Communication method and communication apparatus

By providing a communication method in a communication network, allowing devices to store and publish their identity information in the network, the problem of data storage services being not open in the prior art is solved, and convenient management and authentication of users and third parties are realized.

WO2025103482A1PCT designated stage expired Publication Date: 2025-05-22HUAWEI TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/132434
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-17
Filing Date
2024-11-15
Publication Date
2025-05-22

AI Technical Summary

Technical Problem

In communication networks, it is difficult for the prior art to provide open data storage services for users and third-party devices, resulting in inconvenient management of device identity or attribute information.

Method used

By providing a communication method, the first device is allowed to send a request message to a network element in the communication network to store and publish its device identity information, so that other devices can obtain and use the information through the communication network for authentication, scheduling, deployment and other functions.

Benefits of technology

The communication network provides open data storage services for users and third-party devices, simplifies the management and interaction process of device identity information, and improves user experience and system security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024132434_22052025_PF_FP_ABST
    Figure CN2024132434_22052025_PF_FP_ABST
Patent Text Reader

Abstract

Provided in the present application are a communication method and a communication apparatus, which can enable a communication network to provide an open data storage service for a user and a third-party device, such that the terminal or the third-party device can store / publish device identity information thereof in the communication network. The method can be applied to a communication system. The method comprises: a first device acquiring a first request message, wherein the first request message is used for storing device identity information; and the first device sending the first request message to a first shared device, wherein the first shared device is a network element in a communication network.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method and communication device

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on November 17, 2023, with application number 202311546179.6 and application name “Communication Method and Communication Device”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of communication technology, and in particular to a communication method and a communication device. Background Art

[0003] Currently, the fields of information technology and communications technology require the maintenance of a large amount of device identity or attribute information. In some implementations, users can publish their public device identity information to a decentralized storage system, enabling autonomous management of user information.

[0004] However, in communications networks, core network elements are used to store traditional authentication information, subscriptions, and runtime state data (e.g., mobility status), or to store operational data within the operator's network elements. Each operator centrally manages its internal data and does not open its data storage services to users or third parties. Summary of the Invention

[0005] The embodiments of the present application provide a communication method and a communication device, which enable a communication network to provide open data storage services to users and third-party devices, so that terminals or third-party devices can store / publish their device identity information in the communication network.

[0006] To achieve the above objectives, this application adopts the following technical solutions:

[0007] In a first aspect, a communication method is provided. The communication method includes: a first device obtaining a first request message. The first request message is used to store device identity information. The first device sends the first request message to a first shared device. The first shared device is a network element in a communication network.

[0008] Based on the method provided in the first aspect, the first shared device can obtain the device identity information of the first device, and then store the device identity information on the first shared device, so that other devices can obtain the device identity information through network elements in the communication network, and perform authentication, scheduling, deployment, service provision, etc. according to the device identity information.

[0009] In a possible implementation, the device identity information includes a device type of the first device and / or a device type of the second device.

[0010] In this implementation, the device identity information also includes the device type, which allows the device that obtains the device identity information to implement different authentication, scheduling, deployment, service provision and other functions for different device types.

[0011] In a possible implementation, the device type may include: a 3rd Generation Partnership Project 3GPP terminal, an operator's network element, or a non-3GPP terminal.

[0012] In one possible implementation, the first device is a 3GPP terminal, and the first request message may further indicate authentication information of the first device. The authentication information of the first device may be used to authenticate the terminal for network access, thereby preventing unauthenticated terminals from accessing the network and making communications more secure.

[0013] In a possible implementation, the authentication information of the first device may include an access credential of the first device.

[0014] In a possible implementation, the first device sending the first request message to the first shared device may include: the first device sending the first request message to the first shared device through an authentication network element.

[0015] In a possible implementation, the first device is a non-3GPP terminal, and the first request message is further used to indicate information of an interface of a verification service, where the verification service is used to verify the non-3GPP terminal.

[0016] In one possible implementation, if the device identity information includes the device type of the first device, the device identity information also includes one or more of the following: the first identifier of the first device, the owner of the subject corresponding to the first device, information used to verify ownership of the first identifier, the subject type corresponding to the first device, the network domain identifier corresponding to the first identifier, the verifiable credentials corresponding to the first identifier, the services or service interfaces supported by the first device, and the encryption method corresponding to the first device. In other words, the first device can upload its own device identity information, thereby reducing the complexity of the interaction process.

[0017] In one possible implementation, if the device identity information includes the device type of the second device, the device identity information may also include one or more of the following: the second identifier of the second device, the device corresponding to the second identifier, information used to verify ownership of the second identifier, the subject type corresponding to the second device, the network domain identifier corresponding to the second identifier, the verifiable credential corresponding to the second identifier, the services or interactive interfaces supported by the second device, and the encryption method corresponding to the second device. In other words, the first device can send the device identity information of other devices, which has more application scenarios.

[0018] In a possible implementation, the first request message is also used to publish device identity information, so that other devices can obtain the device identity information of which devices are stored in the first shared device.

[0019] In one possible implementation, the method provided in the first aspect may further include: the first device receiving a first response message from the first sharing device. The first response message indicates whether the first sharing device successfully stored the device identity information. In this way, the storage result of the device identity information can be promptly fed back to the first device, thereby improving the user experience.

[0020] In one possible implementation, the method provided in the first aspect may further include: the first device sending a second request message to the second shared device. The second request message is used to request device identity information corresponding to the third device. The first device receives a second response message from the second shared device. The second response message is used to indicate the device identity information corresponding to the third device. In this way, the first device can query the device identity information of other devices from the communication network as needed.

[0021] In a second aspect, a communication method is provided. The communication method includes: a first sharing device receiving a first request message from a first device. The first request message is used to store device identity information. The first sharing device stores the device identity information in the first request message.

[0022] Based on the method provided in the first aspect, the first shared device can obtain the device identity information of the first device, and then store the device identity information on the first shared device, so that other devices can obtain the device identity information through network elements in the communication network, and perform authentication, scheduling, deployment, service provision, etc. according to the device identity information.

[0023] In a possible implementation, the device identity information includes a device type of the first device and / or a device type of the second device.

[0024] In a possible implementation, the device type may include: a 3rd Generation Partnership Project 3GPP terminal, an operator's network element, or a non-3GPP terminal.

[0025] In a possible implementation, the first device is a 3GPP terminal, and the first request message is further used to indicate authentication information of the first device.

[0026] In a possible implementation, the authentication information of the first device includes an access credential of the first device.

[0027] In a possible implementation, the first shared device receiving the first request message from the first device may include: the first shared device receiving the first request message from the first device through an authentication network element.

[0028] In one possible implementation, the first device is a 3GPP terminal, and the method provided in the second aspect may further include: the first shared device authenticating the first device through an authentication network element. The first shared device storing the device identity information in the first request message may include: if the first device is authenticated, the first shared device storing the device identity information in the first request message.

[0029] In a possible implementation, the first device is a non-3GPP terminal, and the first request message is further used to indicate information about an interface of an authentication service. The authentication service is used to authenticate the non-3GPP terminal.

[0030] In one possible implementation scheme, if the device identity information includes the device type of the first device, the device identity information includes one or more of the following: the device identity information includes one or more of the following: the first identifier of the first device, the owner of the subject corresponding to the first device, information used to verify the ownership of the first identifier, the subject corresponding to the first device, the network domain identifier corresponding to the first identifier, the verifiable credential corresponding to the first identifier, the services or service interfaces supported by the first device, and the encryption method corresponding to the first device.

[0031] In one possible implementation, if the device identity information includes the device type of the second device, the device identity information includes one or more of the following: the second identifier of the second device, the device corresponding to the second identifier, information used to verify the ownership of the second identifier, the subject corresponding to the second device, the network domain identifier corresponding to the second identifier, the verifiable credential corresponding to the second identifier, the services or interactive interfaces supported by the second device, and the encryption method corresponding to the second device.

[0032] In a possible implementation, the first request message is also used to publish device identity information. The method provided in the second aspect may further include: the first sharing device publishes the device identity information.

[0033] In a possible implementation, the method provided in the second aspect may further include: the first sharing device sending a first response message to the first device.

[0034] In a possible implementation, the method provided in the second aspect may further include: the first sharing device sending device identity information to the second sharing device.

[0035] In one possible implementation, the method provided in the second aspect may further include: the first sharing device receiving a third request message from a fourth device. The third request message is used to request device identity information corresponding to the fifth device. The first sharing device sends a third response message to the fourth device. The third response message is used to indicate the device identity information corresponding to the fifth device.

[0036] In a possible implementation, the method provided in the second aspect may further include: the first shared device authenticating the fourth device through the authentication service device.

[0037] Regarding the technical effects of the method provided in the second aspect, please refer to the relevant introduction of the method provided in the first aspect, and will not be repeated here.

[0038] In a third aspect, a communication method is provided. The communication method includes: a fourth device sending a third request message to a second shared device. The third request message is used to request device identity information corresponding to an identifier of a fifth device. The fourth device receives a third response message from the second shared device. The third response message includes the device identity information corresponding to the identifier of the fifth device.

[0039] Based on the communication method provided in the third aspect, the fourth device can request the attribute information corresponding to the identifier of the fifth device from the second sharing device, thereby obtaining the device identity information.

[0040] In a possible implementation, the third request message may further include information indicating an access credential of the fourth device. The access credential of the fourth device is used to verify the identity of the fourth device.

[0041] In a possible implementation, the third request message may further include information indicating a device type of the fourth device.

[0042] In a fourth aspect, a communication method is provided. The communication method includes: a second shared device receiving a third request message from a fourth device. The third request message is used to request device identity information corresponding to an identifier of a fifth device. The second shared device sends a third response message to the fourth device. The third response message includes the device identity information corresponding to the identifier of the fifth device.

[0043] In a possible implementation, the method provided in the fourth aspect may further include: the second sharing device parsing the identifier of the fifth device to obtain device identity information corresponding to the identifier of the fifth device.

[0044] In one possible implementation, the third request message is used to indicate information about the access credentials of the fourth device. The access credentials of the fourth device are used to authenticate the fourth device. The method provided in the fourth aspect may also include: the second shared device performing identity authentication with the second shared device based on the access credentials of the fourth device.

