Communication method and apparatus

The method ensures successful service requests by authenticating service consumer network elements through specific client credential information assertions, addressing the issue of failed authentication in indirect communication scenarios and reducing memory load and security risks.

JP7712393B2Active Publication Date: 2025-07-23HUAWEI TECH CO LTD

Patent Information

Application Number
JP2023569715
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-05-09
Filing Date
2022-05-09
Publication Date
2025-07-23
Estimated Expiration
2042-05-09

AI Technical Summary

Technical Problem

Existing standards do not define how to generate correct client credentials assertions (CCAs) in indirect communication scenarios, leading to failures in service requests by service-consumer network elements.

Method used

A communication method where service consumer network elements convey client credential information assertions including specific network function types to ensure proper authentication through a service communication proxy, allowing for the generation of access tokens and handling of expired tokens to prevent misuse and reduce memory load.

Benefits of technology

Ensures successful service requests by authenticating service consumer network elements, reduces memory load, and enhances security by preventing misuse of client credentials and managing token expiration.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007712393000001
    Figure 0007712393000001
  • Figure 0007712393000002
    Figure 0007712393000002
  • Figure 0007712393000003
    Figure 0007712393000003
Patent Text Reader

Abstract

A communication method and a communication device are disclosed, which may be used in an indirect communication scenario, comprising: a service consumer network element sending a first service request message to a service communication proxy, the service consumer network element receiving a response message to the first service request message from the service communication proxy, the first service request message being used to request a first service from a service producer network element, the first service request message including a first client credential assertion, the first client credential assertion including a first network function type and a second network function type, the first network function type being a network function type of the service producer network element, the second network function type being a network function type of a network element providing a second service, and the second service being associated with the first service.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Cross - reference to Related Applications This application claims priority to Chinese Patent Application No. 202110502638.5, titled "COMMUNICATION METHOD AND APPARATUS", filed with the China National Intellectual Property Administration on May 9, 2021, which is incorporated herein by reference in its entirety.

[0002] Embodiments of the present application relate to the field of wireless communication, and in particular, to communication methods and apparatuses.

Background Art

[0003] FIG. 1 shows an extended service - based architecture. In an extended service - based architecture, network elements may communicate with each other in a direct manner (which may also be simply called direct communication), or may communicate with each other in an indirect manner (which may also be simply called indirect communication or non - direct communication). In the indirect communication process, two network elements communicating with each other may exchange messages via a service communication proxy (SCP). Between direct communication and indirect communication, the two communication partners are respectively called a service consumer and a service producer. A consumer is a service requester or service caller, and a producer is a service producer. A service consumer is also called a service - consumer network element, and a service producer is also called a service - producer network element.

[0004] In an indirect communication scenario, an authentication method based on a client credentials assertion (CCA) is introduced. The consumer includes the CCA in the service request so that the recipient can authenticate the consumer. In different indirect communication scenarios, the consumer (i.e., the peer) needs to generate the correct CCA so that the recipient (i.e., the authenticator) can accurately authenticate the consumer and provide the service requested by the consumer when the authentication is successful. However, the existing standards do not define how to generate the correct CCA in different indirect communication scenarios to avoid the problem that service - consumer - network elements may not be able to request services. Summary of the Invention Means for Solving the Problems

[0005] Embodiments of the present application provide a communication method and apparatus to avoid cases where service - consumer - network elements fail to request services.

[0006] According to a first aspect, an embodiment of the present application provides a communication method. The method includes the following.

[0007] A service consumer network element transmits a first service request message to a service communication proxy. The first service request message is used to request a first service from a service producer network element. The first service request message includes a first client credential information assertion. The first client credential information assertion is used to authenticate the service consumer network element. The first client credential information assertion includes a first network function type and a second network function type. The first network function type is the network function type of the service producer network element. The second network function type is the network function type of a network element that provides a second service. The second service is associated with the first service. The service consumer network element receives a response message to the first service request message from the service communication proxy.

[0008] According to the foregoing method, when a service consumer network element requests a first service from a service producer network element via a service communication proxy, the service consumer network element conveys, in the first service request message sent to the service communication proxy, a client credential information assertion including a first network function type and a second network function type. Thereby, when the service communication proxy requests a second service, it can ensure that a network element that provides the second service authenticates the service consumer network element normally, further ensuring that the service consumer network element requests the first service, and in an indirect communication scenario, it can be guaranteed to solve the problem that the service consumer network element cannot request a service because the authentication based on the client credential information assertion fails.

[0009] In one possible design, the second service is used to provide an access token corresponding to the first service, and the access token corresponding to the first service indicates that the service consumer network element has permission to obtain the first service.

[0010] In one possible design, the service consumer network element determines that there is no available access token corresponding to the first service.

[0011] According to the foregoing design, the service consumer network element can generate a first client credential information assertion as needed, thereby preventing the first client credential information assertion from being misused.

[0012] In addition, after the service consumer network element determines that there is no available access token corresponding to the first service, the service consumer network element may carry parameters for obtaining an access token corresponding to the first service in the first service request message.

[0013] In one possible design, the service consumer network element's determination that there is no available access token corresponding to the first service may include the case where the service consumer network element determines that no access token corresponding to the first service is stored, or the case where the service consumer network element determines that the stored access token corresponding to the first service has expired.

[0014] In one possible design, when the stored access token corresponding to the first service expires, the service consumer network element deletes the expired access token.

[0015] According to the foregoing design, the memory space can be released in a timely manner, and the memory load of the system can be reduced.

[0016] In one possible design, the second service is used to provide information about the service producer network element.

[0017] In one possible design, the service consumer network element determines to trigger the service communication proxy so that the first service request message requests the second service.

[0018] In one possible design, when the service consumer network element determines to trigger the service communication proxy so that the first service request message requests the second service, in a case where the context of the first terminal device is not stored, the first terminal device is associated with the first service, in a case where the context of the first service is not stored, in a case where the service producer network element belongs to the first slice and the context corresponding to the first slice is not stored, or in a case where the service consumer network element communicates with the service communication proxy for the first time, based on one or more of these cases, the service consumer network element determines to trigger the service communication proxy so that the first service request message requests the second service.

[0019] In addition, after the service consumer network element determines that it can trigger the service communication proxy so that the first service request message requests the second service, the service consumer network element may carry parameters for discovering the service producer network element in the first service request message.

[0020] In one possible design, the service consumer network element determines to request the first service in an indirect communication mode, that is, mode D.

[0021] For example, when a service consumer network element communicates with a service communication proxy in mode D, a first service request message always carries a client eligibility information assertion including a first network function type and a second network function type, or when it is determined that the service consumer network element can communicate with the service communication proxy in mode D and trigger the service communication proxy such that the first service request message requests a second service, the first service request message carrying a client eligibility information assertion including a first network function type and a second network function type may be agreed upon by a standard protocol or configured based on pre-configuration information.

[0022] In one possible design, a service consumer network element transmits a second service request message to the service communication proxy, the second service request message is used to request a first service, the second service request message includes a second client eligibility information assertion, the second client eligibility information assertion includes a first network function type, and the second client eligibility information assertion is used to authenticate the service consumer network element. The service consumer network element receives a response message to the second service request message from the service communication proxy, and the response message to the second service request message includes indication information. When the service consumer network element transmits a first service request message to the service communication proxy, the service consumer network element transmits the first service request message to the service communication proxy based on the indication information.

[0023] According to the foregoing design, the service consumer network element may transmit a first service request message to the service communication proxy based on the indication information.

[0024] In one possible design, the indication information includes a third client eligibility information assertion, the third client eligibility information assertion includes a second network function type, and the third client eligibility information assertion is used to authenticate a network element that provides a second service. When a service consumer network element sends a first service request message to a service communication proxy based on the indication information, the service consumer network element sends the first service request message to the service communication proxy when authentication of the network element that provides the second service based on the third client eligibility information assertion is successful.

[0025] According to the foregoing design, the service consumer network element can authenticate a network element that provides a second service based on the third client eligibility information assertion, and when the authentication is successful, send a first service request message based on the second network function type included in the third client eligibility information assertion.

[0026] In one possible design, the network element that provides the second service is a network repository function network element.

[0027] In one possible design, the first client eligibility information assertion further includes one or more of an identifier of the service consumer network element or expiration time information, and the expiration time information represents the expiration time of the first client eligibility information assertion.

[0028] According to a second aspect, the present application provides a communication method. The method includes a step in which a first network element receives a first service request message from a service communication proxy, where the first service request message is used to request a first service from the first network element, the first service request message includes a first client qualification information assertion, the first client qualification information assertion is used to authenticate a service consumer network element, and the first client qualification information assertion includes a plurality of network function types. The first network element authenticates the service consumer network element based on the first client qualification information assertion. The first network element authenticating the service consumer network element based on the first client qualification information assertion includes a step in which the first network element determines whether the network function type of the first network element matches one or more of the plurality of network function types, and a step in which the first network element transmits a response message to the first service request message to the service communication proxy based on the authentication result.

[0029] According to the foregoing method, when the first client qualification information assertion includes a plurality of network function types, the first network element determines whether the network function type of the first network element matches one or more of the plurality of network function types in order to obtain an authentication result. Therefore, according to the foregoing method, when the client qualification information assertion includes a plurality of network function types, it is possible to determine whether authentication of the service consumer network element is successful, and as a result, network elements having different network function types can authenticate the service consumer network element based on the same client qualification information assertion.

[0030] In one possible design, when the authentication result is that the authentication is successful, the first network element sends a response message for the first service request message to the service communication proxy, and the response message for the first service request message is used to provide the first service. Alternatively, when the authentication result is that the authentication fails, the first network element sends a response message for the first service request message to the service communication proxy, and the response message for the first service request message indicates that the request for the first service has failed.

[0031] In one possible design, a plurality of network function types include a first network function type and a second network function type. The first network function type is the network function type of the first network element, and the second network function type is the network function type of the network element that provides the second service, and the second service is associated with the first service.

[0032] According to the foregoing design, a network element having two different network function types can authenticate a service - consumer network element based on the same client credential information assertion.

[0033] In one possible design, the second service is used to provide an access token corresponding to the first service, and the access token corresponding to the first service indicates that the service - consumer network element has permission to obtain the first service, or the second service is used to provide information about the first network element.

[0034] In one possible design, the network element that provides the second service is a network repository function network element.

[0035] In one possible design, the first service is used to provide an access token corresponding to the second service, and the access token corresponding to the second service indicates that the service consumer network element has permission to obtain the second service, or the first service is used to provide information about the second network element.

[0036] According to the foregoing design, network elements having two different network function types can authenticate service consumer network elements based on the same client credential information assertion.

[0037] In one possible design, the first network element is a network repository function network element.

[0038] In one possible design, the first network element receives a second service request message from a service communication proxy, the second service request message is used to request a first service from the first network element, the second service request message includes a second client credential information assertion, and the second client credential information assertion includes a third network function type. When the third network function type does not match the network function type of the first network element, the first network element sends a response message to the service communication proxy for the second service request message, and the response message for the second service request message includes indication information, and the indication information is used to trigger a first service request message.

[0039] According to the foregoing design, when the network function type in the client eligibility information assertion does not match the network function type of the first network element, the first network element may carry indication information in the response message to the second service request message. The indication information may be used to trigger the first service request message in order to obtain a client eligibility information assertion that includes a network function type that matches the network function type of the first network element, so that the first network element can properly authenticate the service consumer network element.

[0040] In one possible design, the indication information includes a third client eligibility information assertion used to authenticate the first network element, and the third client eligibility information assertion includes the network function type of the first network element.

[0041] According to the foregoing design, the network function type of the first network element may be carried in the indication information to trigger the first client eligibility information assertion in the first service request message, carry a network function type that matches the network function type of the first network element, and enable the service consumer network element to be properly authenticated.

[0042] In one possible design, the first client entitlement information assertion further includes an identifier of a service consumer network element and validity time information of the first client entitlement information assertion, and the validity time information of the first client entitlement information assertion represents the validity time of the first client entitlement information assertion. The first network element authenticating the service consumer network element based on the first client entitlement information assertion further includes one or more of: the first network element verifying whether the signature of the first client entitlement information assertion is successful; the first network element verifying whether the first client entitlement information assertion has expired based on the validity time information included in the first client entitlement information assertion; or the first network element verifying whether the identifier of the service consumer network element in the first client entitlement information assertion is the same as the identifier of the network element in the certificate for signing the first client entitlement information assertion.

[0043] According to a third aspect, the present application provides a communication method. The method includes a step in which a service consumer network element transmits a first service request message to a service communication proxy, where the first service request message is used to request a first service from a service producer network element. The first service request message includes a fourth client eligibility information assertion and a fifth client eligibility information assertion, where the fourth client eligibility information assertion is used by the service producer network element to authenticate the service consumer network element, and the fifth client eligibility information assertion is used by a network element providing a second service to authenticate the service consumer network element. The fourth client eligibility information assertion includes a first network function type, and the fifth client eligibility information assertion includes a second network function type. The first network function type is the network function type of the service producer network element, and the second network function type is the network function type of a network element providing the second service, where the second service is associated with the first service. The service consumer network element receives a response message to the first service request message from the service communication proxy.

[0044] In the foregoing embodiments, the service consumer network element transmits a first service request message to the service communication proxy. The first service request message includes a fourth client eligibility information assertion and a fifth client eligibility information assertion. The fourth client eligibility information assertion includes a first network function type, and the fifth client eligibility information assertion includes a second network function type. As a result, the network element providing the second service can successfully authenticate the service consumer network element. This ensures that the service consumer network element requests the first service and solves the problem that in an indirect communication scenario, the service consumer network element cannot request a service because the authentication based on the client eligibility information assertion fails.

[0045] In one possible design, the fourth client eligibility information assertion further includes an identifier of the service consumer network element and validity time information of the fourth client eligibility information assertion, and the validity time information of the fourth client eligibility information assertion represents the validity time of the fourth client eligibility information assertion. The fifth client eligibility information assertion further includes an identifier of the service consumer network element and validity time information of the fifth client eligibility information assertion, and the validity time information of the fifth client eligibility information assertion represents the validity time of the fifth client eligibility information assertion.

[0046] In one possible design, the validity time of the fifth client eligibility information assertion is shorter than the validity time of the fourth client eligibility information assertion.

[0047] According to the foregoing design, the risk that the fifth client eligibility information assertion is maliciously used by the service communication proxy is reduced, and the security of the communication process can be guaranteed.

[0048] In one possible design, the expiration time of the fourth client entitlement information assertion is associated with a first duration, and the first duration is determined based on the transmission delay between the service consumer network element and the service communication proxy and the transmission delay between the service communication proxy and the network element providing the second service.

[0049] The aforementioned configuration rules for the expiration time of the fourth client entitlement information assertion and the expiration time of the fifth client entitlement information assertion can ensure, to the extent possible, that the fourth client entitlement information assertion and the fifth client entitlement information assertion are not maliciously used by the service communication proxy to guarantee the security of the communication process.

[0050] In one possible design, the second service is used to provide an access token corresponding to the first service, and the access token corresponding to the first service indicates that the service consumer network element has permission to obtain the first service.

[0051] In one possible design, the service consumer network element determines that there is no available access token corresponding to the first service.

[0052] In addition, after the service consumer network element determines that there is no available access token corresponding to the first service, the service consumer network element may carry parameters for obtaining an access token corresponding to the first service in the first service request message.

[0053] According to the aforementioned design, the service consumer network element can generate the first client entitlement information assertion as needed, thereby preventing the first client entitlement information assertion from being misused.

[0054] In one possible design, a service consumer network element determining that there is no available access token corresponding to a first service can include a case where the service consumer network element determines that no access token corresponding to the first service is stored, or a case where the service consumer network element determines that a stored access token corresponding to the first service has expired.

[0055] In one possible design, when a stored access token corresponding to a first service expires, the service consumer network element deletes the expired access token.

[0056] According to the foregoing design, memory space can be released in a timely manner, and the memory load of the system can be reduced.

[0057] In one possible design, a second service is used to provide information about a service producer network element.

[0058] In one possible design, the service consumer network element determines to trigger a service communication proxy such that a first service request message requests a second service.

[0059] In one possible design, when a service consumer network element determines to trigger a service communication proxy such that a first service request message requests a second service, in cases where the context of the first terminal device is not stored, the first terminal device is associated with the first service, the context of the first service is not stored, the service producer network element belongs to the first slice and the context corresponding to the first slice is not stored, or the service consumer network element communicates with the service communication proxy for the first time, based on one or more of these cases, the service consumer network element determines to trigger the service communication proxy such that the first service request message requests a second service.

[0060] In addition, after the service consumer network element determines that it can trigger the service communication proxy such that the first service request message requests a second service, the service consumer network element may carry parameters for discovering the service producer network element in the first service request message.

[0061] In one possible design, the service consumer network element determines to request the first service in an indirect communication mode, i.e., mode D.

[0062] For example, when a service consumer network element communicates with a service communication proxy in mode D, the first service request message always carries a client eligibility information assertion including a first network function type and a second network function type, or when it is determined that the service consumer network element can communicate with the service communication proxy in mode D and trigger the service communication proxy such that the first service request message requests a second service, the fact that the first service request message carries a client eligibility information assertion including a first network function type and a second network function type may be agreed upon by a standard protocol or configured based on pre-configuration information.

[0063] In one possible design, the service consumer network element sends a second service request message to the service communication proxy, the second service request message is used to request a first service, the second service request message includes a second client eligibility information assertion, the second client eligibility information assertion includes a first network function type, and the second client eligibility information assertion is used to authenticate the service consumer network element. The service consumer network element receives a response message to the second service request message from the service communication proxy, and the response message to the second service request message includes indication information. When the service consumer network element sends a first service request message to the service communication proxy, the service consumer network element sends the first service request message to the service communication proxy based on the indication information.

[0064] According to the foregoing design, the service consumer network element may send a first service request message to the service communication proxy based on the indication information.

[0065] In one possible design, the indication information includes a third client eligibility information assertion, the third client eligibility information assertion includes a second network function type, and the third client eligibility information assertion is used to authenticate a network element that provides a second service. When a service consumer network element sends a first service request message to a service communication proxy based on the indication information, the service consumer network element sends the first service request message to the service communication proxy when authentication of the network element that provides the second service based on the third client eligibility information assertion is successful.

[0066] According to the foregoing design, the service consumer network element can authenticate a network element that provides a second service based on the third client eligibility information assertion, and when the authentication is successful, send a first service request message based on the second network function type included in the third client eligibility information assertion.

[0067] In one possible design, the network element that provides the second service is a network repository function network element.

[0068] According to a fourth aspect, the present application provides a communication method. The method includes a step in which a service communication proxy receives a first service request message from a service consumer network element, the first service request message being used to request a first service from a service producer network element. The first service request message includes a fourth client eligibility information assertion and a fifth client eligibility information assertion. The fourth client eligibility information assertion is used by the service producer network element to authenticate the service consumer network element, and the fifth client eligibility information assertion is used by a first network element to authenticate the service consumer network element. The fourth client eligibility information assertion includes a first network function type, and the fifth client eligibility information assertion includes a second network function type. The first network function type is the network function type of the service producer network element, and the second network function type is the network function type of the first network element. The service communication proxy transmits a second service request message to the first network element in response to the first service request message, the second service request message being used to request a second service, and the second service request message includes the fifth client eligibility information assertion. The service communication proxy receives a response message to the second service request message from the first network element. The service communication proxy transmits a third service request message to the service producer network element based on the response message to the second service request message, the third service request message being used to request the first service from the service producer network element, and the third service request message includes the fourth client eligibility information assertion.

[0069] In the foregoing embodiments, the service consumer network element transmits a first service request message to the service communication proxy. The first service request message includes a fourth client entitlement information assertion and a fifth client entitlement information assertion. The fourth client entitlement information assertion includes a first network function type, and the fifth client entitlement information assertion includes a second network function type. When requesting the second service, the service communication proxy conveys the fifth client entitlement information assertion. As a result, the network element providing the second service can authenticate the service consumer network element properly. When requesting the first service, the service communication proxy conveys the fourth client entitlement information assertion. As a result, the service producer network element can authenticate the service consumer network element properly. Thereby, it is ensured that the service consumer network element requests the first service, and in the indirect communication scenario, the problem that the service consumer network element cannot request a service due to the failure of authentication based on the client entitlement information assertion is solved.

[0070] In one possible design, based on the first service request message, the service communication proxy determines that the second service needs to be requested from the first network element, and based on the network function type of the first network element, the service communication proxy determines to convey the fifth client entitlement information assertion in the second service request message.

[0071] According to the foregoing design, the service communication proxy analyzes the first service request message, selects the fifth client entitlement information assertion from the fourth client entitlement information assertion and the fifth client entitlement information assertion based on the network function type of the first network element, and may add the fifth client entitlement information assertion to the second service request message.

[0072] In one possible design, the service communication proxy determines to carry a fourth client entitlement information assertion in a third service request message based on the network function type of the service producer network element.

[0073] According to the foregoing design, the service communication proxy may analyze the first service request message, select the fourth client entitlement information assertion from the fourth client entitlement information assertion and the fifth client entitlement information assertion based on the network function type of the service producer network element, and add the fourth client entitlement information assertion to the second service request message.

[0074] In one possible design, before the service communication proxy receives the first service request message from the service consumer network element, the service communication proxy receives a fourth service request message from the service consumer network element, the fourth service request message is used to request the first service, the third service request message includes a sixth client entitlement information assertion, and the sixth client entitlement information assertion includes a third network function type. The service communication proxy sends a fifth service request message to the first network element, the fifth service request message is used to request the second service, and the fifth service request message includes the sixth client entitlement information assertion. The service communication proxy receives a response message to the fifth service request message from the first network element, and the response message to the fifth service request message includes indication information. The service communication proxy sends a response message to the fourth service request message to the service consumer network element based on the indication information.

[0075] According to the foregoing design, the service communication proxy may send a response message to the fourth service request message to the service consumer network element based on the instruction information in order to obtain a client eligibility information assertion that matches the network function type of the first network, and as a result, the first network element authenticates the service consumer network element normally.

[0076] In one possible design, the instruction information includes a seventh client eligibility information assertion, the seventh client eligibility information assertion includes the network function type of the first network element, and the response message to the fourth service request message further includes the seventh client eligibility information assertion.

[0077] According to the foregoing design, the instruction information may be used to trigger the service consumer network element to send a first service request message, and the first service request message includes a client eligibility information assertion that matches the network function type of the first network.

[0078] In one possible design, the second service is used to provide an access token corresponding to the first service, and the access token corresponding to the first service indicates that the service consumer network element has permission to obtain the first service.

[0079] In one possible design, the service communication proxy determines that there is no available access token stored corresponding to the first service, and the first service request message does not include an access token corresponding to the first service.

[0080] In one possible design, the second service is used to provide information about the service producer network element.

[0081] In one possible design, the service communication proxy determines that information about the service producer network element is not stored and that the first service request message does not include information about the service producer network element.

[0082] In one possible design, the fourth client eligibility information assertion further includes an identifier of the service consumer network element and validity time information of the fourth client eligibility information assertion, and the validity time information of the fourth client eligibility information assertion represents the validity time of the fourth client eligibility information assertion. The fifth client eligibility information assertion further includes an identifier of the service consumer network element and validity time information of the fifth client eligibility information assertion, and the validity time information of the fifth client eligibility information assertion represents the validity time of the fifth client eligibility information assertion.

