the service for which the two UEs request discovery is ranging service 1, if the role of the first UE is a target UE and the role of the second UE is also a target UE, this represents a mismatch between the role of the first UE and the role of the second UE in the service for which the two UEs request discovery.

[0079] Step 203e: in response to the role of the first UE and the role of the second UE matching, sending a first response message to the second UE, the first response message being protected by encryption key information corresponding to the service for which the first UE requests discovery, and the first response message including the role of the first UE.

[0080] The above steps 201e to 203e are a discovery process between the first UE and the second UE. After the two UEs discover each other, they can establish a connection to realize the service.

[0081]

[0013] In accordance with the above, in a UE role authorization method provided by an embodiment of the present disclosure, a first UE sends a discovery request message to a network device, requesting role authorization for the first UE. The first UE then receives a discovery response message sent from the network device, where the discovery response message includes the role determined by the network device for the first UE.

[0014] As can be seen from the above, the present disclosure provides a method for role authorization in a service for which a UE requests discovery, where the role of the UE may be determined by the network device based on UE capabilities and UE subscription information, thereby ensuring accurate role authorization for the UE and accuracy during service execution. At the same time, encryption key information corresponding to the service that the UE requests to discover is sent to the UE, and the encryption key information provides security protection for the UE's subsequent process of discovering other UEs, thereby ensuring that irrelevant UEs cannot monitor or tamper with the UE's role when the UE transmits its role in the subsequent discovery process, thereby preventing irrelevant UEs from impersonating the UE's role and avoiding interference from other irrelevant UEs in the subsequent service execution process, thereby improving the accuracy of service execution and improving information security.

[0082] Figure 2f is a schematic flowchart of a UE role authorization method provided by an embodiment of the present disclosure, which is performed by a second UE. As shown in Figure 2f, the UE role authorization method may include the following steps 201f to 202f.

[0083] Step 201f: sending a discovery request message to the network device requesting authorization of a role for the second UE;

[0084] Step 202f: receiving a discovery response message sent from the network device, wherein the discovery response message includes a role determined by the network device for the second UE;

[0085]

[0013] In accordance with the above, in a UE role authorization method provided by an embodiment of the present disclosure, a second UE sends a discovery request message to a network device to request role authorization for the second UE. The second UE then receives a discovery response message sent from the network device, and the discovery response message includes a role determined by the network device for the second UE.

[0014] As can be seen from the above, the present disclosure provides a method for role authorization in a service for which a UE requests discovery, where the role of the UE may be determined by the network device based on UE capabilities and UE subscription information, thereby ensuring accurate role authorization for the UE and accuracy during service execution. At the same time, encryption key information corresponding to the service that the UE requests to discover is sent to the UE, and the encryption key information provides security protection for the UE's subsequent process of discovering other UEs, thereby ensuring that irrelevant UEs cannot monitor or tamper with the UE's role when the UE transmits its role in the subsequent discovery process, thereby preventing irrelevant UEs from impersonating the UE's role and avoiding interference from other irrelevant UEs in the subsequent service execution process, thereby improving the accuracy of service execution and improving information security.

[0086] FIG. 2g is a schematic flowchart of a UE role authorization method provided by an embodiment of the present disclosure, which is performed by a second UE. As shown in FIG. 2g, the UE role authorization method includes the following steps 201g to 202g:

[0087] Step 201g: receiving a first discovery message broadcasted by a first UE, the first discovery message being protected by encryption key information corresponding to a service for which the first UE requests discovery, and the first discovery message including the role of the first UE;

[0088] Step 202g: decrypting and verifying the first discovery message; and determining whether the role of the second UE and the role of the first UE match in response to successful verification.

[0089]

[0013] In accordance with the above, in a UE role authorization method provided by an embodiment of the present disclosure, a second UE sends a discovery request message to a network device to request role authorization for the second UE. The second UE then receives a discovery response message sent from the network device, and the discovery response message includes a role determined by the network device for the second UE.

[0014] As can be seen from the above, the present disclosure provides a method for role authorization in a service for which a UE requests discovery, where the role of the UE may be determined by the network device based on UE capabilities and UE subscription information, thereby ensuring accurate role authorization for the UE and accuracy during service execution. At the same time, encryption key information corresponding to the service that the UE requests to discover is sent to the UE, and the encryption key information provides security protection for the UE's subsequent process of discovering other UEs, thereby ensuring that irrelevant UEs cannot monitor or tamper with the UE's role when the UE transmits its role in the subsequent discovery process, thereby preventing irrelevant UEs from impersonating the UE's role and avoiding interference from other irrelevant UEs in the subsequent service execution process, thereby improving the accuracy of service execution and improving information security.

[0090] FIG. 2h is a schematic flowchart of a UE role authorization method provided by an embodiment of the present disclosure, where the method is performed by a second UE. As shown in FIG. 2h, the role authorization for the UE includes the following steps 201h to 202h:

[0091] Step 201h: broadcasting a second discovery message, where the second discovery message is protected by encryption key information corresponding to a service for which the second UE requests discovery, and the second discovery message includes a role of the second UE.

[0092] Step 202h: receiving a first response message sent from the first UE, the first response message being protected by encryption key information corresponding to the service for which the first UE requests discovery, and the first response message including the role of the first UE;

[0093]

[0013] In accordance with the above, in a UE role authorization method provided by an embodiment of the present disclosure, a second UE sends a discovery request message to a network device to request role authorization for the second UE. The second UE then receives a discovery response message sent from the network device, and the discovery response message includes a role determined by the network device for the second UE.

[0014] As can be seen from the above, the present disclosure provides a method for role authorization in a service for which a UE requests discovery, where the role of the UE may be determined by the network device based on UE capabilities and UE subscription information, thereby ensuring accurate role authorization for the UE and accuracy during service execution. At the same time, encryption key information corresponding to the service that the UE requests to discover is sent to the UE, and the encryption key information provides security protection for the UE's subsequent process of discovering other UEs, thereby ensuring that irrelevant UEs cannot monitor or tamper with the UE's role when the UE transmits its role in the subsequent discovery process, thereby preventing irrelevant UEs from impersonating the UE's role and avoiding interference from other irrelevant UEs in the subsequent service execution process, thereby improving the accuracy of service execution and improving information security.

[0094] Furthermore, in one embodiment of the present disclosure, the network side device may include a first network element, a second network element, and a third network element, where the first network element includes the DDNMF network element of the first UE or the PKMF network element of the first UE, the second network element includes the DDNMF network element of the second UE or the PKMF network element of the second UE, and the third network element includes an access service server or a UDM network element. Based on this, specific steps during interaction between the first network element, the second network element, the third network element, the first UE, and the second UE will be described below.

[0095] FIG. 2i is a schematic flowchart of the interaction of a role authorization method for a UE provided by an embodiment of the present disclosure, which includes the following steps 201i to 204i.

[0096] Step 201i, the first network element receives a discovery request message sent from the first UE.

[0097] Step 202i, the first network element sends a first authorization request message to the third network element.

[0098] Step 203i, the third network element sends a first authorization response message to the first network element, including the role of the first UE determined by the third network element.

[0099] Step 204i, the first network element sends a discovery response message to the first UE.

[0100] The above steps will be explained in detail in the following examples.

[0101]

[0013] Accordingly, the present disclosure provides a method for authorizing a role in a service for which a UE requests discovery, where the role of the UE may be determined by a network device based on the UE's capabilities and UE subscription information, thereby ensuring accurate role authorization for the UE and ensuring accuracy during service execution. At the same time, encryption key information corresponding to the service for which the UE requests discovery is sent to the UE, and the encryption key information provides security protection for the UE's subsequent discovery process of other UEs, thereby ensuring that irrelevant UEs cannot monitor or tamper with the UE's role when the UE transmits the UE's role in the subsequent discovery process, thereby preventing irrelevant UEs from impersonating the UE's role and avoiding interference from other irrelevant UEs during the subsequent service execution process, improving the accuracy of service execution and improving information security.

[0102] FIG. 2j is a schematic flowchart of the interaction of a role authorization method for a UE provided by an embodiment of the present disclosure, which includes the following steps 201j to 204j.

[0103] Step 201j, the second network element receives a discovery request message sent from the second UE.

[0104] Step 202j, the second network element sends a first authorization request message to a third network element.

[0105] Step 203j, the third network element sends a first authorization response message to the second network element, the first authorization response message including the role of the second UE determined by the third network element.

[0106] Step 204j, the second network element sends a discovery response message to the second UE.

[0107] The above steps will be explained in detail in the following examples.

[0108]

[0013] Accordingly, the present disclosure provides a method for authorizing a role in a service for which a UE requests discovery, where the role of the UE may be determined by a network device based on the UE's capabilities and UE subscription information, thereby ensuring accurate role authorization for the UE and ensuring accuracy during service execution. At the same time, encryption key information corresponding to the service for which the UE requests discovery is sent to the UE, and the encryption key information provides security protection for the UE's subsequent discovery process of other UEs, thereby ensuring that irrelevant UEs cannot monitor or tamper with the UE's role when the UE transmits the UE's role in the subsequent discovery process, thereby preventing irrelevant UEs from impersonating the UE's role and avoiding interference from other irrelevant UEs during the subsequent service execution process, improving the accuracy of service execution and improving information security.

[0109] FIG. 2k is a schematic flowchart of an interaction of a role authorization method for a UE provided by an embodiment of the present disclosure, which may include the following steps 201k to 205k.

[0110] Step 201k: The second network element sends a monitoring request message to the first network element, where the monitoring request message includes the role of the second UE, and the monitoring request message is used to request determining whether the role of the second UE and the role of the first UE are consistent.

[0111] Step 202k, the first network element sends a second authorization request message to a third network element, the second authorization request message including the role of the first UE and the role of the second UE.

[0112] Step 203k: The third network element determines whether the role of the first UE and the role of the second UE match, and sends a second authorization response message to the first network element, where the second authorization response message is used to indicate whether the role of the first UE and the role of the second UE match in the service for which the two UEs request discovery.

[0113] Step 204k: In response to the role of the first UE and the role of the second UE matching, the first network element sends to the second network element encryption key information generated corresponding to the service for which the second UE requests discovery.

[0114] Step 205k, the second network element sends to the second UE encryption key information generated corresponding to the service for which the second UE requests discovery.

[0115] The above steps will be explained in detail in the following examples.

[0116]

[0013] Accordingly, the present disclosure provides a method for authorizing a role in a service for which a UE requests discovery, where the role of the UE may be determined by a network device based on the UE's capabilities and UE subscription information, thereby ensuring accurate role authorization for the UE and ensuring accuracy during service execution. At the same time, encryption key information corresponding to the service for which the UE requests discovery is sent to the UE, and the encryption key information provides security protection for the UE's subsequent discovery process of other UEs, thereby ensuring that irrelevant UEs cannot monitor or tamper with the UE's role when the UE transmits the UE's role in the subsequent discovery process, thereby preventing irrelevant UEs from impersonating the UE's role and avoiding interference from other irrelevant UEs during the subsequent service execution process, improving the accuracy of service execution and improving information security.

[0117] Furthermore, the above UE role authorization method is written from the perspective of a network device, the first UE, and the second UE. As can be seen from the above, the network device includes a DDNMF network element of the first UE or a PKMF network element of the first UE, a DDNMF network element of the second UE or a PKMF network element of the second UE, and a third network element includes an access service server or a UDM network element. Based on this, the UE role authorization method will be described below from the perspective of the DDNMF network element of the first UE or the PKMF network element of the first UE, the perspective of the DDNMF network element of the second UE or the PKMF network element of the second UE, the perspective of the server or UDM network element, the perspective of the interaction between the first UE and the DDNMF / PKMF network element, and the perspective of the interaction between the second UE and the DDNMF / PKMF network element.

[0118] Figure 2L is a schematic flowchart of a UE role authorization method provided by an embodiment of the present disclosure, which is performed by a DDNMF network element of a first UE or a PKMF network element of a first UE. As shown in Figure 2, the UE role authorization method may include the following steps 201L to 204L.