[0045] In a possible implementation, the third request message may further include information indicating a device type of the fourth device.

[0046] In addition, the technical effects of the communication method described in the fourth aspect can refer to the technical effects of the communication method described in the third aspect, and will not be repeated here.

[0047] In a fifth aspect, a communication device is provided, which is used to execute the communication method described in any one of the implementations of the first to fourth aspects.

[0048] In the present application, the communication device described in the fifth aspect can be the first device described in the first aspect, or the first shared device described in the second aspect, or the fourth device described in the third aspect, or the second shared device described in the fourth aspect, or a chip (system) or other parts or components that can be set in the first device, the first shared device, the fourth device or the second shared device, or a device that includes the first device, the first shared device, the fourth device or the second shared device.

[0049] It should be understood that the communication device described in the fifth aspect includes a module, unit, or means corresponding to the communication method described in any one of the first to fourth aspects above. The module, unit, or means can be implemented by hardware, software, or hardware executing the corresponding software implementation. The hardware or software includes one or more modules or units for performing the functions involved in the above-mentioned communication method.

[0050] In a sixth aspect, a communication device is provided, comprising: a processor configured to execute the communication method described in any possible implementation of the first to fourth aspects.

[0051] In one possible implementation, the communication device described in the sixth aspect may further include a transceiver. The transceiver may be a transceiver circuit or an interface circuit. The transceiver may be used for the communication device described in the sixth aspect to communicate with other communication devices.

[0052] In one possible implementation, the communication device described in aspect 6 may further include a memory. The memory may be integrated with the processor or provided separately. The memory may be used to store the computer program and / or data involved in the communication method described in any one of aspects 1 to 4. When the processor executes the computer program, the communication device executes the communication method described in any one of aspects 1 to 4.

[0053] In a possible implementation, the processor is coupled to the memory, and after reading the computer program in the memory, executes the communication method as described in any one of the implementations of the first to fourth aspects according to the computer program.

[0054] In the present application, the communication device described in the sixth aspect can be the first device described in the first aspect, or the first shared device described in the second aspect, or the fourth device described in the third aspect, or the second shared device described in the fourth aspect, or a chip (system) or other parts or components that can be set in the first device, the first shared device, the fourth device or the second shared device, or a device that includes the first device, the first shared device, the fourth device or the second shared device.

[0055] In a seventh aspect, a processor is provided, wherein the processor is configured to execute the communication method described in any possible implementation manner of the first to fourth aspects.

[0056] In an eighth aspect, a communication system is provided, which includes one or more terminal devices and one or more network devices.

[0057] In a ninth aspect, a computer-readable storage medium is provided, comprising: a computer program or instructions; when the computer program or instructions are run on a computer, the computer is caused to execute the communication method described in any possible implementation of the first to fourth aspects.

[0058] In a tenth aspect, a computer program product is provided, comprising a computer program or instructions, which, when executed on a computer, enables the computer to execute the communication method described in any one of the possible implementations of aspects one to four.

[0059] In addition, the technical effects of the communication devices described in the fifth to tenth aspects above can refer to the technical effects of the communication methods described in the first to fourth aspects above, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0060] FIG1 is a schematic diagram of the architecture of a communication system provided in an embodiment of the present application;

[0061] FIG2 is a flow chart of a communication method according to an embodiment of the present application;

[0062] FIG3 is a schematic diagram of a device identity information synchronization process according to an embodiment of the present application;

[0063] FIG4 is a second flow chart of the communication method provided in an embodiment of the present application;

[0064] FIG5 is a third flow chart of the communication method provided in an embodiment of the present application;

[0065] FIG6 is a fourth flow chart of a communication method according to an embodiment of the present application;

[0066] FIG7 is a fifth flow chart of a communication method according to an embodiment of the present application;

[0067] FIG8 is a sixth flow chart of a communication method according to an embodiment of the present application;

[0068] FIG9 is a first structural diagram of a communication device provided in an embodiment of the present application;

[0069] FIG10 is a second structural diagram of the communication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0070] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as wireless fidelity (WiFi) systems, vehicle-to-everything (V2X) communication systems, device-to-device (D2D) communication systems, Internet of Vehicles communication systems, 4th generation (4G) mobile communication systems, such as long term evolution (LTE) systems, fifth generation (5G) mobile communication systems, such as new radio (NR) systems, and future communication systems, such as sixth generation (6G) mobile communication systems.

[0071] This application will present various aspects, embodiments, or features in the context of systems that may include multiple devices, components, modules, etc. It should be understood and appreciated that each system may include additional devices, components, modules, etc., and / or may not include all of the devices, components, modules, etc. discussed in conjunction with the figures. Furthermore, combinations of these aspects may also be used.

[0072] Additionally, in the embodiments of this application, words such as "exemplarily" and "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or implementation described in this application as "exemplary" should not be construed as preferred or advantageous over other embodiments or implementations. Rather, the use of the word "exemplary" is intended to present concepts in a concrete manner.

[0073] In the embodiments of the present application, the terms "information," "signal," "message," "channel," and "signaling" may sometimes be used interchangeably. It should be noted that, when the distinction between them is not emphasized, the meanings they intend to convey are the same. The terms "of," "corresponding," and "corresponding" may sometimes be used interchangeably. It should be noted that, when the distinction between them is not emphasized, the meanings they intend to convey are the same.

[0074] In the embodiments of the present application, sometimes a subscript such as W1 may be mistakenly written as a non-subscript form such as W1. When the difference is not emphasized, the meanings to be expressed are the same.

[0075] The network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Ordinary technicians in this field will know that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.

[0076] Currently, the fields of information technology and communications technology require the maintenance of a large amount of device identity or attribute information. In some implementations, users can publish their public device identity information to a decentralized storage system, enabling autonomous management of user information.

[0077] However, in communications networks, core network elements are used to store traditional authentication information, subscriptions, and runtime state data (e.g., mobility status), or to store operational data within network elements within the operator's network. Each operator centrally manages its internal data and does not open its data storage services to users or third parties. Therefore, providing data storage services to users and third parties through operator networks is a pressing technical challenge.

[0078] To facilitate understanding, the following first introduces technical terms related to the embodiments of the present application.

[0079] Attribute information is information used to describe the characteristics of the identity corresponding to the device. The characteristics may be the identity characteristics of the device or the identity characteristics of the subject corresponding to the device.

[0080] The subject corresponding to the device can be a physical entity, such as the device itself. Alternatively, the subject corresponding to the device can be a logically organized unit, such as a person, an organization, or an enterprise. The subjects corresponding to the device listed here are only examples. In actual implementation, the subject corresponding to the device can also be implemented in other ways, which will not be detailed here.

[0081] Device identity information is a collection of device attribute information. A device identity information may include one or more attribute information corresponding to the device's identity. For example, an attribute information may include any of the following: the device type, the device's identity (ID), the owner of the subject corresponding to the device, information used to verify ownership of the first identifier, the subject type corresponding to the device, the network domain identifier corresponding to the device's identity, the verifiable credentials corresponding to the device's identity, the services or service interfaces supported by the device, or the encryption method corresponding to the device.

[0082] Among them, different attribute information can be identified by attribute indexes. For example, the attribute index corresponding to the device's identifier can be "identification", the index corresponding to the owner of the subject corresponding to the device can be "subject controller", the attribute index corresponding to the information used to verify the ownership of the first identifier can be "verification method", the attribute index corresponding to the subject type corresponding to the device can be "subject type", the attribute index corresponding to the device's identifier can be "network domain identifier", the attribute index corresponding to the verifiable credential corresponding to the device's identifier can be "verifiable credential", the attribute index corresponding to the service or service interface supported by the device can be "service interface", and the attribute index corresponding to the encryption method corresponding to the device can be "encryption method".

[0083] The attribute index, data type, whether it is required, quantity, and various interpretations corresponding to different attribute information are shown in Table 1.

[0084] Table 1

[0085] It can be understood that the above attribute indexes are only used as examples. In actual implementation, the above attribute indexes can also have other possible expressions. For example, the attribute index "identification" can also be expressed as "self-controlled identity identification" or "scId". The attribute index "subject type" can also be expressed as "sbjType". The attribute index "subject controller" can also be expressed as "sbjController". The attribute index "network domain identification" can also be expressed as "domaninId". The attribute index "verification method" can also be expressed as "verifyMethod". The attribute index "verifiable credentials" can also be expressed as "assertion method" or "assertMethod". The attribute index "support service" can also be expressed as "service". The attribute index "encryption method" can also be expressed as "point-to-point communication encryption method" or "keyAgreeMethod".

[0086] It should be understood that whether each type of attribute information in Figure 1 above is necessary is only for example. In actual implementation, the attribute information included may be different for different nodes or different node identifiers. For example, the attribute information corresponding to the node or the node identifier can be determined based on the scenario in which the node is located.

[0087] In some possible implementations, the verifiable credential may include a verifiable credential (VC) for the subject's access to the operator's network. This VC may include the identity of the operator issuing the VC and certification information. This certification information can be used to prove the legitimacy of the subject's corresponding device and the address for obtaining subscription data. For example, if the subject's corresponding device is a terminal, this certification information can be used to prove that "the terminal is legitimate."

[0088] In some possible implementations, device identity information may include identification information and profile information. The identification information and profile information are generated and stored separately. The identification information may include the device's identifier, while the profile information may include attribute information other than the identifier in the device's identity information. This allows different types of information to be stored or read separately, reducing the leakage of attribute information and making data processing, such as publishing, more flexible.

[0089] In some possible implementations, device identity information may include identification information and file information. The identification information and file information are generated and stored separately. The identification information may include the device's identification and information that verifies the device's identity, such as a verifiable credential. The file information may include other information in the device identity information, in addition to the device's identification and information that verifies the device's identity. This allows file information to be generated as needed, reducing the amount of stored data.

[0090] It should be understood that the attribute index may also be called the attribute name, or other possible names.

[0091] In some possible implementations, the attribute information may also be implemented using fixed fields. In this case, the attribute information corresponding to each attribute index corresponds to one field. In other words, the attribute information corresponding to each attribute index is carried in one field.