[0083] In one possible design, the validity time of the fifth client eligibility information assertion is shorter than the validity time of the fourth client eligibility information assertion.

[0084] According to the foregoing design, the risk that the fifth client eligibility information assertion is maliciously used by the service communication proxy is reduced, and the security of the communication process can be guaranteed.

[0085] In one possible design, the validity time of the fourth client eligibility information assertion is associated with a first duration, and the first duration is determined based on the transmission delay between the service consumer network element and the service communication proxy and the transmission delay between the service communication proxy and the network element providing the second service.

[0086] The above-described configuration rules regarding the validity periods of the fourth client eligibility information assertion and the fifth client eligibility information assertion can, to the extent possible, ensure that the fourth client eligibility information assertion and the fifth client eligibility information assertion are not maliciously used by the service communication proxy to guarantee the security of the communication process.

[0087] In one possible design, the network element providing the second service is a network repository function network element.

[0088] According to a fifth aspect, the present application provides a communication method. The method includes steps in which a first network element receives a first service request message from a service communication proxy, the first service request message being used to request a first service from the first network element, the first service request message including a plurality of client eligibility information assertions, each client eligibility information assertion including a network function type. The first network element authenticates a service consumer network element based on the plurality of client eligibility information assertions. When the first network element authenticates the service consumer network element based on the plurality of client eligibility information assertions, the first network element determines whether one or more of the client eligibility information assertions within the plurality of client eligibility information assertions successfully authenticate the service consumer network element. The first network element transmits a response message to the service communication proxy for the first service request message based on the authentication result.

[0089] According to the foregoing method, when the first service request message includes a plurality of client qualification information assertions, the first network element determines that one or more client qualification information assertions have successfully authenticated the service consumer network element and obtains the authentication result. Therefore, in the foregoing method, when there are a plurality of client qualification information assertions, it is possible to determine whether the authentication of the service consumer network element has succeeded.

[0090] In one possible design, when the authentication result indicates that one or more client qualification information assertions have successfully authenticated the service consumer network element, the first network element sends a response message to the first service request message to the service communication proxy, and the response message to the first service request message is used to provide the first service. Alternatively, when the authentication result indicates that any one of the plurality of client qualification information assertions has failed to authenticate the service consumer network element, the first network element sends a response message to the first service request message to the service communication proxy, and the response message to the first service request message indicates that the request for the first service has failed.

[0091] According to the foregoing design, when one or more client qualification information assertions successfully authenticate the service consumer network element, it is determined that the authentication of the service consumer network element has succeeded. Alternatively, when any one of the plurality of client qualification information assertions fails to authenticate the service consumer network element, that is, when all client qualification information assertions fail to authenticate the service consumer network element, it is determined that the authentication of the service consumer network element has failed.

[0092] In one possible design, a plurality of client entitlement information assertions includes a fourth client entitlement information assertion and a fifth client entitlement information assertion. The fourth client entitlement information assertion includes a first network function type, and the fifth client entitlement information assertion includes a second network function type. The first network function type is the network function type of a first network element, and the second network function type is the network function type of a network element that provides a second service, where the second service is associated with the first service.

[0093] In one possible design, the second service is used to provide an access token corresponding to the first service, where the access token corresponding to the first service indicates that a service - consumer network element has permission to obtain the first service, or the second service is used to provide information about the first network element.

[0094] In one possible design, the network element that provides the second service is a network repository function network element.

[0095] In one possible design, the first service is used to provide an access token corresponding to the second service, where the access token corresponding to the second service indicates that a service - consumer network element has permission to obtain the second service, or the first service is used to provide information about the second network element.

[0096] In one possible design, the first network element is a network repository function network element.

[0097] In one possible design, the first network element receives a second service request message from the service communication proxy. The second service request message is used to request the first service from the first network element. The second service request message includes a sixth client credential information assertion, and the sixth client credential information assertion includes a third network function type. When the third network function type does not match the network function type of the first network element, the first network element sends a response message to the service communication proxy for the third service request message. The response message for the third service request message includes indication information, and the indication information is used to trigger the first service request message.

[0098] According to the foregoing design, when the network function type in the client credential information assertion does not match the network function type of the first network element, the first network element may carry the indication information in the response message for the third service request message. The indication information may be used to trigger the first service request message in order to obtain a client credential information assertion that includes a network function type that matches the network function type of the first network element so that the first network element can properly authenticate the service consumer network element.

[0099] In one possible design, the indication information includes a seventh client credential information assertion that is used to authenticate the first network element, and the seventh client credential information assertion includes the network function type of the first network element.

[0100] According to the foregoing design, the network function type of the first network element is carried in the indication information to trigger the first client eligibility information assertion in the first service request message, and carry a client eligibility information assertion including a network function type that matches the network function type of the first network element, so as to be able to authenticate the service consumer network element normally.

[0101] According to a sixth aspect, the present application provides a communication method. This method is used in a scenario where a service consumer network element requests a first service from a service producer network element via a service communication proxy. The method includes the step that the service communication proxy sends a client eligibility information assertion request message to the service consumer network element, where the client eligibility information assertion request message is used to request a first client eligibility information assertion, and the first client eligibility information assertion is used by the network element providing the second device to authenticate the service consumer network element, and the second service is associated with the first service. The service communication proxy receives a response message to the client eligibility information assertion request message from the service consumer network element, the response message to the client eligibility information assertion request message includes the first client eligibility information assertion, the first client eligibility information assertion includes a first network function type and a second network function type, or the first client eligibility information assertion includes the second network function type. The first network function type is the network function type of the service producer network element, and the second network function type is the network function type of the network element providing the second service.

[0102] According to the foregoing design, the service communication proxy may request a client qualification information assertion to ensure that the service communication proxy requests a second service and the service consumer network element requests a first service.

[0103] In one possible design, before the service communication proxy sends a client qualification information assertion request message to the service consumer network element, the service communication proxy receives a first service request message from the service consumer network element. The first service request message is used to request a first service, the first service request message includes a second client qualification information assertion, and the second client qualification information assertion includes a first network function type. The service communication proxy sends a second service request message to the first network element. The second service request message is used to request a second service, and the second service request message includes the second client qualification information assertion. The service communication proxy receives a response message to the second service request message from the first network element, and the response message to the second service request message includes indication information. When the service communication proxy sends a client qualification information assertion request message to the service consumer network element, the service communication proxy sends a client qualification information assertion request message to the service consumer network element based on the indication information.

[0104] According to the foregoing design, when the network function type in the client qualification information assertion does not match the network function type of the first network element, the first network element may carry indication information in the response message to the second service request message. The indication information may be used to trigger a client qualification information assertion request message in order to obtain a client qualification information assertion including a network function type that matches the network function type of the first network element so that the first network element can properly authenticate the service consumer network element.

[0105] In one possible design, the indication information includes a third client qualification information assertion, the third client qualification information assertion includes the network function type of the first network element, and the client qualification information assertion request message includes the third client qualification information assertion.

[0106] According to the foregoing design, the network function type of the first network element is carried in the indication information to trigger the first client qualification information assertion in the first service request message, carry a client qualification information assertion including a network function type that matches the network function type of the first network element, and may be used to properly authenticate the service consumer network element.

[0107] In one possible design, the first client entitlement information assertion includes a second network function type. The service communication proxy sends a third service request message to a first network element, where the third service request message is used to request a second service and includes the first client entitlement information assertion. The service communication proxy receives a response message to the third service request message from the first network element. The service communication proxy sends a fourth service request message to a service producer network element based on the response message to the third service request message, where the fourth service request message is used to request a first service and includes a second client entitlement information assertion.

[0108] According to the foregoing design, the service communication proxy analyzes the response message to the client entitlement information assertion, conveys the first client entitlement information assertion in the third service request message based on the network function type of the first network element, and conveys the second client entitlement information assertion in the fourth service request message based on the network function type of the service producer network element.

[0109] In one possible design, the first client entitlement information assertion includes a first network function type and a second network function type. The service communication proxy sends a third service request message to the first network element. The third service request message is used to request a second service and includes the first client entitlement information assertion. The service communication proxy receives a response message for the third service request message from the first network element. The service communication proxy sends a fourth service request message to the service producer network element based on the response message for the third service request message. The fourth service request message is used to request a first service and includes the first client entitlement information assertion, or the fourth service request message includes a second client entitlement information assertion.

[0110] According to the foregoing design, the service communication proxy analyzes the response message for the client entitlement information assertion, conveys the first client entitlement information assertion in the third service request message based on the network function type of the first network element, and conveys the first client entitlement information assertion or the second client entitlement information assertion in the fourth service request message based on the network function type of the service producer network element.

[0111] In one possible design, the second service is used to provide an access token corresponding to the first service, and the access token corresponding to the first service indicates that the service consumer network element has permission to obtain the first service.

[0112] In one possible design, the service communication proxy determines that the access token corresponding to the first service is not stored and the first service request message does not include a first access token.

[0113] In one possible design, the second service is used to provide information about the service-producer network element.

[0114] In one possible design, the service communication proxy determines that information about the service-producer network element is not stored and that the first service request message does not include information about the service-producer network element.

[0115] In one possible design, the network element that provides the second service is a network repository function network element.

[0116] According to a seventh aspect, the present application provides a communication device. The device includes a transceiver unit and a processing unit. The processing unit calls the transceiver unit to send a first service request message to a service communication proxy. The first service request message is used to request a first service from a service-producer network element. The first service request message includes a first client eligibility information assertion. The first client eligibility information assertion is used to authenticate the device. The first client eligibility information assertion includes a first network function type and a second network function type. The first network function type is the network function type of the service-producer network element. The second network function type is the network function type of the network element that provides the second service. The second service is associated with the first service. The processing unit receives a response message to the first service request message from the service communication proxy.

[0117] In one possible design, the second service is used to provide an access token corresponding to the first service. The access token corresponding to the first service indicates that the device has permission to obtain the first service.

[0118] In one possible design, the processing unit is configured to determine that there is no available access token corresponding to the first service.

[0119] In one possible design, when the processing unit determines that there is no available access token corresponding to the first service, the processing unit is configured to determine that the access token corresponding to the first service is not stored, or to determine that the stored access token corresponding to the first service has expired.

[0120] In one possible design, when the stored access token corresponding to the first service has expired, the processing unit is configured to delete the expired access token.

[0121] In one possible design, the second service is used to provide information about the service producer network element.

[0122] In one possible design, the processing unit is configured to determine to trigger the service communication proxy such that the first service request message requests the second service.

[0123] In one possible design, when determining to trigger the service communication proxy such that the first service request message requests the second service, the processing unit is based on one or more of the following cases: the context of the first terminal device is not stored and the first terminal device is associated with the first service; the context of the first service is not stored; the service producer network element belongs to the first slice and the context corresponding to the first slice is not stored; or the device communicates with the service communication proxy for the first time. The processing unit is configured to determine to trigger the service communication proxy such that the first service request message requests the second service.

[0124] In one possible design, the processing unit is configured to determine to request a first service in an indirect communication mode, i.e., mode D.

[0125] In one possible design, the transceiver unit is configured to send a second service request message to the service communication proxy, the second service request message is used to request the first service, the second service request message includes a second client qualification information assertion, the second client qualification information assertion includes a first network function type, the second client qualification information assertion is used to authenticate the device, receive a response message for the second service request message from the service communication proxy, and the response message for the second service request message includes indication information. When the first service request message is sent to the service communication proxy, the processing unit is configured to send the first service request message to the service communication proxy based on the indication information.

[0126] In one possible design, the indication information includes a third client qualification information assertion, the third client qualification information assertion includes a second network function type, and the third client qualification information assertion is used to authenticate a network element that provides the second service. When the transceiver unit determines that the first service request message is sent to the service communication proxy based on the indication information, the transceiver unit is configured to send the first service request message to the service communication proxy when the authentication of the network element that provides the second service based on the third client qualification information assertion is successful.

[0127] In one possible design, the network element that provides the second service is a network repository function network element.

[0128] In one possible design, the first client eligibility information assertion further includes one or more of the device identifier or the expiration time information, and the expiration time information represents the expiration time of the first client eligibility information assertion.

[0129] According to an eighth aspect, the present application provides a communication device. The device includes a transceiver unit and a processing unit. The transceiver unit is configured to receive a first service request message from a service communication proxy, the first service request message is used to request a first service from the device, the first service request message includes a first client eligibility information assertion, and the first client eligibility information assertion is used to authenticate a service - consumer network element. The first client eligibility information assertion includes a plurality of network function types. The processing unit is configured to authenticate the service - consumer network element based on the first client eligibility information assertion. When the service - consumer network element is authenticated based on the first client eligibility information assertion, the processing unit determines whether the network function type of the processing unit matches one or more of the plurality of network function types. The processing unit calls the transceiver unit to send a response message to the service communication proxy for the first service request message based on the authentication result.

[0130] In one possible design, when the authentication result is that the authentication is successful, the transceiver unit is configured to send a response message to the service communication proxy for the first service request message, and the response message for the first service request message is used to provide the first service. Alternatively, when the authentication result is that the authentication fails, the transceiver unit is configured to send a response message to the service communication proxy for the first service request message, and the response message for the first service request message indicates that the request for the first service has failed.

[0131] In one possible design, a plurality of network function types includes a first network function type and a second network function type. The first network function type is the network function type of the device, and the second network function type is the network function type of a network element that provides a second service, where the second service is associated with the first service.

[0132] In one possible design, the second service is used to provide an access token corresponding to the first service, where the access token corresponding to the first service indicates that a service - consumer network element has permission to obtain the first service, or the second service is used to provide information about the device.

[0133] In one possible design, the network element that provides the second service is a network repository function network element.

[0134] In one possible design, the first service is used to provide an access token corresponding to the second service, where the access token corresponding to the second service indicates that a service - consumer network element has permission to obtain the second service, or the first service is used to provide information about the second network element.

[0135] In one possible design, the device is a network repository function network element.

[0136] In one possible design, the transceiver unit receives a second service request message from the service communication proxy, the second service request message is used to request a first service from the device, the second service request message includes a second client credential information assertion, and the second client credential information assertion includes a third network function type, and is configured as such.

[0137] When the third network function type does not match the network function type of the device, the transceiver unit sends a response message to the second service request message to the service communication proxy, the response message to the second service request message includes indication information, and the indication information is used to trigger a first service request message, and is configured as such.

[0138] In one possible design, the indication information includes a third client credential information assertion used to authenticate the device, and the third client credential information assertion includes the network function type of the device.

[0139] In one possible design, the first client entitlement information assertion further includes an identifier of a service consumer network element and validity time information of the first client entitlement information assertion, and the validity time information of the first client entitlement information assertion represents the validity time of the first client entitlement information assertion. The processing unit being configured to authenticate a service consumer network element based on the first client entitlement information assertion further includes verifying whether the signature of the first client entitlement information assertion is successful, verifying whether the first client entitlement information assertion has expired based on the validity time information included in the first client entitlement information assertion, or verifying whether the identifier of the service consumer network element in the first client entitlement information assertion is the same as the identifier of the network element in the certificate for signing the first client entitlement information assertion, one or more of the above.

[0140] According to a ninth aspect, the present application provides a communication device. The device includes a transceiver unit and a processing unit. The processing unit calls the transceiver unit to send a first service request message to a service communication proxy. The first service request message is used to request a first service from a service producer network element. The first service request message includes a fourth client eligibility information assertion and a fifth client eligibility information assertion. The fourth client eligibility information assertion is used by the service producer network element to authenticate a service consumer network element. The fifth client eligibility information assertion is used by a network element providing a second service to authenticate a service consumer network element. The fourth client eligibility information assertion includes a first network function type. The fifth client eligibility information assertion includes a second network function type. The first network function type is the network function type of the service producer network element. The second network function type is the network function type of the network element providing the second service. The second service is associated with the first service. The service communication proxy receives a response message to the first service request message.

[0141] In one possible design, the fourth client eligibility information assertion further includes an identifier of the service consumer network element and validity time information of the fourth client eligibility information assertion. The validity time information of the fourth client eligibility information assertion represents the validity time of the fourth client eligibility information assertion. The fifth client eligibility information assertion further includes an identifier of the service consumer network element and validity time information of the fifth client eligibility information assertion. The validity time information of the fifth client eligibility information assertion represents the validity time of the fifth client eligibility information assertion.

[0142] In one possible design, the expiration time of the fifth client eligibility information assertion is shorter than that of the fourth client eligibility information assertion.

[0143] In one possible design, the expiration time of the fourth client eligibility information assertion is associated with a first duration, and the first duration is determined based on the transmission delay between the service consumer network element and the service communication proxy and the transmission delay between the service communication proxy and the network element providing the second service.

[0144] In one possible design, the second service is used to provide an access token corresponding to the first service, and the access token corresponding to the first service indicates that the device has permission to obtain the first service.

[0145] In one possible design, the processing unit is configured to determine that there is no available access token corresponding to the first service.

[0146] In one possible design, when the processing unit determines that there is no available access token corresponding to the first service, the processing unit is configured to determine that the access token corresponding to the first service is not stored or that the stored access token corresponding to the first service has expired.

[0147] In one possible design, the processing unit is configured to delete the expired access token when the stored access token corresponding to the first service has expired.

[0148] In one possible design, the second service is used to provide information about the service producer network element.

[0149] In one possible design, the processing unit is configured to determine to trigger the service communication proxy such that the first service request message requests the second service.

[0150] In one possible design, when the processing unit determines to trigger the service communication proxy such that the first service request message requests the second service, the processing unit is configured to determine to trigger the service communication proxy such that the first service request message requests the second service based on one or more of the following cases: the context of the first terminal device is not stored, the first terminal device is associated with the first service; the context of the first service is not stored; the service producer network element belongs to the first slice and the context corresponding to the first slice is not stored; or the device communicates with the service communication proxy for the first time.

[0151] In one possible design, the processing unit is configured to determine to request the first service in an indirect communication mode, i.e., mode D.

[0152] In one possible design, the transceiver unit is configured to send a second service request message to the service communication proxy, where the second service request message is used to request the first service, the second service request message includes a second client credential information assertion, the second client credential information assertion includes a first network function type, the second client credential information assertion is used to authenticate the device, receive a response message to the second service request message from the service communication proxy, and the response message to the second service request message includes indication information. When the first service request message is sent to the service communication proxy, the processing unit is configured to send the first service request message to the service communication proxy based on the indication information.

[0153] In one possible design, the indication information includes a third client eligibility information assertion, the third client eligibility information assertion includes a second network function type, and the third client eligibility information assertion is used to authenticate a network element that provides a second service. When a first service request message is transmitted to the service communication proxy based on the indication information, the transceiver unit is configured to transmit the first service request message to the service communication proxy when authentication of the network element that provides the second service based on the third client eligibility information assertion is successful.

[0154] In one possible design, the network element that provides the second service is a network repository function network element.

[0155] In one possible design, the first client eligibility information assertion further includes one or more of an identifier of the device or validity time information, and the validity time information represents the validity time of the first client eligibility information assertion.

[0156] According to a tenth aspect, the present application provides a communication device. The device includes a transceiver unit and a processing unit. The processing unit calls the transceiver unit to receive a first service request message from a service consumer network element, the first service request message being used to request a first service from a service producer network element, the first service request message including a fourth client entitlement information assertion and a fifth client entitlement information assertion, the fourth client entitlement information assertion being used by the service producer network element to authenticate the service consumer network element, the fifth client entitlement information assertion being used by a first network element to authenticate the service consumer network element, the fourth client entitlement information assertion including a first network function type, the fifth client entitlement information assertion including a second network function type, the first network function type being the network function type of the service producer network element, the second network function type being the network function type of the first network element, transmits a second service request message to the first network element in response to the first service request message, the second service request message being used to request a second service, the second service request message including the fifth client entitlement information assertion, receives a response message to the second service request message from the first network element, and based on the response message to the second service request message, transmits a third service request message to the service producer network element, the third service request message being used to request a first service from the service producer network element, the third service request message including the fourth client entitlement information assertion.

[0157] In one possible design, the processing unit is configured to determine, based on a first service request message, that a second service needs to be requested from a first network element, and to determine to carry a fifth client eligibility information assertion in a second service request message based on the network function type of the first network element.

[0158] In one possible design, the processing unit is configured to determine to carry a fourth client eligibility information assertion in a third service request message based on the network function type of a service producer network element.

[0159] In one possible design, before receiving a first service request message from a service consumer network element, the transceiver unit receives a fourth service request message from the service consumer network element, the fourth service request message is used to request a first service, the third service request message includes a sixth client eligibility information assertion, the sixth client eligibility information assertion includes a third network function type, sends a fifth service request message to the first network element, the fifth service request message is used to request a second service, the fifth service request message includes the sixth client eligibility information assertion, receives a response message to the fifth service request message from the first network element, the response message to the fifth service request message includes indication information, and is configured to send a response message to the fourth service request message to the service consumer network element based on the indication information.

[0160] In one possible design, the indication information includes a seventh client eligibility information assertion, the seventh client eligibility information assertion includes the network function type of the first network element, and the response message to the fourth service request message further includes the seventh client eligibility information assertion.

[0161] In one possible design, the second service is used to provide an access token corresponding to the first service, and the access token corresponding to the first service indicates that the service consumer network element has permission to obtain the first service.

[0162] In one possible design, the processing unit is configured to determine that there is no available access token corresponding to the first service stored and that the first service request message does not include an access token corresponding to the first service.

[0163] In one possible design, the second service is used to provide information about the service producer network element.

[0164] In one possible design, the processing unit is configured to determine that there is no information about the service producer network element stored and that the first service request message does not include information about the service producer network element.

[0165] In one possible design, the fourth client eligibility information assertion further includes an identifier of the service consumer network element and validity time information of the fourth client eligibility information assertion, and the validity time information of the fourth client eligibility information assertion represents the validity time of the fourth client eligibility information assertion. The fifth client eligibility information assertion further includes an identifier of the service consumer network element and validity time information of the fifth client eligibility information assertion, and the validity time information of the fifth client eligibility information assertion represents the validity time of the fifth client eligibility information assertion.

[0166] In one possible design, the validity time of the fifth client eligibility information assertion is shorter than the validity time of the fourth client eligibility information assertion.

[0167] In one possible design, the expiration time of the fourth client eligibility information assertion is associated with a first duration, which is determined based on the transmission delay between the service consumer network element and the service communication proxy, and the transmission delay between the service communication proxy and the network element providing the second service.

[0168] In one possible design, the network element providing the second service is a network repository function network element.

[0169] According to an eleventh aspect, the present application provides a communication device. The device includes a transceiver unit and a processing unit. The processing unit calls the transceiver unit to receive a first service request message from a service communication proxy. The first service request message is used to request a first service from a first network element. The first service request message includes a plurality of client eligibility information assertions, and each client eligibility information assertion includes a network function type. The first network element authenticates the service consumer network element based on the plurality of client eligibility information assertions. The first network element authenticating the service consumer network element based on the plurality of client eligibility information assertions includes the first network element determining whether one or more of the client eligibility information assertions within the plurality of client eligibility information assertions can successfully authenticate the service consumer network element. The first network element transmits a response message to the service communication proxy for the first service request message based on the authentication result.