[0119] Step 201L: receiving a discovery request message sent from a first UE, the discovery request message being used to request authorization for a role for a service that the first UE requests discovery of;

[0120] In one embodiment of the present disclosure, Step 202L: sending a first authorization request message (Authorization Request) to a server or a UDM network element based on the discovery request message;

[0121] Specifically, in one embodiment of the present disclosure, a method for sending a first authorization request message to a server or a UDM network element based on the discovery request message may be as follows: first, convert the RAUID corresponding to the first UE into a first identifier for indicating the first UE that can be identified by the server or the UDM network element, and then carry at least one of the first identifier, the service for which the first UE requests discovery, and the capabilities of the first UE in a first authorization request message and send it to the server or the UDM network element.

[0122] Furthermore, in one embodiment of the present disclosure, the server may be, for example, a ranging or sidelink positioning server (Ranging / SL positioning server).

[0123] Step 203L receives a first authorization response message sent from a server or a UDM network element, where the first authorization response message includes the role of the first UE determined by the server or the UDM network element.

[0124] The role of the first UE may be determined, for example, by a server or a UDM network element based on the capabilities of the first UE and the roles of the first UE permitted in the service for which the first UE requests discovery. Specifically, the role of the first UE may be determined, for example, based on roles supported by the capabilities of the first UE among the roles permitted in the service for which the first UE requests discovery. For example, if the roles supported by the capabilities of the first UE are a target UE and a UE as a server, the role permitted in the service for which the first UE requests discovery may be a target UE, and in this case, the role of the first UE may be a target UE. This determination of the role of the first UE by the server or the UDM network element will be described in detail in the embodiment of the server or the UDM network element.

[0125] In addition, in one embodiment of the present disclosure, if the server or UDM network element cannot determine the role of the first UE based on the capabilities of the first UE and the roles of the first UE that are permitted in the service for which the first UE requests discovery (i.e., the roles of the first UE that are permitted in the service for which the first UE requests discovery do not include roles that are supported by the capabilities of the first UE), the first authorization response message may be used to indicate to the server or UDM network element authorization failure and / or the cause of the authorization failure.

[0126] Step 204L: Send a discovery response message (Discovery Request) to the first UE, the discovery response message including the role of the first UE.

[0127] In one embodiment of the present disclosure, the discovery response message may include encryption key information (Discovery Security Material) generated by the DDNMF network element of the first UE or the PKMF network element of the first UE for the service for which the first UE requests discovery, which provides security protection for the subsequent discovery process of the first UE, thereby ensuring that irrelevant UEs cannot monitor or tamper with the role of the first UE when the first UE transmits the role of the first UE in the subsequent discovery process, thereby preventing irrelevant UEs from impersonating the role of the first UE to deceive the counterpart UE of the first UE, preventing interference by other irrelevant UEs when performing the subsequent service, improving the accuracy of service execution, and improving information security.

[0128] Furthermore, in one embodiment of the present disclosure, when the DDNMF network element of the first UE or the PKMF network element of the first UE receives the role of the first UE, the DDNMF network element of the first UE or the PKMF network element of the first UE further determines an application code corresponding to the service that the first UE needs to perform, and carries the application code corresponding to the service that the first UE needs to perform in a discovery response message and sends it to the first UE, and the application code may be used by the first UE to discover other UEs that perform the same service as the first UE based on the application code.

[0129] In addition, in one embodiment of the present disclosure, if the first authorization response message received by the DDNMF network element of the first UE or the PKMF network element of the first UE indicates authorization failure, the DDNMF network element of the first UE or the PKMF network element of the first UE does not generate encryption key information and application code, and sends a discovery response message to the first UE indicating a discovery request for the first UE.

[0130]

[0023] Based on the above, in the UE role authorization method provided by the embodiments of the present disclosure, the DDNMF network element of the first UE or the PKMF network element of the first UE receives a discovery request message sent from the first UE, which is used to request role authorization for a service for which the first UE requests discovery, then sends a first authorization request message to a server or a UDM network element based on the discovery request message, receives a first authorization response message sent from the server or the UDM network element, which first authorization response message includes the role of the first UE determined by the server or the UDM network element, and finally, the DDNMF network element of the first UE or the PKMF network element of the first UE sends a discovery response message to the first UE, which includes the role of the first UE and encryption key information generated by the DDNMF network element of the first UE or the PKMF network element of the first UE for the service for which the first UE requests discovery. From this, it can be seen that the present disclosure provides a method for authorizing a role for a service for which a first UE requests discovery, where the role of the first UE may be determined by a server or a UDM network element based on the capabilities of the first UE and the roles that the first UE is allowed to play in the service for which the first UE requests discovery, thereby ensuring accurate role authorization for the first UE and improving accuracy during service execution. At the same time, the first UE may send encryption key information corresponding to the service for which discovery is requested to the first UE, where the encryption key information may be used to provide security protection for the process in which the first UE subsequently discovers other UEs, thereby ensuring that irrelevant UEs cannot monitor or tamper with the role of the first UE when the first UE transmits the role of the first UE in the subsequent discovery process, thereby preventing irrelevant UEs from impersonating the role of the first UE, avoiding interference by other irrelevant UEs during subsequent service execution, improving service execution accuracy, and improving information security.

[0131] FIG. 3 is a schematic flowchart of a UE role authorization method provided by an embodiment of the present disclosure, where the method is performed by a DDNMF network element of a first UE or a PKMF network element of a first UE. As shown in FIG. 3, the UE role authorization method may include the following steps 301 to 304:

[0132] Step 301: receive a Monitor Request message sent from a DDNMF network element of a second UE or a PKMF network element of a second UE;

[0133] In one embodiment of the present disclosure, the monitoring request message may be sent by the DDNMF network element of the second UE or the PKMF network element of the second UE to the DDNMF network element of the first UE after receiving the role of the second UE determined by the server or the UDM network element, and the monitoring request message includes at least one of the role of the second UE, the service that the second UE requests to discover, and a second identifier for indicating the second UE. A specific process by which the DDNMF network element of the second UE or the PKMF network element of the second UE obtains the role of the second UE determined by the server or the UDM network element is similar to the specific process by which the DDNMF network element of the first UE or the PKMF network element of the first UE obtains the role of the first UE, see the description of the embodiment on the side of the DDNMF network element of the second UE or the PKMF network element of the second UE below.

[0134] Step 302, in response to the service for which the second UE requests discovery being the same as the service for which the first UE requests discovery, send a second authorization request message to a server or a UDM network element, the second authorization request message including the role of the first UE, the role of the second UE, and the services for which the two UEs request discovery.

[0135] In one embodiment of the present disclosure, when the service that the second UE requests to be discovered is the same as the service that the first UE requests to be discovered, if the role of the first UE and the role of the second UE match, it indicates that the first UE and the second UE can complete the service that the two UEs request to be discovered. Based on this, when the DDNMF network element or PKMF network element of the first UE determines that the service that the second UE requests to be discovered is the same as the service that the first UE requests to be discovered, it can send a second authorization request message to the server or UDM network element through the server or UDM network element to determine whether the role of the first UE and the role of the second UE match, so as to know whether the first UE and the second UE can complete the service that the two UEs request. If the service can be completed, the two UEs will establish a connection by continuing the discovery process; if the service cannot be completed, it will be ignored.

[0136] Furthermore, in one embodiment of the present disclosure, the fact that the roles of the first UE and the second UE match in the services for which the two UEs request discovery can be understood as the fact that the roles of the first UE and the second UE can be combined with each other to complete the services for which the two UEs request discovery. Here, for a ranging service, the two roles that can be combined with each other to complete the ranging service are often a target UE and a reference UE. For a sidelink positioning service, the two roles that can be combined with each other to complete the sidelink positioning service may be a positioning UE and a target UE. Based on this, if the service for which the two UEs request discovery is a ranging service 1, and the role of the first UE is a target UE and the role of the second UE is a reference UE, this indicates that the role of the first UE and the role of the second UE match in the services for which the two UEs request discovery.

[0137] In another embodiment of the present disclosure, if the role of the first UE and the role of the second UE do not match in the services that the two UEs request discovery of, it indicates that the combination of the role of the first UE and the role of the second UE cannot complete the services that the two UEs request discovery of. For example, assuming that the services that the two UEs request discovery of are ranging service 1, if the role of the first UE is a target UE and the role of the second UE is also a target UE, it indicates that the role of the first UE and the role of the second UE do not match in the services that the two UEs request discovery of.

[0138] Step 303: receive a second authorization response message sent from the server or the UDM network element, where the second authorization response message indicates whether the role of the first UE and the role of the second UE are consistent in the service that the two UEs request discovery for.

[0139] Step 304: In response to the second authorization response message indicating that the role of the first UE and the role of the second UE are identical, send a Monitor Response message to the DDNMF network element of the second UE or the PKMF network element of the second UE.

[0140] In one embodiment of the present disclosure, the monitoring response message includes encryption key information generated by the DDNMF network element of the first UE or the PKMF network element of the first UE for the same service that the first UE requests discovery of, so that the encryption key information corresponding to the service that the second UE requests discovery of is the same as the encryption key information corresponding to the service that the first UE requests discovery of.

[0141] In addition, in one embodiment of the present disclosure, if the role of the first UE and the role of the second UE are consistent, it indicates that the combination of the first UE and the second UE can complete the service that the two UEs require discovery for. At this time, the DDNMF network element of the first UE or the PKMF network element of the first UE should generate a security discovery encryption key for the service that the second UE requires discovery for, which is the same as the security discovery encryption key generated by the first UE for the service that the first UE requires discovery for. In this way, the second UE can then successfully verify the information transmitted by the first UE in the discovery process based on the same security discovery encryption key, thereby allowing the two UEs to discover each other and successfully complete the service that the UEs require discovery for.

[0142] In addition, in one embodiment of the present disclosure, if the second authorization response message received by the DDNMF network element of the first UE or the PKMF network element of the first UE from the server or the UDM network element indicates that the role of the first UE and the role of the second UE do not match in the service for which the two UEs request discovery, the DDNMF network element of the first UE or the PKMF network element of the first UE should send an instruction to the DDNMF network element of the second UE or the PKMF network element of the second UE to reject the monitoring response message requesting monitoring.

[0143]

[0023] Based on the above, in the UE role authorization method provided by the embodiments of the present disclosure, the DDNMF network element of the first UE or the PKMF network element of the first UE receives a discovery request message sent from the first UE, which is used to request role authorization for a service for which the first UE requests discovery, then sends a first authorization request message to a server or a UDM network element based on the discovery request message, receives a first authorization response message sent from the server or the UDM network element, which first authorization response message includes the role of the first UE determined by the server or the UDM network element, and finally, the DDNMF network element of the first UE or the PKMF network element of the first UE sends a discovery response message to the first UE, which includes the role of the first UE and encryption key information generated by the DDNMF network element of the first UE or the PKMF network element of the first UE for the service for which the first UE requests discovery. From this, it can be seen that the present disclosure provides a method for authorizing a role for a service for which a first UE requests discovery, where the role of the first UE may be determined by a server or a UDM network element based on the capabilities of the first UE and the roles that the first UE is allowed to play in the service for which the first UE requests discovery, thereby ensuring accurate role authorization for the first UE and improving accuracy during service execution. At the same time, the first UE may send encryption key information corresponding to the service for which discovery is requested to the first UE, where the encryption key information may be used to provide security protection for the process in which the first UE subsequently discovers other UEs, thereby ensuring that irrelevant UEs cannot monitor or tamper with the role of the first UE when the first UE transmits the role of the first UE in the subsequent discovery process, thereby preventing irrelevant UEs from impersonating the role of the first UE, avoiding interference by other irrelevant UEs during subsequent service execution, improving service execution accuracy, and improving information security.

[0144] FIG. 4 is a schematic flowchart of a UE role authorization method provided by an embodiment of the present disclosure, where the method is performed by a DDNMF network element of a second UE or a PKMF network element of a second UE. As shown in FIG. 4, the UE role authorization method may include the following steps 401 to 405:

[0145] Step 401: receiving a discovery request message sent from a second UE, the discovery request message being used to request authorization for a role for a service that the second UE requests discovery of;

[0146] Optionally, in one embodiment of the present disclosure, the discovery request message may include at least one of a RAUID corresponding to the second UE, a service for which the second UE requests discovery, and a capability of the second UE.