[0092] The attribute information corresponding to the attribute index refers to the attribute information that can be identified by the attribute index. The attribute index corresponding to the attribute information refers to the attribute information that can be identified by the attribute index. The technical solution in this application will be described below with reference to the accompanying drawings.

[0093] To facilitate understanding of the embodiments of the present application, a communication system applicable to the embodiments of the present application is first described in detail using the communication system shown in Figure 1 as an example. For example, Figure 1 is a schematic diagram of the architecture of a communication system applicable to the communication method provided in the embodiments of the present application.

[0094] As shown in FIG. 1 , the communication system includes first-category devices (such as first-category devices 101 a to 101 c ), second-category devices (such as second-category devices 102 a and 102 b ), and a first-category shared device 103 .

[0095] The first type of devices (such as the first type of devices 101a to 101c ) and the second type of devices (such as the second type of devices 102a and 102b ) can all exchange information with the first type of shared device 103 .

[0096] The first type of devices (such as the first type of devices 101a to 101c) may be 3rd Generation Partnership Project (3GPP) terminals. The second type of devices (such as the second type of devices 102a and 102b) may be non-3GPP terminals.

[0097] A 3GPP terminal is a terminal that uses 3GPP access when accessing a network, and a non-3GPP terminal is a terminal that uses non-3GPP access when accessing a network. In other words, the same terminal has different types of terminals when using different access types.

[0098] The first type of shared device is a network element in a communication network, such as a network element in a core network. For example, the first type of shared device may be a decentralized shared profile repository (dSPR). A communication system may include one or more first type of shared devices.

[0099] In addition, the communication system shown in Figure 1 may further include an authentication network element, which may be used to authenticate the 3GPP terminal. For example, the authentication network element may be an authentication server function (AUSF) network element.

[0100] The communication system shown in Figure 1 may also include other network elements, such as network functions (NFs). For example, the NFs may be unified data management (UDM), authentication server function (AUSF), policy control function (PCF), or unified data repository (UDR). Furthermore, the communication system shown in Figure 1 may also include access network equipment.

[0101] The communication system shown in FIG1 may further include one or more authentication service devices (not shown in FIG1 ). The authentication service device may be a network element or device that can provide verification services.

[0102] In some possible implementations, the authentication service device may be used to authenticate devices in the network. For example, the authentication service device may be used to verify the identity of the device, such as whether the device is a device authenticated by the core network or whether the device is legal or valid.

[0103] In some possible implementations, the authentication service device can be used to authenticate non-3GPP terminals. For example, the authentication service device can be the authentication server of the device provider that initiates the authentication process. For example, if the device that initiates the authentication process is a terminal, the device provider is the terminal manufacturer, and the authentication service device can be the terminal manufacturer's authentication server. For example, if the device that initiates the authentication process is a card with communication capabilities, the device provider is the card manufacturer, and the authentication service device can be the card manufacturer's authentication server. The device provider can also be referred to as the device manufacturer or other names, which are not limited in the embodiments of the present application.

[0104] The communication system shown in FIG1 may further include a second type of shared device, wherein the second type of shared device is a device with a storage function, for example, the second type of shared device may be a device in a non-3GPP network.

[0105] The above-mentioned terminal is a terminal that accesses the above-mentioned communication system and has a transceiver function, or a chip or chip system that can be set in the terminal, or a unit or module with terminal function. The terminal can also be called a terminal device, and can also be called user equipment (UE), mobile station (MS), mobile terminal (MT), etc., or a device used to provide voice or data connectivity to users, or an Internet of Things device. For example, the terminal includes a handheld device with wireless connection function, a vehicle-mounted device, etc. Currently, terminals can be: mobile phones, tablets, laptops, PDAs, mobile internet devices (MIDs), wearable devices (such as smart watches, smart bracelets, pedometers, smart glasses, etc.), vehicle-mounted equipment (such as cars, bicycles, electric vehicles, airplanes, ships, trains, high-speed trains, etc.), satellite terminals, virtual reality (VR) devices, augmented reality (AR) devices, smart point of sale (POS) machines, customer-premises equipment (CPE), wireless terminals in industrial control, smart home devices (such as refrigerators, televisions, air conditioners, electricity meters, etc.), intelligent robots, robotic arms, workshop equipment, wireless terminals in unmanned driving, wireless terminals in telemedicine, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, or wireless terminals in smart homes, flying equipment (such as intelligent robots, hot air balloons, drones, airplanes), etc. The terminal can also be a vehicle device, such as a complete vehicle device, a vehicle-mounted module, a vehicle-mounted chip, an on-board unit (OBU) or a telematics box (T-BOX), etc. The terminal can also be other devices with terminal functions. For example, the terminal can also be a device that serves as a terminal in D2D communication.

[0106] The terminal of the present application may also be a module or unit that can be used to implement terminal functions. For example, the terminal may also be a universal integrated circuit card (UICC) or a blockchain universal integrated circuit card (B-UICC).

[0107] The embodiments of this application do not limit the device form factor of the terminal. The device used to implement the terminal's function can be a terminal; it can also be a device that supports the terminal in implementing the function, such as a chip system. The device can be installed in the terminal or used in conjunction with the terminal. In the embodiments of this application, the chip system can be composed of a chip or include a chip and other discrete components.

[0108] In one possible scenario, an access network device can be a base station, an evolved NodeB (eNodeB), a transmitting and receiving point (TRP), a transmitting point (TP), a next-generation NodeB (gNB), a next-generation base station in a sixth-generation (6G) mobile communication system, a base station in a future mobile communication system, a satellite, an access point (AP) in a WiFi system, an integrated access and backhaul (IAB) node, or an access network device in a mobile switching center non-terrestrial network (NTN) communication system, i.e., it can be deployed on a high-altitude platform or satellite. The access network device can be a macro base station, a micro base station, an indoor station, a relay node or a donor node, or a wireless controller in a cloud radio access network (CRAN) scenario. The access network device can also be a device that functions as a base station in device-to-device (D2D) communication, vehicle-to-vehicle communication, drone communication, or machine communication. Optionally, the access network device may also be a server, a wearable device, a vehicle or an onboard device, etc. For example, the access network device in vehicle to everything (V2X) technology may be a road side unit (RSU).

[0109] In another possible scenario, multiple access network devices collaborate to assist the terminal in achieving wireless access, and different access network devices respectively implement part of the functions of the base station. For example, the access network device can be a centralized unit (CU), a distributed unit (DU), a CU-control plane (CP), a CU-user plane (UP), or a radio unit (RU). The CU and DU can be set separately, or they can also be included in the same network element, such as a baseband unit (BBU). The RU can be included in a radio frequency device or a radio frequency unit, such as a remote radio unit (RRU), an active antenna unit (AAU), or a remote radio head (RRH). It can be understood that the access network device can be a CU node, a DU node, or a device including a CU node and a DU node. In addition, the CU can be divided into an access network device in the radio access network (RAN), or the CU can be divided into an access network device in the core network (CN), without limitation here.

[0110] In different systems, CU (or CU-CP and CU-UP), DU or RU may also have different names, but those skilled in the art can understand their meanings. For example, in an open RAN (open RAN, ORAN) system, CU may also be called O-CU (open CU), DU may also be called O-DU, CU-CP may also be called O-CU-CP, CU-UP may also be called O-CU-UP, and RU may also be called O-RU. For the convenience of description, this application uses CU, CU-CP, CU-UP, DU and RU as examples for description. Any unit of CU (or CU-CP, CU-UP), DU and RU in this application can be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.

[0111] It should be noted that the communication method provided in the embodiment of the present application can be applicable between any two devices shown in Figure 1, such as between terminal devices, between network devices, and between terminal devices and network devices. The specific implementation can refer to the following method embodiment, which will not be repeated here.

[0112] It should be noted that the solutions in the embodiments of the present application can also be applied to other communication systems, and the corresponding names can also be replaced by the names of corresponding functions in other communication systems.

[0113] It should be understood that FIG1 is only a simplified schematic diagram for ease of understanding, and the communication system may also include other network devices and / or other terminal devices, which are not shown in FIG1 .

[0114] The communication method provided in the embodiment of the present application will be described in detail below with reference to Figures 2 to 8.

[0115] For example, Figure 2 is a flow chart of a communication method according to an embodiment of the present application. The communication method can be applied to the communication between the nodes shown in Figure 1 .

[0116] As shown in FIG2 , the communication method includes the following steps:

[0117] S201: A first device obtains a first request message.

[0118] Among them, the first device can be a device in a 3GPP network, a device in a non-3GPP network, or a device corresponding to an operator. That is, the first device can be a first-category device or a second-category device in the communication system provided in Figure 1. In other words, the first device can be a device with an access type of 3GPP access, in which case the first device can communicate through the 3GPP network. Alternatively, the first device can be a device with an access type of non-3GPP access, in which case the first device can communicate through the non-3GPP network. The first device can also be an access network device of an operator, a device in an operator's core network, or a server of an operator. In one possible implementation scheme, the device type may include: a Third Generation Partnership Project 3GPP terminal, an operator's network element, or a non-3GPP terminal. That is, for a terminal, the device type is the access type of the terminal.

[0119] The first request message is used to store the device identity information, that is, to request the storage of the device identity information. The first request message may carry the device identity information. For the implementation of the device identity information, please refer to the relevant introduction of the above technical terms, which will not be repeated here.

[0120] In one possible implementation, the device identity information may include the device identity information corresponding to the first device and / or the device identity information corresponding to the second device. The device identity information corresponding to the first device includes the device type of the first device, and the device identity information corresponding to the second device may include the device type of the second device. In this implementation, the device identity information also includes the device type, allowing the device obtaining the device identity information to implement different authentication, scheduling, deployment, service provision, and other functions for different device types.

[0121] In one possible implementation, the device identity information of the first device may also include one or more of the following: the first identifier of the first device, the owner of the subject corresponding to the first device, information used to verify the ownership of the first identifier, the subject type corresponding to the first device, the network domain identifier corresponding to the first identifier, the verifiable credential corresponding to the first identifier, the services or service interfaces supported by the first device, and the encryption method corresponding to the first device.