[0170] In one possible design, when the authentication result indicates that one or more client entitlement information assertions have successfully authenticated the service consumer network element, the first network element sends a response message for the first service request message to the service communication proxy, and the response message for the first service request message is used to provide the first service. Alternatively, when the authentication result indicates that any one of the multiple client entitlement information assertions has failed to authenticate the service consumer network element, the first network element sends a response message for the first service request message to the service communication proxy, and the response message for the first service request message indicates that the request for the first service has failed.

[0171] In one possible design, the multiple client entitlement information assertions include a fourth client entitlement information assertion and a fifth client entitlement information assertion. The fourth client entitlement information assertion includes a first network function type, and the fifth client entitlement information assertion includes a second network function type. The first network function type is the network function type of the first network element, and the second network function type is the network function type of the network element that provides the second service, and the second service is associated with the first service.

[0172] In one possible design, the second service is used to provide an access token corresponding to the first service, and the access token corresponding to the first service indicates that the service consumer network element has permission to obtain the first service, or the second service is used to provide information about the first network element.

[0173] In one possible design, the network element that provides the second service is a network repository function network element.

[0174] In one possible design, the first service is used to provide an access token corresponding to the second service, and the access token corresponding to the second service indicates that the service consumer network element has permission to obtain the second service, or the first service is used to provide information about the second network element.

[0175] In one possible design, the first network element is a network repository function network element.

[0176] In one possible design, the transceiver unit receives a second service request message from the service communication proxy, the second service request message is used to request the first service from the first network element, the second service request message includes a sixth client credential information assertion, and the sixth client credential information assertion includes a third network function type.

[0177] When the third network function type does not match the network function type of the first network element, the transceiver unit transmits a response message to the service communication proxy for the second service request message, and the response message for the second service request message includes indication information, and the indication information is configured to be used to trigger the first service request message.

[0178] In one possible design, the indication information includes a seventh client credential information assertion used to authenticate the first network element, and the seventh client credential information assertion includes the network function type of the first network element.

[0179] According to a twelfth aspect, the present application provides a communication device. The device includes a transceiver unit and a processing unit. A service consumer network element uses the device to request a first service from a service producer network element. The processing unit calls the transceiver unit to send a client eligibility information assertion request message to the service consumer network element, where the client eligibility information assertion request message is used to request a first client eligibility information assertion, and the first client eligibility information assertion is used by a network element providing a second device to authenticate the service consumer network element, the second service being associated with the first service. The service consumer network element receives a response message to the client eligibility information assertion request message, where the response message to the client eligibility information assertion request message includes the first client eligibility information assertion, and the first client eligibility information assertion includes a first network function type and a second network function type, or the first client eligibility information assertion includes the second network function type. The first network function type is the network function type of the service producer network element, and the second network function type is the network function type of the network element providing the second service.

[0180] In one possible design, before a client eligibility information assertion request message is sent to the service consumer network element, the transceiver unit receives a first service request message from the service consumer network element, the first service request message is used to request a first service, the first service request message includes a second client eligibility information assertion, the second client eligibility information assertion includes a first network function type, sends a second service request message to a network element that provides a second service, the second service request message is used to request the second service, the second service request message includes the second client eligibility information assertion, receives a response message to the second service request message from the network element that provides the second service, the response message to the second service request message includes indication information, and when the client eligibility information assertion request message is sent to the service consumer network element, the client eligibility information assertion request message is sent to the service consumer network element based on the indication information.

[0181] In one possible design, the indication information includes a third client eligibility information assertion, the third client eligibility information assertion includes the network function type of the first network element, and the client eligibility information assertion request message includes the third client eligibility information assertion.

[0182] In one possible design, the first client eligibility information assertion includes a second network function type. The service communication proxy sends a third service request message to the first network element. The third service request message is used to request a second service and includes the first client eligibility information assertion. The service communication proxy receives a response message to the third service request message from the first network element. The service communication proxy sends a fourth service request message to the service producer network element based on the response message to the third service request message. The fourth service request message is used to request a first service and includes a second client eligibility information assertion.

[0183] In one possible design, the first client eligibility information assertion includes a first network function type and a second network function type. The transceiver unit sends a third service request message to the first network element. The third service request message is used to request a second service and includes the first client eligibility information assertion. The transceiver unit receives a response message to the third service request message from the first network element and sends a fourth service request message to the service producer network element based on the response message to the third service request message. The fourth service request message is used to request a first service and is configured to include the first client eligibility information assertion or the fourth service request message includes a second client eligibility information assertion.

[0184] In one possible design, the second service is used to provide an access token corresponding to the first service, and the access token corresponding to the first service indicates that the service consumer network element has permission to obtain the first service.

[0185] In one possible design, before a client eligibility information assertion request message is sent to a service consumer network element, the processing unit is configured to determine that the first access token is not stored and that the first service request message does not include an access token corresponding to the first service.

[0186] In one possible design, a second service is used to provide information about a service producer network element.

[0187] In one possible design, before a client eligibility information assertion request message is sent to a service consumer network element, the processing unit is configured to determine that information about the service producer network element is not stored and that the first service request message does not include information about the service producer network element.

[0188] In one possible design, the network element that provides the second service is a network repository function network element.

[0189] According to a thirteenth aspect, the present application further provides a communication device. The device can execute the foregoing method design. The device can be a chip or a circuit capable of executing functions corresponding to the foregoing method, or a device including a chip or a circuit.

[0190] In a possible embodiment, the device includes a memory configured to store computer-executable program code and a processor coupled to the memory. The program code stored in the memory includes instructions. When the processor executes the instructions, the device or the device installed in a device is enabled to execute a method according to any one of the possible designs of the first aspect to the sixth aspect.

[0191] The device may further include a communication interface. The communication interface may be a transceiver. Alternatively, if the device is a chip or a circuit, the communication interface may be an input / output interface of the chip, for example, an input / output pin.

[0192] In one possible design, the device includes corresponding functional units configured to implement the steps of the foregoing method respectively. The functions may be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more units corresponding to the foregoing functions.

[0193] According to a 14th aspect, an embodiment of the present application provides a computer-readable storage medium, which stores a computer program. When the computer program runs on a device, the method in any one of the possible designs of the 1st aspect to the 6th aspect is executed.

[0194] According to a 15th aspect, an embodiment of the present application provides a computer program product, which includes a computer program. When the computer program runs on a device, the method in any one of the possible designs of the 1st aspect to the 6th aspect is executed.

[0195] According to a 16th aspect, the present application provides a communication chip, which stores instructions. When the instructions run on a communication device, the communication chip is enabled to execute the method in any one of the possible designs of the 1st aspect to the 6th aspect.

Brief Description of the Drawings

[0196]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

Figure 17

Figure 18

Figure 19A

Figure 19B

Figure 20A

Figure 20B

Figure 21

Figure 22

Embodiments for Carrying Out the Invention

[0197] The following clearly and completely describes the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application. It is obvious that the described embodiments are only part of the embodiments of the present application, not all of them. In the specification, claims, and accompanying drawings of the present application, terms such as "first", "second", corresponding term numbers, etc. are intended to distinguish similar objects and do not necessarily indicate a specific order or sequence. It should be understood that such terms are interchangeable in appropriate situations, which is only a distinguishing method used when objects having the same attributes are described in the embodiments of the present application. In addition, terms such as "including", "containing" and any other variants mean that a process, method, system, product, or device including a series of units is not necessarily limited to those units, and may include other units not explicitly listed or specific to such a process, method, system, product, or device, corresponding to non-exclusive inclusion.

[0198] In the description of this application, unless otherwise specified, " / " means "or". For example, A / B can represent A or B. In this application, "and / or" only describes the association relationship for describing related objects, indicating that three relationships can exist. For example, A and / or B can represent the following three cases, namely, the case where only A exists, the case where both A and B exist, and the case where only B exists. In addition, in the description of this application, "at least one item" means one or more items, and "a plurality of items" means two or more items. The following "at least one item (piece)" or its similar expression means any combination of these items, including any combination of a single item (piece) or a plurality of items (pieces). For example, at least one item (piece) among a, b, or c can represent a, b, c, a and b, a and c, b and c, or a, b, and c, and a, b, and c can be singular or plural.

[0199] The technical solutions in the embodiments of this application can be applied to various communication systems such as Wideband Code Division Multiple Access (WCDMA) systems, General Packet Radio Service (GPRS), Long Term Evolution (LTE) systems, LTE Frequency Division Duplex (FDD) systems, LTE Time Division Duplex (TDD) systems, Universal Mobile Telecommunication System (UMTS), Worldwide Interoperability for Microwave Access (WiMAX) communication systems, 5th generation (5G) systems, or even future 6th generation communication systems.

[0200] To facilitate the understanding of the embodiments of the present application, the application scenario used in the present application is described by way of example using the extended service-based architecture shown in FIG. 1. Specifically, the extended service-based architecture can particularly include, but is not limited to, the following devices.

[0201] 1. Session management network element: It is mainly configured to manage sessions, allocate and manage the Internet protocol (IP) addresses of terminal devices, select endpoints that can manage user equipment plane function interfaces and policy control or charging function interfaces, execute downlink data notifications, etc. In 5G communication, the session management network element may be a session management function (SMF) network element. In future communications such as 6G communication, the session management function network element may continue to be an SMF network element or may have another name. This is not limited in the present application. Nsmf is a service-based interface provided by the SMF. The SMF can communicate with another network function via the Nsmf.

[0202] 2. Access Management Network Element: It is mainly configured to perform mobility management, access management, etc. The access management network element may be configured to implement legal eavesdropping and access authorization (or authentication) with functions, for example, mobility management entity (MME) functions other than session management. In 5G communication, the access management network element may be an access and mobility management function (AMF) network element. In future communications such as 6G communication, the access management network element may continue to be an AMF network element, or may have another name. This is not limited in this application. Namf is a service-based interface provided by the AMF. The AMF can communicate with another network function via Namf.

[0203] 3. Authentication Service Network Element: It is mainly configured to perform user authentication, etc. In 5G communication, the authentication service network element may be an authentication server function (AUSF) network element. In future communications such as 6G communication, the authentication service network element may continue to be an AUSF network element, or may have another name. This is not limited in this application. Nausf is a service-based interface provided by the AUSF. The AUSF may communicate with another network function via Nausf.

[0204] 4. Network exposure network element: It is configured to securely expose services, capabilities, etc. provided by 3rd generation partnership project (3GPP) network functions to the outside. In 5G communication, the network exposure network element may be a network exposure function (NEF) network element. In future communications such as 6G communication, the network exposure function network element may continue to be an NEF network element or may have another name. This is not limited in this application. Nnef is a service-based interface provided by the NEF. The NEF may communicate with another network function via the Nnef.

[0205] 5. Network Repository Network Element: It is configured to provide service registration, discovery, and authorization and maintain available network function (NF) instance information. These functions help achieve NF interconnection and on-demand network function and service configuration. Service registration means that an NF network element can provide services only after being registered with the network repository network element. Service discovery means that when an NF network element needs another NF network element to provide a service, the NF network element needs to use the network repository network element to perform service discovery to discover the expected NF network element that will provide the service to the NF network element. For example, when NF network element 1 needs NF network element 2 to provide a service to NF network element 1, NF network element 1 needs to use the network repository network element to perform service discovery to discover NF network element 2. Service authorization means that when an NF network element needs another NF network element to provide a service, the NF network element needs to use the network repository network element to obtain authorization information to further obtain the service provided by another NF network element based on the authorization information. For example, before NF network element 1 requests a service from NF network element 2, NF network element 1 first requests authorization information for accessing NF network element 2 from the network repository network element, and NF network element 1 requests a service from NF network element 2 based on the obtained authorization information. In 5G communication, the network repository network element may be a network repository function (NRF) network element.In future communications such as 6G communications, the network repository function network element may continue to be an NRF network element or may have another name. This is not limited in this application. Nnrf is a service-based interface provided by the NRF. The NRF may communicate with another network function via Nnrf.

[0206] 6. Policy control network element: It is configured to guide a unified policy framework for network behavior and provide policy rule information for control plane function network elements (e.g., AMF or SMF). In 5G communications, the policy control network element may be a policy control function (PCF) network element. In future communications such as 6G communications, the policy control function network element may continue to be a NEF network element or may have another name. This is not limited in this application. Npcf is a service-based interface provided by the PCF. The PCF may communicate with another network function via Npcf.

[0207] 7. Data management network element: It is configured to perform user identifier processing, access authentication, registration, mobility management, etc. In 5G communications, the data management network element may be a unified data management (UDM) network element. In future communications such as 6G communications, the data management network element may continue to be a UDM network element or may have another name. This is not limited in this application. Nudm is a service-based interface provided by the UDM. The UDM may communicate with another network function via Nudm.

[0208] 8. Application network element: It is configured to route data affected by an application, access the network exposure function, and interact with the policy framework for policy control, etc. In 5G communication, the application network element may be an application function (AF) network element. In future communications such as 6G communication, the application network element may continue to be an AF network element or may have another name. This is not limited in this application. Naf is a service-based interface provided by the AF. The AF may communicate with another network function via the Naf.

[0209] 9. User equipment (UE): Various handheld devices, in-vehicle devices, wearable devices, or computing devices having a wireless communication function, or another processing device connected to a wireless modem, and various forms of terminals, mobile stations (MS), terminals, user equipment (UE), software terminals, etc., may include, for example, water meters, electricity meters, and sensors.

[0210] 10. Network element of the (radio) access network ((R)AN): It is configured to provide a network access function to authorized user equipment within a specific area and can use transmission tunnels of different qualities based on the user equipment level, service requirements, etc.

[0211] The RAN network element can manage radio resources and provide access services to terminal devices to transfer control signals and user equipment data between the terminal and the core network. The RAN network element may also be understood as a base station in a conventional network.

[0212] 11. User plane function (UPF) network element: It is configured to perform functions such as packet routing and forwarding, and quality of service (QoS) processing for user plane data. In 5G communication, the user plane network element may be a user plane function (UPF) network element. In future communications such as 6G communication, the user plane network element may continue to be a UPF network element or may have another name. This is not limited in this application.

[0213] 12. Data network (DN) network element: It is configured to provide a network for transmitting data, such as the Internet network. The DN network element may be a network element for data network authentication, authorization, and accounting (data network authentication, authorization, accounting), an application server (application function), etc.

[0214] 13. The SCP is configured to route and forward service-oriented interface messages. This can also be understood as the SCP being able to provide routing and forwarding services to the sender of service-oriented interface signaling. For example, when the AMF requests the SMF to establish a session, the AMF sends a session establishment request message to the SCP, the SCP sends the session establishment request message to the SMF, and the SMF determines whether to respond to the session establishment request message. If the SMF sends a session establishment response message to the SCP, the SCP sends the session establishment response message to the AMF. If the SMF sends a session establishment rejection message to the SCP, the SCP sends the session establishment rejection message to the AMF. The messages exchanged between the AMF and the SMF can pass through a one-hop SCP or a multi-hop SCP.

[0215] It can be understood that the functions and network elements described above may be network elements within a hardware device, software functions operating on dedicated hardware, or virtual functions generated as instances on a platform (e.g., a cloud platform). The application scenarios of the embodiments of the present application are not limited thereto, and any network architecture capable of implementing the foregoing network functions is applicable to the embodiments of the present application.

[0216] In the following content, it should be noted that the consumer, service consumer network element, and NF service consumer are network elements of the same type, and the producer, service producer network element, and NF service producer are network elements of the same type. In the following embodiments of this application, it is assumed that the local operator policy indicates that the service request message sent by the NF service consumer to the SCP needs to carry the CCA. For example, the local operator policy may be configured such that the NF service consumer generates the CCA during indirect communication and authenticates the NF service consumer based on the CCA.

[0217] Based on the aforementioned extended service-based architecture, several modes of the indirect communication procedure will be briefly described below.

[0218] 1. Indirect communication without delegated discovery (this is simply referred to as mode C)

[0219] The consumer directly communicates with the NRF to execute the service discovery procedure to select the corresponding service producer network element, and the SCP network element does not need to participate in the service discovery procedure.

[0220] The following will describe mode C with reference to Figure 2.

[0221] Step 201: The consumer sends a producer discovery message to the NRF.

[0222] Step 202: The NRF sends information about the available producers to the consumer.

[0223] In some embodiments, a consumer may select a target producer based on the obtained information about available producers. The information about available producers may include an NF set Id, a specific NF instance identifier, etc. Specifically, the target producer may be any NF instance corresponding to the NF set Id (i.e., any producer within the producer set), a specific NF instance within the NF instance corresponding to the specific NF set Id (i.e., a specific producer), or a specific NF instance (i.e., a specific producer).

[0224] In some embodiments, the SCP may be responsible for the selection of the target producer. For details, see step 204 below.

[0225] Step 203: The consumer sends a service request message to the SCP to request a specific service from the target producer via the SCP.

[0226] Step 204: The SCP interacts with the NRF to obtain parameters for selecting the target producer.

[0227] For example, the parameters obtained by the SCP may include, but are not limited to, the location, capacity, etc. of the NF instance.

[0228] Note that step 204 is an optional step. For example, the service request message contains information about available producers. For example, the information about available producers includes the NF set Id, in other words, the information about available producers refers to a group of NF instances. The SCP needs to select an NF instance from the group of NF instances as the target producer. Specifically, the SCP may select the target producer based on the parameters obtained from the NRF. For example, the SCP may determine the target producer from the group of NF instances based on the obtained location of the NF instance.

[0229] Step 205: The SCP sends a service request message to the target producer to request a specific service from the target producer.

[0230] Step 206: The target producer sends a service request response message for providing the specific service to the SCP.

[0231] Step 207: The SCP sends the service request response message for providing the specific service to the consumer.

[0232] 2. Indirect communication with delegated discovery (this is simply called mode D)

[0233] The consumer does not communicate directly with the NRF. The SCP network element functions as a proxy for the consumer to communicate with the NRF in order to execute a service discovery procedure to select the corresponding service producer network element.

[0234] Hereinafter, mode D will be described with reference to FIG. 3.

[0235] Step 301: The consumer sends a service request message to the SCP to request a specific service from the target producer via the SCP.

[0236] The service request message includes parameters used for discovery and selection of the target producer.

[0237] Step 302: The SCP interacts with the NRF to obtain information about available producers.

[0238] The SCP can obtain information about available producers based on the parameters within the service request message in Step 301, which are used for discovery and selection of the target producer, and determine the target producer from the information about available producers.

[0239] Step 303: The SCP sends the service request message to the target producer to request a specific service from the target producer.

[0240] Step 304: The target producer sends a service request response message to the SCP to provide a specific service.

[0241] Step 305: The SCP sends the service request response message for providing a specific service to the consumer.

[0242] Note that in the embodiments of the present application, the service request message received by the SCP from the consumer and the service request message sent by the SCP to the target producer may be the same or different. For example, the SCP may modify the service request message received from the consumer (e.g., add, delete, or modify some information) to generate and send a service request message to the target producer. Similarly, the service request response message received by the SCP from the target producer and the service request response message sent by the SCP to the consumer may be the same or different. For example, the SCP may modify the service request response message received from the target producer to generate a service request response message sent to the consumer.

[0243] Furthermore, in the indirect communication procedures shown in FIGS. 2 and 3, when the consumer communicates with the producer via the SCP, the producer needs to further authenticate the consumer who initiates the service request. Similarly, when the consumer communicates with the NRF via the SCP, the NRF also needs to authenticate the consumer who initiates the service request.

[0244] Regarding the authentication requirements in the above-mentioned indirect communication scenario, the verification information in the embodiments of the present application will be described below.

[0245] 1. Client Credentials Assertion (CCA)

[0246] For example, the CCA may be a token signed by a peer and used by the authenticator to authenticate / verify the peer, i.e., to determine the identity of the peer.

[0247] For example, the CCA is a token signed by the NF service consumer. The CCA is included in the message so that the recipient of the message (i.e., the authenticator, e.g., the NRF or NF service producer) can authenticate the NF service consumer. For example, the CCA may be included in the message header or message body of a hypertext transfer protocol (HTTP) message.

[0248] The CCA may include three parts: a message header (head), a payload, and a signature.

[0249] The payload includes claims. For example, the claims include the NF instance ID of the NF service consumer, a timestamp, an expiration date, and the NF type of the expected audience. The timestamp indicates the release time of the CCA, and the expiration date indicates that the CCA is considered expired after that time. The NF type of the expected audience is the NF type of the network element that authenticates the NF service consumer.

[0250] The message header and payload are signed by the NF service consumer based on the private key of the NF service consumer certificate. The message header includes certificate information, i.e., related information of the NF service consumer certificate. For example, the certificate information includes a certificate or certificate chain placed in the public key, or the certificate information includes a uniform resource locator (URL) of the certificate or certificate chain placed in the public key.

[0251] When the authenticator (e.g., the NRF or NF service producer) receives a message containing the CCA, the authenticator authenticates the NF service consumer based on the CCA. The authentication process is as follows:

[0252] The signature of the CCA is verified. If the signature verification is successful, whether the CCA has expired is verified based on the time stamp and / or expiration date of the CCA. If the CCA has not expired, the authenticator further verifies whether the NF type of the expected audience matches the NF type of the authenticator. If the NF type of the expected audience matches the NF type of the authenticator, the authenticator verifies whether the NF instance ID of the NF service consumer in the CCA matches the NF instance ID in the certificate used to sign the CCA. If the NF instance ID of the NF service consumer matches the NF instance ID in the certificate, all verifications are successful, and the authenticator determines that the authentication of the NF service consumer is successful. It should be noted that the above verification order is not limited in this application.

[0253] When the authenticator verifies whether the NF type of the expected audience matches the NF type of the authenticator, it may include, for example, the authenticator determining whether the NF type of the expected audience is the same as the NF type of the authenticator. For example, if the NF type of the expected audience is AMF, the authenticator verifies whether the NF type of the authenticator is AMF. The step of verifying whether the NF instance ID of the NF service consumer in the CCA matches the NF instance ID in the certificate used to sign the CCA may include, for example, the step of determining whether the NF instance ID of the NF service consumer in the CCA is the same as the NF instance ID in the certificate used to sign the CCA.

[0254] It should be understood that the above authentication process is merely an example, and the authenticator may further verify the CCA in a different order. This is not limited in this application.

[0255] 2. Access token

[0256] An access token represents / shows that the consumer has the permission to obtain the service. The producer provides the service corresponding to the consumer only when the verification of the access token is successful.

[0257] For example, the NRF receives an access token request message from an NF service consumer or an SCP, the NRF performs an authorization check and determines that the authorization is successful. In this case, the NRF generates an access token containing claims.

[0258] There are two types of access tokens, namely, the access token based on the NF type of the NF service producer (simply called type A) and the access token based on the NF service producer instance or the NF service producer service instance (simply called type B).

[0259] An instance is defined based on a function. The instance may be an NF service consumer instance or an NF service producer instance. An instance is defined based on a service. An instance is sometimes called a service instance. For example, the service instance may be a service instance that provides service A or a service instance that provides service B.

[0260] When an NF service consumer requests an access token of type A, the requested access token indicates that the NF service consumer has permission to access any NF service producer corresponding to the NF type in order to obtain the service, or the requested access token indicates that the NF service consumer has permission to access the service of any NF service producer corresponding to the NF type. The access token request message includes the NF instance ID of the NF service consumer, the expected service name, the NF type of the NF service consumer, and the NF type of the expected NF service producer. Optionally, the access token request message may further include a single network slice selection assistance information (S-NSSAI) list or a network slice instance identifier (NSI ID) list of the expected NF service producer instance, the NF set Id of the expected NF service producer instance, the S-NSSAI list of the NF service consumer, etc.