[0147] The RAUID indicates the UE, so that the network device can know from which UE the discovery request message is sent.

[0148] Step 402: Send a first authorization request message to a server or a UDM network element based on the discovery request message.

[0149] Optionally, the step of sending a first authorization request message to a server or UDM network element based on the discovery request message may include a step of converting a RAUID corresponding to the second UE into a second identifier identifiable by the server or UDM network element, wherein the second identifier is used to indicate the second UE; and a step of carrying at least one of the second identifier, the service for which the second UE requests discovery, and the capabilities of the second UE in the authorization request message and sending it to the server or UDM network element.

[0150] Step 403: receiving a first authorization response message sent from a server or a UDM network element, where the first authorization response message includes a role of the second UE determined by the server or the UDM network element;

[0151] Optionally, in one embodiment of the present disclosure, the role of the second UE is determined by a server or UDM network element based on the capabilities of the second UE and the role that the second UE is allowed to play in the service for which the second UE requests discovery.

[0152] Step 404: The second UE determines encryption key information corresponding to the service for which discovery is required.

[0153] The encryption key information corresponding to the service that the second UE requests to discover is generally the same as the encryption key information corresponding to the service that the first UE requests to discover. In this step, for determining the encryption key information corresponding to the service that the second UE requests to discover, please refer to the description in the following examples.

[0154] Step 405: Send a discovery response message to the second UE, the discovery response message including the role of the second UE.

[0155] Here, the discovery response message may include encryption key information generated by the DDNMF network element of the first UE or the PKMF network element of the second UE for the service that the second UE requests to discover.

[0156] The principles of the above steps 401 to 403 and 405 are the same as the principles of steps 201 to 204 in the embodiment of FIG. 2, and for the rest, please refer to the explanation of the embodiment described above.

[0157]

[0023] Based on the above, in the UE role authorization method provided by the embodiments of the present disclosure, the DDNMF network element of the second UE or the PKMF network element of the second UE receives a discovery request message sent from the second UE, which is used to request role authorization for a service for which the second UE requests discovery, then sends a first authorization request message to a server or a UDM network element based on the discovery request message, receives a first authorization response message sent from the server or the UDM network element, which includes the role of the second UE determined by the server or the UDM network element, the DDNMF network element of the second UE or the PKMF network element of the second UE determines encryption key information corresponding to the service for which the second UE requests discovery, and finally, the DDNMF network element of the second UE or the PKMF network element of the second UE sends a discovery response message to the second UE, which includes the role of the second UE and the encryption key information corresponding to the service for which the second UE requests discovery. From this, it can be seen that the present disclosure provides a method for authorizing a role for a second UE in a service that requires discovery, where the role of the second UE may be determined by a server or a UDM network element based on the capabilities of the second UE and the role that the second UE is allowed to play in the service that requires discovery, thereby ensuring accurate role authorization for the second UE and accuracy during service execution. At the same time, the second UE may send encryption key information corresponding to the service that requires discovery to the second UE, and the encryption key information may be used to successfully verify the information transmitted by the first UE in the discovery process based on the same security discovery encryption key, thereby ensuring that the two UEs can discover each other and successfully complete the service that requires discovery. Furthermore, since other UEs cannot know the security encryption key, interference by other unrelated UEs during subsequent service execution is avoided, improving the accuracy of service execution and information security.

[0158] FIG. 5 is a schematic flowchart of a UE role authorization method provided by an embodiment of the present disclosure, where the method is performed by a DDNMF network element of a second UE or a PKMF network element of a second UE. As shown in FIG. 5, the UE role authorization method may include the following steps 501 to 502:

[0159] Step 501: Send a monitoring request message to a DDNMF network element of a first UE or a PKMF network element of a first UE, carrying at least one of a role of a second UE, a service for which the second UE requests discovery, and a second identifier for indicating the second UE.

[0160] In addition, in one embodiment of the present disclosure, the second UE actually knows which UE the counterpart UE (i.e., the first UE) is. Based on this, when the second UE sends a discovery request message to the DDNMF network element of the second UE or the PKMF network element of the second UE, the second UE may carry indication information in the discovery request message to indicate the first UE or the DDNMF network element or PKMF network element of the first UE. In this way, the DDNMF network element of the second UE or the PKMF network element of the second UE can determine to which UE's DDNMF network element or PKMF network element to send the monitoring request message based on the indication information, thereby ensuring that the DDNMF network element or PKMF network element of the second UE successfully sends the monitoring request message to the DDNMF network element or PKMF network element of the first UE.

[0161] Step 502: receive a monitoring response message sent from the DDNMF network element of the first UE or the PKMF network element of the first UE.

[0162] Here, in one embodiment of the present disclosure, the monitoring response message carries encryption key information corresponding to the service for which the second UE requests discovery, where the encryption key information is sent to the DDNMF network element of the second UE or the PKMF network element of the second UE after the DDNMF network element of the first UE or the PKMF network element of the first UE receives a second authorization response message sent from a server or a UDM network element indicating that the role of the first UE and the role of the second UE are the same, and the encryption key information corresponding to the service for which the second UE requests discovery is the same as the security encryption key corresponding to the service for which the first UE requests discovery.

[0163] For a detailed explanation of steps 501 and 502, please refer to the above-described embodiment, and a detailed explanation will be omitted in the embodiment of the present disclosure.

[0164]

[0023] Based on the above, in the UE role authorization method provided by the embodiments of the present disclosure, the DDNMF network element of the second UE or the PKMF network element of the second UE receives a discovery request message sent from the second UE, which is used to request role authorization for a service for which the second UE requests discovery, then sends a first authorization request message to a server or a UDM network element based on the discovery request message, receives a first authorization response message sent from the server or the UDM network element, which includes the role of the second UE determined by the server or the UDM network element, the DDNMF network element of the second UE or the PKMF network element of the second UE determines encryption key information corresponding to the service for which the second UE requests discovery, and finally, the DDNMF network element of the second UE or the PKMF network element of the second UE sends a discovery response message to the second UE, which includes the role of the second UE and the encryption key information corresponding to the service for which the second UE requests discovery. From this, it can be seen that the present disclosure provides a method for authorizing a role for a second UE in a service that requires discovery, where the role of the second UE may be determined by a server or a UDM network element based on the capabilities of the second UE and the role that the second UE is allowed to play in the service that requires discovery, thereby ensuring accurate role authorization for the second UE and accuracy during service execution. At the same time, the second UE may send encryption key information corresponding to the service that requires discovery to the second UE, and the encryption key information may be used to successfully verify the information transmitted by the first UE in the discovery process based on the same security discovery encryption key, thereby ensuring that the two UEs can discover each other and successfully complete the service that requires discovery. Furthermore, since other UEs cannot know the security encryption key, interference by other unrelated UEs during subsequent service execution is avoided, improving the accuracy of service execution and information security.

[0165] FIG. 6 is a schematic flowchart of a UE role authorization method provided by an embodiment of the present disclosure, which is performed by a server or a UDM network element. As shown in FIG. 6, the UE role authorization method may include the following steps 601 to 603:

[0166] Step 601: receive a first authorization request message sent from a DDNMF network element or a PKMF network element of a first UE and / or a second UE, the first authorization request message being used to request authorization for a role for a service that the first UE and / or the second UE requests discovery of.

[0167] Optionally, the first authorization request message includes at least one of an identifier for indicating the first UE and / or second UE, a service for which the first UE and / or second UE requests discovery, and a capability of the first UE and / or second UE.

[0168] Step 602: Determine the role of the first UE and / or the second UE based on the first authorization request message.

[0169] In this step, for the description of determining the role of the first UE and / or the second UE, please refer to the description of the following embodiment.

[0170] Step 603: Send a first authorization response message, including the role of the first UE and / or the second UE, to a DDNMF network element or a PKMF network element of the first UE and / or the second UE.

[0171] For a detailed explanation of the principles of steps 601 to 603, please refer to the explanation of the above-mentioned embodiment.

[0172] As described above, in the UE role authorization method provided by the embodiments of the present disclosure, a server or UDM network element receives a first authorization request message sent from a DDNMF network element or a PKMF network element of a first UE and / or a second UE, the first authorization request message is used to request role authorization for a service that the first UE and / or the second UE requests to discover, determines the role of the first UE and / or the second UE based on the first authorization request message, and then the server or UDM network element sends a first authorization response message including the role of the first UE and / or the second UE to the DDNMF network element or the PKMF network element of the first UE and / or the second UE. As can be seen from this, the present disclosure provides a method for authorizing a role in a service for which a first UE and / or a second UE requests discovery, and the role of the first UE and / or the second UE is determined by a server or a UDM network element based on the capabilities of the first UE and / or the second UE and the role that the first UE and / or the second UE is allowed to play in the service for which the first UE and / or the second UE requests discovery, thereby ensuring that the role can be accurately authorized for the first UE and / or the second UE and ensuring accuracy during service execution.

[0173] FIG. 7 is a schematic flowchart of a UE role authorization method provided by an embodiment of the present disclosure, where the method is performed by a server or a UDM network element. As shown in FIG. 7, the UE role authorization method may include the following steps 701 to 702:

[0174] Step 701: Determine, based on an identifier for indicating the first UE and / or the second UE and a service for which the first UE and / or the second UE requests discovery, a role that the first UE and / or the second UE is allowed to play in the service for which the first UE and / or the second UE requests discovery.

[0175] In one embodiment of the present disclosure, each UE's authorized role in the ranging service and / or sidelink positioning service may be registered in a service protocol of the server, or the corresponding UE's authorized role in the ranging service and / or sidelink positioning service may be registered in each UE subscription of the UDM. Based on this, the server can determine the authorized role of a specific UE in the ranging service and / or sidelink positioning service by searching the service protocol, and the UDM can determine the authorized role of a specific UE in the ranging service and / or sidelink positioning service by searching the UE subscription.

[0176] Based on this, the first UE is taken as an example to describe how the server or UDM determines the role of the first UE, and the second UE is similar.

[0177] Specifically, for example, if the service that two UEs request to discover is a ranging service, the server can search the service protocol based on the identifier of the first UE to find out that the roles that the first UE is allowed to play in the ranging service are target UE and serving UE, and / or the UDM can determine the subscription of the first UE based on the identifier of the first UE and check the subscription of the first UE to find out that the roles that the first UE is allowed to play in the sidelink positioning service are target UE and serving UE.

[0178] Step 702: Determine, among the permitted roles of the first UE and / or the second UE, a role supported by the capabilities of the first UE and / or the second UE as a role of the first UE and / or the second UE.

[0179] For illustrative purposes, taking the first UE as an example, assuming that the server or UDM network element determines based on the capabilities of the first UE that the roles supported by the first UE in the ranging service are target UE and positioning UE, the roles permitted for the first UE in the ranging service determined in step 701 are target UE and serving UE, so the server or UDM network element can determine that the role of the first UE is target UE.

[0180] In addition, in one embodiment of the present disclosure, if there are multiple roles among the permitted roles of the first UE that are supported by the capabilities of the first UE, the server or UDM network element determines all of the multiple roles as the roles of the first UE, that is, the first UE may have multiple roles.

[0181] As described above, in the UE role authorization method provided by the embodiments of the present disclosure, a server or UDM network element receives a first authorization request message sent from a DDNMF network element or a PKMF network element of a first UE and / or a second UE, the first authorization request message is used to request role authorization for a service that the first UE and / or the second UE requests to discover, determines the role of the first UE and / or the second UE based on the first authorization request message, and then the server or UDM network element sends a first authorization response message including the role of the first UE and / or the second UE to the DDNMF network element or the PKMF network element of the first UE and / or the second UE. As can be seen from this, the present disclosure provides a method for authorizing a role in a service for which a first UE and / or a second UE requests discovery, and the role of the first UE and / or the second UE is determined by a server or a UDM network element based on the capabilities of the first UE and / or the second UE and the role that the first UE and / or the second UE is allowed to play in the service for which the first UE and / or the second UE requests discovery, thereby ensuring that the role can be accurately authorized for the first UE and / or the second UE and ensuring accuracy during service execution.