[0122] For the implementation of the attribute information corresponding to the first device, please refer to the relevant introduction in the technical terminology introduction section, which will not be repeated here.

[0123] In one possible implementation, the device identity information of the second device may also include one or more of the following: the second identifier of the second device, the device corresponding to the second identifier, information used to verify the ownership of the second identifier, the subject type corresponding to the second device, the network domain identifier corresponding to the second identifier, the verifiable credential corresponding to the second identifier, the services or interactive interfaces supported by the second device, and the encryption method corresponding to the second device.

[0124] For the implementation of the attribute information corresponding to the first device, please refer to the relevant introduction in the technical terminology introduction section, which will not be repeated here.

[0125] It is understood that in some possible implementations, the first request message may also carry a subtype of the first device or the second device. For example, the subtype is used to indicate whether the first device or the second device is a mobile phone, a car, or an Internet of Things (IoT) device.

[0126] S202: The first device sends a first request message to the first sharing device. Correspondingly, the first sharing device receives the first request message from the first device.

[0127] The first shared device is a network element in a communication network. The communication network may be a 3GPP network. For example, the first shared device may be a first type of shared device in the communication system provided in FIG. 1 .

[0128] S203: The first sharing device stores the device identity information in the first request message.

[0129] In a possible implementation, the first request message is also used to publish the device identity information. In this case, the method provided in FIG2 may further include S204.

[0130] S204: The first sharing device publishes device identity information.

[0131] The first sharing device may send first information, where the first information is used to indicate that device identity information is stored in the first sharing device.

[0132] It is understandable that the first sharing device may publish the device identity information in a broadcast, multicast or unicast manner.

[0133] It is understood that the execution order in the embodiments of the present application is for example only. In actual implementation, different steps can be executed in other orders as long as they are logical. For example, S204 can be executed after S203, or S204 can be executed together with S203.

[0134] Based on the method provided in Figure 2, the first shared device can obtain the device identity information of the first device, and then store the device identity information on the first shared device, so that other devices can obtain the device identity information through network elements in the communication network, and perform authentication, scheduling, deployment, service provision, etc. based on the device identity information.

[0135] In a possible implementation, the method provided in the first aspect may further include S205.

[0136] S205: The first sharing device sends a first response message to the first device. Correspondingly, the first device receives the first response message from the first sharing device.

[0137] The first response message is used to indicate whether the first shared device successfully stored the device identity information. For example, the first response message may be used to indicate that the first shared device successfully stored the device identity information. For another example, the first response message may be used to indicate that the first shared device failed to store the device identity information.

[0138] It is understandable that, when the solution provided in FIG. 2 includes S204 , the first response message may also be used to indicate whether the device identity information is successfully released.

[0139] In addition, the method provided in FIG2 may further include one or more of the following Designs 1 to 3. Designs 1 to 3 are described below respectively.

[0140] In Design 1, the first device may also obtain the device identity information of other devices from the second sharing device. In this case, the method provided in FIG2 may further include S206 and S207.

[0141] S206: The first device sends a second request message to the second sharing device. Correspondingly, the second sharing device receives the second request message from the first device.

[0142] The second request message is used to request device identity information corresponding to the third device.

[0143] The second request message may carry an identifier of the third device, and the identifier may correspond to device identity information of the third device.

[0144] The implementation principles of the second shared device can refer to those of the first shared device. It should be understood that the second shared device can be the same as the first shared device, i.e., the second shared device can be a first-category shared device. For example, the second shared device can be a first-category shared device. Alternatively, the second shared device can be different from the first shared device, for example, the second shared device can be a second-category shared device.

[0145] S207: The second sharing device sends a second response message to the first device. Correspondingly, the first device receives the second response message from the second sharing device.

[0146] The second response message is used to indicate the device identity information corresponding to the third device.

[0147] It is understood that S207 can be performed when the first device passes the authentication. In this case, the method provided in FIG2 may further include: the second shared device authenticates the first device. The principle of the second shared device authenticating the first device can be referred to the relevant description of S209 below and will not be repeated here.

[0148] Design 2: The first sharing device may provide device identity information for the fourth device. In this case, the method provided in FIG. 2 may further include S208 to S210.

[0149] S208: The fourth device sends a third request message to the first sharing device. Correspondingly, the first sharing device receives the third request message from the fourth device.

[0150] The fourth device may be a device of the first category or a device of the second category. The third request message is used to request device identity information corresponding to the fifth device.

[0151] In one possible implementation, the third request message may carry information indicating the fifth device, such as an identifier of the fifth device. The third request message also includes identity information of the fourth device, such as a subscription concealed identifier (SUCI), a username and password pair, or a temporary verification code.

[0152] S209: The first sharing device authenticates or verifies the fourth device.

[0153] The following explains different situations.

[0154] In scenario 1, if the fourth device is a Category 1 device, the first shared device accesses the authentication network element corresponding to the fourth device and sends an authentication request to the authentication network element. This authentication request includes the fourth device's identity information, for example, its identifier (SUCI), carried in the third request message. The authentication network element verifies the provided fourth device's identity information, determines whether authentication is successful, and returns the authentication result to the first shared device.

[0155] Scenario 2: If the fourth device is a second-category device, the first shared device accesses the authentication service device for the fourth device (for example, the fourth device can access the authentication server through the interface of the authentication service), and sends a verification request to the authentication service device. The verification request contains the identity information provided by the fourth device in the third request message (for example, a username and password pair, or a temporary verification code, etc.). The authentication service device verifies the identity information of the provided fourth device to determine whether the verification is successful, and returns the verification result to the first shared device. Among them, the authentication service device can be the verification server of the fourth device provider. The authentication service device has a corresponding relationship with the device provider's verification service address, and the authentication service device can be determined based on the device provider's verification service address.

[0156] In some possible implementations, the authentication service device may be a device corresponding to a blockchain node in a blockchain system.

[0157] In scenario 2, the first request message is further used to indicate information of an interface of an authentication service, where the authentication service is used to authenticate the non-3GPP terminal.

[0158] S210: The first sharing device sends a third response message to the fourth device. Correspondingly, the fourth device receives the third response message from the first sharing device.

[0159] The third response message is used to indicate the device identity information corresponding to the fifth device.

[0160] It is understood that in Design 2, S209 is an optional step. In the case that S209 is present in Design 2, S210 can be executed when the fourth device is successfully authenticated.

[0161] In Design 3, the first shared device may store the device identity information on a second shared device. In this case, the second shared device may be of the same type as the first shared device, i.e., a device in a 3GPP network, or may be of a different type than the first shared device, e.g., a device in a non-3GPP network. The method provided in FIG2 may further include S211.

[0162] S211: The first sharing device shares device identity information with the second sharing device.

[0163] In this case, the second shared device is different from the first shared device.

[0164] The second shared device may be the first type of shared device or the second type of shared device.

[0165] Regarding the implementation principle of S211, reference may be made to the flowchart of sharing device identity information shown in FIG3 below.

[0166] As shown in FIG3 , the process of sharing device identity information includes steps S211 a to S211 f.

[0167] S211a: The first sharing device negotiates a communication handshake protocol type with the second sharing device.

[0168] The first sharing device sends a communication protocol supported by the first sharing device to the second sharing device. For example, the communication protocol may be a secure communication protocol.

[0169] The second sharing device selects a communication protocol from the communication protocols supported by the first sharing device as a target protocol.

[0170] For example, the target protocol can be a protocol in which the communicating parties can use an existing key exchange method (e.g., Diffie-Hellman Key Exchange) to construct a one-time session encryption symmetric key to communicate. Alternatively, the target protocol can be a protocol in which the communicating parties communicate based on decentralized identifier communication (DIDComm). During the communication process using this communication protocol, the communicating parties exchange each other's public key certificates. After the public key certificates are verified, the encrypting party can use the public keys of both parties to encrypt the transmitted information, and the decrypting party uses the local corresponding private key to decrypt it.

[0171] S211b: The first sharing device sends a connection request to the second sharing device. Correspondingly, the second sharing device receives the connection request from the first sharing device.

[0172] The connection request includes the handshake certificate of the first shared device, which is used to verify the identity of the first shared device.

[0173] In S211b, a secure channel may be established between the first sharing device and the second sharing device.

[0174] Using the established secure channel, the first sharing device sends a connection request credential to the second sharing device. The connection request credential is used by the second sharing device to verify the identity of the first sharing device.

[0175] S211c: The second sharing device verifies the identity of the first sharing device according to the handshake credential of the first sharing device.

[0176] After the second sharing device verifies the identity of the first sharing device, it can determine whether to initiate data synchronization based on the identity verification result of the first sharing device.

[0177] Verification of the identity of the first shared device can be performed locally on the second shared device or through a third-party verification service. For example, if the first shared device and the second shared device belong to different carriers, verification of the first shared device requires verification of the carrier's verification service.

[0178] S211d: The second sharing device sends a connection response to the first sharing device. Correspondingly, the first sharing device receives the connection response from the second sharing device.

[0179] The connection response includes the handshake certificate of the second shared device, which can be used to verify the identity of the second shared device.

[0180] S211e: The first sharing device negotiates a data synchronization protocol with the second sharing device.

[0181] In one possible implementation, S211e may include: the first sharing device sending the supported data synchronization protocols to the second sharing device; the second sharing device selecting a target data synchronization protocol from the data synchronization protocols supported by the first device and returning the selected protocol to the first sharing device. The data synchronization protocol supported by the first device may be a distributed database synchronization method, or a decentralized synchronization method based on a distributed ledger database.

[0182] In a possible implementation, the first sharing device verifies the identity of the second sharing device based on the handshake certificate of the second sharing device. For the implementation principle, please refer to the relevant introduction of S211c. In this case, if the identity of the second sharing device passes, S211e is executed.

[0183] S211f: The first sharing device sends device identity information to the second sharing device. Correspondingly, the second sharing device receives the device identity information from the first sharing device.

[0184] The first sharing device pre-processes the device identity information according to the data synchronization protocol replied by the second sharing device, and sends the pre-processed device identity information to the second sharing device. The pre-processing of the device identity information may include: packaging (compressing) the device identity information data as a whole, or dividing the device identity information into blocks.