[0261] Correspondingly, the claims in the access token generated by the NRF include the NF instance ID of the NRF, the NF instance ID of the NF service consumer, the NF type of the NF service producer, the expected service name, and the validity period of the access token. Optionally, the claims may further include additional scopes (e.g., the requested resources and the requested operations on the resources), the S-NSSAI list or NSI ID list of the expected NF service producer instance, and the NF set Id of the expected NF service producer instance.

[0262] When an NF service consumer requests a type B access token, the requested access token is used to permit access to a specific NF service producer instance or NF service producer service instance to obtain a service. The access token request message includes the NF instance ID of the NF service consumer, the expected service name, and the requested NF service producer instance ID.

[0263] Correspondingly, the claims within the access token generated by the NRF include the NF instance ID of the NRF, the NF instance ID of the NF service consumer, the NF instance ID(s) of the NF service producer, the expected service name, and the validity period of the access token. Optionally, the claims may further include additional scopes (e.g., the requested resources and the requested operations on the resources).

[0264] In addition, generally, the validity period of the CCA is shorter than that of the access token.

[0265] Furthermore, after the NRF generates the access token, the NRF performs integrity protection on the access token, for example, performs integrity protection on the claims based on a key shared with the NF service producer, for example, generates a message authentication code (MAC), or signs the claims based on the private key of the NRF certificate.

[0266] When a producer (e.g., an NF service producer) receives a service request message containing an access token, the producer performs integrity verification, for example, verifying the MAC of the access token based on a key shared with the NRF or verifying the signature of the access token based on the public key of the NRF certificate. If the integrity verification is successful, the claims within the access token are further verified.

[0267] Regarding the claims within an access token of type A, the producer specifically verifies the following:

[0268] (1) The producer verifies whether the NF type of the requested NF service producer within the claims matches the producer's NF type.

[0269] (2) If the claims include a list of S-NSSAIs or a list of NSI IDs of the expected NF service producer instance, the producer verifies whether it can provide the corresponding slice.

[0270] (3) If the claims include the NF set Id of the expected NF service producer instance, the producer verifies whether the NF set Id within the claims matches the producer's NF set Id.

[0271] (4) If the claims include the expected service name, the producer verifies whether the service operation requested by the service request message is matched.

[0272] (5) If the claims include additional scope information, the producer verifies whether the additional scope information matches the service operation requested by the service request message.

[0273] (6) The producer verifies the validity period in the access token based on the current data / time to check whether the access token has expired or the producer verifies the validity period in the access token based on the current data / time to check whether the access token is within the validity period.

[0274] Regarding the claims in the access token of type B, the producer specifically verifies the following.

[0275] (1) The producer verifies whether the requested NF service producer's NF instance ID(s) in the claims contain the producer's ID.

[0276] (2) If the claims contain the expected service name, the producer verifies whether the service operation requested by the service request message matches.

[0277] (3) If the claims contain additional scope information, the producer verifies whether the additional scope information matches the service operation requested by the service request message.

[0278] (4) The producer verifies the validity period in the access token based on the current data / time to check whether the access token has expired or the producer verifies the validity period in the access token based on the current data / time to check whether the access token is within the validity period.

[0279] Below, with reference to the aforementioned CCA and access token verification processes, the indirect communication scenario is further described.

[0280] Scenario 1: Indirect procedure without delegation discovery (mode C)

[0281] The NF service consumer interacts directly with the NRF, as shown in Figure 4.

[0282] Step 401: The NF service consumer determines that there is no information about available NF service producers, and the NF service consumer starts the NF service producer discovery procedure.

[0283] The discovery procedure is used to discover available NF service producers.

[0284] For example, if a type B access token is required in steps 402 and 403, the discovery procedure needs to be started before step 402, and the identifier of a specific NF service producer instance or the identifier of the NF service producer service instance needs to be determined.

[0285] For example, if a type A access token is required in steps 402 and 403, the NF service producer discovery procedure may be started before steps 402 and 403 (i.e., step 401), or the NF service producer discovery procedure may be started after steps 402 and 403 (i.e., step 404).

[0286] It should be understood that the NF service consumer needs to start only one NF service producer discovery procedure.

[0287] Step 402: The NF service consumer sends an access token request message (e.g., Nnrf_AccessToken_Get_Request) to the NRF. From the above content, it can be found that there are two types of access tokens. For different types of access tokens, the specific content included in the access token request message is different. For details, please refer to the above related description of the access token.

[0288] Step 403: The NRF sends an access token response message (e.g., Nnrf_AccessToken_Get_Response) to the NF service consumer, and the access token response message includes the access token generated by the NRF.

[0289] Specifically, the NRF receives an access token request message from the NF service consumer, and the NRF performs an authorization check. Specifically, it verifies whether the NF service consumer is permitted to obtain the requested service. If the authorization is successful, the NRF generates an access token and performs integrity protection on the access token.

[0290] Step 404: The NF service consumer determines that there is no information about the available producer (i.e., Step 401 is not executed), and the NF service consumer starts the producer discovery procedure.

[0291] Step 404 is an optional step, and only one of Step 401 and Step 404 may be executed.

[0292] Step 405: The NF service consumer sends a service request message (e.g., Service Request) to the SCP, and the service request message includes the access token and the CCA.

[0293] CCA is used by the NF service producer to authenticate the NF service consumer. Specifically, the claims in the CCA include the NF instance ID, timestamp, expiration date, and NF type of the expected audience of the NF service consumer. According to the definition of CCA, when the recipient of the service request message is the NF service producer, the NF type of the expected audience is the NF type of the NF service producer. For CCA, please refer to the relevant content mentioned above. Details are not repeated in this specification.

[0294] For example, when the AMF requests the SMF to establish a session via the SCP, the AMF sends a session establishment request message to the SCP, and the session establishment request message includes an access token and CCA. In this case, the CCA includes the NF instance ID, timestamp, and expiration date of the AMF, and the NF type of the expected audience is the SMF.

[0295] Step 406: The SCP sends the service request message to the NF service producer.

[0296] For example, the SCP executes a change to the Application Programming Interface (API) and sends the received service request message to the NF service producer.

[0297] If the service request message contains the identifier of a specific NF service producer instance or the identifier of an NF service producer service instance, the SCP shall send the service request message to the specific NF service producer instance or NF service producer service instance. If the service request message contains an NF set Id, the SCP may select NF instances from the specific NF service producer instance and NF service producer service instances and send the service request message to the NF instances.

[0298] Step 407: The NF service producer receives the service request message from the SCP. The NF service producer verifies the CCA and the access token.

[0299] The NF service producer performs an integrity verification on the access token. If the integrity verification is successful, the NF service producer further verifies the claims within the access token. For details, please refer to the relevant content of the verification regarding the claims within the access token. The NF service producer shall further verify the NF service consumer based on the CCA. For the specific process of verifying the CCA, please refer to the aforementioned relevant description of CCA verification.

[0300] Step 408: If the NF service producer determines that the verification of the access token and CCA is successful, the NF service producer shall send a service response message (e.g., Service Response) to the SCP.

[0301] Step 409: The SCP sends the service response message to the NF service consumer.

[0302] For example, the SCP receives a service response message from the NF service producer, executes API modifications, and sends the service response message to the NF service consumer.

[0303] Scenario 2: Indirect procedure without delegation discovery (Mode C): As shown in Figure 5, the NF service consumer interacts with the NRF via the SCP.

[0304] Step 501: The NF service consumer determines that there is no information about available NF service producers, and the NF service consumer starts the NF service producer discovery procedure.

[0305] The discovery procedure is used to discover available NF service producers.

[0306] For example, if a type B access token is required in steps 502 and 503, the discovery procedure needs to be started before step 502, and the identifier of a specific NF service producer instance or the identifier of the NF service producer service instance needs to be determined.

[0307] For example, if a type A access token is required in steps 502 and 503, the NF service producer discovery procedure may be started before steps 502 and 503 (i.e., step 501), or the NF service producer discovery procedure may be started after steps 502 and 503 (i.e., step 504).

[0308] It should be understood that the NF service producer only needs to start one discovery procedure.

[0309] Step 502: The NF service consumer sends an access token request message to the SCP.

[0310] The specific parameters included in the access token request message can be determined based on the type of the requested access token. For details, please refer to the relevant description of the access token. In addition, the access token request message may further include CCA*, which is used by the NRF to authenticate the NF service consumer. Specifically, the claims in CCA* include the NF instance ID, timestamp, expiration date, and NF type of the expected audience of the NF service consumer. According to the definition of CCA, when the recipient of the access token request message is the NF service producer, the NF type of the expected audience is the NFR.

[0311] Step 503: The SCP sends the access token request message received in step 50 2 to the NRF.

[0312] Step 504: The NRF determines that the verification of CCA* is successful and generates an access token.

[0313] Specifically, the NRF authenticates the NF service consumer based on CCA*. If the authentication is successful, the NRF further performs an authorization check. If the authorization is successful, the NRF generates an access token and performs integrity protection on the access token.

[0314] Step 505: The NRF sends an access token response message to the SCP, and the access token response message includes the access token generated by the NRF.

[0315] Step 506: The SCP sends an access token response message to the NF service consumer, and the access token response message contains the access token generated by the NRF.

[0316] For the specific content from Step 507 to Step 511, please refer to Steps 505 to 509 of the embodiment shown in FIG. 5.

[0317] Scenario 3: Communication Permission in the Delegated Discovery Procedure (Mode D): As shown in FIG. 6, the NF service consumer interacts with the NRF via the SCP.

[0318] Step 601: The NF service consumer sends a service request message to the SCP. The service request message contains the CCA and the access token. The CCA and the access token are not expired. The claims in the CCA include the NF instance ID, timestamp, expiration date, and NF type of the expected audience of the NF service consumer. According to the definition of the CCA, when the recipient of the service request message is the NF service producer, the NF type of the expected audience is the NF type of the NF service producer.

[0319] Step 602: The SCP sends the service request message to the NF service producer, and the service request message contains the CCA and the access token.

[0320] For the specific content from Step 603 to Step 605, please refer to Steps 509 to 511 of the embodiment shown in FIG. 5.

[0321] Scenario 4: Communication Permission in the Delegated Discovery Procedure (Mode D): As shown in FIG. 7, the NF service consumer interacts with the NRF via the SCP.

[0322] Step 701: The NF service consumer sends a service request message to the SCP. The service request message contains a CCA. The claims in the CCA include the NF instance ID, timestamp, expiration date, and NF type of the expected audience of the NF service consumer. If the recipient of the service request message is the NF service producer, the NF type of the expected audience is the NF type of the NF service producer.

[0323] Step 702: The SCP sends an access token request message to the NRF.

[0324] For example, the SCP may determine whether to initiate the access token request procedure to the NRF based on the service request message. For example, if the received service request message does not contain an access token and the SCP determines that the access token corresponding to the service request message does not exist locally, the SCP sends an access token request message to the NRF.

[0325] The access token request message contains the CCA in Step 701.

[0326] Step 703: The NRF determines that the CCA verification has failed.

[0327] The NF type of the expected audience in the CCA is the NF type of the NF service producer. Since the NF type in the CCA does not match the NF type of the NRF, the NRF determines that the CCA verification has failed.

[0328] Step 704: The NRF sends an access token response message to the SCP. The access token response message does not contain an access token.

[0329] Therefore, the SCP fails to obtain the access token. As a result, the NF service consumer fails to request a service from the NF service producer.

[0330] In the indirect communication scenario based on mode D, in the embodiments of the present application, when the NF service consumer directly sends a service request message to the SCP to trigger the SCP to request another service, since the recipient of the service request (the producer of another service) cannot authenticate the NF service consumer, the SCP cannot request another service, and as a result, the NF service consumer cannot request a service. To solve this problem, the following embodiments are provided.

[0331] First, the technical concept in the embodiments of the present application will be described below.

[0332] 1. The embodiments of the present application relate to at least two network function types. The first network function type is different from the second network function type. A network function type is a general name of a network function that provides a group of functional behaviors or a group of services in a network. For example, the network function types in a 5G network may include an AMF type, an SMF type, etc. A functional network element of the AMF type may provide services related to access and mobility management, and a functional network element of the SMF type may provide services related to PDU session management.

[0333] 2. The embodiments of the present application further relate to at least two services. The first service is different from the second service, and the first service is associated with the second service.

[0334] For example, the first service may be a request for session establishment, and the second service may be a request for an access token corresponding to the first service. Alternatively, the first service may be a request for session establishment, and the second service may be a request for information regarding a network element that provides the first service.

[0335] For example, in an indirect communication scenario based on mode D, when the AMF requests the SMF to establish a session, the AMF sends a session establishment request message to the SCP. Before the SCP sends a session establishment request to the SMF, if the SCP needs to first obtain an access token (hereinafter referred to as access token1) corresponding to the session establishment request from the NRF, after the SCP obtains access token1 from the NRF, the SCP sends a session establishment request message to the SMF. In this case, the session establishment request message includes access token1. The first service in this specification is a request for session establishment, the second service is a request for an access token corresponding to the first service, and the SCP requests an access token corresponding to the first service from the NRF before the SCP sends a session establishment request message to the SMF, that is, the SCP requests the second service before requesting the first service. In addition, in some scenarios, the SCP may request the second service after requesting the first service. This is not limited in the embodiments of this application. Unless otherwise specified, hereinafter, only an example where the SCP requests the second service before requesting the first service is used for explanation.

[0336] The association between the first service and the second service may be, for example, that requesting the first service may trigger requesting the second service.

[0337] For example, the second service is used to provide an access token corresponding to the first service, and the access token corresponding to the first service indicates that the service consumer network element has permission to obtain the first service. Since the service consumer network element requests the first service and the access token corresponding to the first service provided by the second service indicates that the service consumer network element has permission to obtain the first service, the first service is associated with the second service. For example, an NF service consumer requesting the first service may trigger the SCP to request an access token corresponding to the first service. The access token corresponding to the first service indicates that the NF service consumer has permission to obtain the first service or permission to access the first service.

[0338] In another example, the second service is used to provide information about the service producer network element. Since the service consumer network element requests the first service and the service producer network element indicated by the information about the service producer network element provided by the second service may provide the first service, the first service is associated with the second service. For example, an NF service consumer requesting the first service may trigger the SCP to request information about the NF service producer. The NF service producer provides the first service to the NF service consumer.

[0339] In addition, the request for the first service may further trigger the request for multiple second services. For example, an NF service consumer's request for the first service may trigger the SCP to request information about the NF service producer and trigger the SCP to request an access token corresponding to the first service. The NF service producer provides the first service to the NF service consumer, and the access token corresponding to the first service indicates that the service consumer network element has permission to obtain the first service. Specifically, the SCP may request an access token corresponding to the first service from NRF1 and request information about the NF service producer from NRF1. In this case, NRF1 provides two second services. Alternatively, the SCP may request an access token corresponding to the first service from NRF1 and request information about the NF service producer from NRF2. In this case, NRF1 is different from NRF2, and the second service provided by NRF1 is different from the second service provided by NRF2.

[0340] It should be understood that the first service and the second service are merely examples and are not intended to limit the embodiments of the present application.

[0341] In the following, for the sake of explanation, only an example where the network element providing the second service is a network repository function network element is used. Alternatively, the network element providing the second service may be another type of network element. This is not limited in the embodiments of the present application.

[0342] One embodiment of the present application provides a communication method. A service consumer network element transmits a service request message to a service communication proxy, the service request message includes a first client credential assertion, and the first client credential assertion may include at least two different network function types, so that different network elements can authenticate the service consumer network element based on the first client credential assertion. Hereinafter, the embodiment shown in FIG. 8 is used as an example for explanation.

[0343] Step 801: The service consumer network element transmits a first service request message to the service communication proxy. The first service request message is used to request a first service from the service producer network element, and the first service request message includes a first client credential assertion.

[0344] The first client credential assertion is used to authenticate the service consumer network element. The first client credential assertion includes a first network function type and a second network function type. The first network function type is the network function type of the network element that provides the first service, that is, the network function type of the service producer network element. The second network function type is the network function type of the network element that provides the second service. The second service is associated with the first service. The network function type of the network element that provides the second service may be the network function type of the network repository function network element.

[0345] Compared with existing CCAs, the first client eligibility information assertion includes two network function types. Thus, an existing CCA is only used by the recipient of a service request to authenticate a service consumer network element, i.e., to authenticate the identity of the service consumer network element. In this embodiment of the present application, the first client eligibility information assertion may be used by network elements of two network function types to authenticate a service consumer network element. Specifically, the recipient of the service request and the recipient of the request message triggered by the service request authenticate the identity of the service consumer network element. In addition, the first client eligibility information assertion further includes one or more of an identifier of the service consumer network element and validity time information of the first client eligibility information assertion. The validity time information of the first client eligibility information assertion indicates the validity time of the first client eligibility information assertion. For example, the validity time information of the first client eligibility information assertion may include a timestamp and an expiration date of the first client eligibility information assertion. The content has the same meaning as the corresponding concept in the existing CCA and will not be described in detail again herein. For example, if the timestamp indicates moment A and the expiration date indicates moment B, the first client eligibility information assertion is valid within the period determined between moment A and moment B. Alternatively, the validity time information of the first client eligibility information assertion may include a timestamp and a duration of validity of the first client eligibility information assertion. The timestamp herein has the same meaning as the corresponding concept in the existing CCA, and the duration of validity may be the period after the timestamp. For example, if the timestamp indicates moment A and the duration of validity indicates period C (e.g., 5 minutes), the first client eligibility information assertion is valid within period C after moment A.

[0346] The validity time information of the first client eligibility information assertion is associated with a first duration, and the first duration is determined based on the transmission delay between the service consumer network element and the service communication proxy, the transmission delay between the service communication proxy and the network element providing the second service, and the transmission delay between the service communication proxy and the service producer network element (i.e., the network element providing the first service).

[0347] For example, the transmission delay between the service consumer network element and the service communication proxy is represented as T1, the transmission delay between the service communication proxy and the network element providing the second service is represented as T2, and the transmission delay between the service communication proxy and the service producer network element is represented as T3. The aforementioned transmission delays may be the average value of the transmission delays between two network elements, or may be slightly larger than the average value of the transmission delays. When the service communication proxy requests the second service earlier than the first service, the first duration = T1 + 2T2 + T3. In this case, the effective duration of the first client eligibility information assertion may be the sum of the first duration and the preset duration. Alternatively, the expiration date of the first client eligibility information assertion may be determined based on the timestamp, the first duration, and the preset duration. The preset duration in this specification may be preset or determined by dynamic adjustment. It should be noted that if the preset duration is set to an excessively long duration, the validity time of the CCA may become excessively long, and the CCA may be used repeatedly.

[0348] The aforementioned configuration rules for the validity time information of the first client eligibility information assertion can ensure as much as possible that the first client eligibility information assertion is not maliciously used by the service communication proxy in order to guarantee the security of the communication process.

[0349] Before the service consumer network element sends a first service request message to the service communication proxy, the service consumer network element needs to further determine whether an available first client credential information assertion is locally stored. If an available client credential information assertion is stored (for example, a client credential information assertion with an unexpired expiration date is stored), it will be understood that the client credential information assertion with an unexpired expiration date is used as the first client credential information assertion. If no available client credential information assertion is stored (for example, the client credential information assertion has expired or no client credential information assertion is stored), the service consumer network element generates a first client credential information assertion. In addition, when there is an expired client credential information assertion, the service consumer network element may delete the expired client credential information assertion. Therefore, the service consumer network element can delete the expired client credential information assertion to free up storage space and reduce the memory load of the system.

[0350] The following describes several possible scenarios in which the service consumer network element is triggered to send a first service request message to the service communication proxy.

[0351] Scenario 1: When a first service needs to be requested and there is no available access token corresponding to the first service, the service consumer network element sends a first service request message to the service communication proxy.

[0352] For example, when a service consumer network element determines that a first service needs to be requested and there is no available access token corresponding to the first service, the service consumer network element sends a first service request message to the service communication proxy.

[0353] In some embodiments, the service consumer network element determining that there is no available access token corresponding to the first service includes the service consumer network element determining that no access token corresponding to the first service is stored, or the service consumer network element determining that the stored access token corresponding to the first service has expired. Further, when the stored access token corresponding to the first service expires, the service consumer network element may delete the expired access token corresponding to the first service.

[0354] For example, the access token can be stored in the public memory space of the NF service consumer (for example, the access token is stored in the node-level context). The NF service consumer can receive the service request message of the UE and determine, based on the service request message, that the first service needs to be requested. The NF service consumer obtains the relevant information of the UE (for example, the context information of the UE) based on the identifier of the UE. Further, the NF service consumer checks whether the public memory space contains the access token corresponding to the first service. If the access token corresponding to the first service is included and the access token is not expired, the access token is used. If the access token corresponding to the first service is not included, it is determined that there is no available access token. Alternatively, if the access token corresponding to the first service is included but the access token is expired, it is determined that there is no available access token. Further, optionally, the NF service consumer deletes the access token. The relevant information of the UE may be stored in the public memory space of the NF service consumer, or the relevant information of the UE may be obtained by the NF service consumer from another network element based on the identifier of the UE.

[0355] It will be understood that when the service consumer network element determines that there is an available access token corresponding to the first service, the first service request message transmitted by the service consumer network element to the service communication proxy may not include the second network function type and may only include the first network function type.

[0356] Scenario 2: When the first service needs to be requested and the request for the first service triggers the service communication proxy to request information about the service producer network element, the service consumer network element sends a first service request message to the service communication proxy.

[0357] For example, when the service consumer network element determines that the first service needs to be requested and the request for the first service triggers the service communication proxy to request information about the service producer network element, the service consumer network element sends a first service request message to the service communication proxy.

[0358] When one or more of the following cases occur, the service consumer network element may determine that the request for the first service triggers the service communication proxy to request information about the service producer network element. For example, the service consumer network element receives a first message associated with the first terminal device, and based on the first message, the service consumer network element determines that the first service needs to be requested. Further, the service consumer network element determines that the request for the first service triggers the service communication proxy to request information about the service producer network element based on one or more of the following cases.

[0359] Case 1: The context of the first terminal device is not stored.

[0360] For example, the NF service consumer may receive the service request message of the UE and determine, based on the service request message, that the first service needs to be requested. The NF service consumer acquires the UE's context information based on the UE's identifier. If the UE's context information has not been acquired, that is, if the UE is a new UE and the NF service consumer has not been triggered to request a service from the NF service producer, the NF service consumer determines to trigger the SCP such that the request for the first service requests information about the NF service producer. The UE's context information may be stored in the NF service consumer, or the UE's context information may be acquired by the NF service consumer from another network element based on the UE's identifier.

[0361] Case 2: The context of the first service is not stored.

[0362] For example, the NF service consumer may receive the service request message of the UE and determine, based on the service request message, that the first service needs to be requested. The NF service consumer acquires the UE's context information based on the UE's identifier. Based on the UE's context information, if it is determined that the context of the first service is not included, that is, the NF service consumer has not been triggered to request the first service from the NF service producer, the NF service consumer determines to trigger the SCP such that the request for the first service requests information about the NF service producer. The UE's context information may be stored in the NF service consumer, or the UE's context information may be acquired by the NF service consumer from another network element based on the UE's identifier.