[0182] FIG. 8 is a schematic flowchart of a UE role authorization method provided by an embodiment of the present disclosure, where the method is performed by a server or a UDM network element. As shown in FIG. 8, the UE role authorization method may include the following steps 801 to 803:

[0183] Step 801: Receive a second authorization request message sent from a DDNMF network element or a PKMF network element of a first UE, where the second authorization request message includes the role of the first UE, the role of the second UE, and the services that the two UEs request to discover.

[0184] Step 802: Determine whether the role of the first UE and the role of the second UE match in the service for which the two UEs request discovery.

[0185] Step 803: Send a second authorization response message to the DDNMF network element or the PKMF network element of the first UE, for indicating whether the role of the first UE and the role of the second UE are consistent.

[0186] For a detailed explanation of steps 801 to 803, please refer to the explanation of the above embodiment.

[0187] As described above, in the UE role authorization method provided by the embodiments of the present disclosure, a server or UDM network element receives a first authorization request message sent from a DDNMF network element or a PKMF network element of a first UE and / or a second UE, the first authorization request message is used to request role authorization for a service that the first UE and / or the second UE requests to discover, determines the role of the first UE and / or the second UE based on the first authorization request message, and then the server or UDM network element sends a first authorization response message including the role of the first UE and / or the second UE to the DDNMF network element or the PKMF network element of the first UE and / or the second UE. As can be seen from this, the present disclosure provides a method for authorizing a role in a service for which a first UE and / or a second UE requests discovery, and the role of the first UE and / or the second UE is determined by a server or a UDM network element based on the capabilities of the first UE and / or the second UE and the role that the first UE and / or the second UE is allowed to play in the service for which the first UE and / or the second UE requests discovery, thereby ensuring that the role can be accurately authorized for the first UE and / or the second UE and ensuring accuracy during service execution.

[0188] FIG. 9 is a schematic flowchart of a UE role authorization method provided by an embodiment of the present disclosure, which is performed by a first UE. As shown in FIG. 9, the UE role authorization method includes the following steps 901 to 902:

[0189] Step 901: A first UE sends a discovery request message to a DDNMF network element of the first UE or a PKMF network element of the first UE, requesting authorization for a role for a service that requires discovery.

[0190] Step 902: Receive a discovery response message sent from the DDNMF network element of the first UE or the PKMF network element of the first UE, where the discovery response message includes encryption key information corresponding to the role of the first UE and the service for which the first UE requests discovery.

[0191]

[0013] As described above, in a UE role authorization method provided by an embodiment of the present disclosure, a first UE sends a discovery request message to a DDNMF network element of the first UE or a PKMF network element of the first UE, requesting authorization of a role for a service for which the first UE requests discovery, and the first UE receives a discovery response message sent from the DDNMF network element of the first UE or the PKMF network element of the first UE, the discovery response message including encryption key information corresponding to the role of the first UE and the service for which the first UE requests discovery. As can be seen from this, the present disclosure provides a method for authorizing a role for a service for which the first UE requests discovery, where the role of the first UE may be determined by a server or a UDM network element based on the capability of the first UE and the role of the first UE that is permitted for the service for which the first UE requests discovery, thereby ensuring accurate role authorization for the first UE and improving accuracy during service execution. At the same time, the first UE sends encryption key information corresponding to the service that it requests to discover to the first UE, and the encryption key information may be used to provide security protection for the first UE's subsequent process of discovering other UEs, thereby ensuring that irrelevant UEs cannot monitor the role of the first UE when the first UE transmits the role of the first UE in the subsequent discovery process, and preventing irrelevant UEs from impersonating the role of the first UE, thereby avoiding interference by other irrelevant UEs when performing the subsequent service, improving the accuracy of service execution, and improving information security.

[0192] FIG. 10 is a schematic flowchart of a UE role authorization method provided by an embodiment of the present disclosure, where the method is performed by a first UE. As shown in FIG. 10, the UE role authorization method may include the following step 1001:

[0193] Step 1001: broadcast a first discovery message, the first discovery message being protected by encryption key information corresponding to a service for which the first UE requests discovery, and the first discovery message including a role of the first UE and an application code corresponding to the service for which the first UE requests discovery.

[0194] In one embodiment of the present disclosure, the first UE broadcasts a first discovery message protected by encryption key information corresponding to the service for which the first UE requests discovery. Since the encryption key information corresponding to the service for which the second UE requests discovery is the same as the security encryption key corresponding to the service for which the first UE requests discovery, the second UE uses the same encryption key information to successfully verify the first discovery message broadcast by the first UE and successfully discover the first UE. Thereafter, the second UE can verify whether the role of the second UE is consistent with the role of the first UE, and can then determine whether to establish a connection with the first UE.

[0195]

[0013] As described above, in a UE role authorization method provided by an embodiment of the present disclosure, a first UE sends a discovery request message to a DDNMF network element of the first UE or a PKMF network element of the first UE, requesting authorization of a role for a service for which the first UE requests discovery, and the first UE receives a discovery response message sent from the DDNMF network element of the first UE or the PKMF network element of the first UE, the discovery response message including encryption key information corresponding to the role of the first UE and the service for which the first UE requests discovery. As can be seen from this, the present disclosure provides a method for authorizing a role for a service for which the first UE requests discovery, where the role of the first UE may be determined by a server or a UDM network element based on the capability of the first UE and the role of the first UE that is permitted for the service for which the first UE requests discovery, thereby ensuring accurate role authorization for the first UE and improving accuracy during service execution. At the same time, the first UE sends encryption key information corresponding to the service that it requests to discover to the first UE, and the encryption key information may be used to provide security protection for the process in which the first UE subsequently discovers other UEs, thereby ensuring that irrelevant UEs cannot monitor or tamper with the role of the first UE when the first UE transmits the role of the first UE in the subsequent discovery process, thereby preventing irrelevant UEs from impersonating the role of the first UE, avoiding interference by other irrelevant UEs when performing the subsequent service, improving the accuracy of service execution, and improving information security.

[0196] FIG. 11 is a schematic flowchart of a UE role authorization method provided by an embodiment of the present disclosure, which is performed by a first UE. As shown in FIG. 11, the UE role authorization method may include the following steps 1101 to 1103.

[0197] Step 1101: receive a second discovery message broadcast by a second UE, the second discovery message being protected by encryption key information corresponding to a service for which the second UE requests discovery, and the second discovery message including a role of the second UE and an application code corresponding to the service for which the second UE requests discovery.

[0198] Step 1102: The first UE decrypts and verifies the second discovery message based on encryption key information corresponding to the service for which discovery is requested, and in response to successful verification, determines whether the application code corresponding to the service for which discovery is requested by the second UE matches the application code corresponding to the service for which discovery is requested by the first UE, and if they match, determines whether the role of the second UE matches the role of the first UE.

[0199] The principle of the first UE verifying the second discovery message using encryption key information may be explained with reference to the above embodiment, and if the application code corresponding to the service that the second UE requests discovery is consistent with the application code corresponding to the service that the first UE requests discovery, it indicates that the services that the two UEs request discovery are the same. Therefore, at this time, it can further be determined whether the roles of the two UEs are consistent. If they are consistent, it indicates that the combination of the two UEs can complete the service that the two UEs request discovery; if they are not consistent, it indicates that the two UEs cannot complete the service that the two UEs request discovery.

[0200] Step 1103: In response to the role of the first UE and the role of the second UE matching, send a first response message to the second UE, where the first response message is protected by encryption key information corresponding to the service for which the first UE requests discovery, and the first response message includes the role of the first UE and an application code corresponding to the service for which the first UE requests discovery.

[0201] The above steps 1101 to 1103 are a discovery process between the first UE and the second UE. After the two UEs discover each other, they can establish a connection to realize the service.

[0202]

[0013] As described above, in a UE role authorization method provided by an embodiment of the present disclosure, a first UE sends a discovery request message to a DDNMF network element of the first UE or a PKMF network element of the first UE, requesting authorization of a role for a service for which the first UE requests discovery, and the first UE receives a discovery response message sent from the DDNMF network element of the first UE or the PKMF network element of the first UE, the discovery response message including encryption key information corresponding to the role of the first UE and the service for which the first UE requests discovery. As can be seen from this, the present disclosure provides a method for authorizing a role for a service for which the first UE requests discovery, where the role of the first UE may be determined by a server or a UDM network element based on the capability of the first UE and the role of the first UE that is permitted for the service for which the first UE requests discovery, thereby ensuring accurate role authorization for the first UE and improving accuracy during service execution. At the same time, the first UE sends encryption key information corresponding to the service that it requests to discover to the first UE, and the encryption key information may be used to provide security protection for the first UE's subsequent process of discovering other UEs, thereby ensuring that irrelevant UEs cannot monitor the role of the first UE when the first UE transmits the role of the first UE in the subsequent discovery process, and preventing irrelevant UEs from impersonating the role of the first UE, thereby avoiding interference by other irrelevant UEs when performing the subsequent service, improving the accuracy of service execution, and improving information security.

[0203] Figure 12 is a schematic flowchart of a UE role authorization method provided by an embodiment of the present disclosure, where the method is performed by a second UE. As shown in Figure 12, the UE role authorization method may include the following steps 1201 to 1202.

[0204] Step 1201: A second UE sends a discovery request message to a DDNMF network element of the second UE or a PKMF network element of the second UE, requesting authorization of a role for a service that requires discovery.

[0205] Step 1202: Receive a discovery response message sent from the DDNMF network element of the second UE or the PKMF network element of the second UE, where the discovery response message includes encryption key information corresponding to the role of the second UE and the service for which the second UE requests discovery.

[0206]

[0013] As described above, in a UE role authorization method provided by an embodiment of the present disclosure, a second UE sends a discovery request message to a DDNMF network element of the second UE or a PKMF network element of the second UE, requesting authorization of a role for a service for which the second UE requests discovery, and the second UE receives a discovery response message sent from the DDNMF network element of the second UE or the PKMF network element of the second UE, the discovery response message including encryption key information corresponding to the role of the second UE and the service for which the second UE requests discovery.

[0014] As can be seen from the above, the present disclosure provides a method for authorizing a role for a service for which the second UE requests discovery, where the role of the second UE may be determined by a server or a UDM network element based on the capabilities of the second UE and the role of the second UE permitted for the service for which the second UE requests discovery, thereby ensuring accurate role authorization for the second UE and accuracy during service execution. At the same time, the second UE sends encryption key information corresponding to the service that the second UE requests discovery to the second UE, and the encryption key information can be used to successfully verify the information transmitted by the first UE in the discovery process based on the same security discovery encryption key, thereby ensuring that the two UEs can discover each other and successfully complete the service that the two UEs request discovery. Furthermore, other UEs cannot know the security encryption key, which avoids interference by other unrelated UEs when performing the subsequent service, improves the accuracy of service execution, and enhances information security.

[0207] Figure 13 is a schematic flowchart of a UE role authorization method provided by an embodiment of the present disclosure, where the method is performed by a second UE. As shown in Figure 13, the UE role authorization method may include the following steps 1301 to 1302.

[0208] Step 1301: Receive a first discovery message broadcast by a first UE, the first discovery message being protected by encryption key information corresponding to a service for which the first UE requests discovery, and the first discovery message including a role of the first UE and an application code corresponding to the service for which the first UE requests discovery.

[0209] Step 1302: Decrypt and verify the first discovery message based on encryption key information corresponding to the service for which the second UE requests discovery, and in response to successful verification, determine whether the application code corresponding to the service for which the first UE requests discovery matches the application code corresponding to the service for which the second UE requests discovery, and if they match, determine whether the role of the second UE matches the role of the first UE.