[0185] In the method provided in FIG. 3 , S211a to S211e are optional steps and may be performed when the first sharing device and the second sharing device are of different types, such as when the second sharing device is a device in a non-3GPP network.

[0186] It should be understood that the identity credentials submitted by the first sharing device and the second sharing device may be of different credential types, and the method for verifying the identity of the first sharing device may also be different from the method for verifying the identity of the second sharing device.

[0187] To facilitate understanding of the method provided in FIG. 2 , the communication method provided in FIG. 2 is described below in conjunction with different scenarios.

[0188] In some possible scenarios, the first device is a 3GPP terminal (hereinafter referred to as the terminal), and the first device directly authenticates with the authentication network element and directly sends the device identity information to the first shared device. In this case, the method provided in Figure 2 can refer to the communication method provided in Figure 4 below. As shown in Figure 4, the communication method includes:

[0189] S401: A first device is authenticated through an authentication network element.

[0190] For example, the first device may send an authentication request to the authentication network element. The authentication request is used to request authentication of the identity of the first device. The authentication request may include an identifier of the first device, such as a SUCI. It is understood that the SUCI is used for example only. In actual implementation, the identifier of the first device may also be other information that can be used to identify the first device.

[0191] After receiving the authentication request, the authentication network element authenticates the first device. For example, the authentication network element may call an authentication service interface (such as a Nausf_auth service interface) to authenticate the first device. After the first device passes the authentication, the authentication network element may send an authentication response to the first device. The authentication response may carry the access credentials of the first device (such as a token). For detailed steps, please refer to Section 6.1 of the 3GPP Technical Specification (TS) 33.501.

[0192] Among them, the implementation principle of the authentication network element can refer to the relevant introduction of the communication system provided in Figure 1, and will not be repeated here.

[0193] S402: The first device sends a first request message to the first sharing device. Correspondingly, the first sharing device receives the first request message from the first device.

[0194] For details about the first request message, please refer to the relevant introduction in S201.

[0195] Optionally, the authentication information of the first device may include an access credential of the first device, wherein the authentication information of the first device may be used to verify the terminal's access to the network, thereby preventing unauthenticated terminals from accessing the network, thereby making communication more secure.

[0196] In one possible implementation, the first request message can be implemented by calling a publishing service interface (such as a Publish() service interface). Exemplarily, the publishing service interface can be a representational state transfer application program interface (RESTful API). The API complies with the Uniform Resource Identifier (URI) standard. The API's interface address includes: the host name (host) of the first shared device, a host identifier (id), and a publishing method parameter (method) indicating how the device identity information is stored. The first device can access or call the API through the interface address. The parameters (i.e., input parameters) required when calling the API include: information used to authenticate the identity of the first device (e.g., oAuth2ClientCredential), and device identity information required to be carried in the first request message (e.g., ProfileDataResource). The API's response information includes: a first response message. For example, when the identity information is successfully published, the response information includes "OK"; when the identity information fails to be published, the response information includes "Error message," etc.

[0197] S403: The first sharing device stores the device identity information in the first request message.

[0198] For the implementation principle of S403, please refer to the relevant introduction of S203 in the method provided in FIG2 , which will not be repeated here.

[0199] S404: The first sharing device publishes device identity information.

[0200] For the process of S404, please refer to the relevant introduction of S204 in the method provided in FIG2 , which will not be repeated here.

[0201] S405: The first sharing device sends a first response message to the first device. Correspondingly, the first device receives the first response message from the first sharing device.

[0202] Regarding the implementation principle of the first response message, please refer to the relevant introduction in the method provided in Figure 2 above, which will not be repeated here.

[0203] Regarding the technical effects of the method provided in Figure 4, reference can be made to the technical effects of the method provided in Figure 2. In addition, the first device directly authenticates with the authentication network element. In this way, the storage process of the device identity information and the authentication process of the first device are performed separately, and the timing of storing the device identity information is more flexible.

[0204] In some possible scenarios, the first device is a 3GPP terminal (hereinafter referred to as the terminal), and the first device sends device identity information to the first shared device through the authentication network element. In this case, the method provided in FIG2 can refer to the communication method provided in FIG5 below. As shown in FIG5, the communication method includes:

[0205] S501: A first device sends a first message to an authentication network element. Correspondingly, the authentication network element receives the first message from the first device.

[0206] The first message includes a first request message and an authentication request of the first device.

[0207] Regarding the implementation principle of the first request message, reference may be made to the relevant introduction in the method provided in FIG4 . The authentication request of the first device may be used to authenticate the identity of the first device, or to authenticate the first device.

[0208] It should be understood that in S501, the first device may send the first message to the authentication network element via a non-access stratum (NAS) message. Correspondingly, the authentication network element may receive the first message from the first device via the NAS message.

[0209] S502: The first device is authenticated by an authentication network element.

[0210] The implementation principle of S502 may refer to the relevant introduction of S401, the difference being that the step of the first device sending the authentication request to the authentication network element is completed in S501.

[0211] S503: The authentication network element sends a first request message to the first shared device. Correspondingly, the first shared device receives the first request message from the authentication network element.

[0212] In one possible implementation, the first request message can be implemented by calling a publishing service interface (such as the Publish() service interface). Exemplarily, the publishing service interface can be: a RESTful API. The API complies with the URI rule standard. The interface address of the API includes: the host name host identifier of the first shared device and the parameters of the publishing method. The first device can access or call the API through the interface address. The parameters that need to be provided when calling the API (i.e., input parameters) include: identity information for authenticating the first device (for example, oAuth2ClientCredential), the valid publishing domain (for example, validDomain), and the data of the device identity information that needs to be carried in the first request message (for example, ProfileDataResource). The response information of the API includes: a first response message.

[0213] S504: The first sharing device stores the device identity information in the first request message.

[0214] For the implementation principle of S504, reference may be made to the relevant introduction of S203 in the method provided in FIG2 , which will not be repeated here.

[0215] S505: The first sharing device publishes device identity information.

[0216] In the embodiment of the present application, the first sharing device may publish the device identity information after receiving the first request message.

[0217] Regarding the implementation principle of S505, reference may be made to the relevant introduction of S204 in the method provided in FIG2 , which will not be repeated here.

[0218] S506: The first shared device sends a first response message to the authentication network element. Correspondingly, the authentication network element receives the first response message from the first shared device.

[0219] Regarding the implementation principle of the first response message, please refer to the relevant introduction of S205 in the method provided in Figure 2 above, which will not be repeated here.

[0220] S507: The authentication network element sends a first response message to the first device. Correspondingly, the first device receives the first response message from the authentication network element.

[0221] Regarding the technical effects of the method provided in FIG5, reference may be made to the technical effects of the method provided in FIG2. In addition, by sending the first request message through the authentication network element, the first request message and the authentication request of the first device are carried in the same message, which can reduce the signaling interaction process, reduce resource overhead, improve communication efficiency, and reduce terminal overhead.

[0222] In this case, in FIG5 , S501 to S503, i.e., the first device sends a first request message to the first shared device through the authentication network element. The first shared device receives the first request message from the first device through the authentication network element. That is, in the method provided in FIG2 , the first device sends the first request message to the first shared device, which may include: the first device sends the first request message to the first shared device through the authentication network element. In the method provided in FIG2 , the first shared device receives the first request message from the first device, which may include: the first shared device receives the first request message from the first device through the authentication network element.

[0223] In some possible scenarios, the first device is a 3GPP terminal (hereinafter referred to as the terminal), and the first device directly sends the device identity information to the first shared device. The first shared device authenticates the first device through the authentication network element. In this case, the method provided in FIG2 can refer to the communication method provided in FIG6 below. As shown in FIG6, the communication method includes:

[0224] S601: A first device sends a first request message to a first sharing device. Correspondingly, the first sharing device receives the first request message from the first device.

[0225] For the implementation principle of the first request message, please refer to the relevant introduction in S401.

[0226] S602: The first shared device authenticates the first device through an authentication network element.

[0227] For the implementation principle of S602, please refer to the relevant introduction of scenario 2, which will not be repeated here.

[0228] S603: The first sharing device stores the device identity information in the first request message.

[0229] Optionally, S603 may include: when the first device passes authentication, the first sharing device storing the device identity information in the first request message.

[0230] Regarding the implementation principle of the first sharing device storing the device identity information in the first request message, reference may be made to the relevant introduction of S203 and will not be repeated here.

[0231] S604: The first sharing device publishes the device identity information in the first request message.

[0232] Optionally, S604 may include: if the first device passes authentication, the first sharing device publishing the device identity information in the first request message.

[0233] Regarding the implementation principle of the first sharing device publishing the device identity information in the first request message, reference may be made to the relevant introduction of S204 and will not be repeated here.

[0234] S605: The first sharing device sends a first response message to the first device. Correspondingly, the first device receives the first response message from the first sharing device.

[0235] For the implementation principle of S605, please refer to the relevant introduction of S405 in Figure 4, which will not be repeated here.

[0236] For the technical effects of the method provided in FIG6 , reference may be made to the technical effects of the method provided in FIG2 . Furthermore, after receiving the first request message, the first shared device authenticates the first device through the authentication network element, thereby reducing the amount of data exchanged between the first device and the first shared device, thereby reducing resource overhead and power consumption of the terminal.

[0237] In some possible scenarios, the first device is a non-3GPP terminal (hereinafter referred to as the terminal), and the first device directly sends the device identity information to the first shared device. The first shared device verifies the first device through the authentication service device. In this case, the method provided in Figure 2 can refer to the communication method provided in Figure 7 below. As shown in Figure 7, the communication method includes:

[0238] S701: A first device sends a first request message to a first sharing device. Correspondingly, the first sharing device receives the first request message from the first device.

[0239] The first request message is further used to indicate information about an interface of the authentication service. The authentication service is used to authenticate the non-3GPP first device. Based on the interface information of the authentication service, the first device can access the authentication service device.

[0240] In addition, for the implementation principle of the first request message, reference may be made to the relevant introduction in S201.

[0241] S702: The first sharing device verifies the first device through the authentication service device.