[0363] Case 3: The first slice belongs to the service producer network element, and the context of the first slice is not stored.

[0364] For example, the NF service consumer may receive the UE's service request message and, based on the service request message, determine that the first service needs to be requested and that the first service needs to be requested from the service producer network element within the first slice. The NF service consumer obtains the UE's context information based on the UE's identifier. Based on the UE's context information, if it is determined that the context of the first slice is not included, that is, the NF service consumer has not been triggered to request the first service from the NF service producer in the first slice, the NF service consumer determines to trigger the SCP so that the request for the first service requests information about the NF service producer. The UE's context information may be stored in the NF service consumer, or the UE's context information may be obtained by the NF service consumer from another network element based on the UE's identifier.

[0365] Case 4: The service consumer network element communicates with the service communication proxy for the first time.

[0366] It should be understood that the service consumer network element may request a service from the service producer network element via multiple service communication proxies. When the service consumer network element determines to send a first service request message to a new service communication proxy, that is, when the service consumer network element communicates with the service communication proxy for the first time, the service consumer network element determines to trigger the service communication proxy so that the first service request message requests a second service.

[0367] In addition, the NF service consumer receives a service request response message, which contains a binding instruction that is used in subsequent related service messages. In this scenario, when the NF service consumer requests a first service, the first service request message carries binding information that can be used by the SCP to route the first service request message to a specific NF service producer. In this case, the SCP does not need to initiate the NF service producer discovery procedure.

[0368] Scenario 3: When a first service needs to be requested and the service consumer network element communicates with the service communication proxy in the indirect communication mode, i.e., mode D, the service consumer network element sends a first service request message to the service communication proxy.

[0369] For example, when the service consumer network element communicates with the service communication proxy in mode D, it may be agreed upon in the standard protocol or configured based on pre-configuration information that the first service request message always carries a client eligibility information assertion including a first network function type and a second network function type.

[0370] Scenario 4: Before the service consumer network element sends a first service request message to the service communication proxy, the service consumer network element obtains instruction information and then sends the first service request message to the service communication proxy based on the instruction information.

[0371] As shown in Figure 9, the following describes the specific process in which the service consumer network element sends a first service request message to the service communication proxy based on the instruction information of Scenario 4 in Step 801 of Figure 8.

[0372] Step 901: Before the service consumer network element sends a first service request message to the service communication proxy, the service consumer network element sends a second service request message to the service communication proxy. The second service request message is used to request the first service. The second service request message includes a second client credential information assertion. The second client credential information assertion includes a first network function type. The second client credential information assertion is used by the service producer network element to authenticate the service consumer network element.

[0373] Note that in this case, the second client credential information assertion does not include a second network function type.

[0374] Step 902: The service communication proxy sends a third service request message to the network repository function network element. The third service request message is used to request the second service. The third service request message includes the second client credential information assertion. The network repository function network element is configured to provide the second service.

[0375] The service communication proxy's determination that a request for a first service triggers a request for a second service may include, but is not limited to, the following scenarios:

[0376] Scenario A: When there is no available access token stored for the first service and the second service request message does not include an access token for the first service, the service communication proxy sends a third service request message to the network repository function network element, and the third service request message is used to request an access token for the first service. The service communication proxy determines that there is no available access token stored for the first service and the second service request message does not include an access token for the first service, and the service communication proxy sends the third service request message to the network repository function network element.

[0377] For example, the service communication proxy may determine that an access token for the first service is required based on the received second service request message. For example, the service communication proxy may determine that an access token for the first service is required based on the type of the service request message or the access scope of the service request. Further, the service communication proxy queries whether an access token for the first service is stored. If there is no access token stored for the first service, or the stored access token for the first service has expired and the second service request message does not include an access token, the parameters required to request an access token for the first service, that is, the claim parameters, for example, the expected service name of the consumer or the NF instance ID, may be determined based on the type of the service request message. In addition, when the stored access token for the first service expires, the service communication proxy may delete the expired access token.

[0378] Scenario B: When information about available service producer network elements is not stored and the second service request message does not contain information about service producer network elements, the service communication proxy sends a third service request message to the network repository function network element, and the third service request message is used to request information about service producer network elements. The service communication proxy determines that information about available service producer network elements is not stored and the second service request message does not contain information about service producer network elements, and sends the third service request message to the network repository function network element. For example, the service communication proxy may be determined based on the type of the second service request message and / or the indication information in the second service request message.

[0379] After the service communication proxy receives the second service request message, the service communication proxy analyzes the second service request message to determine who the recipient of the message is and whether it is necessary to discover the recipient of the message (i.e., the service producer network element). The service communication proxy's determination of whether it is necessary to discover the service producer network element is logically similar to the direct communication service consumer network element's determination of whether it is necessary to discover the service producer. For example, if the request message received by the SCP is a session establishment request, the SCP determines that the message needs to be forwarded to the SMF, and the SCP determines whether condition - meeting SMF instance information exists locally based on the parameters in the message.

[0380] Step 903: The network repository function network element determines that the authentication of the service consumer network element has failed based on the second client eligibility information assertion.

[0381] For example, when a network repository function network element determines that authentication of a service consumer network element has failed based on a second client entitlement information assertion, it includes the network repository function network element determining that a first network function type does not match the network function type of the network repository function network element.

[0382] Alternatively, when a network repository function network element determines that authentication of a service consumer network element has failed based on a second client entitlement information assertion, it includes the network repository function network element verifying that the signature of the second client entitlement information assertion has succeeded, verifying that the second client entitlement information assertion is not expired based on the timestamp included in the second client entitlement information assertion and / or the expiration date of the second client entitlement information assertion, verifying that the identifier of the service consumer network element within the second client entitlement information assertion is the same as the identifier of the network element within the certificate for signing the second client entitlement information assertion, and verifying that a first network function type does not match the network function type of the network repository function network element.

[0383] Step 904: When the first network function type does not match the network function type of the network repository function network element, the network repository function network element transmits a response message for the third service request message to the service communication proxy. The response message for the third service request message includes a cause value and / or first indication information.

[0384] The cause value and / or the first indication information indicates that the second client eligibility information assertion does not include the second network function type, that the first network function type included in the second client eligibility information assertion does not match the network function type of the network repository function network element, or that the second client eligibility information assertion does not include the correct network function type.

[0385] Optionally, the first indication information may be a third client eligibility information assertion. The third client eligibility information assertion includes an identifier of the network repository function network element, a timestamp of the third client eligibility information assertion, an expiration date of the third client eligibility information assertion, and a network function type of the service consumer network element. Optionally, the third client eligibility information assertion may further include the network function type of the network repository function network element to indicate to the service consumer network element to generate a client eligibility information assertion that includes the network function type of the network repository function network element.

[0386] It can be found from step 903 that the network repository function network element fails to authenticate the service consumer network element, and the response message to the third service request message may further indicate that the second service request has failed.

[0387] Step 905: The service communication proxy sends a response message to the second service request message to the service consumer network element based on the response message to the third service request message, and the response message to the second service request message includes the second indication information.

[0388] The second instruction information is used to trigger a service consumer network element in step 801 of the embodiment of FIG. 8 to send a first service request message (i.e., a service request message that carries both the network function type of the service producer network element and the network function type of the network repository function network element).

[0389] In one possible embodiment, the second instruction information indicates that the second client eligibility information assertion does not include the network function type of the network repository function network element (i.e., the second network function type), that the first network function type included in the second client eligibility information assertion does not match the network function type of the network repository function network element, or that the second client eligibility information assertion does not include the correct network function type.

[0390] In a particular embodiment, the second instruction information may be the same as the first instruction information or may be information obtained by processing the first instruction information by the service communication proxy. This is not limited in the embodiments of this application.

[0391] In some embodiments, the service communication proxy may further generate the second instruction information based on a response message to the third service request message. The second instruction information can be used to trigger the service consumer network element to restart a service request message for requesting the first service, and when the first service is requested again, it can be used to carry a client eligibility information assertion including the network function type of the network repository function network element and the network function type of the service producer network element (i.e., to execute step 801).

[0392] Step 906: The service consumer network element sends a first service request message to the service communication proxy based on the second instruction information.

[0393] In some embodiments, when the second instruction information includes a third client eligibility information assertion and the third client eligibility information assertion includes the network function type of the network repository function network element, the service consumer network element may authenticate the network repository function network element based on the third client eligibility information assertion. When the authentication of the network repository function network element is successful, the service consumer network element sends a first service request message to the service communication proxy, and the service consumer network element determines that the second network function type is the network function type of the network repository function network element (the network repository function network element is configured to provide a second service, and the network function type of the network repository function network element is the network function type of the network element providing the second service).

[0394] Step 802: The service communication proxy receives a first service request message from the service consumer network element, the service communication proxy sends a fourth service request message to the network repository function network element, the fourth service request message is used to request a second service, and the fourth service request message includes a first client eligibility information assertion.

[0395] Regarding the determination by the service communication proxy when the request for the first service triggers the request for the second service, refer to step 902 above. Details are not repeated.

[0396] Step 803: The network repository function network element receives a fourth service request message from the service communication proxy, and the network repository function network element authenticates the service consumer network element based on the first client credential information assertion.

[0397] If the network repository function network element determines that a network function type that is the same as the network function type of the network repository function network element exists in the first network function type and the second network function type, the network repository function network element determines that the authentication of the service consumer network element has succeeded. The second network function type is the same as the network function type of the network repository function network element.

[0398] Specifically, when the network repository function network element verifies that the signature of the first client credential information assertion is successful, verifies that the first client credential information assertion is not expired based on the timestamp and / or expiration date of the first client credential information assertion included in the first client credential information assertion, verifies that the identifier of the service consumer network element in the first client credential information assertion is the same as the identifier of the network element in the certificate for signing the first client credential information assertion, and verifies that the second network function type among the first network function type and the second network function type matches the network function type of the network repository function network element, the network repository function network element determines that the authentication of the service consumer network element has succeeded.

[0399] Step 804: When the authentication for the service consumer network element is successful, the network repository function network element sends a response message for the fourth service request message to the service communication proxy.

[0400] For example, when the fourth service request message is used to request an access token for the first service, after the authentication for the service consumer network element is successful, the network repository function network element performs an authorization check. If it is determined that the authorization is successful, the network repository function network element generates an access token for the first service. The network repository function network element sends a response message for the fourth service request message to the service communication proxy. The response message for the fourth service request message includes the access token for the first service.

[0401] For example, when the fourth service request message is used to request information about the service producer network element, after the authentication for the service consumer network element is successful, the network repository function network element sends a response message for the fourth service request message to the service communication proxy. The response message for the fourth service request message includes information about the service producer network element.

[0402] Step 805: The service communication proxy receives the response message for the fourth service request message from the network repository function network element, and based on the response message for the fourth service request message, the service communication proxy sends a fifth service request message to the service producer network element. The fifth service request message is used to request the first service and includes the first client credential assertion.

[0403] It will be appreciated that the fifth service request message further includes an access token corresponding to the first service.

[0404] For example, when a response message to the fourth service request message includes an access token corresponding to the first service, the service communication proxy transmits a fifth service request message to the service producer network element, the fifth service request message is used to request the first service, and the fifth service request message includes a first client credential assertion and an access token corresponding to the first service.

[0405] For example, when a response message to the fourth service request message includes information about the service producer network element, the service communication proxy transmits a fifth service request message to the service producer network element indicated by the information about the service producer network element, the fifth service request message is used to request the first service, and the fifth service request message includes a first client credential assertion and an access token corresponding to the first service. In this case, the access token corresponding to the first service may be stored by the service communication proxy or may be carried within the first request message.

[0406] In another embodiment, the service communication proxy requests, based on the first client credential assertion, an access token corresponding to the first service and information regarding the service producer network element from the network repository function network element. That is, steps 802 to 804 are executed twice. As a result, the service communication proxy may initiate the service request message for the second service twice to respectively request the access token corresponding to the first service and the information regarding the service producer network element. In this case, the access token corresponding to the first service in step 805 may be obtained by the service communication proxy from the network repository function network element in steps 802 to 804.

[0407] Step 806: The service producer network element receives the fifth service request message from the service communication proxy, and the service producer network element authenticates the service consumer network element based on the first client credential assertion.

[0408] It will be appreciated that the service producer network element needs to further verify the access token corresponding to the first service. For details, refer to the aforementioned access token verification process. Details are not repeated herein.

[0409] The service producer network element authenticating the service consumer network element based on the first client credential assertion includes the service producer network element determining whether the network function type of the service producer network element matches one or more of the first network function type and the second network function type.

[0410] Specifically, the service producer network element authenticating the service consumer network element based on the first client entitlement information assertion further includes the service producer network element verifying whether the signature of the first client entitlement information assertion is successful, verifying whether the first client entitlement information assertion has expired based on the timestamp and / or expiration date of the first client entitlement information assertion included in the first client entitlement information assertion, and verifying whether the identifier of the service consumer network element in the first client entitlement information assertion is the same as the identifier of the network element in the certificate for signing the first client entitlement information assertion.

[0411] The network repository function network element and the service producer network element authenticate the service consumer network element based on the same authentication idea based on the first client entitlement information assertion. For corresponding content, refer to each other. Details will not be described again.

[0412] Step 807: When the authentication for the service consumer network element is successful, the service producer network element sends a response message for the fifth service request message to the service communication proxy.

[0413] For example, when the authentication for the service consumer network element is successful and the verification for the access token corresponding to the first service is successful, the response message for the fifth service request message indicates providing the first service or indicates that the fifth service request is successful. Alternatively, when the authentication for the service consumer network element fails and / or the verification for the access token corresponding to the first service fails, the response message for the fifth service request message indicates that the request for the first service has failed.

[0414] Step 808: The service communication proxy transmits a response message to the first service request message to the service consumer network element.

[0415] When the response message to the fifth service request message indicates that the first service is provided or that the fifth service request has succeeded, the response message to the first service request message indicates that the first service is provided or that the first service request has succeeded. Alternatively, when the response message to the fifth service request message indicates that the first service request has failed, the response message to the first service request message indicates that the first service request has failed. For example, the service communication proxy may modify the information in the message header of the response message to the fifth service request message, but the content of the response message to the fifth service request message remains basically unchanged. The service communication proxy is mainly used for message routing.

[0416] In the foregoing embodiment, when the service consumer network element requests the first service from the service producer network element via the service communication proxy, the service consumer network element carries a client qualification information assertion including the first network function type and the second network function type in the first service request message transmitted to the service communication proxy. Thereby, when the service communication proxy requests the second service, the network element providing the second service authenticates the service consumer network element normally, further ensuring that the service consumer network element requests the first service, and in an indirect communication scenario, it is guaranteed to solve the problem that the service consumer network element cannot request the service because the authentication based on the client qualification information assertion fails.

[0417] One embodiment of the present application provides a communication method. A service consumer network element transmits a service request message to a service communication proxy, the service request message including a fourth client credential information assertion and a fifth client credential information assertion, the fourth client credential information assertion and the fifth client credential information assertion each including a different network function type. The service communication proxy transmits corresponding client credential information assertions to different network elements so that different network elements can authenticate the service consumer network element based on different client credential information assertions. In the following, the embodiment shown in FIG. 10 is used as an example for explanation.

[0418] This embodiment of the present application provides a communication method. As shown in FIG. 10, the method includes the following steps.

[0419] Step 1001: A service consumer network element transmits a first service request message to a service communication proxy, the first service request message being used to request a first service, the first service request message including a fourth client credential information assertion and a fifth client credential information assertion.

[0420] The fourth client entitlement information assertion is used by a service producer network element to authenticate a service consumer network element, and the fifth client entitlement information assertion is used by a network element providing a second service to authenticate a service consumer network element. The fourth client entitlement information assertion includes a first network function type, and the fifth client entitlement information assertion includes a second network function type. The first network function type is the network function type of the service producer network element, and the second network function type is the network function type of the network element providing the second service, where the second service is associated with the first service.

[0421] The fourth client eligibility information assertion further includes one or more of an identifier of a service consumer network element and validity time information of the fourth client eligibility information assertion. The validity time information of the fourth client eligibility information assertion indicates the expiration time of the fourth client eligibility information assertion. For example, the validity time information of the fourth client eligibility information assertion includes a timestamp and an expiration time of the fourth client eligibility information assertion. Alternatively, the validity time information of the fourth client eligibility information assertion may include a timestamp of the fourth client eligibility information assertion and a valid duration of the fourth client eligibility information assertion. The fifth client eligibility information assertion further includes one or more of an identifier of a service consumer network element and validity time information of the fifth client eligibility information assertion. The validity time information of the fifth client eligibility information assertion indicates the validity time of the fifth client eligibility information assertion. For example, the validity time information of the fifth client eligibility information assertion includes a timestamp and an expiration time of the fifth client eligibility information assertion. Alternatively, the validity time information of the fifth client eligibility information assertion may include a timestamp of the fifth client eligibility information assertion and a valid duration of the fifth client eligibility information assertion.

[0422] When the service communication proxy requests the second service earlier than the first service, the validity period of the fifth client qualification information assertion is shorter than that of the fourth client qualification information assertion. For example, when the service communication proxy requests the second service earlier than the first service, the validity period of the fifth client qualification information assertion is associated with the first duration. The first duration is determined based on the transmission delay between the service consumer network element and the service communication proxy and the transmission delay between the service communication proxy and the network element providing the second service. For example, the transmission delay between the service consumer network element and the service communication proxy is represented as T1, and the transmission delay between the service communication proxy and the network element providing the second service is represented as T2. The aforementioned transmission delay may be the average value of the transmission delay, or may be slightly larger than the average value of the transmission delay. The first duration = T1 + T2. For example, the expiration date of the first client qualification information assertion may be determined based on the timestamp, the first duration, and the preset duration. The preset duration in this specification may be determined based on empirical values.

[0423] When the service communication proxy requests the second service later than the first service, the validity period of the fifth client qualification information assertion is longer than that of the fourth client qualification information assertion.

[0424] The aforementioned configuration rules regarding the validity periods of the fourth client qualification information assertion and the fifth client qualification information assertion can ensure, to the greatest extent possible, that the fourth client qualification information assertion and the fifth client qualification information assertion are not maliciously used by the service communication proxy to guarantee the security of the communication process.

[0425] Before the service consumer network element sends a first service request message to the service communication proxy, the service consumer network element needs to further determine whether an available client credential information assertion is locally stored. If an available client credential information assertion is stored (for example, a client credential information assertion with an expiration date that has not passed is stored), it will be understood that the available client credential information assertion is used as a fourth client credential information assertion. If an available client credential information assertion is not stored (for example, the stored client credential information assertion has expired or no client credential information assertion is stored), the service consumer network element generates a fourth client credential information assertion. In addition, when there is an expired client credential information assertion, the service consumer network element may delete the expired client credential information assertion. Therefore, the service consumer network element can delete the expired client credential information assertion to free up storage space and reduce the memory load of the system. Similarly, this also applies to the fifth client credential information assertion. Details are not repeated herein.

[0426] The network function type of the network element that provides the second service may be the network function type of the network repository function network element.

[0427] For some scenarios in which the service consumer network element is triggered to send a first service request message to the service communication proxy, refer to the relevant content of the embodiment shown in FIG. 8. Details are not described again.

[0428] Step 1002: The service communication proxy receives a first service request message from the service consumer network element, and the service communication proxy sends a second service request message to the network repository function network element. The second service request message is used to request a second service, and the second service request message includes a fifth client entitlement information assertion.

[0429] For the service communication proxy to determine that a request for a first service triggers a request for a second service, refer to step 902 above. Details are not repeated.

[0430] After the service communication proxy determines that a request for a first service triggers a request for a second service, the service communication proxy sends a second service request message to the network repository function network element based on the network function type of the network repository function network element. The second service request message includes a fifth client entitlement information assertion.

[0431] For example, the service communication proxy determines that it is necessary to request an access token corresponding to the first service from the network repository function network element, and based on the network function type of the network repository function network element, selects the fifth client eligibility information assertion from the fourth client eligibility information assertion and the fifth client eligibility information assertion, and adds the fifth client eligibility information assertion to the second service request message. Alternatively, the service communication proxy determines that it is necessary to request information about the service producer network element from the network repository function network element, and based on the network function type of the network repository function network element, selects the fifth client eligibility information assertion from the fourth client eligibility information assertion and the fifth client eligibility information assertion, and adds the fifth client eligibility information assertion to the second service request message.

[0432] Step 1003: The network repository function network element receives the second service request message from the service communication proxy, and the network repository function network element authenticates the service consumer network element based on the fifth client eligibility information assertion.

[0433] The network repository function network element determines that the authentication for the service consumer network element has been successful. Specifically, the network repository function network element verifies that the signature of the fifth client credential information assertion has been successful, verifies that the fifth client credential information assertion is not expired based on the timestamp and / or expiration date of the fifth client credential information assertion included in the fifth client credential information assertion, verifies that the identifier of the service consumer network element within the fifth client credential information assertion is the same as the identifier of the network element within the certificate for signing the fifth client credential information assertion, and when verifying that the second network function type matches the network function type of the network repository function network element, the network repository function network element determines that the authentication for the service consumer network element has been successful.

[0434] Step 1004: The network repository function network element sends a response message for the second service request message to the service communication proxy.

[0435] For example, when the second service request message is used to request an access token corresponding to the first service, after the authentication for the service consumer network element is successful, the network repository function network element performs an authorization check. If it is determined that the authorization is successful, the network repository function network element generates an access token corresponding to the first service. The network repository function network element sends a response message for the second service request message to the service communication proxy. The response message for the second service request message includes the access token corresponding to the first service.

[0436] For example, when a second service request message is used to request information about a service producer network element, after successful authentication of the service consumer network element, the network repository function network element sends a response message for the second service request message to the service communication proxy. The response message for the second service request message contains information about the service producer network element.

[0437] Optionally, when authentication of the service consumer network element fails, the network repository function network element sends a response message for the second service request message to the service communication proxy to indicate that the request for the second service has failed.

[0438] Step 1005: The service communication proxy receives a response message for the second service request message from the network repository function network element, and based on the response message for the second service request message, the service communication proxy sends a third service request message to the service producer network element. The third service request message is used to request the first service, and the third service request message contains a fourth client entitlement information assertion.

[0439] It will be appreciated that the third service request message further includes an access token corresponding to the first service.

[0440] For example, the service communication proxy determines that the service consumer network element requests the first service, and based on the network function type of the service producer network element, selects the fourth client entitlement information assertion from the fourth client entitlement information assertion and the fifth client entitlement information assertion, and adds the fourth client entitlement information assertion to the third service request message.

[0441] For example, when a response message for a second service request message includes an access token corresponding to a first service, the service communication proxy transmits a third service request message to the service producer network element, the third service request message is used to request the first service, and the third service request message includes a fourth client credential information assertion and an access token corresponding to the first service. Alternatively, when a response message for a second service request message includes information about the service producer network element, the service communication proxy transmits a third service request message to the service producer network element indicated by the information about the service producer network element, the third service request message is used to request the first service, and the third service request message includes a fourth client credential information assertion and an access token corresponding to the first service. In this case, the access token corresponding to the first service may be stored by the service communication proxy or may be carried within the first service request message.

[0442] Step 1006: The service producer network element receives the third service request message from the service communication proxy, and the service producer network element authenticates the service consumer network element based on the fourth client credential information assertion.