[0210]

[0013] As described above, in a UE role authorization method provided by an embodiment of the present disclosure, a second UE sends a discovery request message to a DDNMF network element of the second UE or a PKMF network element of the second UE, requesting authorization of a role for a service for which the second UE requests discovery, and the second UE receives a discovery response message sent from the DDNMF network element of the second UE or the PKMF network element of the second UE, the discovery response message including encryption key information corresponding to the role of the second UE and the service for which the second UE requests discovery.

[0014] As can be seen from the above, the present disclosure provides a method for authorizing a role for a service for which the second UE requests discovery, where the role of the second UE may be determined by a server or a UDM network element based on the capabilities of the second UE and the role of the second UE permitted for the service for which the second UE requests discovery, thereby ensuring accurate role authorization for the second UE and accuracy during service execution. At the same time, the second UE sends encryption key information corresponding to the service that the second UE requests discovery to the second UE, and the encryption key information can be used to successfully verify the information transmitted by the first UE in the discovery process based on the same security discovery encryption key, thereby ensuring that the two UEs can discover each other and successfully complete the service that the two UEs request discovery. Furthermore, other UEs cannot know the security encryption key, which avoids interference by other unrelated UEs when performing the subsequent service, improves the accuracy of service execution, and enhances information security.

[0211] Figure 14 is a schematic flowchart of a UE role authorization method provided by an embodiment of the present disclosure, where the method is performed by a second UE. As shown in Figure 14, the UE role authorization method may include the following steps 1401 to 1402.

[0212] Step 1401: broadcast a second discovery message, where the second discovery message is protected by encryption key information corresponding to a service for which the second UE requests discovery, and the second discovery message includes a role of the second UE and an application code corresponding to the service for which the second UE requests discovery.

[0213] Step 1402: Receive a first response message sent from the first UE, the first response message being protected by encryption key information corresponding to the service for which the first UE requests discovery, and the first response message including the role of the first UE and an application code corresponding to the service for which the first UE requests discovery.

[0214]

[0013] As described above, in a UE role authorization method provided by an embodiment of the present disclosure, a second UE sends a discovery request message to a DDNMF network element of the second UE or a PKMF network element of the second UE, requesting authorization of a role for a service for which the second UE requests discovery, and the second UE receives a discovery response message sent from the DDNMF network element of the second UE or the PKMF network element of the second UE, the discovery response message including encryption key information corresponding to the role of the second UE and the service for which the second UE requests discovery.

[0014] As can be seen from the above, the present disclosure provides a method for authorizing a role for a service for which the second UE requests discovery, where the role of the second UE may be determined by a server or a UDM network element based on the capabilities of the second UE and the role of the second UE permitted for the service for which the second UE requests discovery, thereby ensuring accurate role authorization for the second UE and accuracy during service execution. At the same time, the second UE sends encryption key information corresponding to the service that the second UE requests discovery to the second UE, and the encryption key information can be used to successfully verify the information transmitted by the first UE in the discovery process based on the same security discovery encryption key, thereby ensuring that the two UEs can discover each other and successfully complete the service that the two UEs request discovery. Furthermore, other UEs cannot know the security encryption key, which avoids interference by other unrelated UEs when performing the subsequent service, improves the accuracy of service execution, and enhances information security.

[0215] FIG. 15 is a schematic flowchart of the interaction of a UE role authorization method provided by an embodiment of the present disclosure, as shown in FIG. 15, including:

[0216] 1. The A-UE (which may be the first UE in the above embodiment) sends a discovery request message including a ranging application user ID (RAUID) to its 5G DDNMF / PKMF to obtain a ranging application code, thereby announcing and obtaining related encryption key information. The A-UE should also include a UE ranging service capability (i.e., the "capability of the first UE" in the above embodiment, e.g., impersonating a target / server UE) in the discovery request message.

[0217] 2. The 5G DDNMF / PKMF of the A-UE announces authorization by sending a first authorization request message to the ranging / SL positioning server or UDM of the A-UE, where the UE's capability for the ranging service received from the A-UE is included.

[0218] 3. The ranging / SL positioning server checks the service protocol, or the A-UE's UDM checks the A-UE's subscription, thereby determining whether the A-UE is allowed to play the role corresponding to its capabilities (e.g., whether the A-UE is allowed to be a target / server UE).

[0219] 4. If the UE capabilities match the permitted roles (e.g., A-UE is the target UE, or A-UE is the target UE and server UE), the ranging / SL positioning server or the UDM of the A-UE returns a first authorization response message including the role of the A-UE to the 5G DDNMF / PKMF. If the UE capabilities do not match the permitted roles (e.g., A-UE should not be the target UE or server UE), the Ranging / SL positioning server or the UDM A-UE returns a first authorization response message including the cause of failure.

[0220] 5. If authorization of the UDM with the Ranging / SL positioning server or the A-UE is successful, the A-UE's 5G DDNMF / PKMF returns the ranging application code and corresponding encryption key information in a discovery response message. The encryption key information protects the transmission of the ranging application code by providing the A-UE with the necessary information and is stored together with the ranging application code. The A-UE's 5G DDNMF / PKMF further includes the A-UE's role received from the Ranging / SL positioning server or the A-UE's UDM in the discovery response message. If authorization of the A-UE's Ranging / SL positioning server or UDM is unsuccessful, the A-UE's 5G DDNMF / PKMF does not generate encryption key information and rejects the discovery request from the A-UE.

[0221] 6. The M-UE (which may be the second UE in the above embodiment) obtains the ranging application code by sending a discovery request message including a ranging application user ID (RAUID) to its 5G DDNMF / PKMF, thereby announcing and obtaining related encryption key information. The M-UE should also include its UE ranging service capability (i.e., the "capability of the second UE" in the above embodiment, such as the capability to impersonate a reference / positioning UE) in the discovery request message.

[0222] 7. The 5G DDNMF / PKMF of the M-UE sends a first authorization request message containing the UE capability of the ranging service received from the M-UE to the Ranging / SL positioning server or the UDM of the M-UE.

[0223] 8. The Ranging / SL positioning server checks the service protocol, or the M-UE's UDM checks the M-UE's subscription, thereby determining whether the M-UE is allowed to play the role corresponding to its capabilities (e.g., whether the M-UE is allowed to be a reference / positioning UE).

[0224] 9. If the UE capabilities match the permitted roles (e.g., allow M-UE to be the reference UE or allow A-UE to be both the reference UE and the positioning UE), the ranging / SL positioning server or UDM of the M-UE returns a first authorization response message including the role of the M-UE to the 5G DDNMF / PKMF. If the UE capabilities do not match the permitted roles (e.g., allow M-UE to be the reference UE or not to be the positioning UE), the Ranging / SL positioning server or UDM M-UE returns a first authorization response message including a failure cause.

[0225] 10.If the UDM authorization to the Ranging / SL positioning server or A-UE is successful, the 5G DDNMF / PKMF of the M-UE contacts the 5G DDNMF / PKMF of the A-UE by sending a monitoring request message.If the Ranging / SL positioning server or UDM authorization to the A-UE fails, the 5G DDNMF / PKMF of the M-UE rejects the M-UE's Discovery Request and does not perform the following steps.

[0226] 11. The 5G DDNMF / PKMF of the A-UE sends a second authorization request message to the Ranging / SL positioning server, which message includes the roles of the M-UE and the A-UE.

[0227] 12. The Ranging / SL positioning server checks whether the roles of M-UE and A-UE match in the requested service (for example, for a ranging service between two UEs, whether the roles of the two UEs are Target UE and Reference UE respectively, or whether they are positioning UE and target UE; if so, they are used for the Ranging / SL positioning service between the two UEs).

[0228] 13. The Ranging / SL positioning server returns a second authorization response message indicating whether authorization was successful or not.

[0229] 14. If authorization with the Ranging / SL positioning server is successful, the A-UE's 5G DDNMF / PKMF responds to the M-UE's 5G DDNMF / PKMF with a monitoring response message containing a ranging application code and corresponding encryption key information (the security encryption key is the same as the security encryption key fed back to the A-UE). The encryption key information provides the information required for the M-UE to cancel the protection of the A-UE application (i.e., the information required for verifying messages transmitted by the A-UE). If authorization with the Ranging / SL positioning server is unsuccessful, the A-UE's 5G DDNMF / PKMF rejects the monitoring request message from the M-UE's 5G DDNMF / PKMF and does not perform the following steps.

[0230] 15. The 5G DDNMF / PKMF of the M-UE returns the encryption key information and the M-UE role received from the ranging / SL positioning server or the M-UE's UDM in a discovery response message.

[0231] 16. The A-UE initiates the notification of a first discovery message. The A-UE generates and protects the first discovery message with cryptographic key information. The first discovery message further includes the authorization role of the A-UE.

[0232] 17. The M-UE monitors the first discovery message and verifies it using the encryption key information.

[0233] 18. The M-UE checks the role of the A-UE in the first discovery message and determines whether the role of the A-UE in the first discovery message is its monitoring role, for example, if the role of the A-UE is the target UE, the M-UE, which is the reference UE, can determine that a matching item is found.

[0234] FIG. 16 is a schematic flowchart of the interaction of a UE role authorization method provided by an embodiment of the present disclosure, as shown in FIG. 16, including:

[0235] Steps 1 to 15 of the embodiment of FIG. 16 are the same as steps 1 to 15 of FIG. 15, where R-UE in FIG. 16 may be the second UE, and E-UE may be the first UE.

[0236] 16. The R-UE generates and protects a second discovery message with cryptographic key information, the second discovery message further including the role of the R-UE.

[0237] 17. The E-UE monitors the second discovery message and verifies the second discovery message using encryption key information, then the E-UE checks the role of the R-UE in the second discovery message and determines whether the role of the R-UE in the second discovery message matches the role of the E-UE, and if the role of the R-UE is the target UE, the E-UE as the positioning UE can determine that a matching item has been found.

[0238] 18. The E-UE returns a first response message to the R-UE, which message includes the role of the R-UE.

[0239] FIG. 17 is a structural schematic diagram of a communication device provided by an embodiment of the present disclosure. As shown in FIG. 17, the device may include a transceiver module for receiving a discovery request message sent from a first UE and / or a second UE, where the discovery request message is used to request authorization of a role for the first UE and / or the second UE, and the transceiver module is also used for sending a discovery response message to the first UE and / or the second UE, the discovery response message including the role determined by the network device for the first UE and / or the second UE.

[0240]

[0013] As described above, in a communication device provided by an embodiment of the present disclosure, a network device receives a discovery request message sent from a first UE and / or a second UE, where the discovery request message requests role authorization for the first UE and / or the second UE, and then the network device transmits a discovery response message to the first UE and / or the second UE, the discovery response message including the role determined for the first UE and / or the second UE by the network device. As can be seen from the above, the present disclosure provides a method for authorizing a role in a service for which a UE requests discovery, where the role of the UE may be determined by the network device based on the UE's capabilities and UE subscription information, thereby ensuring accurate role authorization for the UE and ensuring accuracy when the service is executed. At the same time, encryption key information corresponding to the service that the UE requests to discover is sent to the UE, and the encryption key information provides security protection for the UE's subsequent process of discovering other UEs, thereby ensuring that irrelevant UEs cannot monitor or tamper with the UE's role when the UE transmits its role in the subsequent discovery process, thereby preventing irrelevant UEs from impersonating the UE's role and avoiding interference from other irrelevant UEs in the subsequent service execution process, thereby improving the accuracy of service execution and improving information security.

[0241] Optionally, in one embodiment of the present disclosure, the discovery request message includes at least one of an application user identifier RAUID, an identifier of a service, and capabilities of the first UE and / or second UE.

[0242] Optionally, in one embodiment of the present disclosure, the apparatus is also used to determine the role of the first UE and / or the second UE based on the capabilities of the first UE and / or the second UE and subscription information of the first UE and / or the second UE stored in the network device.

[0243] Optionally, in one embodiment of the present disclosure, the discovery response message further includes encryption key information generated by the network device corresponding to a service for which the first UE and / or the second UE request discovery, wherein the encryption key information corresponding to the service for which the first UE requests discovery is the same as the encryption key information corresponding to the service for which the second UE requests discovery.