[0242] The authentication service device may be a functional node controlled by a third party, and is used to provide identity confirmation for the first device authorized by the third party based on identity information proprietary to the third party, and to confirm the legitimacy and validity of the first device.

[0243] Regarding the implementation principle of S702, reference may be made to the relevant introduction in S209. The difference is that the fourth device is an authentication service device, which will not be described in detail here.

[0244] S703: The first sharing device stores the device identity information in the first request message.

[0245] Optionally, in S703 , when the first device passes verification, the first sharing device stores the device identity information in the first request message.

[0246] Regarding the implementation principle of the first sharing device storing the device identity information in the first request message, reference may be made to the relevant introduction of S203 and will not be repeated here.

[0247] S704: When the first device passes the verification, the first sharing device publishes the device identity information in the first request message.

[0248] Optionally, S704 may include: if the first device passes verification, the first sharing device publishing the device identity information in the first request message.

[0249] Regarding the implementation principle of the first sharing device publishing the device identity information in the first request message, reference may be made to the relevant introduction of S204 and will not be repeated here.

[0250] S705: The first sharing device sends a first response message to the first device. Correspondingly, the first device receives the first response message from the first sharing device.

[0251] For the implementation principle of S705, please refer to the relevant introduction of S405 in Figure 4, which will not be repeated here.

[0252] Regarding the technical effects of the method provided in FIG7 , reference may be made to the technical effects of the method provided in FIG2 above, which will not be repeated here.

[0253] In some possible embodiments, a device may obtain the device identity information of other devices from a shared device, as shown in Figure 8:

[0254] S801: The fourth device sends a third request message to the second sharing device. Correspondingly, the second sharing device receives the third request message from the fourth device.

[0255] The third request message is used to request the device identity information corresponding to the fifth device. For the implementation principle of the third request, please refer to the relevant introduction in the method provided in Figure 2, and will not be repeated here.

[0256] The fourth device may be a device corresponding to an individual, organization, or institution, such as the first type device or the second type device in the communication system provided in Figure 1. In some possible implementations, the device type of the fourth device may be a 3GPP device. In some possible implementations, the device type of the fourth device may be a non-3GPP device.

[0257] In the method provided in FIG8 , the second shared device is a device with a data storage function, and the second shared device can exchange information with other devices. The second shared device can be a first-category shared device. In this case, in a possible implementation scheme, the second shared device can also be the first shared device in the method provided in FIG2 above. Alternatively, the second shared device can also be a second-category shared device. The fourth device can be a device in a 3GPP network or a device in a non-3GPP network. At least one device identity information is pre-stored in the second shared device. Each device identity information corresponds to an identifier. For the implementation principle of the device identity information, please refer to the relevant introduction in FIG2 above, which will not be repeated here.

[0258] The second shared device is described below in conjunction with different scenarios.

[0259] In scenario 3, the second shared device can be a device in the 3GPP network. For example, the second shared device can be a network element in the core network. This core network element can also be a node in the blockchain. In this case, the implementation principles of the second shared device can refer to those of the first shared device described above.

[0260] In scenario 4, the second shared device can be a device in a non-3GPP network. For example, the implementation of the second shared device can refer to the first shared device, with the difference being that the ownership of the second shared device is different from that of the first shared device, or in other words, the owner of the second shared device is different from that of the first shared device. For another example, the second shared device can be a device corresponding to a distributed node in a distributed storage system, a device corresponding to a blockchain node in a blockchain system, or other devices with storage capabilities.

[0261] Optionally, the third request message may further include information indicating a device type of the fourth device.

[0262] Optionally, the third request message may include information indicating the identifier of the fifth device.

[0263] S802: The second sharing device performs identity authentication based on the access credential of the fourth device.

[0264] If the fourth device is a 3GPP device, the second shared device performs identity authentication based on the access credentials of the fourth device, including: the second shared device performs identity authentication with the authentication network element based on the access credentials of the fourth device. For the principle of the second shared device performing identity authentication with the authentication network element based on the access credentials of the fourth device, please refer to the relevant description of S602.

[0265] If the fourth device is a non-3GPP device, the second shared device performs identity authentication based on the access credentials of the fourth device, including: the second shared device performs identity authentication with the authentication service device based on the access credentials of the fourth device. The principle of the second shared device performing identity authentication with the authentication service device based on the access credentials of the fourth device can be referred to the relevant description of S702 and is not repeated here.

[0266] In this case, the third request message may also include information indicating the access credentials of the fourth device. The access credentials of the fourth device are used to verify the identity of the fourth device. If the fourth device is a 3GPP device, the access credentials of the fourth device may be information used for authentication in the 3GPP network, such as a username, password, or the ID information of the fourth device that has been registered. If the fourth device is a non-3GPP device, the access credentials of the fourth device may be the VC corresponding to the fourth device.

[0267] S803: The second sharing device parses the identifier of the fifth device to obtain device identity information corresponding to the identifier of the fifth device.

[0268] Optionally, the second sharing device parsing the identifier of the fifth device to obtain device identity information corresponding to the identifier of the fifth device may include: when the fourth device identity authentication is successful, the second sharing device parsing the identifier of the fifth device to obtain device identity information corresponding to the identifier of the fifth device.

[0269] In one possible implementation, the third request message can be implemented by calling a resolution service interface, such as a "Resolve() service interface". Exemplarily, the resolution service interface can be expressed as a RESTful API. The API complies with the URI rule standard. The interface address of the API includes: the host name of the second shared device. The first device can access or call the API through the interface address. The parameters (i.e., input parameters) that need to be provided when calling the API include: access verification information (such as access credentials) and the identifier of the fifth device. The response information of the API includes: a third response message.

[0270] S804: The second sharing device sends a third response message to the fourth device. Correspondingly, the fourth device receives the third response message (Response) from the second sharing device.

[0271] The third response message includes the device identity information corresponding to the identifier of the fifth device.

[0272] Optionally, the third response message may further include information indicating that the fourth device successfully requested the device identity information. For example, the third response message may indicate that the first shared device successfully stored the device identity information. For another example, the third response message may indicate that the first shared device failed to store the device identity information.

[0273] Based on the method provided in FIG. 8 , the fourth device may request the second sharing device for attribute information corresponding to the identifier of the fifth device, thereby obtaining the device identity information.

[0274] The communication method provided in the embodiment of the present application is described in detail above in conjunction with Figures 2 to 8. The communication device for executing the communication method provided in the embodiment of the present application is described in detail below in conjunction with Figures 9 and 10.

[0275] For example, Figure 9 is a structural diagram of a communication device according to an embodiment of the present application. As shown in Figure 9 , the communication device 900 includes a processing module 901 and a transceiver module 902. For ease of illustration, Figure 9 only shows the main components of the communication device 900.

[0276] In some embodiments, the communication apparatus 900 may be applicable to the communication system shown in FIG. 1 , and perform the functions of the first device in the communication methods shown in FIG. 2 and FIG. 4 - FIG. 7 .

[0277] Processing module 901 is configured to obtain a first request message. The first request message is used to store device identity information. The device identity information includes the device type of communication device 900 and / or the device type of a second device. Transceiver module 902 is configured to send the first request message to a first shared device. The first shared device is a network element in a communication network.

[0278] In a possible implementation, the device type may include: a 3rd Generation Partnership Project 3GPP terminal, an operator's network element, or a non-3GPP terminal.

[0279] In one possible implementation, the communication device 900 is a 3GPP terminal, and the first request message may also be used to indicate authentication information of the communication device 900. The authentication information of the communication device 900 may be used to verify the terminal's network access, thereby preventing unverified terminals from accessing the network, thereby making communication more secure.

[0280] In a possible implementation, the authentication information of the communication device 900 may include an access credential of the communication device 900 .

[0281] In a possible implementation, the transceiver module 902 is further configured to send a first request message to the first shared device through the authentication network element.

[0282] In a possible implementation, the communication device 900 is a non-3GPP terminal, and the first request message is further used to indicate information about an interface of an authentication service. The authentication service is used to authenticate the non-3GPP terminal.

[0283] In one possible implementation, if the device identity information includes the device type of the communication device 900, the device identity information also includes one or more of the following: the first identifier of the communication device 900, the owner of the subject corresponding to the communication device 900, information used to verify the ownership of the first identifier, the subject type corresponding to the communication device 900, the network domain identifier corresponding to the first identifier, the verifiable credential corresponding to the first identifier, the services or service interfaces supported by the communication device 900, and the encryption method corresponding to the communication device 900.

[0284] In one possible implementation, if the device identity information includes the device type of the second device, the device identity information may also include one or more of the following: the second identifier of the second device, the device corresponding to the second identifier, information used to verify the ownership of the second identifier, the subject type corresponding to the second device, the network domain identifier corresponding to the second identifier, the verifiable credential corresponding to the second identifier, the services or interactive interfaces supported by the second device, and the encryption method corresponding to the second device.

[0285] In a possible implementation, the first request message is also used to publish device identity information.

[0286] In a possible implementation, the transceiver module 902 is further configured to receive a first response message from the first sharing device, wherein the first response message is used to indicate whether the first sharing device has successfully stored the device identity information.

[0287] In one possible implementation, the transceiver module 902 is further configured to send a second request message to the second shared device. The second request message is configured to request device identity information corresponding to the third device. The communication device 900 receives a second response message from the second shared device. The second response message is configured to indicate the device identity information corresponding to the third device.

[0288] Optionally, the transceiver module 902 may include a receiving module and a sending module (not shown in FIG9 ). The transceiver module 902 is used to implement the sending function and the receiving function of the communication device 900 .

[0289] Optionally, the communication device 900 may further include a storage module (not shown in FIG9 ) storing a program or instruction. When the processing module 901 executes the program or instruction, the communication device 900 may perform the function of the first device in the communication method shown in any one of FIG2 and FIG4-FIG7 .

[0290] It should be understood that the processing module 901 involved in the communication device 900 can be implemented by a processor or a processor-related circuit component, which can be a processor or a processing unit; the transceiver module 902 can be implemented by a transceiver or a transceiver-related circuit component, which can be a transceiver or a transceiver unit.