[0443] It will be appreciated that the service producer network element needs to further verify the access token corresponding to the first service. For details, refer to the aforementioned access token verification process. Details are not repeated herein.

[0444] The service producer network element determines that the authentication of the service consumer network element is successful. Specifically, the service producer network element verifies that the signature of the fourth client entitlement information assertion is successful, verifies that the fourth client entitlement information assertion is not expired based on the timestamp and / or expiration date of the fourth client entitlement information assertion included in the fourth client entitlement information assertion, verifies that the identifier of the service consumer network element in the fourth client entitlement information assertion is the same as the identifier of the network element in the certificate for signing the fourth client entitlement information assertion, and verifies that the first network function type matches the network function type of the service producer network element. When the verification is successful, the service producer network element determines that the authentication of the service consumer network element is successful.

[0445] Step 1007: The service producer network element sends a response message to the third service request message to the service communication proxy.

[0446] When the authentication of the service consumer network element is successful and the verification of the access token corresponding to the first service is successful, the response message to the third service request message indicates that the first service is provided or that the third service request is successful. Alternatively, when the authentication of the service consumer network element fails and / or the verification of the access token corresponding to the first service fails, the response message to the third service request message indicates that the first service request has failed.

[0447] Step 1008: The service communication proxy sends a response message to the first service request message to the service consumer network element.

[0448] When the response message to the third service request message indicates that the first service is provided or that the third service request was successful, the response message to the first service request message indicates that the first service is provided or that the first service request was successful. Alternatively, when the response message to the third service request message indicates that the first service request failed, the response message to the first service request message indicates that the first service request failed. For example, the service communication proxy may modify the information in the message header of the response message to the third service request message, but the content of the response message to the third service request message remains basically unchanged. The service communication proxy is mainly used for message routing.

[0449] In the foregoing embodiment, the service consumer network element transmits a first service request message to the service communication proxy. The first service request message includes a fourth client qualification information assertion and a fifth client qualification information assertion. The fourth client qualification information assertion includes a first network function type, and the fifth client qualification information assertion includes a second network function type. Thereby, when the service communication proxy requests the second service, it can be guaranteed that the network element providing the second service authenticates the service consumer network element normally, and it can be further guaranteed that the service consumer network element requests the first service.

[0450] One embodiment of the present application provides a communication method. A service consumer network element transmits a service request message to a service communication proxy, and the service request message includes a fourth client credential assertion and a fifth client credential assertion, and the fourth client credential assertion and the fifth client credential assertion each include a different network function type. When receiving the fourth client credential assertion and the fifth client credential assertion, the network repository function network element (or service producer network element) determines that the authentication for the service consumer network element is successful based on the fourth client credential assertion, or determines that the authentication for the service consumer network element is successful based on the fifth client credential assertion. It can be determined that the authentication for the service consumer network element is successful. Hereinafter, the embodiment shown in FIG. 11 is used as an example for explanation.

[0451] This embodiment of the present application provides a communication method. As shown in FIG. 11, the method includes the following steps.

[0452] Step 1101: A service consumer network element transmits a first service request message to a service communication proxy, the first service request message is used to request a first service, and the first service request message includes a fourth client credential assertion and a fifth client credential assertion.

[0453] For details, refer to step 1001 in FIG. 10. Details will not be described again.

[0454] Step 1102: The service communication proxy receives a first service request message from a service consumer network element, and the service communication proxy sends a second service request message to a network repository function network element. The second service request message is used to request a second service, and the second service request message includes a fourth client entitlement information assertion and a fifth client entitlement information assertion.

[0455] For the service communication proxy to determine that a request for a first service triggers a request for a second service, refer to step 902 above. Details are not repeated.

[0456] Step 1103: The network repository function network element receives the second service request message from the service communication proxy, and the network repository function network element authenticates the service consumer network element based on the fourth client entitlement information assertion and the fifth client entitlement information assertion.

[0457] If the network repository function network element successfully authenticates the service consumer network element based on one or more of the fourth client entitlement information assertion and the fifth client entitlement information assertion, the network repository function network element determines that the authentication of the service consumer network element is successful.

[0458] The network repository function network element determines that the authentication of the service consumer network element has succeeded based on the fifth client entitlement information assertion. Specifically, the network repository function network element verifies that the signature of the fifth client entitlement information assertion has succeeded, verifies that the fifth client entitlement information assertion is not expired based on the timestamp and / or expiration date of the fifth client entitlement information assertion included in the fifth client entitlement information assertion, verifies that the identifier of the service consumer network element within the fifth client entitlement information assertion is the same as the identifier of the network element within the certificate for signing the fifth client entitlement information assertion, and when verifying that the second network function type matches the network function type of the network repository function network element, the network repository function network element determines that the authentication of the service consumer network element has succeeded.

[0459] The network repository function network element determines that the authentication of the service consumer network element has failed based on the fourth client entitlement information assertion. Specifically, the network repository function network element verifies that the signature of the fourth client entitlement information assertion has succeeded, verifies that the fourth client entitlement information assertion is not expired based on the timestamp and / or expiration date of the fourth client entitlement information assertion included in the fourth client entitlement information assertion, verifies that the identifier of the service consumer network element within the fourth client entitlement information assertion is the same as the identifier of the network element within the certificate for signing the fourth client entitlement information assertion, and when verifying that the first network function type does not match the network function type of the network repository function network element, the network repository function network element determines that the authentication of the service consumer network element has failed.

[0460] As can be seen from the above, when the network repository function network element successfully authenticates the service consumer network element based on the fifth client qualification information assertion and fails to authenticate the service consumer network element based on the fourth client qualification information assertion, the network repository function network element determines that the authentication of the service consumer network element is successful.

[0461] Step 1104: When the authentication of the service consumer network element is successful, the network repository function network element sends a response message for the second service request message to the service communication proxy.

[0462] For example, when the second service request message is used to request an access token corresponding to the first service, after the authentication of the service consumer network element is successful, the network repository function network element performs an authorization check. If it is determined that the authorization is successful, the network repository function network element generates an access token corresponding to the first service. The network repository function network element sends a response message for the second service request message to the service communication proxy. The response message for the second service request message includes the access token corresponding to the first service.

[0463] For example, when the second service request message is used to request information about the service producer network element, after the authentication of the service consumer network element is successful, the network repository function network element sends a response message for the second service request message to the service communication proxy. The response message for the second service request message includes information about the service producer network element.

[0464] Step 1105: The service communication proxy receives a response message for a second service request message from the network repository function network element, and based on the response message for the second service request message, the service communication proxy sends a third service request message to the service producer network element, where the third service request message is used to request the first service, and the third service request message includes a fourth client qualification information assertion and a fifth client qualification information assertion.

[0465] It will be appreciated that the third service request message further includes an access token corresponding to the first service.

[0466] For example, when the response message for the second service request message includes an access token corresponding to the first service, the service communication proxy sends a third service request message to the service producer network element, where the third service request message is used to request the first service, and the third service request message includes a fourth client qualification information assertion and an access token corresponding to the first service.

[0467] For example, when the response message for the second service request message includes information about the service producer network element, the service communication proxy sends a third service request message to the service producer network element indicated by the information about the service producer network element, where the third service request message is used to request the first service, and the third service request message includes a fourth client qualification information assertion and an access token corresponding to the first service. In this case, the access token corresponding to the first service may be stored by the service communication proxy or carried within the first service request message.

[0468] Step 1106: The service producer network element receives a third service request message from the service communication proxy, and the service producer network element verifies a fourth client credential assertion and a fifth client credential assertion.

[0469] It will be appreciated that the service producer network element needs to further verify the access token corresponding to the first service. For details, refer to the aforementioned access token verification process. Details are not repeated herein.

[0470] If the service producer network element successfully authenticates the service consumer network element based on one or more of the fourth client credential assertion and the fifth client credential assertion, the service producer network element determines that the authentication of the service consumer network element has succeeded.

[0471] The service producer network element determines that the authentication of the service consumer network element is successful based on the fourth client eligibility information assertion. Specifically, when the service producer network element verifies that the signature of the fourth client eligibility information assertion is successful, verifies that the fourth client eligibility information assertion is not expired based on the timestamp and / or expiration date of the fourth client eligibility information assertion included in the fourth client eligibility information assertion, verifies that the identifier of the service consumer network element in the fourth client eligibility information assertion is the same as the identifier of the network element in the certificate for signing the fourth client eligibility information assertion, and verifies that the first network function type matches the network function type of the service producer network element, the service producer network element determines that the authentication of the service consumer network element is successful.

[0472] The service producer network element determines that the authentication of the service consumer network element has failed based on the fifth client eligibility information assertion. Specifically, when the service producer network element verifies that the signature of the fifth client eligibility information assertion is successful, verifies that the fifth client eligibility information assertion is not expired based on the timestamp and / or expiration date of the fifth client eligibility information assertion included in the fifth client eligibility information assertion, verifies that the identifier of the service consumer network element in the fifth client eligibility information assertion is the same as the identifier of the network element in the certificate for signing the fifth client eligibility information assertion, and verifies that the second network function type does not match the network function type of the service producer network element, the service producer network element determines that the authentication of the service consumer network element has failed.

[0473] As can be seen from the above, when the service producer network element successfully authenticates the service consumer network element based on the fourth client qualification information assertion and fails to authenticate the service consumer network element based on the fifth client qualification information assertion, the service producer network element determines that the authentication of the service consumer network element is successful.

[0474] Step 1107: The service producer network element sends a response message to the third service request message to the service communication proxy.

[0475] Step 1108: The service communication proxy sends a response message to the first service request message to the service consumer network element.

[0476] Step 1107 and Step 1108 are the same as Step 1007 and Step 1008 in the embodiment of FIG. 10 respectively. Details will not be described again.

[0477] Compared with the embodiment of FIG. 10, in the embodiment of FIG. 11, the service communication proxy does not need to carry different CCAs in the service request message based on different targets requesting the service. This simplifies the processing logic of the service communication proxy. In addition, after receiving a service request from a service consumer network element, the service communication proxy carries two CCAs regardless of whether it requests a second service from a network repository function network element or requests a first service from a service producer network element. Therefore, it can always be guaranteed that the network repository function network element and the service producer network element can normally authenticate the service consumer network element, and the problem that the service consumer network element cannot request a service is avoided.

[0478] An embodiment of the present application provides a communication method. When the service communication proxy fails to request a second service, the service communication proxy may actively request a client credential information assertion from the service consumer network element to ensure that the service communication proxy can obtain the second service and further ensure that the service consumer network element can obtain the first service.

[0479] This embodiment of the present application provides a communication method. As shown in FIG. 12, the method includes the following steps.

[0480] Step 1201: The service consumer network element sends service request message 1 to the service communication proxy. Service request message 1 is used to request the first service. Service request message 1 includes client credential information assertion A. Client credential information assertion A includes the first network function type. Client credential information assertion A is used by the service producer network element to authenticate the service consumer network element. The first network function type is the network function type of the service producer network element.

[0481] Note that in this case, client credential information assertion A does not include the second network function type. The second network function type is the network function type of the network element that provides the second service, and the second service is associated with the first service.

[0482] Step 1202: The service communication proxy sends service request message 2 to the network repository function network element. Service request message 2 is used to request the second service. Service request message 2 includes client credential information assertion A. The network repository function network element is configured to provide the second service.

[0483] Step 1203: The network repository function network element determines that the authentication of the service consumer network element has failed based on client credential information assertion A.

[0484] Step 1204: The network repository function network element sends a response message to service request message 2 to the service communication proxy.

[0485] Steps 1201 to 1204 are the same as steps 901 to 904 in the embodiment of FIG. 9 respectively. Details will not be described again.

[0486] Step 1205: The service communication proxy sends a client qualification information assertion request message to the service consumer network element based on the response message to the service request message 2.

[0487] The client qualification information assertion request message may indicate that the first service request has failed. The client qualification information assertion request message may further include indication information.

[0488] In some embodiments, the indication information may include a client qualification information assertion B and / or a cause value. When the indication information includes the client qualification information assertion B, the service communication proxy can be prevented from maliciously triggering the service consumer network element to request the client qualification information assertion.

[0489] In some embodiments, the service communication proxy may further generate indication information based on the response message to the service request message 2. The indication information may alternatively not include the client qualification information assertion B or the cause value. The indication information may indicate to the service consumer network element to request the client qualification information assertion and carry the client qualification information assertion including the network function type of the network repository function network element when requesting the client qualification information assertion.

[0490] Step 1206: The service consumer network element sends a response message to the client qualification information assertion request message to the service communication proxy based on the indication information.

[0491] In some embodiments, when the indication information includes the client eligibility information assertion B and the client eligibility information assertion B includes the network function type of the network repository function network element, the service consumer network element may verify the client eligibility information assertion B. When the verification of the client eligibility information assertion B is successful, the service consumer network element sends a response message to the service communication proxy for the client eligibility information assertion request message. The response message to the client eligibility information assertion request message includes the client eligibility information assertion C. The client eligibility information assertion C includes the first network function type and the second network function type, or the client eligibility information assertion C includes the second network function type. The first network function type is the network function type of the service producer network element, and the second network function type is the network function type of the network element that provides the second service.

[0492] Step 1207: The service communication proxy receives a response message to the client eligibility information assertion request message from the service consumer network element, and sends a service request message 3 to the network repository function network element. The service request message 3 is used to request the second service, and the service request message 3 includes the client eligibility information assertion C.

[0493] For example, when the available access token corresponding to the first service is not stored and the first service request message does not include the access token corresponding to the first service, the service communication proxy sends the service request message 3 to the network repository function network element, and the service request message 3 is used to request the access token corresponding to the first service.

[0494] Alternatively, when information about the service producer network element is not stored and the first service request message does not include information about the service producer network element, the service communication proxy sends service request message 3 to the network repository function network element, and service request message 3 is used to request information about the service producer network element.

[0495] Step 1208: The network repository function network element receives service request message 3 from the service communication proxy, and the network repository function network element authenticates the service consumer network element based on the client credential information assertion C.

[0496] The client eligibility information assertion C includes a first network function type and a second network function type. When the network repository function network element determines that there exists a network function type that matches the network function type of the network repository function network element among the first network function type and the second network function type, the network repository function network element determines that the verification of the client eligibility information assertion C has succeeded. The second network function type matches the network function type of the network repository function network element. Specifically, when the network repository function network element verifies that the signature of the client eligibility information assertion C has succeeded, verifies based on the timestamp and / or expiration date of the client eligibility information assertion C included in the client eligibility information assertion C that the client eligibility information assertion C is not expired, verifies that the identifier of the service consumer network element within the client eligibility information C is the same as the identifier of the network element within the certificate for signing the client eligibility information assertion C, and verifies that the second network function type among the first network function type and the second network function type matches the network function type of the network repository function network element, the network repository function network element determines that the authentication of the service consumer network element has succeeded.

[0497] The client eligibility information assertion C includes a second network function type, and the network repository function network element verifies that the signature of the client eligibility information assertion C is successful, and based on the timestamp and / or expiration date of the client eligibility information assertion C included in the client eligibility information assertion C, verifies that the client eligibility information assertion C is not expired, and verifies that the identifier of the service consumer network element in the client eligibility information C is the same as the identifier of the network element in the certificate for signing the client eligibility information assertion C. When it is verified that the second network function type matches the network function type of the network repository function network element, the network repository function network element determines that the authentication of the service consumer network element is successful.

[0498] Step 1209: When the authentication of the service consumer network element is successful, the network repository function network element sends a response message to the service request message 3 to the service communication proxy.

[0499] For example, when the service request message 3 is used to request an access token corresponding to the first service, after the authentication of the service consumer network element is successful, the network repository function network element performs an authorization check. If it is determined that the authorization is successful, the network repository function network element generates an access token corresponding to the first service. The network repository function network element sends a response message to the service request message 3 to the service communication proxy. The response message to the service request message 3 includes an access token corresponding to the first service.

[0500] For example, when service request message 3 is used to request information about a service producer network element, after authentication of the service consumer network element is successful, the network repository function network element sends a response message to service request message 3 to the service communication proxy. The response message to service request message 3 contains information about the service producer network element.

[0501] Step 1210: The service communication proxy receives a response message to service request message 3 from the network repository function network element, and the service communication proxy sends service request message 4 to the service producer network element based on the response message to service request message 3. Service request message 4 is used to request a first service, and service request message 4 contains client credential information assertion A or client credential information C.

[0502] It will be appreciated that service request message 4 further includes an access token corresponding to the first service.

[0503] For example, when the response message to service request message 3 contains an access token corresponding to the first service, the service communication proxy sends service request message 4 to the service producer network element. Service request message 4 is used to request the first service, and service request message 4 contains the first client credential information assertion and an access token corresponding to the first service.

[0504] For example, when a response message to the service request message 3 includes information about a service producer network element, the service communication proxy sends the service request message 4 to the service producer network element indicated by the information about the service producer network element, and the service request message 4 is used to request a first service. The service request message 4 includes a first client eligibility information assertion and an access token corresponding to the first service. In this case, the access token corresponding to the first service may be stored by the service communication proxy or may be carried within the service request message 1.

[0505] Step 1211: The service producer network element receives the service request message 4 from the service communication proxy, and the service producer network element authenticates the NF service consumer based on the client eligibility information assertion A or the client eligibility information assertion C.

[0506] It will be understood that the service producer network element needs to further verify the access token corresponding to the first service. For details, please refer to the aforementioned access token verification process. Details are not repeated herein.

[0507] The service request message 4 includes the client eligibility information assertion C. When the service producer network element determines that there exist a first network function type and a second network function type whose network function types match the network function type of the service producer network element, the service producer network element determines that the authentication for the service consumer network element has succeeded based on the client eligibility information assertion C. The first network function type matches the network function type of the service producer network element. Specifically, when the service producer network element verifies that the signature of the client eligibility information assertion C has succeeded, verifies based on the timestamp and / or expiration date of the client eligibility information assertion C included in the client eligibility information assertion C that the client eligibility information assertion C is not expired, verifies that the identifier of the service consumer network element in the client eligibility information C is the same as the identifier of the network element in the certificate for signing the client eligibility information assertion C, and verifies that the first network function type among the first network function type and the second network function type matches the network function type of the service producer network element, the service producer network element determines that the authentication for the service consumer network element has succeeded.

[0508] If the service request message 4 includes the client eligibility information assertion A, the service producer network element verifies that the signature of the client eligibility information assertion A is successful, verifies that the client eligibility information assertion A is not expired based on the timestamp and / or expiration date of the client eligibility information assertion A included in the client eligibility information assertion A, verifies that the identifier of the service consumer network element in the client eligibility information assertion A is the same as the identifier of the network element in the certificate for signing the client eligibility information assertion A, verifies that the first network function type matches the network function type of the service producer network element, and the service producer network element determines that the authentication of the service consumer network element is successful.

[0509] Step 1212: The service producer network element sends a response message to the service request message 4 to the service communication proxy.

[0510] When the authentication of the service consumer network element is successful and the verification of the access token corresponding to the first service is successful, the response message to the service request message 4 indicates that the first service is provided or that the service request 4 is successful. Alternatively, when the authentication of the service consumer network element fails and / or the verification of the access token corresponding to the first service fails, the response message to the service request message 4 indicates that the first service request has failed.

[0511] Step 1213: The service communication proxy sends a response message to the service request message 1 to the service consumer network element.

[0512] When the response message to the service request message 4 indicates that the first service is provided or that the service request 4 has succeeded, the response message to the service request message 1 indicates that the first service is provided or that the service request 1 has succeeded. Alternatively, when the response message to the service request message 4 indicates that the first service request has failed, the response message to the service request message 1 indicates that the first service request has failed.

[0513] In the foregoing embodiment, when the service communication proxy requests the second service, the service communication proxy ensures that the network element providing the second service authenticates the service consumer network element normally, and further ensures that the service consumer network element requests the first service. To this end, the service consumer network element is sent a client credential information assertion request message.

[0514] The embodiments shown in FIGS. 8 to 12 will be described below using examples with reference to Embodiments 1 to 8.

[0515] Embodiment 1: Referring to the embodiment shown in FIG. 8, when it is necessary to request the first service and it is determined that there is no available access token corresponding to the first service, the NF service consumer may obtain the first service according to the following embodiment as shown in FIG. 13, but is not limited thereto.

[0516] Step 1301: The NF service consumer determines to request the first service and determines that there is no available access token corresponding to the first service. The NF service consumer obtains a CCA, and the access token corresponding to the first service represents / indicates that the NF service consumer has permission to obtain the first service or permission to access the first service.

[0517] It should be understood that the NF service consumer may further determine that the current indirect communication mode is mode D before step 1301.

[0518] After the NF service consumer determines to request the first service, the NF service consumer checks whether an access token corresponding to the first service is stored locally. The NF service consumer's determination that there is no available access token corresponding to the first service means that the NF service consumer determines that the access token corresponding to the first service is not stored or that the stored access token corresponding to the first service has expired. Further, if the NF service consumer determines that the stored access token corresponding to the first service has expired, the NF service consumer deletes the expired access token corresponding to the first service.

[0519] For example, the NF service consumer may receive the UE's service request message and determine, based on the service request message, that the first service needs to be requested. The NF service consumer obtains the UE's related information (e.g., the UE's context information) based on the UE's identifier. Further, the NF service consumer checks whether the public storage space contains an access token corresponding to the first service. If the access token corresponding to the first service is included and the access token is not expired, the access token is used. If the access token corresponding to the first service is not included, it is determined that there is no available access token. Alternatively, if the access token corresponding to the first service is included but the access token is expired, it is determined that there is no available access token. Further, optionally, the NF service consumer deletes the access token. The UE's related information may be stored in the NF service consumer's public storage space, or the UE's related information may be obtained by the NF service consumer from another network element based on the UE's identifier.

[0520] In addition, the NF service consumer needs to further determine whether an available CCA is stored locally. If an available CCA is stored (e.g., if the CCA is not expired), the CCA is used. If no available CCA is stored (e.g., if the CCA is expired or not stored), the NF service consumer generates a CCA. In addition, if the CCA has expired, the NF service consumer deletes the expired CCA.

[0521] The CCA includes a first NF type and a second NF type. The first NF type is the NF type of an NF service producer expected to provide a first service, and the second NF type is the NF type of an NRF expected to provide an access token.

[0522] In addition, the CCA further includes the NF instance identifier, timestamp, and expiration date of the NF service consumer.

[0523] Step 1302: The NF service consumer sends a first service request message to the SCP. The first service request message includes parameters for obtaining the CCA and access token of step 1301. The first service request message is used to request the first service.

[0524] The parameters for obtaining the access token and the parameters for discovering the NF service producer may be the same, or may be completely or partially different. The parameters for obtaining the access token and the parameters for discovering the NF service producer may be indicated by the same information element or different information elements. For example, if both the parameters for obtaining the access token and the parameters for discovering the NF service producer are the same, the same information element can be used for the indication. If the parameters for obtaining the access token and the parameters for discovering the NF service producer are completely different, the first service request message further includes the parameters for discovering the NF service producer. If the parameters for obtaining the access token and the parameters for discovering the NF service producer are partially different, the first service request message further includes the remaining parameters for discovering the NF service producer.