[0244] Optionally, in one embodiment of the present disclosure, the services include ranging services and / or sidelink positioning services.

[0245] Optionally, in one embodiment of the present disclosure, the network side device includes a first network element, a second network element, and a third network element, wherein the first network element includes a proximity service name management function (DDNMF) network element of the first UE or a proximity service encryption key management function (PKMF) network element of the first UE, the second network element includes a DDNMF network element of the second UE or a PKMF network element of the second UE, and the third network element includes a proximity service server or an integrated data management (UDM) network element.

[0246] Optionally, in one embodiment of the present disclosure, the first network element receives a discovery request message sent from the first UE, the first network element sends a discovery response message to the first UE, the first network element sends a first authorization request message to a third network element, and the third network element sends a first authorization response message to the first network element, the first authorization request message including the role of the first UE determined by the third network element.

[0247] Optionally, in one embodiment of the present disclosure, the second network element receives a discovery request message sent from the second UE, the second network element sends a discovery response message to the second UE, the second network element sends a first authorization request message to a third network element, and the third network element sends a first authorization response message to the second network element, the first authorization response message including the role of the second UE determined by the third network element.

[0248] Optionally, in one embodiment of the present disclosure, the second network element sends a monitoring request message to the first network element, the monitoring request message including the role of the second UE, and the monitoring request message is used to request a determination of whether the role of the second UE and the role of the first UE match; the first network element sends a second authorization request message to a third network element, the second authorization request message including the role of the first UE and the role of the second UE, and the third network element determines whether the role of the first UE and the role of the second UE match and sends a second authorization response message to the first network element; the second authorization response message is used to indicate whether the role of the first UE and the role of the second UE match in a service for which two UEs request discovery; and in response to the match of the role of the first UE and the role of the second UE, the first network element sends to the second network element encryption key information generated corresponding to the service for which the second UE requests discovery.

[0249] FIG. 18 is a structural schematic diagram of a communication device provided by an embodiment of the present disclosure. As shown in FIG. 18, the device may include a transceiver module for sending a discovery request message to a network device to request an authorization role for a first UE, and the transceiver module is also used to receive a discovery response message sent from the network device, where the discovery response message includes a role determined by the network device for the first UE.

[0250]

[0013] As described above, in a communication device provided by an embodiment of the present disclosure, a first UE sends a discovery request message to a network device, requesting authorization of a role for the first UE. The first UE then receives a discovery response message sent from the network device, where the discovery response message includes the role determined by the network device for the first UE. As can be seen from the above, the present disclosure provides a method for authorizing a role in a service for which a UE requests discovery, where the role of the UE may be determined by the network device based on UE capabilities and UE subscription information, thereby ensuring accurate role authorization for the UE and accuracy during service execution. At the same time, encryption key information corresponding to the service that the UE requests to discover is sent to the UE, and the encryption key information provides security protection for the UE's subsequent process of discovering other UEs, thereby ensuring that irrelevant UEs cannot monitor or tamper with the UE's role when the UE transmits its role in the subsequent discovery process, thereby preventing irrelevant UEs from impersonating the UE's role and avoiding interference from other irrelevant UEs in the subsequent service execution process, thereby improving the accuracy of service execution and improving information security.

[0251] Optionally, in one embodiment of the present disclosure, the device is also used to broadcast a first discovery message, the first discovery message being protected by encryption key information corresponding to a service for which the first UE requests discovery, and the first discovery message including the role of the first UE.

[0252] Optionally, in one embodiment of the present disclosure, the device is also used to receive a second discovery message broadcast by a second UE, the second discovery message being protected by encryption key information corresponding to a service for which the second UE requests discovery, and the second discovery message including the role of the second UE, decrypt and verify the second discovery message, and in response to successful verification, determine whether the role of the second UE matches the role of the first UE, and in response to the role of the first UE matching the role of the second UE, send a first response message to the second UE, the first response message being protected by encryption key information corresponding to the service for which the first UE requests discovery, and the first response message including the role of the first UE.

[0253] Figure 19 is a structural schematic diagram of a communication device provided by an embodiment of the present disclosure. As shown in Figure 19, the device may include a transceiver module for sending a discovery request message to a network device requesting authorization of a role for a second UE, and the transceiver module is also used to receive a discovery response message sent from the network device, where the discovery response message includes the role determined by the network device for the second UE.

[0254]

[0013] As described above, in a communication device provided by an embodiment of the present disclosure, a second UE sends a discovery request message to a network device to request authorization of a role for the second UE. The second UE then receives a discovery response message sent from the network device, and the discovery response message includes the role determined by the network device for the second UE. As can be seen from the above, the present disclosure provides a method for authorizing a role in a service for which a UE requests discovery, where the role of the UE may be determined by the network device based on the UE's capabilities and UE subscription information, thereby ensuring accurate role authorization for the UE and accuracy during service execution. At the same time, encryption key information corresponding to the service that the UE requests to discover is sent to the UE, and the encryption key information provides security protection for the UE's subsequent process of discovering other UEs, thereby ensuring that irrelevant UEs cannot monitor or tamper with the UE's role when the UE transmits its role in the subsequent discovery process, thereby preventing irrelevant UEs from impersonating the UE's role and avoiding interference from other irrelevant UEs in the subsequent service execution process, thereby improving the accuracy of service execution and improving information security.

[0255] Optionally, in one embodiment of the present disclosure, the device is also used to receive a first discovery message broadcast by a first UE, the first discovery message being protected by cryptographic key information corresponding to a service for which the first UE requests discovery, the first discovery message including the role of the first UE, decrypting and verifying the first discovery message, and, in response to successful verification, determining whether the role of the second UE matches the role of the first UE.

[0256] Optionally, in one embodiment of the present disclosure, the device broadcasts a second discovery message, the second discovery message being protected by encryption key information corresponding to a service for which the second UE requests discovery, and the second discovery message including a role of the second UE; and receives a first response message sent from the first UE, the first response message being protected by encryption key information corresponding to a service for which the first UE requests discovery, and the first response message including a role of the first UE.

[0257] Figure 20 is a structural schematic diagram of a communication device provided by an embodiment of the present disclosure. As shown in Figure 20, the device may include a transceiver module for receiving a discovery request message sent from the first UE, where the discovery request message is used to request authorization of a role for a service for which the first UE requests discovery. The transceiver module is also used to send a first authorization request message to a server or UDM network element based on the discovery request message. The transceiver module is also used to receive a first authorization response message sent from the server or UDM network element, where the first authorization response message includes the role of the first UE determined by the server or UDM network element. The transceiver module is also used to send a discovery response message including the role of the first UE to the first UE.

[0258] As described above, in a communication device provided by an embodiment of the present disclosure, the DDNMF network element of the first UE or the PKMF network element of the first UE receives a discovery request message sent from the first UE, which is used to request authorization of a role for a service for which the first UE requests discovery, then sends a first authorization request message to a server or UDM network element based on the discovery request message, receives a first authorization response message sent from the server or UDM network element, which first authorization response message includes the role of the first UE determined by the server or UDM network element, and finally, the DDNMF network element of the first UE or the PKMF network element of the first UE sends a discovery response message to the first UE, which includes the role of the first UE and encryption key information generated by the DDNMF network element of the first UE or the PKMF network element of the first UE for the service for which the first UE requests discovery. From this, it can be seen that the present disclosure provides a method for authorizing a role for a service for which a first UE requests discovery, where the role of the first UE may be determined by a server or a UDM network element based on the capabilities of the first UE and the roles that the first UE is allowed to play in the service for which the first UE requests discovery, thereby ensuring accurate role authorization for the first UE and improving accuracy during service execution. At the same time, the first UE may send encryption key information corresponding to the service for which discovery is requested to the first UE, where the encryption key information may be used to provide security protection for the process in which the first UE subsequently discovers other UEs, thereby ensuring that irrelevant UEs cannot monitor or tamper with the role of the first UE when the first UE transmits the role of the first UE in the subsequent discovery process, thereby preventing irrelevant UEs from impersonating the role of the first UE, avoiding interference by other irrelevant UEs during subsequent service execution, improving service execution accuracy, and improving information security.

[0259] Optionally, in one embodiment of the present disclosure, the transceiver module converts the RAUID corresponding to the first UE into a first identifier identifiable by the server or UDM network element, the first identifier indicating the first UE, and carries at least one of the first identifier, the service that the first UE requests to be discovered, and the capabilities of the first UE in the first authorization request message and sends it to the server or UDM network element.

[0260] 21a is a structural schematic diagram of a communication device provided by an embodiment of the present disclosure. As shown in FIG. 21a, the device may include a transceiver module for receiving a discovery request message sent from a second UE, where the discovery request message is used to request role authorization for a service for which the second UE requests discovery. The transceiver module is also used for sending a first authorization request message to a server or a UDM network element based on the discovery request message. The transceiver module is also used for receiving a first authorization response message sent from the server or UDM network element, where the first authorization response message includes the role of the second UE determined by the server or UDM network element. The device further includes a processing module used to determine encryption key information corresponding to the service for which the second UE requests discovery. The transceiver module is also used for sending a discovery response message to the second UE, where the discovery request message includes the role of the second UE.

[0261] As described above, in a communication device provided by an embodiment of the present disclosure, the DDNMF network element of the second UE or the PKMF network element of the second UE receives a discovery request message sent from the second UE, which is used to request authorization of a role for a service for which the second UE requests discovery, then sends a first authorization request message to a server or a UDM network element based on the discovery request message, receives a first authorization response message sent from the server or the UDM network element, which includes the role of the second UE determined by the server or the UDM network element, the DDNMF network element of the second UE or the PKMF network element of the second UE determines encryption key information corresponding to the service for which the second UE requests discovery, and finally, the DDNMF network element of the second UE or the PKMF network element of the second UE sends a discovery response message to the second UE, which includes the role of the second UE and the encryption key information corresponding to the service for which the second UE requests discovery. From this, it can be seen that the present disclosure provides a method for authorizing a role for a second UE in a service that requires discovery, where the role of the second UE may be determined by a server or a UDM network element based on the capabilities of the second UE and the role that the second UE is allowed to play in the service that requires discovery, thereby ensuring accurate role authorization for the second UE and accuracy during service execution. At the same time, the second UE may send encryption key information corresponding to the service that requires discovery to the second UE, and the encryption key information may be used to successfully verify the information transmitted by the first UE in the discovery process based on the same security discovery encryption key, thereby ensuring that the two UEs can discover each other and successfully complete the service that requires discovery. Furthermore, since other UEs cannot know the security encryption key, interference by other unrelated UEs during subsequent service execution is avoided, improving the accuracy of service execution and information security.

[0262] Optionally, in one embodiment of the present disclosure, the transceiver module is also used to convert the RAUID corresponding to the second UE into a second identifier identifiable by the server or UDM network element, the second identifier being used to indicate the second UE, and carrying at least one of the second identifier, the service that the second UE requests to be discovered, and the capabilities of the second UE in the authorization request message and sending it to the server or UDM network element.

[0263] Optionally, in one embodiment of the present disclosure, the device sends a monitoring request message to a DDNMF network element of the first UE or a PKMF network element of the first UE, the monitoring request message carries the role of the second UE, the monitoring request message is used to request determining whether the role of the second UE and the role of the first UE are consistent, and receives a monitoring response message sent from the DDNMF network element of the first UE or the PKMF network element of the first UE, the monitoring response message carries encryption key information corresponding to a service for which the second UE requests discovery, and the encryption key information corresponding to the service for which the second UE requests discovery is the same as the encryption key information corresponding to the service for which the first UE requests discovery.

[0264] Figure 21b is a structural schematic diagram of a communication device provided by an embodiment of the present disclosure. As shown in Figure 21b, the device may include: a transceiver module for receiving a first authorization request message sent from a DDNMF network element or a PKMF network element of a first UE and / or a second UE, where the first authorization request message is used to request authorization of a role for a service that the first UE and / or the second UE requests discovery; and a determination module for determining the role of the first UE and / or the second UE based on the first authorization request message, where the transceiver module is also used to send a first authorization response message to the DDNMF network element or the PKMF network element of the first UE and / or the second UE, where the first authorization response message includes the role of the first UE and / or the second UE.