[0291] It should be noted that the communication device 900 can be a terminal device, a chip (system) or other parts or components that can be set in the terminal device, or a device that includes a terminal device. This application does not limit this.

[0292] In addition, the technical effects of the communication device 900 can refer to the technical effects of the communication method shown in any one of Figures 2 and 4 to 7, and will not be repeated here.

[0293] In some other embodiments, the communication apparatus 900 may be applicable to the communication system shown in FIG. 1 , and perform the function of the first shared device in the communication method shown in FIG. 2 and FIG. 4 to FIG. 7 .

[0294] The transceiver module 902 is configured to receive a first request message from a first device. The first request message is used to store device identity information. The device identity information includes the device type of the first device and / or the device type of the second device. The processing module 901 is configured to store the device identity information in the first request message.

[0295] In a possible implementation, the device type may include: a 3rd Generation Partnership Project 3GPP terminal, an operator's network element, or a non-3GPP terminal.

[0296] In a possible implementation, the first device is a 3GPP terminal, and the first request message is further used to indicate authentication information of the first device.

[0297] In a possible implementation, the authentication information of the first device includes an access credential of the first device.

[0298] In a possible implementation, the transceiver module 902 is further configured to receive a first request message from the first device through the authentication network element.

[0299] In a possible implementation, the first device is a 3GPP terminal, and the processing module 901 is further configured to verify the first device through an authentication network element. The processing module 901 is further configured to store the device identity information in the first request message if the first device passes the verification.

[0300] In a possible implementation, the first device is a non-3GPP terminal, and the first request message is further used to indicate information about an interface of an authentication service. The authentication service is used to authenticate the non-3GPP terminal.

[0301] In one possible implementation scheme, if the device identity information includes the device type of the first device, the device identity information includes one or more of the following: the device identity information includes one or more of the following: the first identifier of the first device, the owner of the subject corresponding to the first device, information used to verify the ownership of the first identifier, the subject corresponding to the first device, the network domain identifier corresponding to the first identifier, the verifiable credential corresponding to the first identifier, the services or service interfaces supported by the first device, and the encryption method corresponding to the first device.

[0302] In one possible implementation, if the device identity information includes the device type of the second device, the device identity information includes one or more of the following: the second identifier of the second device, the device corresponding to the second identifier, information used to verify the ownership of the second identifier, the subject corresponding to the second device, the network domain identifier corresponding to the second identifier, the verifiable credential corresponding to the second identifier, the services or interactive interfaces supported by the second device, and the encryption method corresponding to the second device.

[0303] In a possible implementation, the first request message is further used to publish device identity information, and the processing module 901 is further used to publish the device identity information.

[0304] In a possible implementation, the transceiver module 902 is further configured to send a first response message to the first device.

[0305] In a possible implementation, the transceiver module 902 is further configured to send device identity information to the second shared device.

[0306] In one possible implementation, the transceiver module 902 is further configured to receive a third request message from the fourth device. The third request message is used to request device identity information corresponding to the fifth device. The transceiver module 902 is further configured to send a third response message. The third response message is used to indicate the device identity information corresponding to the fifth device.

[0307] In a possible implementation, the processing module 901 is further configured to verify the fourth device through the authentication service device.

[0308] Optionally, the transceiver module 902 may include a receiving module and a sending module (not shown in FIG9 ). The transceiver module 902 is used to implement the sending function and the receiving function of the communication device 900 .

[0309] Optionally, the communication device 900 may further include a storage module (not shown in FIG9 ) storing a program or instruction. When the processing module 901 executes the program or instruction, the communication device 900 may perform the function of the first device in the communication method shown in any one of FIG2 and FIG4-FIG7 .

[0310] It should be understood that the processing module 901 involved in the communication device 900 can be implemented by a processor or a processor-related circuit component, which can be a processor or a processing unit; the transceiver module 902 can be implemented by a transceiver or a transceiver-related circuit component, which can be a transceiver or a transceiver unit.

[0311] It should be noted that the communication device 900 can be a network device, a chip (system) or other parts or components that can be set in the network device, or a device that includes a network device. This application does not limit this.

[0312] In addition, the technical effects of the communication device 900 can refer to the technical effects of the communication method shown in any one of Figures 2 and 4 to 7, and will not be repeated here.

[0313] In some other embodiments, the communication apparatus 900 may be applicable to the communication system shown in FIG. 1 , and perform the functions of the first device in the communication method shown in FIG. 2 and FIG. 4 to FIG. 7 .

[0314] Processing module 901 is configured to send a third request message to the second shared device via transceiver module 902. The third request message is configured to request device identity information corresponding to the identifier of the fifth device. Processing module 901 is further configured to receive a third response message from the second shared device via transceiver module 902. The third response message includes the device identity information corresponding to the identifier of the fifth device.

[0315] In a possible implementation, the third request message may further include information indicating an access credential of the communication device 900. The access credential of the communication device 900 is used to verify the identity of the communication device 900.

[0316] In a possible implementation, the third request message may further include information indicating the device type of the communication apparatus 900 .

[0317] Optionally, the transceiver module 902 may include a receiving module and a sending module (not shown in FIG9 ). The transceiver module 902 is used to implement the sending function and the receiving function of the communication device 900 .

[0318] Optionally, the communication device 900 may further include a storage module (not shown in FIG9 ) that stores a program or instruction. When the processing module 901 executes the program or instruction, the communication device 900 may perform the function of the first device in the communication method shown in FIG8 .

[0319] It should be understood that the processing module 901 involved in the communication device 900 can be implemented by a processor or a processor-related circuit component, which can be a processor or a processing unit; the transceiver module 902 can be implemented by a transceiver or a transceiver-related circuit component, which can be a transceiver or a transceiver unit.

[0320] It should be noted that the communication device 900 can be a terminal device, a chip (system) or other parts or components that can be set in the terminal device, or a device that includes a terminal device. This application does not limit this.

[0321] In addition, the technical effects of the communication device 900 can refer to the technical effects of the communication method shown in Figure 8, and will not be repeated here.

[0322] In some other embodiments, the communication apparatus 900 may be applicable to the communication system shown in FIG. 1 , and perform the function of the second shared device in the communication method shown in FIG. 8 .

[0323] Processing module 901 is configured to receive, via transceiver module 902, a third request message from a fourth device. The third request message is configured to request device identity information corresponding to the identifier of the fifth device. Processing module 901 is further configured to send, via transceiver module 902, a third response message to the fourth device. The third response message includes the device identity information corresponding to the identifier of the fifth device.

[0324] In a possible implementation, the processing module 901 is further configured to parse the identifier of the fifth device to obtain device identity information corresponding to the identifier of the fifth device.

[0325] In one possible implementation, the third request message is used to indicate information about the access credentials of the fourth device. The access credentials of the fourth device are used to authenticate the fourth device. The processing module 901 is further configured to perform identity authentication with the second shared device based on the access credentials of the fourth device.

[0326] In a possible implementation, the third request message may further include information indicating a device type of the fourth device.

[0327] Optionally, the transceiver module 902 may include a receiving module and a sending module (not shown in FIG9 ). The transceiver module 902 is used to implement the sending function and the receiving function of the communication device 900 .

[0328] Optionally, the communication device 900 may further include a storage module (not shown in FIG9 ) that stores a program or instruction. When the processing module 901 executes the program or instruction, the communication device 900 may perform the function of the second shared device in the communication method shown in FIG9 .

[0329] It should be understood that the processing module 901 involved in the communication device 900 can be implemented by a processor or a processor-related circuit component, which can be a processor or a processing unit; the transceiver module 902 can be implemented by a transceiver or a transceiver-related circuit component, which can be a transceiver or a transceiver unit.

[0330] It should be noted that the communication device 900 can be a network device, a chip (system) or other parts or components that can be set in the network device, or a device that includes a network device. This application does not limit this.

[0331] In addition, the technical effects of the communication device 900 can refer to the technical effects of the communication method shown in Figure 8, and will not be repeated here.

[0332] For example, FIG10 is a second structural diagram of a communication device provided in an embodiment of the present application. The communication device may be a terminal or a network device, or a chip (system) or other component or assembly that can be provided in a terminal device or a network device. As shown in FIG10 , the communication device 1000 may include a processor 1001. Optionally, the communication device 1000 may further include a memory 1002 and / or a transceiver 1003. The processor 1001 is coupled to the memory 1002 and the transceiver 1003, such as by a communication bus.

[0333] The following is a detailed introduction to the various components of the communication device 1000 in conjunction with FIG10 :

[0334] The processor 1001 is the control center of the communication device 1000 and can be a single processor or a collective term for multiple processing elements. For example, the processor 1001 can be one or more central processing units (CPUs), an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application, such as one or more digital signal processors (DSPs) or one or more field programmable gate arrays (FPGAs).

[0335] Optionally, the processor 1001 may execute various functions of the communication device 1000 by running or executing a software program stored in the memory 1002 and calling data stored in the memory 1002 .

[0336] In a specific implementation, as an embodiment, the processor 1001 may include one or more CPUs, such as CPU0 and CPU1 shown in FIG10 .

[0337] In a specific implementation, as an embodiment, the communication device 1000 may also include multiple processors, such as the processor 1001 and the processor 1004 shown in FIG10 . Each of these processors may be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). The processor herein may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).

[0338] The memory 1002 is used to store the software program for executing the solution of the present application, and the execution is controlled by the processor 1001. The specific implementation method can refer to the above method embodiment and will not be repeated here.

[0339] Alternatively, the memory 1002 may be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, an optical disc storage (including a compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 1002 may be integrated with the processor 1001 or exist independently and be coupled to the processor 1001 via an interface circuit (not shown in FIG. 10 ) of the communication device 1000. This embodiment of the present application does not specifically limit this.

[0340] Transceiver 1003 is used for communication with other communication devices. For example, if communication device 1000 is a terminal device, transceiver 1003 can be used to communicate with a network device or another terminal device. For another example, if communication device 1000 is a network device, transceiver 1003 can be used to communicate with a terminal device or another network device.

[0341] Optionally, the transceiver 1003 may include a receiver and a transmitter (not shown separately in FIG10 ), wherein the receiver is used to implement a receiving function, and the transmitter is used to implement a sending function.