[0525] For example, the parameters for obtaining an access token may include the expected service name, the NF type of the NF service consumer, the NF type of the expected NF service producer, the S-NSSAI list or NSI ID list of the expected NF service producer instance, the NF set Id of the expected NF service producer instance, the S-NSSAI list of the NF service consumer, etc. The parameters for discovering an NF service producer may include the NF type of the expected NF service producer and the S-NSSAI list or NSI ID list of the expected NF service producer instance. In this case, the parameters for obtaining an access token may be partially the same as the parameters for discovering an NF service producer.

[0526] Step 1303: The SCP sends an access token request message to the NRF, and the access token request message includes the CCA and the parameters for obtaining an access token.

[0527] Before the SCP sends the access token request message to the NRF, the SCP determines that the first service request message does not include the access token corresponding to the first service and the access token corresponding to the first service is not stored locally, or determines that the first service request message does not include the access token corresponding to the first service and the stored access token corresponding to the first service has expired. If it is determined that the stored access token corresponding to the first service has expired, the SCP deletes the expired access token corresponding to the first service.

[0528] In addition, it should be understood that when the access token corresponding to the first service is a type B access token, the SCP needs to further initiate the NF service producer discovery procedure before step 1303. Otherwise, the SCP may initiate the NF service producer discovery procedure after obtaining the access token corresponding to the first service. Alternatively, when information about the NF service producer is stored locally, the SCP may not need to initiate the NF service producer discovery procedure.

[0529] The access token request message may be an NNrf_AccessToken_Get_Request or another message. This is not limited in the embodiments of the present application.

[0530] Step 1304: The NRF receives the access token request message, and the NRF authenticates the NF service consumer based on the CCA.

[0531] The NRF authenticates the NF service consumer successfully based on the CCA and performs an authorization check. If it is determined that the authorization is successful, an access token corresponding to the first service is generated.

[0532] The NRF verifies the signature of the CCA, verifies whether the CCA has expired based on the timestamp and / or expiration date of the CCA, and verifies whether the NF instance ID of the NF service consumer in the CCA matches the NF instance ID in the certificate for signing the CCA. In addition to all the above verifications being successful, the NRF needs to further verify whether there is the same NF type as the NRF's NF type in the first NF type and the second NF type included in the CCA. When the NRF determines that the second NF type matches the NRF's NF type, the NRF determines that the authentication of the NF service consumer is successful.

[0533] Step 1305: The NRF sends an access token response message to the SCP, and the access token response message contains an access token corresponding to the first service.

[0534] Step 1306: The SCP sends a second service request message to the NF service producer. The second service request message contains the CCA and the access token corresponding to the first service.

[0535] Step 1307: The NF service producer receives the second service request message from the SCP. The NF service producer authenticates the NF service consumer based on the CCA.

[0536] The NF service producer performs integrity verification on the access token corresponding to the first service. If the integrity verification is successful, the NF service producer further verifies the claims within the access token corresponding to the first service. For details, please refer to the relevant content of the verification regarding the claims within the access token.

[0537] The NF service producer needs to further authenticate the NF service consumer based on the CCA. The NF service producer verifies the signature of the CCA, verifies whether the CCA has expired based on the CCA's timestamp and / or expiration date, and verifies whether the NF instance ID of the NF service consumer in the CCA matches the NF instance ID in the certificate for signing the CCA. In addition to the successful verification of all the above verification contents, the NF service producer needs to further verify whether there is an NF type that matches the NF type of the NF service producer in the first NF type and the second NF type included in the CCA. When the NF service producer determines that the first NF type matches the NF type of the NF service producer, the NF service producer determines that the authentication of the NF service consumer has succeeded.

[0538] Alternatively, the above sequence of verifying the access token and the CCA may be that the CCA is verified first and then the access token is verified after the verification is successful. This is not limited in this specification.

[0539] In addition, the NF service producer further checks whether the NF instance ID of the NF service consumer in the CCA is the same as the NF instance ID of the NF service consumer included in the access token. If the NF instance ID of the NF service consumer in the CCA is the same as the NF instance ID of the NF service consumer included in the access token, the requested service is provided to the NF service consumer.

[0540] Step 1308: If the NF service producer determines that the verification of the first access token is successful and the authentication of the NF service consumer is successful, the NF service producer sends a response message to the SCP for the second service request message. The response message for the second service request message indicates either providing the first service or that the second service request was successful.

[0541] It will be understood that if the verification of the first access token fails and / or the authentication of the NF service consumer fails, the response message for the second service request message indicates that the first service request has failed.

[0542] Step 1309: The SCP receives the response message for the second service request message from the NF service producer and sends the response message for the first service request message to the NF service consumer.

[0543] The response message for the second service request message may include the access token corresponding to the first service. The NF service consumer stores the access token corresponding to the first service to subsequently request the first service.

[0544] In addition, when the NF service consumer determines that there is an available access token corresponding to the first service, the NF service consumer may determine whether an available CCA is stored. If an available CCA is stored, the CCA is used. If an available CCA is not stored, a CCA is generated. In this case, it will be understood that the CCA may not include the second NF type. However, if the NF service consumer determines that the current indirect communication mode is mode D before step 1301, the first service request message needs to carry the first NF type and the second NF type.

[0545] In the foregoing embodiment, the CCA includes the first NF type and the second NF type. Thereby, it can be guaranteed that the NRF and the NF service producer can normally authenticate the NF service consumer based on the CCA, and it can be further guaranteed that the NF service consumer can obtain the first service.

[0546] Embodiment 2: Referring to the embodiment shown in FIG. 10, when the first service needs to be requested and it is determined that there is no available access token corresponding to the first service, the NF service consumer may obtain the first service according to the following embodiments as shown in FIG. 14, but is not limited thereto.

[0547] Step 1401: The NF service consumer determines to request the first service and determines that there is no available access token corresponding to the first service. The NF service consumer obtains CCA1 and CCA2, and the access token corresponding to the first service represents / indicates that the NF service consumer has permission to obtain the first service or permission to access the first service.

[0548] It should be understood that the NF service consumer may further determine that the current indirect communication mode is mode D before step 1401. The NF service consumer determines to request a first service and determines that there is no available access token corresponding to the first service. For details, refer to the related description of step 1301 in FIG. 13. The details will not be repeated.

[0549] In addition, the NF service consumer needs to determine whether the available CCA1 and CCA2 are stored locally. If the available CCA1 is stored (for example, if CCA1 is not expired), CCA1 is used. If the available CCA1 is not stored (for example, if CCA1 is expired), the NF service consumer generates CCA1. If the available CCA2 is stored (for example, if CCA2 is not expired or CCA2 is not stored), CCA2 is used. If the available CCA2 is not stored (for example, if CCA2 is expired or CCA2 is not stored), the NF service consumer generates CCA2. If CCA1 or CCA2 is expired, the NF service consumer deletes the expired CCA.

[0550] CCA1 includes the first NF type, and CCA2 includes the second NF type. The first NF type is the NF type of the NF service producer expected to provide the first service, and the second NF type is the NF type of the NRF expected to provide the access token.

[0551] In addition, CCA1 further includes the NF instance identifier, timestamp, and expiration period of CCA1 of the NF service consumer. CCA2 further includes the NF instance identifier, timestamp, and expiration period of CCA2 of the NF service consumer.

[0552] Step 1402: The NF service consumer sends a first service request message to the SCP. The first service request message includes the CCA1 and CCA2 from step 1401 and the parameters for obtaining the access token. The first service request message is used to request the first service.

[0553] For the parameters for obtaining the access token and the parameters for discovering the NF service producer, refer to step 1402 of Embodiment 1. Details will not be repeated.

[0554] Step 1403: The SCP sends an access token request message to the NRF. The access token request message includes CCA2 and the parameters for obtaining the access token.

[0555] Before the SCP sends the access token request message to the NRF, the SCP determines that the first service request message does not include the access token corresponding to the first service and that the access token corresponding to the first service is not stored locally, or determines that the first service request message does not include the access token corresponding to the first service and that the stored access token corresponding to the first service has expired. If it is determined that the stored access token corresponding to the first service has expired, the SCP deletes the expired access token corresponding to the first service.

[0556] The SCP needs to send the access token request message to the NRF. Therefore, the SCP adds CCA2 to the access token request message.

[0557] In addition, it should be understood that when the access token corresponding to the first service is a type B access token, the SCP needs to further initiate the NF service producer discovery procedure before step 1403. Otherwise, the SCP may initiate the NF service producer discovery procedure after obtaining the access token corresponding to the first service. Alternatively, when information about the NF service producer is stored locally, the SCP may not need to initiate the NF service producer discovery procedure.

[0558] For example, the access token request message may be an NNrf_AccessToken_Get_Request or another message. This is not limited in the embodiments of the present application.

[0559] Step 1404: The NRF receives the access token request message, and the NRF authenticates the NF service consumer based on CCA2.

[0560] The NRF successfully authenticates the NF service consumer based on CCA2 and performs an authorization check. If it is determined that the authorization is successful, an access token corresponding to the first service is generated.

[0561] The NRF verifies the signature of CCA2, verifies whether CCA2 has expired based on the timestamp and / or expiration date of CCA2, and verifies whether the NF instance ID of the NF service consumer in CCA2 matches the NF instance ID in the certificate for signing CCA2. In addition to all the above verifications being successful, the NRF also needs to further verify whether the second NF type included in CCA2 is the same as the NF type of the NRF. Since the second NF type matches the NF type of the NRF, the NRF determines that the verification of CCA2 is successful.

[0562] Step 1405: The NRF sends an access token response message to the SCP, and the access token response message includes an access token corresponding to the first service.

[0563] Step 1406: The SCP sends a second service request message to the NF service producer. The second service request message includes CCA1 and an access token corresponding to the first service.

[0564] Since the SCP needs to send the second service request message to the NF service producer, the SCP selects CCA1 and adds CCA1 to the second service request message.

[0565] Step 1407: The NF service producer receives the second service request message from the SCP, and the NF service producer verifies CCA1 and the access token corresponding to the first service.

[0566] The NF service producer performs integrity verification on the access token corresponding to the first service. If the integrity verification is successful, the NF service producer further verifies the claims within the access token corresponding to the first service. For details, please refer to the relevant content of the verification regarding the claims within the access token.

[0567] The NF service producer needs to further authenticate the NF service consumer based on CCA1. The NF service producer verifies the signature of CCA1, verifies whether CCA1 has expired based on the timestamp and / or expiration date of CCA1, and verifies whether the NF instance ID of the NF service consumer in CCA1 matches the NF instance ID in the certificate for signing CCA1. In addition to the success of all the above verifications, the NF service producer also needs to verify whether the first NF type included in CCA1 matches the NF type of the NF service producer. Since the first NF type matches the NF type of the NF service producer, it is determined that the authentication of the NF service consumer is successful.

[0568] Alternatively, the above sequence of verifying the access token and CCA1 may be that CCA1 is verified first, and then the access token is verified after the verification is successful. This is not limited in this specification.

[0569] After both the verification of the access token and the verification of CCA1 are successful, the NF service producer further checks whether the NF instance ID of the NF service consumer in CCA1 is the same as the NF instance ID of the NF service consumer included in the access token. If the NF instance ID of the NF service consumer in CCA1 is the same as the NF instance ID of the NF service consumer included in the access token, the requested service is provided to the NF service consumer.

[0570] Step 1408: If the NF service producer determines that the verification of the first access token is successful and the authentication of the NF service consumer is successful, the NF service producer sends a response message for the second service request message to the SCP. The response message for the second service request message indicates that the first service is provided or that the second service request is successful.

[0571] It will be understood that if the verification of the first access token fails and / or the authentication of the NF service consumer fails, the response message for the second service request message indicates that the first service request has failed.

[0572] Step 1409: The SCP receives the response message for the second service request message from the NF service producer and sends the response message for the first service request message to the NF service consumer.

[0573] The response message for the first service request message may include the access token corresponding to the first service. The NF service consumer stores the access token corresponding to the first service to subsequently request the first service.

[0574] In addition, when the NF service consumer determines that there is an available access token corresponding to the first service, the NF service consumer may determine whether an available CCA1 is stored. If an available CCA1 is stored, the CCA1 is used. If an available CCA1 is not stored, a CCA1 is generated. In this case, it should be understood that the NF service consumer does not need to determine whether an available CCA2 is stored. Even if an available CCA2 is not stored, the NF service consumer does not need to generate a CCA2 and does not need to obtain an access token corresponding to the first service via the SCP. The first service request message may not include a CCA2. However, if the NF service consumer determines that the current indirect communication mode is mode D before step 1401, the first service request message needs to carry the CCA1 and the CCA2.

[0575] In the foregoing embodiment, the CCA1 includes the first NF type, and the CCA2 includes the second NF type. Thereby, it can be guaranteed that the NRF authenticates the NF service consumer normally based on the CCA2, and the NF service producer authenticates the NF service consumer normally based on the CCA1, and it can be further guaranteed that the NF service consumer obtains the first service.

[0576] Embodiment 3: Referring to the embodiment shown in FIG. 11, when the first service needs to be requested and it is determined that there is no available access token corresponding to the first service, the NF service consumer may obtain the first service according to the following embodiments as shown in FIG. 15, but is not limited thereto.

[0577] For steps 1501 and 1502, refer to steps 1401 and 1402 in FIG. 14. Details will not be repeated.

[0578] Step 1503: The SCP sends an access token request message to the NRF. The access token request message includes CCA2, CCA1, and parameters for obtaining an access token.

[0579] Before the SCP sends the access token request message to the NRF, the SCP determines that the first service request message does not include an access token corresponding to the first service and that the access token corresponding to the first service is not stored locally, or the SCP determines that the first service request message does not include an access token corresponding to the first service and that the stored access token corresponding to the first service has expired. If it is determined that the stored access token corresponding to the first service has expired, the SCP deletes the expired access token corresponding to the first service.

[0580] In addition, it should be understood that if the access token corresponding to the first service is a type B access token, the SCP needs to further start the NF service producer discovery procedure before step 1503. Otherwise, the SCP may start the NF service producer discovery procedure after obtaining the access token corresponding to the first service. Alternatively, when information about the NF service producer is stored locally, the SCP may not need to start the NF service producer discovery procedure.

[0581] For example, the access token request message may be an NNrf_AccessToken_Get_Request or another message. This is not limited in the embodiments of this application.

[0582] Step 1504: The NRF receives an access token request message, and the NRF authenticates the NF service consumer based on CCA1 and CCA2.

[0583] The NRF either authenticates the NF service consumer successfully based on CCA1 or authenticates the NF service consumer successfully based on CCA2 and performs an authorization check. If it is determined that the authorization is successful, an access token corresponding to the first service is generated.

[0584] The NRF authenticates the NF service consumer based on CCA1 and CCA2. In this case, the NRF does not necessarily have to determine that the authentication of the NF service consumer is successful based on CCA1, nor does it have to determine that the authentication of the NF service consumer is successful based on CCA2. When it is determined that the authentication of the NF service consumer is successful based on CCA1 or when it is determined that the authentication of the NF service consumer is successful based on CCA2, the NRF determines that the authentication of the NF service consumer is successful.

[0585] The NRF verifies the signature of CCA1, verifies whether CCA1 has expired based on the timestamp and / or expiration date of CCA1, and verifies whether the NF instance ID of the NF service consumer in CCA1 matches the NF instance ID in the certificate for signing CCA1. In addition to the success of all the above verification contents, the NRF also needs to further verify whether the first NF type included in CCA1 matches the NF type of the NRF. Since the first NF type does not match the NF type of the NRF, the NRF determines that the authentication of the NF service consumer has failed.

[0586] The NRF verifies the signature of the CCA2, verifies whether the CCA2 has expired based on the timestamp and / or expiration date of the CCA2, and verifies whether the NF instance ID of the NF service consumer within the CCA2 matches the NF instance ID within the certificate for signing the CCA2. In addition to the success of all the above verifications, the NRF also needs to further verify whether the second NF type included in the CCA2 matches the NF type of the NRF. Since the second NF type matches the NF type of the NRF, the NRF determines that the authentication for the NF service consumer has succeeded.

[0587] Step 1505: The NRF sends an access token response message to the SCP, and the access token response message contains an access token corresponding to the first service.

[0588] Step 1506: The SCP sends a second service request message to the NF service producer. The second service request message contains the CCA1, CCA2, and an access token corresponding to the first service.

[0589] Step 1507: The NF service producer receives the second service request message from the SCP. The NF service producer verifies the CCA1, CCA2, and the access token.

[0590] The NF service producer performs an integrity verification on the access token corresponding to the first service. If the integrity verification is successful, the NF service producer further verifies the claims within the access token corresponding to the first service. For details, please refer to the relevant content of the verification regarding the claims within the access token.

[0591] The NF service producer authenticates the NF service consumer based on CCA1 and CCA2. In this case, the NF service producer does not have to determine that the authentication of the NF service consumer is successful based on CCA1, nor does it have to determine that the authentication of the NF service consumer is successful based on CCA2. If the NF service producer determines that the authentication of the NF service consumer is successful based on CCA1 or determines that the authentication of the NF service consumer is successful based on CCA2, the NF service producer determines that the authentication of the NF service consumer is successful.

[0592] The NF service producer verifies the signature of CCA1, verifies whether CCA1 has expired based on the timestamp and / or expiration date of CCA1, and verifies whether the NF instance ID of the NF service consumer in CCA1 matches the NF instance ID in the certificate for signing the CCA. In addition to the success of all the above verifications, the NF service producer also needs to further verify whether the first NF type included in CCA1 matches the NF type of the NF service producer. Since the first NF type matches the NF type of the NF service producer, the NF service producer determines that the authentication of the NF service consumer is successful.

[0593] The NF service producer verifies the signature of CCA2, verifies whether CCA2 has expired based on the timestamp and / or expiration date of CCA2, and verifies whether the NF instance ID of the NF service consumer in CCA2 matches the NF instance ID in the certificate for signing CCA2. In addition to the successful verification of the above verification content, the NF service producer needs to further verify whether the second NF type included in CCA2 matches the NF type of the NF service producer. The second NF type is the NF type of the NF service producer expected to provide the access token corresponding to the first service. Since the second NF type does not match the NF type of the NF service producer, the NF service producer determines that the authentication of the NF service consumer has failed.

[0594] Step 1508: If the NF service producer determines that the verification of the first access token is successful and the authentication of the NF service consumer is successful, the NF service producer sends a response message for the second service request message to the SCP. The response message for the second service request message indicates that the first service is provided or that the second service request has been successful.

[0595] It will be understood that if the verification of the first access token fails and / or the authentication of the NF service consumer fails, the response message for the second service request message indicates that the first service request has failed.

[0596] Step 1509: The SCP receives the response message for the second service request message from the NF service producer and sends the response message for the first service request message to the NF service consumer.

[0597] The response message to the second service request message may include an access token corresponding to the first service. The NF service consumer stores the access token corresponding to the first service to subsequently request the first service.

[0598] In the foregoing embodiment, CCA1 includes the first NF type, and CCA2 includes the second NF type. Thereby, it can be guaranteed that the NRF authenticates the NF service consumer normally based on CCA1, and the NF service producer authenticates the NF service consumer normally based on CCA2, and it can be further guaranteed that the NF service consumer obtains the first service.

[0599] Embodiment 4: When it is necessary to request the first service and it is determined that there is an available access token corresponding to the first service, the NF service consumer may obtain the first service according to the following embodiments as shown in FIG. 16, but is not limited thereto.

[0600] Step 1601: The NF service consumer determines to request the first service and determines that there is an available access token corresponding to the first service. The NF service consumer obtains the CCA, and the access token corresponding to the first service represents / indicates that the NF service consumer has permission to obtain the first service or permission to access the first service.

[0601] If the NF service consumer determines that there is an available access token corresponding to the first service, the NF service consumer may further determine whether an available CCA is stored. If an available CCA is stored, the CCA is used. If an available CCA is not stored, a CCA is generated. In this case, it should be understood that the CCA generated by the NF service consumer may not include the second NF type.

[0602] The CCA includes the NF instance identifier, timestamp, expiration date, and the first NF type of the NF service consumer, and the first NF type is the NF type of the NF service producer expected to provide the first service.

[0603] Step 1602: The NF service consumer sends a first service request message to the SCP, and the first service request message includes the CCA from Step 1601 and the access token corresponding to the first service.

[0604] Step 1603: The SCP sends a second service request message to the NF service producer. The second service request message includes the CCA and the access token corresponding to the first service.

[0605] Before the SCP sends the second service request message to the NF service producer, the SCP determines that the first service request message includes an access token corresponding to the first service or a locally stored access token corresponding to the first service.

[0606] Step 1604: The NF service producer receives the second service request message from the SCP. The NF service producer authenticates the NF service consumer based on the CCA.

[0607] The NF service producer performs integrity verification on the access token corresponding to the first service. If the integrity verification is successful, the NF service consumer further verifies the claims within the access token corresponding to the first service. For details, refer to the relevant content of the verification regarding the claims within the access token. The NF service producer needs to further authenticate the NF service consumer based on the CCA. For details, refer to the existing CCA verification process.

[0608] The NF service producer verifies the signature of the CCA, verifies whether the CCA has expired based on the CCA's timestamp and / or expiration date, and verifies whether the NF instance ID of the NF service consumer within the CCA matches the NF instance ID within the certificate for signing the CCA. In addition to the success of all the above verifications, the NF service producer needs to further verify whether the first NF type included in the CCA matches the NF type of the NF service producer. Since the first NF type matches the NF type of the NF service producer, the NF service producer determines that the authentication of the NF service consumer is successful.

[0609] Step 1605: If the NF service producer determines that the verification of the first access token is successful and the authentication of the NF service consumer is successful, the NF service producer sends a response message for the second service request message to the SCP.

[0610] The response message for the second service request message indicates either providing the first service or the success of the second service request.

[0611] If the verification of the first access token fails and / or the authentication of the NF service consumer fails, it will be understood that the response message for the second service request message indicates that the first service request has failed.

[0612] Step 1606: The SCP receives a response message for the second service request message from the NF service producer and sends a response message for the first service request message to the NF service consumer.

[0613] In the foregoing embodiments, by determining that available CCA is stored, the NF service consumer may carry the first NF type to obtain the first service.

[0614] Embodiment 5: Referring to the embodiment shown in FIG. 8, when the first service needs to be requested and the request for the first service triggers the SCP to request the parameters of the NF service producer (triggers the SCP to start the NF service producer discovery procedure), the NF service consumer may obtain the first service according to the following embodiments as shown in FIG. 17, but is not limited thereto.

[0615] Step 1701: The NF service consumer determines to trigger the SCP to start the NF service producer discovery procedure, and the NF service consumer obtains CCA.

[0616] It will be understood that the NF service consumer may further determine that the current indirect communication mode is mode D before step 1701.

[0617] For example, the NF service consumer may determine to trigger the SCP to start the NF service producer discovery procedure based on one or more of the following cases.

[0618] Case 1: The UE context is not stored. For example, the NF service consumer determines that the first service needs to be requested based on the UE's service request message.

[0619] Case 2: The context of the first service is not stored.

[0620] Case 3: The first slice belongs to the service producer network element, and the context of the first slice is not stored. For example, the NF service consumer determines that the first service needs to be requested from the service producer network element within the first slice based on the UE's service request message.

[0621] Case 4: The service consumer network element communicates with the service communication proxy for the first time.