[0265] As described above, in a communication device provided by an embodiment of the present disclosure, a server or UDM network element receives a first authorization request message sent from a DDNMF network element or a PKMF network element of a first UE and / or a second UE, the first authorization request message is used to request authorization of a role for a service that the first UE and / or the second UE requests to discover, determines the role of the first UE and / or the second UE based on the first authorization request message, and then the server or UDM network element sends a first authorization response message including the role of the first UE and / or the second UE to the DDNMF network element or the PKMF network element of the first UE and / or the second UE. As can be seen from this, the present disclosure provides a method for authorizing a role in a service for which a first UE and / or a second UE requests discovery, and the role of the first UE and / or the second UE is determined by a server or a UDM network element based on the capabilities of the first UE and / or the second UE and the role that the first UE and / or the second UE is allowed to play in the service for which the first UE and / or the second UE requests discovery, thereby ensuring that the role can be accurately authorized for the first UE and / or the second UE and ensuring accuracy during service execution.

[0266] Optionally, in one embodiment of the present disclosure, the processing module is also used to determine, based on subscription information of the first UE and / or second UE, an allowed role for the first UE and / or second UE in a service for which the first UE and / or second UE requests discovery, and to determine, from the allowed roles for the first UE and / or second UE, a role that can be realized by the capabilities of the first UE and / or second UE as the role for the first UE and / or second UE.

[0267] Optionally, in one embodiment of the present disclosure, the device receives a second authorization request message sent from a DDNMF network element or a PKMF network element of a first UE, the second authorization request message including a role of the first UE, a role of the second UE, and a service for which the two UEs request discovery, determines whether the role of the first UE and the role of the second UE match in the service for which the two UEs request discovery, and sends a second authorization response message to the DDNMF network element or the PKMF network element of the first UE, the second authorization response message being used to indicate whether the role of the first UE and the role of the second UE match.

[0268] Figure 22 is a structural schematic diagram of a communication system provided by an embodiment of the present disclosure, which, as shown in Figure 22, includes: a first UE for sending a discovery request message; a second UE for sending a discovery request message; and a network device for sending a discovery response message including a role determined by the network device for the first UE and / or the second UE, wherein the first UE is used to receive the discovery response message, and the discovery response message includes the role determined by the network device for the first UE; and the second UE is also used to receive the discovery response message, and the discovery response message includes the role determined by the network device for the second UE.

[0269] 23, Fig. 2 is a structural schematic diagram of a communication device 2300 provided by an embodiment of the present application. The communication device 2300 may be a base station, a terminal device, a chip, a chip system, a processor, etc. that supports the base station to implement the above method, or a chip, a chip system, a processor, etc. that supports the terminal device to implement the above method. The device may be used to implement the method described in the above method embodiment, specifically see the description of the above method embodiment.

[0270] The communication device 2300 may include one or more processors 2301. The processor 2301 may be a general-purpose processor or a special-purpose processor, etc. For example, it may be a baseband processor or a central processor. The baseband processor may be used to process communication protocols and communication data, and the central processor may be used to control measurement devices (e.g., base stations, baseband chips, terminal devices, terminal device chips, DUs or CUs, etc.), execute computer programs, and process data of the computer programs.

[0271] Optionally, the communications device 2300 may include one or more memories 2302 having stored therein a computer program 2304. The processor 2301 executes the computer program 2304, causing the communications device 2300 to perform the methods described in the method embodiments above. Optionally, the memory 2302 may store data. The communications device 2300 and the memory 2302 may be provided separately or integrated together.

[0272] Optionally, the communication device 2300 may further include a transceiver 2305 and an antenna 2306. The transceiver 2305 may also be referred to as a transceiver unit, transceiver, or transceiver circuit, and is used to realize a transmission and reception function. The transceiver 2305 may include a receiver and a transmitter, and the receiver may also be referred to as a receiving device or receiving circuit, and is used to realize a reception function, and the transmitter may also be referred to as a transmitting device or transmitting circuit, and is used to realize a transmission function.

[0273] Optionally, the communication device 2300 may further include one or more interface circuits 2307. The interface circuit 2307 receives and transmits code instructions to the processor 2301. The processor 2301 executes the code instructions to cause the communication device 2300 to perform the methods described in the method embodiments above.

[0274] In one implementation, the processor 2301 may include a transceiver for implementing receiving and transmitting functions. For example, the transceiver may be a transceiver circuit, an interface, or an interface circuit. The transceiver circuit, interface, or interface circuit for implementing receiving and transmitting functions may be separate or integrated. The transceiver circuit, interface, or interface circuit may be used to read and write code / data, or the transceiver circuit, interface, or interface circuit may be used to transmit or convey signals.

[0275] In one implementation, the processor 2301 may include a computer program 2303 that executes on the processor 2301, thereby causing the communication device 2300 to perform the methods described in the method embodiments above. The computer program 2303 may be fixed to the processor 2301, in which case the processor 2301 may be implemented in hardware.

[0276] In one implementation, the communications device 2300 may include circuitry capable of performing the transmit, receive, or communication functions of the method embodiments described above. The processors and transceivers described herein may be integrated into an integrated circuit (IC), an analog IC, a radio frequency integrated circuit (RFIC), a mixed-signal IC, an application specific integrated circuit (ASIC), a printed circuit board (PCB), an electronic device, or the like. The processors and transceivers may be fabricated using a variety of IC process technologies, such as complementary metal oxide semiconductor (CMOS), n-type metal oxide semiconductor (NMOS), p-type metal oxide semiconductor (PMOS), bipolar junction transistor (BJT), bipolar CMOS (BiCMOS), silicon germanium (SiGe), gallium arsenide (GaS), etc.

[0277] Although the communication device described in the above embodiment may be a network device, the scope of the communication device described in this application is not limited thereto, and the structure of the communication device may be limited by Fig. 23. The communication device may be an independent device or part of a larger device. For example, the measurement device may be as follows: (1) An independent integrated circuit IC or chip, or a chip system or subsystem; (2) a set having one or more ICs, optionally including a memory component for storing data, computer programs; (3) ASIC, e.g., modem, (4) Modules that can be embedded into other devices; (5) Receivers, terminal devices, intelligent terminal devices, cellular phones, wireless devices, handhelds, mobile units, in-vehicle devices, network devices, cloud devices, artificial intelligence devices, etc. (6)Others.

[0278] Regarding the case where the communication device may be a chip or a chip system, please refer to the structural schematic diagram of the chip shown in Fig. 24. The chip shown in Fig. 24 includes a processor 2401 and an interface 2402. Here, the number of processors 2401 may be one or more, and the number of interfaces 2402 may be more than one.

[0279] Optionally, the chip further includes a memory 2403, which stores necessary computer programs and data.

[0280] As will be appreciated by those skilled in the art, the various illustrative logical blocks and steps enumerated in the embodiments of the present application can be realized by electronic hardware, computer software, or a combination of both. Whether such functions are realized by hardware or software depends on the specific application and the overall system design requirements. Those skilled in the art can realize the functions using various methods for each specific application, but such realization should not be understood as exceeding the scope of protection of the embodiments of the present application.

[0281] The present application further provides a readable storage medium having instructions stored thereon, which, when executed by a computer, implement the functions of any one of the method embodiments described above.

[0282] The present application further provides a computer program product, which, when executed by a computer, implements the functions of any one of the above method embodiments.

[0283] In the above embodiments, all or a portion thereof can be implemented in software, hardware, firmware, or any combination thereof. When implemented using software, all or a portion thereof can be implemented in the form of a computer program product. The computer program product includes one or more computer programs. When the computer programs are loaded and executed on a computer, they generate, in whole or in part, the flow or functions described in the embodiments of the present application. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer program may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer program may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, radio, microwave, etc.) methods. The computer-readable storage medium may be any available medium accessible to a computer, or a data storage device such as a server, data center, or the like, integrating one or more available media. The usable medium may be a magnetic medium (e.g., a floppy disk, a hard disk, a magnetic tape), an optical medium (e.g., a high-density digital video disc (DVD)), or a semiconductor medium (e.g., a solid state disk (SSD)).

[0284] As will be appreciated by those skilled in the art, the various numerals, such as first, second, etc., used herein are merely divisions made for ease of explanation and do not limit the scope of the embodiments of the present application, but also represent priorities.

[0285] "At least one" in this application may be explained as "one or more," and "more" may be two, three, four or more, and is not limited by this application. In the embodiments of this application, for one technical feature, the technical features in the category are distinguished by "first," "second," "third," "A," "B," "C," and "D," etc., and there is no priority or size order between the technical features explained by "first," "second," "third," "A," "B," "C," and "D."

[0286] The correspondences shown in each table in this application may be set or defined in advance. The possible values ​​of information in each table are merely examples and may be set to other values ​​and are not limited by this application. When setting the correspondences between information and each parameter, it is not necessary to set all of the correspondences shown in each table. For example, in the tables of this application, the correspondences shown in some rows may not be set. Furthermore, the tables may be appropriately modified or adjusted, such as by dividing or merging. The names of the parameters shown in the themes of each table may also be called other names understandable to the communication device, and the possible values ​​or display methods of the parameters may also be other values ​​or display methods understandable to the communication device. When implemented, each table may use other data structures, such as arrays, queues, containers, stacks, linear lists, pointers, linked lists, trees, graphs, structures, classes, heaps, and hash tables.

[0287] Predefined in this application may be understood as defined, predefined, stored, pre-stored, pre-agreed upon, pre-set, hardened or pre-baked.

[0288] As can be understood by those skilled in the art, the units and algorithm steps of each example described in the embodiments disclosed herein can be implemented in electronic hardware or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can implement the described functions using different methods for each specific application, and such implementation should not be considered as going beyond the scope of the present application.

[0289] As can be clearly understood by those skilled in the art, for convenience and simplification of explanation, the specific working processes of the systems, devices and units described above are to be referred to the corresponding processes in the aforementioned method embodiments, and detailed descriptions thereof will be omitted here.

[0290] The above description is merely a specific embodiment of the present application, and the scope of protection of the present application is not limited thereto. Any modifications or substitutions that can be easily conceived by a person skilled in the art without departing from the technical scope disclosed in the present application should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be governed by the claims.

Claims

1. A method for role authorization of a UE performed by a network device, the method comprising: receiving a discovery request message sent from a first UE and / or a second UE, the discovery request message being used to request authorization for a role for the first UE and / or the second UE; transmitting a discovery response message to the first UE and / or the second UE, the discovery response message including a role determined by the network device for the first UE and / or the second UE; A method for role authorization for a UE, comprising:

2. The discovery request message: Application User Identifier RAUID, the service identifier, a capability of the first UE and / or the second UE; 2. The method of claim 1 .

3. determining a role of the first UE and / or the second UE based on capabilities of the first UE and / or the second UE and subscription information of the first UE and / or the second UE stored in the network device; 3. The method according to claim 1 or 2.

4. The discovery response message further includes encryption key information generated by the network device corresponding to a service for which the first UE and / or the second UE request discovery, wherein the encryption key information corresponding to the service for which the first UE requests discovery is the same as the encryption key information corresponding to the service for which the second UE requests discovery.

4. The method according to claim 1, wherein the first and second electrodes are connected to a first electrode.

5. the services include ranging services and / or sidelink positioning services; 5. The method according to claim 1, wherein the first and second electrodes are connected to a first electrode.

6. The network side device includes a first network element, a second network element, and a third network element, wherein the first network element includes a proximity service name management function (DDNMF) network element of the first UE or a proximity service cipher key management function (PKMF) network element of the first UE, the second network element includes a DDNMF network element of the second UE or a PKMF network element of the second UE, and the third network element includes a proximity service server or a unified data management (UDM) network element; 6. The method according to any one of claims 1 to 5.

7. The step of receiving, by the network device, a discovery request message transmitted from the first UE includes: receiving, by the first network element, a discovery request message sent from the first UE; The step of the network device sending a discovery response message to the first UE includes: the first network element sending a discovery response message to the first UE; The method comprises: the first network element sending a first authorization request message to a third network element; and the third network element sending a first authorization response message to the first network element, the first authorization response message including the role of the first UE determined by the third network element.