[0342] Optionally, the transceiver 1003 may be integrated with the processor 1001 or exist independently and be coupled to the processor 1001 through an interface circuit (not shown in FIG. 10 ) of the communication device 1000 . This embodiment of the present application does not specifically limit this.

[0343] It should be noted that the structure of the communication device 1000 shown in FIG10 does not constitute a limitation on the communication device. An actual communication device may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.

[0344] In addition, the technical effects of the communication device 1000 can refer to the technical effects of the communication method described in the above method embodiment, and will not be repeated here.

[0345] An embodiment of the present application provides a communication system, which includes one or more terminal devices described above and one or more network devices.

[0346] It should be understood that the processor in the embodiments of the present application may be a CPU, but may also be other general-purpose processors, DSPs, ASICs, FPGAs, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor.

[0347] It should also be understood that the memory in the embodiments of the present application can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a ROM, a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an EEPROM, or a flash memory. The volatile memory can be a RAM, which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).

[0348] The above embodiments can be implemented in whole or in part by software, hardware (such as circuits), firmware or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer program are loaded or executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired (such as infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more available media sets. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a tape), an optical medium (for example, a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.

[0349] It should be understood that the term "and / or" as used herein simply describes a relationship between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A alone, A and B together, or B alone. A and B can be singular or plural. Furthermore, the character " / " as used herein generally indicates an "or" relationship between the associated objects, but it may also indicate an "and / or" relationship. For specific understanding, please refer to the context.

[0350] In this application, "at least one" means one or more, and "plurality" means two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or plural.

[0351] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0352] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and implementation constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0353] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0354] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0355] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0356] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0357] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a ROM, a RAM, a magnetic disk, or an optical disk.

[0358] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. A communication method, applied to a first device, characterized in that: The method comprises: Get a first request message; the first request message is used to store device identity information; The first request message is sent to a first shared device; the first shared device is a network element in a communication network.

2. The method according to claim 1, characterized in that The device identity information includes a device type of the first device and / or a device type of the second device.

3. The method according to claim 2, characterized in that The device type includes: a 3rd Generation Partnership Project 3GPP terminal, a network element of an operator, or a non-3GPP terminal.

4. The method according to claim 3, characterized in that The first device is a 3GPP terminal, and the first request message is also used to indicate authentication information of the first device.

5. The method according to claim 4, characterized in that The authentication information of the first device includes access credentials of the first device.

6. The method according to claim 4 or 5, characterized in that: The sending the first request message to the first shared device includes: The first request message is sent to the first shared device through an authentication network element.

7. The method according to claim 3, characterized in that The first device is a non-3GPP terminal, and the first request message is further used to indicate information of an interface of a verification service; the verification service is used to verify the non-3GPP terminal.

8. The method according to any one of claims 1 to 7, characterized in that If the device identity information includes the device type of the first device, the device identity information also includes one or more of the following: the first identifier of the first device, the owner of the subject corresponding to the first device, information used to verify the ownership of the first identifier, the subject type corresponding to the first device, the network domain identifier corresponding to the first identifier, the verifiable credential corresponding to the first identifier, the services or service interfaces supported by the first device, and the encryption method corresponding to the first device.

9. The method according to any one of claims 1 to 8, characterized in that If the device identity information includes the device type of the second device, the device identity information also includes one or more of the following: the second identifier of the second device, the device corresponding to the second identifier, information used to verify the ownership of the second identifier, the subject type corresponding to the second device, the network domain identifier corresponding to the second identifier, the verifiable credential corresponding to the second identifier, the services or interaction interfaces supported by the second device, and the encryption method corresponding to the second device.

10. The method according to any one of claims 1 to 9, characterized in that The first request message is also used to publish the device identity information.

11. The method according to any one of claims 1 to 10, characterized in that The method further comprises: A first response message is received from the first sharing device; wherein the first response message is used to indicate whether the first sharing device successfully stores the device identity information.

12. The method according to any one of claims 1 to 11, characterized in that The method further comprises: Sending a second request message to the second shared device; wherein the second request message is used to request device identity information corresponding to the third device; A second response message is received from the second sharing device; wherein the second response message is used to indicate the device identity information corresponding to the third device.

13. A communication method, characterized in that: Applied to the first shared device, the method further includes: Receiving a first request message from a first device; the first request message is used to store device identity information; The first request message is stored.

14. The method according to claim 13, characterized in that The device identity information includes a device type of the first device and / or a device type of the second device.

15. The method according to claim 14, characterized in that The device type includes: a 3rd Generation Partnership Project 3GPP terminal, a network element of an operator, or a non-3GPP terminal.

16. The method according to claim 15, characterized in that The first device is a 3GPP terminal, and the first request message is also used to indicate authentication information of the first device.

17. The method according to claim 16, characterized in that The authentication information of the first device includes access credentials of the first device.

18. The method according to claim 15 or 16, characterized in that The receiving a first request message from a first device includes: A first request message from a first device is received through an authentication network element.

19. The method according to claim 15, characterized in that The first device is a 3GPP terminal, and the method further includes: authenticating the first device through an authentication network element; The storing the first request message comprises: When the first device is authenticated successfully, the first request message is stored.

20. The method according to claim 15, characterized in that The first device is a non-3GPP terminal, and the first request message is further used to indicate information of an interface of a verification service; the verification service is used to verify the non-3GPP terminal.

21. The method according to any one of claims 13 to 20, characterized in that If the device identity information includes the device type of the first device, the device identity information includes one or more of the following: the device identity information includes one or more of the following: the first identifier of the first device, the owner of the subject corresponding to the first device, information used to verify the ownership of the first identifier, the subject corresponding to the first device, the network domain identifier corresponding to the first identifier, the verifiable credentials corresponding to the first identifier, the services or service interfaces supported by the first device, and the encryption method corresponding to the first device.

22. The method according to any one of claims 13 to 20, characterized in that If the device identity information includes the device type of the second device, the device identity information includes one or more of the following: the second identifier of the second device, the device corresponding to the second identifier, information used to verify the ownership of the second identifier, the subject corresponding to the second device, the network domain identifier corresponding to the second identifier, the verifiable credential corresponding to the second identifier, the services or interaction interfaces supported by the second device, and the encryption method corresponding to the second device.

23. The method according to any one of claims 13 to 22, characterized in that The first request message is also used to publish the device identity information. The method further includes: The device identity information is published.

24. The method according to any one of claims 13 to 23, characterized in that The method further comprises: Send a first response message to the first device.

25. The method according to any one of claims 13 to 24, characterized in that The method further comprises: The device identity information is sent to the second shared device.

26. The method according to any one of claims 13 to 25, characterized in that The method further comprises: receiving a third request message from a fourth device; the third request message being used to request device identity information corresponding to a fifth device; A third response message is sent to the fourth device; the third response message is used to indicate the device identity information corresponding to the fifth device.

27. The method according to claim 26, characterized in that The method further comprises: The fourth device is authenticated by an authentication service device.

28. A communication method, characterized in that: Applied to a fourth device, the method includes: Sending a third request message to the second shared device; wherein the third request message is used to request device identity information corresponding to the identifier of the fifth device; A third response message is received from the second sharing device; the third response message includes device identity information corresponding to the identifier of the fifth device.

29. The method according to claim 28, characterized in that The third request message also includes information indicating an access credential of the fourth device, where the access credential of the fourth device is used to verify the identity of the fourth device.

30. The method according to claim 28 or 29, characterized in that The third request message further includes information indicating a device type of the fourth device.

31. A communication method, characterized in that: Applied to the second shared device, the method includes: receiving a third request message from a fourth device, wherein the third request message is used to request device identity information corresponding to an identifier of a fifth device; A third response message is sent to the fourth device, wherein the third response message includes device identity information corresponding to the identifier of the fifth device.

32. The method according to claim 31, characterized in that The method further comprises: The identifier of the fifth device is parsed to obtain device identity information corresponding to the identifier of the fifth device.

33. The method according to claim 31 or 32, characterized in that The method further comprises: The third request message is used to indicate information about the access credential of the fourth device, and the access credential of the fourth device is used to verify the fourth device. The method further includes: Authentication is performed with the second shared device according to the access credentials of the fourth device.

34. The method according to any one of claims 31 to 33, characterized in that The third request message further includes information indicating a device type of the fourth device.

35. A communication device, characterized in that: The communication device is used to execute the communication method according to any one of claims 1 to 34.

36. A communication device, characterized in that: The method comprises a processor configured to execute the communication method according to any one of claims 1 to 34.

37. A communication device, characterized in that: include: a processor coupled to the memory; The processor is used to execute the computer program stored in the memory, so that the communication device executes the communication method according to any one of claims 1 to 34.

38. A communication device, characterized in that: include: processor and interface circuit; wherein, The interface circuit is used to receive code instructions and transmit them to the processor; The processor is configured to execute the code instructions to perform the method according to any one of claims 1-34.

39. A communication device, characterized in that: The communication device includes a processor and a transceiver, the transceiver is used for information exchange between the communication device and other communication devices, and the processor executes program instructions to perform the communication method as described in any one of claims 1-34.

40. A communication system, characterized in that: The communication system includes one or more terminal devices and one or more network devices, the one or more terminal devices are used to execute the method as described in any one of claims 1-12 or any one of claims 28-30, and the one or more network devices are used to execute the method as described in any one of claims 13-27 or any one of claims 31-34.

41. A computer-readable storage medium, characterized in that The computer-readable storage medium includes a computer program or an instruction, and when the computer program or the instruction is executed on a computer, the computer is caused to execute the communication method according to any one of claims 1 to 34.

42. A computer program product, characterized in that The computer program product comprises: a computer program or instructions, and when the computer program or instructions are executed on a computer, the computer is caused to execute the communication method according to any one of claims 1 to 34.

Citation Information

Patent Citations

  • Communication method and communication device

    CN120021293A

  • Security authentication method and related equipment

    CN109756447A

  • Method and user equipment for connecting by means of plurality of accesses in next generation network

    US20190208562A1

  • Network capability opening method, apparatus and system

    WO2022032597A1

  • Communication method and apparatus

    WO2022057673A1