[0622] Before the NF service consumer generates a CCA, the NF service consumer needs to determine whether an available CCA is stored locally. If an available CCA is stored (for example, if the CCA is not expired), the CCA is used. If an available CCA is not stored (for example, if the CCA is expired or not stored), the NF service consumer generates a CCA. If the CCA has expired, the NF service consumer deletes the expired CCA.

[0623] The CCA includes a first NF type and a second NF type. The first NF type is the NF type of the NF service producer expected to provide the first service, and the second NF type is the NF type of the NRF expected to provide information about the NF service producer.

[0624] In addition, the CCA further includes the NF instance identifier, timestamp, and expiration date of the NF service consumer.

[0625] Step 1702: The NF service consumer sends a first service request message to the SCP. The first service request message includes the CCA from Step 1701 and parameters for discovering the NF service producer, and the first service request message is used to request the first service.

[0626] For example, the parameters for discovering the NF service producer may include the NF type of the expected NF service producer, or the S-NSSAI list or NSI ID list of the expected NF service producer instance, etc.

[0627] Step 1703: The SCP sends a discovery request message to the NRF. The discovery request message includes the CCA and parameters for discovering the NF service producer.

[0628] Before the SCP sends the discovery request message to the NRF, the SCP determines that the first service request message does not include information about the NF service producer and that the information about the NF service producer is not stored locally.

[0629] It is assumed herein that the first service request message further includes an access token corresponding to the first service, or that the SCP stores the access token corresponding to the first service locally.

[0630] Step 1704: The NRF receives the discovery request message, and the NRF authenticates the NF service consumer based on the CCA.

[0631] The NRF verifies the signature of the CCA, verifies whether the CCA has expired based on the CCA's timestamp and / or expiration date, and verifies whether the NF instance ID of the NF service consumer within the CCA matches the NF instance ID within the certificate for signing the CCA. In addition to successfully verifying all of the above verification contents, the NRF also needs to further verify whether there is an NF type that matches the NRF's NF type for the first NF type and the second NF type included in the CCA. When the NRF determines that the second NF type matches the NRF's NF type, the NRF determines that the authentication for the NF service consumer has succeeded.

[0632] Step 1705: The NRF sends a discovery response message to the SCP, and the discovery response message contains the parameters of the NF service producer.

[0633] When the authentication for the NF service consumer succeeds, the NRF sends a discovery response message to the SCP, and the discovery response message contains the parameters of the NF service producer.

[0634] Step 1706: The SCP sends a second service request message to the NF service producer. The second service request message contains the CCA and the access token corresponding to the first service.

[0635] The SCP sends a second service request message to the NF service producer indicated by the parameters of the NF service producer in the discovery response message.

[0636] Step 1707: The NF service producer receives the second service request message from the SCP. The NF service producer authenticates the NF service consumer based on the CCA.

[0637] The NF service producer performs integrity verification on the access token corresponding to the first service. If the integrity verification is successful, the NF service producer further verifies the claims in the access token corresponding to the first service. For details, refer to the relevant content of the verification regarding the claims in the access token. The NF service producer needs to further authenticate the NF service consumer based on the CCA.

[0638] The NF service producer verifies the signature of the CCA, verifies whether the CCA has expired based on the timestamp and / or expiration date of the CCA, and verifies whether the NF instance ID of the NF service consumer in the CCA matches the NF instance ID in the certificate for signing the CCA. In addition to the success of the verification of all the above verification contents, the NF service producer needs to further verify whether there is an NF type that matches the NF type of the NF service producer in the first NF type and the second NF type included in the CCA. When the NF service producer determines that the first NF type matches the NF type of the NF service producer, the NF service producer determines that the authentication of the NF service consumer has been successful.

[0639] Step 1708: If the NF service producer determines that the verification of the first access token is successful and the authentication of the NF service consumer is successful, the NF service producer sends a response message for the second service request message to the SCP. The response message for the second service request message indicates either providing the first service or the success of the second service request.

[0640] If the verification of the first access token fails and / or the authentication of the NF service consumer fails, it will be understood that the response message for the second service request message indicates that the first service request has failed.

[0641] Step 1709: The SCP receives a response message for the second service request message from the NF service producer and sends a response message for the first service request message to the NF service consumer.

[0642] In the foregoing embodiments, the CCA includes a first NF type and a second NF type. Thereby, it can be guaranteed that the NRF and the NF service producer can normally authenticate the NF service consumer based on the CCA, and it can be further guaranteed that the NF service consumer can obtain the first service.

[0643] Embodiment 6: Referring to the embodiment shown in FIG. 10, when a first service needs to be requested and the request for the first service triggers the SCP to request the parameters of the NF service producer (triggers the SCP to start the NF service producer discovery procedure), the NF service consumer can obtain the first service according to the following embodiments as shown in FIG. 18, but is not limited thereto.

[0644] Step 1801: The NF service consumer determines to trigger the SCP to execute the NF service producer discovery procedure, and the NF service consumer obtains CCA1 and CCA2.

[0645] It will be understood that the NF service consumer may further determine that the current indirect communication mode is mode D before step 1801.

[0646] For example, regarding the determination by the NF service consumer to trigger the SCP and execute the NF service producer discovery procedure, refer to the relevant description in step 1701 of Embodiment 5.

[0647] In addition, before the NF service consumer generates CCA1 and CCA2, the NF service consumer needs to determine whether the available CCA1 and the available CCA2 are stored locally. If the available CCA1 is stored (for example, if the CCA1 has not reached its expiration date), the CCA1 is used. If the available CCA1 is not stored (for example, if the CCA1 has expired or the CCA1 is not stored), the NF service consumer generates the CCA1. If the available CCA2 is stored (for example, if the CCA2 has not expired), the CCA2 is used. If the available CCA2 is not stored (for example, if the CCA2 has expired or the CCA2 is not stored), the NF service consumer generates the CCA2. If CCA1 or CCA2 has expired, the NF service consumer deletes the expired CCA.

[0648] CCA1 includes a first NF type, and CCA2 includes a second NF type. The first NF type is the NF type of the NF service producer expected to provide the first service, and the second NF type is the NF type of the NRF expected to provide information about the NF service producer.

[0649] In addition, CCA1 further includes the NF instance identifier of the NF service consumer, a timestamp, and the expiration date of CCA1. CCA2 further includes the NF instance identifier of the NF service consumer, a timestamp, and the expiration date of CCA2.

[0650] Step 1802: The NF service consumer sends a first service request message to the SCP. The first service request message includes the CCA1 and CCA2 from step 1801, as well as parameters for discovering the NF service producer. The first service request message is used to request the first service.

[0651] Step 1803: The SCP sends a discovery request message to the NRF. The discovery request message includes the CCA2 and parameters for discovering the NF service producer.

[0652] Before the SCP sends the discovery request message to the NRF, the SCP determines that the first service request message does not contain information about the NF service producer and that information about the NF service producer is not stored locally.

[0653] It is assumed herein that the first service request message further includes an access token corresponding to the first service, or that the SCP stores locally an access token corresponding to the first service.

[0654] The SCP needs to send a discovery request message to the NRF. Therefore, the SCP selects the CCA2 and adds the CCA2 to the discovery request message.

[0655] Step 1804: The NRF receives the discovery request message, and the NRF authenticates the NF service consumer based on the CCA2.

[0656] The NRF verifies the signature of the CCA2, verifies whether the CCA2 has expired based on the timestamp and / or expiration date of the CCA2, and verifies whether the NF instance ID of the NF service consumer in the CCA2 matches the NF instance ID in the certificate for signing the CCA2. In addition to the success of all the above verifications, the NRF needs to further verify whether the second NF type included in the CCA2 matches the NF type of the NRF. Since the second NF type matches the NF type of the NRF, the NRF determines that the authentication of the NF service consumer has succeeded.

[0657] Step 1805: The NRF sends a discovery response message to the SCP, and the discovery response message contains information about the NF service producer.

[0658] When the authentication of the NF service consumer is successful, the NRF sends a discovery response message to the SCP, and the discovery response message contains the parameters of the NF service producer.

[0659] Step 1806: The SCP sends a second service request message to the NF service producer. The second service request message contains the CCA1 and the access token corresponding to the first service.

[0660] The SCP sends a second service request message to the NF service producer indicated by the parameters of the NF service producer in the discovery response message.

[0661] Since the SCP needs to send a second service request message to the NF service producer, the SCP selects the CCA1 and adds the CCA1 to the second service request message.

[0662] Step 1807: The NF service producer receives a second service request message from the SCP. The NF service producer authenticates the NF service consumer based on CCA1.

[0663] The NF service producer performs integrity verification on the access token corresponding to the first service. If the integrity verification is successful, the NF service producer further verifies the claims within the access token corresponding to the first service. For details, please refer to the relevant content of the verification regarding the claims within the access token. The NF service producer needs to further authenticate the NF service consumer based on CCA1.

[0664] The NF service producer verifies the signature of CCA1, verifies whether CCA1 has expired based on the timestamp and / or expiration date of CCA1, and verifies whether the NF instance ID of the NF service consumer within CCA1 matches the NF instance ID within the certificate for signing the CCA. In addition to the success of all the above verification contents, the NF service producer needs to further verify whether the first NF type included in CCA1 matches the NF type of the NF service producer. Since the first NF type matches the NF type of the NF service producer, the NF service producer determines that the authentication of the NF service consumer is successful.

[0665] Step 1808: If the NF service producer determines that the verification of the first access token is successful and the authentication of the NF service consumer is successful, the NF service producer sends a response message for the second service request message to the SCP. The response message for the second service request message indicates either providing the first service or the success of the second service request.

[0666] If the verification of the first access token fails and / or the authentication of the NF service consumer fails, it will be understood that the response message for the second service request message indicates that the first service request has failed.

[0667] Step 1809: The SCP receives a response message for the second service request message from the NF service producer and sends a response message for the first service request message to the NF service consumer.

[0668] In addition, if the NF service consumer determines that the SCP does not need to be triggered to execute the NF service producer discovery procedure, the NF service consumer may determine whether a usable CCA1 is stored. If a usable CCA1 is stored, the CCA1 is used. If a usable CCA1 is not stored, a CCA1 is generated. In this case, it will be understood that the NF service consumer does not need to determine whether a usable CCA2 is stored. Even if a usable CCA2 is not stored, the NF service consumer does not need to generate a CCA2. The first service request message may not include a CCA2. However, if the NF service consumer determines that the current indirect communication mode is mode D before step 1801, the first service request message needs to carry a CCA1 and a CCA2.

[0669] In the foregoing embodiment, the CCA1 includes a first NF type, and the CCA2 includes a second NF type. Thereby, it can be ensured that the NRF authenticates the NF service consumer normally based on the CCA1, and the NF service producer authenticates the NF service consumer normally based on the CCA2, and it can be further ensured that the NF service consumer obtains the first service.

[0670] Embodiment 7: Referring to the embodiments shown in FIGS. 8 and 10, the NF service consumer obtains indication information, the NF service consumer sends a service request message to the SCP based on the indication information, and the NF service consumer may obtain the first service according to the following embodiments, but is not limited thereto, as shown in FIGS. 19A and 19B.

[0671] Step 1901: The NF service consumer obtains CCA1.

[0672] It will be understood that the NF service consumer may further determine that the current indirect communication mode is mode D before step 1901.

[0673] The NF service consumer determines to request the first service, and the NF service consumer obtains CCA1. Before the NF service consumer generates CCA1, the NF service consumer needs to determine whether the available CCA1 is stored locally. If the available CCA1 is stored (for example, if the CCA1 is not expired), the CCA1 is used. If the available CCA1 is not stored (for example, if the CCA1 is expired or the CCA1 is not stored), the NF service consumer generates CCA1. In addition, if the CCA1 has expired, the NF service consumer deletes the expired CCA1.

[0674] CCA1 includes the NF instance identifier of the NF service consumer, a timestamp, the expiration date of CCA1, and the first NF type, and the first NF type is the NF type of the NF service producer expected to provide the first service.

[0675] Step 1902: The NF service consumer sends a first service request message to the SCP. The first service request message includes the CCA1 in step 1901. The first service request message is used to request the first service.

[0676] Step 1903: The SCP sends a second service request message to the NRF. The second service request message includes the CCA1. The second service request message is used to request the second service.

[0677] Step 1904: The NRF receives the second service request message, and the NRF fails to authenticate the NF service consumer based on the CCA1.

[0678] The NRF verifies the signature of the CCA1, verifies whether the CCA1 has expired based on the timestamp and / or expiration date of the CCA1, and verifies whether the NF instance ID of the NF service consumer in the CCA1 matches the NF instance ID in the certificate for signing the CCA1. In addition to the success of all the above verifications, the NRF needs to further verify whether the first NF type included in the CCA1 matches the NF type of the NRF. Since the first NF type does not match the NF type of the NRF, the NRF determines that the authentication of the NF service consumer has failed.

[0679] Step 1905: The NRF sends a response message for the second service request message to the SCP. The response message for the second service request message includes the CCA2. The CCA2 includes the NF instance identifier of the NRF, the timestamp, the expiration date, the NF type of the NF service consumer, and the NF type of the NRF.

[0680] Step 1906: The SCP sends a response message for the first service request message to the NF service consumer. The response message for the first service request message includes CCA2.

[0681] Step 1907: The NF service consumer sends a third service request message to the SCP. The third service request message includes CCA3 and CCA4, or the third service request message includes CCA5.

[0682] CCA3 includes the NF instance identifier of the NF service consumer, a timestamp, the expiration period of CCA3, and the first NF type.

[0683] CCA4 includes the NF instance identifier of the NF service consumer, a timestamp, the expiration period of CCA4, and the second NF type.

[0684] CCA5 includes the NF instance identifier of the NF service consume...

Claims

1. A communication method, the method comprising: a step of determining, by a service consumer network element, to trigger a service communication proxy such that a first service request message requests a second service, wherein the first service request message is used to request a first service from a service producer network element, the first service request message includes a first client eligibility information assertion, the first client eligibility information assertion is used to authenticate the service consumer network element, the first client eligibility information assertion includes a first network function type and a second network function type, the first network function type is the network function type of the service producer network element, the second network function type is the network function type of the network element providing the second service, and the second service is used to provide information about the service producer network element; a step of transmitting, by the service consumer network element, the first service request message to the service communication proxy; a step of receiving, by the service consumer network element, a response message to the first service request message from the service communication proxy A communication method comprising the above steps.

2. Before the step of determining, by the service consumer network element, to trigger the service communication proxy such that the first service request message requests the second service, a case where the context of the first terminal device is not stored and the first terminal device is associated with the first service; a case where the context of the first service is not stored; a case where the service producer network element belongs to a first slice and the context corresponding to the first slice is not stored; or a case where the service consumer network element communicates with the service communication proxy for the first time Based on one or more of the foregoing, a step of determining by the service consumer network element The method according to claim 1, comprising:

3. A step of determining by the service consumer network element to request the first service in an indirect communication mode, i.e., mode D The method according to claim 1, further comprising:

4. The method is A step of transmitting, by the service consumer network element, a second service request message to the service communication proxy, wherein the second service request message is used to request the first service, the second service request message includes a second client qualification information assertion, the second client qualification information assertion includes the first network function type, and the second client qualification information assertion is used to authenticate the service consumer network element; A step of receiving, by the service consumer network element, a response message to the second service request message from the service communication proxy, wherein the response message to the second service request message includes indication information; Further comprising The step of transmitting, by the service consumer network element, a first service request message to the service communication proxy is A step of transmitting, by the service consumer network element, the first service request message to the service communication proxy based on the indication information Including The method according to claim 1.

5. The indication information includes a third client qualification information assertion, the third client qualification information assertion includes the second network function type, and the third client qualification information assertion is used to authenticate the network element providing the second service. The step of transmitting, by the service consumer network element, the first service request message to the service communication proxy based on the indication information is When the authentication based on the third client eligibility information assertion for the network element providing the second service is successful, the step of transmitting the first service request message to the service communication proxy by the service consumer network element comprising The method according to claim 4.

6. The method according to claim 1, wherein the network element providing the second service is a network repository function network element.

7. The first client eligibility information assertion further includes one or more of an identifier of the service consumer network element or expiration time information, and the expiration time information represents the expiration time of the first client eligibility information assertion The method according to claim 1.

8. A communication device, a memory for storing instructions, executing the instructions to cause the device to determine to trigger a service communication proxy such that a first service request message requests a second service, the first service request message is used to request a first service from a service producer network element, the first service request message includes a first client eligibility information assertion, the first client eligibility information assertion is used to authenticate the device, the first client eligibility information assertion includes a first network function type and a second network function type, the first network function type is the network function type of the service producer network element, the second network function type is the network function type of the network element providing the second service, and the second service is used to provide information about the service producer network element transmit the first service request message to the service communication proxy, receive a response message to the first service request message from the service communication proxy, a processor and a communication device comprising.

9. The communication device according to claim 8, wherein when the instructions are executed by the processor, the device is further determined to request the first service in an indirect communication mode, that is, mode D.

10. The communication device according to claim 8, wherein the network element that provides the second service is a network repository function network element.

11. The communication device according to claim 8, wherein the first client eligibility information assertion further includes one or more of an identifier of the device or validity time information, and the validity time information represents the validity time of the first client eligibility information assertion.

12. A computer-readable storage medium storing a computer program or instructions, wherein when the computer program or instructions are executed by a communication device, the method according to any one of claims 1 to 7 is implemented.

13. A communication system comprising a service consumer network element and a service communication proxy, wherein the service consumer network element is configured to determine to trigger the service communication proxy such that a first service request message requests a second service, the first service request message being used to request a first service from a service producer network element, the first service request message including a first client eligibility information assertion, the first client eligibility information assertion being used to authenticate the service consumer network element, the first client eligibility information assertion including a first network function type and a second network function type, the first network function type being the network function type of the service producer network element, the second network function type being the network function type of the network element that provides the second service, and the second service being associated with the first service, the service consumer network element is further configured to send the first service request message to the service communication proxy, the service communication proxy is configured to receive the first service request message and send a response message to the first service request message to the service consumer network element. The service consumer network element is further configured to receive the response message for the first service request message from the service communication proxy, Communication system.

14. The system according to claim 13, wherein the service consumer network element is further configured to determine to request the first service in an indirect communication mode, i.e., mode D.

15. The system further comprises a network element for providing the second service, After receiving the first service request message from the service consumer network element, the service communication proxy is further configured to send a second service request message to the network element for providing the second service, the second service request message is used to request the second service, and the second service request message includes the first client qualification information assertion, The network element for providing the second service is configured to receive the second service request message from the service communication proxy and authenticate the service consumer network element based on the first client qualification information assertion. Authenticating the service consumer network element based on the first client qualification information assertion includes determining whether the network function type of the network element for providing the second service matches one or more of the first network function type and the second network function type, and when the authentication for the service consumer network element is successful, sending a response message for the second service request message to the service communication proxy, and the response message for the second service request message indicates that the second service is provided. The system according to claim 13.

16. The first client qualification information assertion further includes one or more of an identifier of the service consumer network element or validity time information, and the validity time information represents the validity time of the first client qualification information assertion. The network element providing the second service is configured to authenticate the service consumer network element based on the first client qualification information assertion, further comprising verifying whether the signature of the first client qualification information assertion is successful, verifying whether the first client qualification information assertion has expired based on the validity time information included in the first client qualification information assertion, and verifying whether the identifier of the service consumer network element in the first client qualification information assertion is the same as the identifier of the network element in the certificate for signing the first client qualification information assertion, including one or more of: The system according to claim 15.

17. The system according to claim 13, wherein the network element providing the second service is a network repository function network element.

18. The system according to claim 13, wherein the second service is used to provide information about the service producer network element.

19. The system further comprises the service producer network element, wherein when the authentication for the service consumer network element is successful, the service communication proxy receives the response message for the second service request message from the network element providing the second service, and based on the response message for the second service request message, transmits a third service request message to the service producer network element, the third service request message is used to request the first service, and the third service request message further comprises the first client qualification information assertion. The service producer network element receives the third service request message from the service communication proxy and is configured to authenticate the service consumer network element based on the first client qualification information assertion. Authenticating the service consumer network element based on the first client qualification information assertion includes determining whether the network function type of the service producer network element matches one or more of the first network function type and the second network function type, and when the authentication of the service consumer network element is successful, sending a response message for the third service request message to the service communication proxy, where the response message for the third service request message indicates providing the first service. The system according to claim 15.

20. The first client qualification information assertion further includes one or more of an identifier of the service consumer network element or validity time information, and the validity time information represents the validity time of the first client qualification information assertion. The service producer network element being configured to authenticate the service consumer network element based on the first client qualification information assertion includes verifying whether the signature of the first client qualification information assertion is successful, verifying whether the first client qualification information assertion has expired based on the validity time information included in the first client qualification information assertion, or verifying whether the identifier of the service consumer network element in the first client qualification information assertion is the same as the identifier of the network element in the certificate for signing the first client qualification information assertion. further including one or more of The system according to claim 19.

21. A communication method, the method comprising A step of determining by a service consumer network element to trigger a service communication proxy so that a first service request message requests a second service, wherein the first service request message is used to request a first service from a service producer network element, the first service request message includes a first client qualification information assertion, the first client qualification information assertion is used to authenticate the service consumer network element, the first client qualification information assertion includes a first network function type and a second network function type, the first network function type is the network function type of the service producer network element, the second network function type is the network function type of the network element providing the second service, and the second service is associated with the first service, step; A step of transmitting, by the service consumer network element, the first service request message to the service communication proxy; A step of receiving, by the service communication proxy, the first service request message from the service consumer network element; A step of transmitting, by the service communication proxy, a response message to the first service request message to the service consumer network element A communication method comprising.

22. The method according to claim 21, wherein the second service is used to provide information about the service producer network element.

23. A step of determining by the service consumer network element to request the first service in an indirect communication mode, i.e., mode D The method according to claim 21, further comprising.

24. The method is A step of transmitting, by the service consumer network element, a second service request message to the service communication proxy, wherein the second service request message is used to request the first service, the second service request message includes a second client qualification information assertion, the second client qualification information assertion includes the first network function type, and the second client qualification information assertion is used to authenticate the service consumer network element; A step of receiving, by the service communication proxy, a second service request message from the service consumer network element; A step of transmitting, by the service communication proxy, a response message to the second service request message to the service consumer network element, wherein the response message to the second service request message includes indication information; Further comprising; The step of transmitting, by the service consumer network element, a first service request message to the service communication proxy is: A step of transmitting, by the service consumer network element, the first service request message to the service communication proxy based on the indication information Including; The method according to claim 21.

25. The indication information includes a third client qualification information assertion, the third client qualification information assertion includes the second network function type, and the third client qualification information assertion is used to authenticate the network element providing the second service; The step of transmitting, by the service consumer network element, the first service request message to the service communication proxy based on the indication information is: When the authentication based on the third client qualification information assertion for the network element providing the second service is successful, a step of transmitting, by the service consumer network element, the first service request message to the service communication proxy Including; The method according to claim 24.

26. The method according to claim 21, wherein the network element providing the second service is a network repository function network element. **Claim 27** The method according to claim 21, wherein the first client entitlement information assertion further includes one or more of an identifier of the service consumer network element or validity time information, and the validity time information represents a validity time of the first client entitlement information assertion.

Citation Information

Patent Citations

  • Method and apparatus for network function service discovery

    WO2021027177A1

Cited By

  • Communication methods and devices

    KR1020240005900A

  • Communication method and device

    KR102969913B1