7. The method of claim 6.

8. The step of receiving, by the network device, a discovery request message transmitted from the second UE, includes: receiving, by the second network element, a discovery request message sent from the second UE; The step of the network device sending a discovery response message to the second UE includes: the second network element sending a discovery response message to the second UE; The method comprises: the second network element sending a first authorization request message to a third network element; and the third network element sending a first authorization response message to the second network element, the first authorization response message including the role of the second UE determined by the third network element.

7. The method of claim 6.

9. a step of the second network element sending a monitoring request message to the first network element, the monitoring request message including a role of a second UE, the monitoring request message being used to request determining whether the role of the second UE and the role of the first UE are consistent; the first network element sending a second authorization request message to a third network element, the second authorization request message including a role of the first UE and a role of the second UE; a third network element determining whether a role of the first UE and a role of the second UE match and sending a second authorization response message to the first network element, the second authorization response message being used to indicate whether a role of the first UE and a role of the second UE match in a service for which two UEs request discovery; In response to the role of the first UE and the role of the second UE matching, the first network element transmits, to the second network element, encryption key information generated corresponding to a service for which the second UE requests discovery.

9. The method of claim 8.

10. A UE role authorization method performed by a first UE, the method comprising: sending a discovery request message to a network device requesting an authorization role for the first UE; receiving a discovery response message transmitted from the network device, the discovery response message including a role determined by the network device for the first UE; A method for role authorization for a UE, comprising:

11. broadcasting a first discovery message, wherein the first discovery message is protected by encryption key information corresponding to a service for which the first UE requests discovery, and the first discovery message includes a role of the first UE; 11. The method of claim 10.

12. receiving a second discovery message broadcasted by a second UE, the second discovery message being protected by encryption key information corresponding to a service for which the second UE requests discovery, and the second discovery message including a role of the second UE; decoding and verifying the second discovery message, and in response to successful verification, determining whether a role of the second UE and a role of the first UE match; and transmitting a first response message to the second UE in response to a match between the role of the first UE and the role of the second UE, the first response message being protected by encryption key information corresponding to a service for which the first UE requests discovery, and the first response message including the role of the first UE.

11. The method of claim 10.

13. A UE role authorization method performed by a second UE, comprising: sending a discovery request message to the network device requesting authorization of a role for the second UE; receiving a discovery response message transmitted from the network device, the discovery response message including a role determined by the network device for the second UE; A method for role authorization for a UE, comprising:

14. receiving a first discovery message broadcasted by a first UE, the first discovery message being protected by encryption key information corresponding to a service for which the first UE requests discovery, and the first discovery message including a role of the first UE; and decoding and verifying the first discovery message, and determining, in response to successful verification, whether a role of the second UE and a role of the first UE match.

14. The method of claim 13.

15. broadcasting a second discovery message, wherein the second discovery message is protected by encryption key information corresponding to a service for which the second UE requests discovery, and the second discovery message includes a role of the second UE; receiving a first response message sent from the first UE, the first response message being protected by encryption key information corresponding to a service for which the first UE requests discovery, and the first response message including a role of the first UE; 14. The method of claim 13.

16. A UE role authorization method performed by a DDNMF network element of a first user device UE or a PKMF network element of the first UE, the method comprising: receiving a discovery request message sent from the first UE, the discovery request message being used to request authorization for a role for a service for which the first UE requests discovery; sending a first authorization request message to a server or a UDM network element based on the discovery request message; receiving a first authorization response message sent from the server or UDM network element, the first authorization response message including a role of the first UE determined by the server or UDM network element; sending a discovery response message to the first UE, the discovery response message including a role of the first UE; A method for role authorization for a UE, comprising:

17. The step of sending a first authorization request message to a server or a UDM network element based on the discovery request message includes: converting a RAUID corresponding to the first UE into a first identifier identifiable by the server or a UDM network element, the first identifier indicating the first UE; and sending the first authorization request message carrying at least one of the first identifier, the service for which the first UE requests discovery, and the capabilities of the first UE to the server or UDM network element.

17. The method of claim 16.

18. A UE role authorization method performed by a DDNMF network element of a second UE or a PKMF network element of a second UE, the method comprising: receiving a discovery request message sent from a second UE, the discovery request message being used to request authorization for a role for a service for which the second UE requests discovery; sending a first authorization request message to a server or a UDM network element based on the discovery request message; receiving a first authorization response message sent from the server or UDM network element, wherein the first authorization response message includes a role of the second UE determined by the server or UDM network element; determining encryption key information corresponding to a service for which the second UE requests discovery; sending a discovery response message to the second UE, the discovery response message including a role of the second UE; A method for role authorization for a UE, comprising:

19. The step of sending a first authorization request message to a server or a UDM network element based on the discovery request message includes: converting a RAU ID corresponding to the second UE into a second identifier identifiable by the server or a UDM network element, the second identifier being used to indicate the second UE; and sending the authorization request message to the server or UDM network element carrying at least one of the second identifier, the service for which the second UE requests discovery, and the capabilities of the second UE.

20. The method of claim 18.

20. sending a monitoring request message to a DDNMF network element of the first UE or a PKMF network element of the first UE, the monitoring request message carrying a role of a second UE, the monitoring request message being used to request determining whether the role of the second UE and the role of the first UE are consistent; receiving a monitoring response message sent from a DDNMF network element of the first UE or a PKMF network element of the first UE, wherein the monitoring response message carries cipher key information corresponding to a service for which the second UE requests discovery, and the cipher key information corresponding to the service for which the second UE requests discovery is the same as the cipher key information corresponding to the service for which the first UE requests discovery; 20. The method of claim 18.

21. A method for UE role authorization performed by a server or a UDM network element, the method comprising: receiving a first authorization request message sent from a DDNMF network element or a PKMF network element of a first UE and / or a second UE, the first authorization request message being used to request authorization of a role for a service that the first UE and / or the second UE requests discovery of; determining a role of the first UE and / or a second UE based on the first authorization request message; sending a first authorization response message to a DDNMF network element or a PKMF network element of the first UE and / or the second UE, wherein the first authorization response message includes a role of the first UE and / or the second UE; A method for role authorization for a UE, comprising:

22. determining a role of the first UE and / or the second UE based on the first authorization request message, determining an allowed role of the first UE and / or the second UE in a service for which the first UE and / or the second UE requests discovery based on subscription information of the first UE and / or the second UE; determining, from permitted roles of the first UE and / or the second UE, a role that can be realized by the capabilities of the first UE and / or the second UE as a role of the first UE and / or the second UE; 22. The method of claim 21 .

23. receiving a second authorization request message sent from a DDNMF network element or a PKMF network element of a first UE, the second authorization request message including a role of the first UE, a role of the second UE, and services that two UEs request to discover; determining whether the role of the first UE and the role of the second UE match in a service for which two UEs request discovery; sending a second authorization response message to a DDNMF network element or a PKMF network element of the first UE, wherein the second authorization response message is used to indicate whether a role of the first UE and a role of the second UE are consistent; 22. The method of claim 21 .

24. A communication device disposed in a network device, a transceiver module for receiving a discovery request message transmitted from a first UE and / or a second UE, the discovery request message being used to request authorization for a role for the first UE and / or the second UE; the transceiver module is also used to send a discovery response message to the first UE and / or the second UE, the discovery response message including a role determined by the network device for the first UE and / or the second UE. A communication device comprising:

25. A communication device disposed in a first UE, a transceiver module for transmitting a discovery request message to a network device requesting an authorization role for the first UE; The transceiver module is also used to receive a discovery response message sent from the network device, the discovery response message including a role determined by the network device for the first UE. A communication device comprising:

26. A communication device disposed in a second UE, a transceiver module for transmitting a discovery request message to the network device requesting authorization for a role for the second UE; The transceiver module is also used to receive a discovery response message sent from the network device, wherein the discovery response message includes a role determined by the network device for the second UE. A communication device comprising:

27. A communication device disposed in a DDNMF network element of a first UE or a PKMF network element of the first UE, a transceiver module for receiving a discovery request message transmitted from the first UE, the discovery request message being used to request authorization for a role for a service for which the first UE requests discovery; The transceiver module is also used to send a first authorization request message to a server or a UDM network element based on the discovery request message; The transceiver module is also used to receive a first authorization response message sent from the server or UDM network element, wherein the first authorization response message includes a role of the first UE determined by the server or UDM network element; The transceiver module is also used to send a discovery response message to the first UE, the discovery response message including the role of the first UE. A communication device comprising:

28. A communication device disposed and executed in a DDNMF network element of a second UE or a PKMF network element of a second UE, a transceiver module for receiving a discovery request message sent from a second UE, the discovery request message being used to request authorization for a role for a service for which the second UE requests discovery; The transceiver module is also used to send a first authorization request message to a server or a UDM network element based on the discovery request message; The transceiver module is also used to receive a first authorization response message sent from the server or UDM network element, wherein the first authorization response message includes a role of the second UE determined by the server or UDM network element; a processing block for determining encryption key information corresponding to a service for which the second UE requests discovery; The transceiver module is also used to send a discovery response message to the second UE, the discovery response message including the role of the second UE. A communication device comprising:

29. A communication device located and executed on a server or a UDM network element, a transceiver module for receiving a first authorization request message sent from a DDNMF network element or a PKMF network element of a first UE and / or a second UE, wherein the first authorization request message is used to request authorization of a role for a service that the first UE and / or the second UE requests discovery of; a processing module for determining a role of the first UE and / or the second UE based on the first authorization request message; The transceiver module is also used for sending a first authorization response message to a DDNMF network element or a PKMF network element of the first UE and / or the second UE, wherein the first authorization response message includes the role of the first UE and / or the second UE. A communication device comprising:

30. A communication device including a processor and a memory, wherein a computer program is stored in the memory, and wherein the processor executes the computer program stored in the memory to cause the communication device to perform the method of any one of claims 1 to 9, or the processor executes the computer program stored in the memory to cause the communication device to perform the method of any one of claims 10 to 12, or the processor executes the computer program stored in the memory to cause the communication device to perform the method of any one of claims 13 to 15, or the processor executes the computer program stored in the memory to cause the communication device to perform the method of any one of claims 16 to 17, or the processor executes the computer program stored in the memory to cause the communication device to perform the method of any one of claims 18 to 20, or the processor executes the computer program stored in the memory to cause the communication device to perform the method of any one of claims 21 to 23. A communication device comprising:

31. A communication device including a processor and an interface circuit, the interface circuit is used to receive and transmit code instructions to the processor; The processor is used to perform the method of any one of claims 1 to 9 by executing the code instructions, or is used to perform the method of any one of claims 10 to 12 by executing the code instructions, or is used to perform the method of any one of claims 13 to 15 by executing the code instructions, or is used to perform the method of any one of claims 16 to 17 by executing the code instructions, or is used to perform the method of any one of claims 18 to 20 by executing the code instructions, or is used to perform the method of any one of claims 21 to 23 by executing the code instructions. A communication device comprising:

32. 1. A communication system comprising: a first UE for transmitting a discovery request message; a second UE for transmitting a discovery request message; a network device for transmitting a discovery response message including a role determined by the network device for the first UE and / or the second UE; The first UE is also used to receive the discovery response message, the discovery response message including a role determined for the first UE by the network device; The second UE is also used to receive the discovery response message, and the discovery response message includes a role determined for the second UE by the network device. A communication system comprising:

33. A computer readable storage medium having stored thereon instructions which, when executed, result in the method of any one of claims 1 to 9 being realized, or which, when executed, result in the method of any one of claims 10 to 12 being realized, or which, when executed, result in the method of any one of claims 13 to 15 being realized, or which, when executed, result in the method of any one of claims 16 to 17 being realized, or which, when executed, result in the method of any one of claims 18 to 20 being realized, or which, when executed, result in the method of any one of claims 21 to 23 being realized. A computer-readable storage medium comprising: