Communication method and communication apparatus

By sending the first identification and service information of the first node to the storage node, the problem of strong dependence on the service information acquisition process in the prior art is solved, and a wider application scenario is achieved.

WO2025103486A1PCT designated stage expired Publication Date: 2025-05-22HUAWEI TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/132445
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-17
Filing Date
2024-11-15
Publication Date
2025-05-22

AI Technical Summary

Technical Problem

In the prior art, the process of obtaining service information depends on the nodes that provide services or nodes that generate service information, which limits the breadth of application scenarios.

Method used

Through a communication method, the first node acquires the first information, including the service information corresponding to the first identifier and the first identifier, and sends it to the storage node, so that other nodes can obtain the service information through the storage node, and reduce dependence on the first node.

Benefits of technology

It realizes multi-channel acquisition of service information, reduces dependence on service nodes, and expands the applicability of application scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024132445_22052025_PF_FP_ABST
    Figure CN2024132445_22052025_PF_FP_ABST
Patent Text Reader

Abstract

The present application provides a communication method and a communication apparatus, capable of uploading service information of a first node to a storage node, and applicable to a communication system. The communication method comprises: the first node acquires first information, wherein the first information comprises a first identifier and service information corresponding to the first identifier; and the first node sends the first information to the storage node.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method and communication device

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on November 17, 2023, with application number 202311556197.2 and application name “Communication Method and Communication Device”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of communication technology, and in particular to a communication method and a communication device. Background Art

[0003] In information technology (IT) or communication technology (CT), a node can provide services to other nodes through the service information corresponding to the node, or in other words, the service of a node can be obtained by obtaining the service information of the node. The service information of a node can be obtained from the node or from the node that generates the service information. For example, the node corresponding to the card dealer or terminal manufacturer can generate the service information of the terminal (node), and the terminal can also store the service information of the terminal. Therefore, if you need to obtain the service provided by the terminal, you need to obtain the service information of the terminal from the terminal or the node corresponding to the card dealer or terminal manufacturer. In the above scheme, the process of obtaining service information needs to rely on the node that provides the service or the node that generates the service information, and the application scenario is limited. Summary of the Invention

[0004] The embodiments of the present application provide a communication method and a communication device, which can make the service information acquisition process independent of the node providing the service or the node generating the service information, and can be applied to more scenarios.

[0005] In a first aspect, a communication method is provided. The communication method includes: a first node obtaining first information, wherein the first information includes a first identifier and service information corresponding to the first identifier; and the first node sending the first information to a storage node.

[0006] Based on the method provided in the first aspect, the first node can send the first identifier and the service information corresponding to the first identifier to the storage node. In this way, the storage node can obtain the first identifier of the first node and the service information corresponding to the first identifier, so that other nodes can obtain the service information corresponding to the first identifier through the storage node, which increases the channels for obtaining service information and reduces dependence on the first node. Therefore, it can be applied to more scenarios.

[0007] In one possible implementation, the first node can include one or more of the following: a device from a card vendor or terminal manufacturer, a terminal, a device from a carrier, a device from an authorized institution, a device from a third-party trusted institution, or an over-the-air card writing server. The first node can be determined based on the actual scenario. Each of these devices can store their identification and service information in the storage node, allowing for greater flexibility in application scenarios.

[0008] In one possible implementation, if the first node is a device corresponding to a card merchant or a terminal manufacturer, the method provided by the first aspect also includes: the first node obtains second information, the second information is used to indicate the second identifier of the terminal and the credential information corresponding to the second identifier, the credential information corresponding to the second identifier is used to verify the attributes corresponding to the terminal and / or the second identifier, the second identifier and the credential information corresponding to the second identifier are generated by the first node, and the first node sends the second information and / or the hash value of the second information to the storage node.

[0009] In this way, the first node (i.e., the device corresponding to the card vendor or terminal manufacturer) can send the second information to the storage node. Since the service information of the first node is also uploaded to the storage node, and the second identifier and the credential information corresponding to the second identifier are generated by the first node, the first node can endorse the second identifier and the credential information corresponding to the second identifier. For example, the second identifier and the credential information corresponding to the second identifier are signed by the private key corresponding to the first node. Therefore, if the first node is trustworthy, the second identifier and the credential information corresponding to the second identifier can be trusted and communicated between different domains.

[0010] In one possible implementation, the credential information corresponding to the second identifier includes authentication information corresponding to the second identifier and / or proof information corresponding to the second identifier, and the authentication information corresponding to the second identifier is used to verify the terminal. The proof information corresponding to the second identifier is used to verify the attribute corresponding to the second identifier. In this way, when the credential information corresponding to the second identifier includes the authentication information corresponding to the second identifier, the identity of the terminal can be verified, and when the credential information corresponding to the second identifier includes the proof information corresponding to the second identifier, the attribute corresponding to the second identifier can be verified.

[0011] In one possible implementation, the second information includes the second identifier and one or more of the following: credential information corresponding to the second identifier, service information corresponding to the second identifier, information indicating the type of the terminal, information about the issuer of the second identifier, or information indicating disclosure conditions for the credential information corresponding to the second identifier. Thus, one or more of the aforementioned information can be stored in a storage node, allowing other devices to obtain or provide corresponding services based on the aforementioned information in the storage node.

[0012] In one possible implementation, the second identifier and the credential information corresponding to the second identifier are carried in the identification information corresponding to the second identifier. In this case, the second information may also include file information, where the file information includes one or more of the following: service information corresponding to the second identifier, information indicating the type of terminal, information about the issuer of the second identifier, or information indicating the disclosure conditions of the credential information corresponding to the second identifier. In this way, the identification information of the second identifier includes the credential information used to authenticate the terminal, so that file information can be generated based on actual conditions, making the file information more accurate and reducing the amount of stored data. Alternatively, the second identifier is carried in the identification information corresponding to the second identifier, and one or more of the credential information corresponding to the second identifier, the service information corresponding to the second identifier, information indicating the type of terminal, information about the issuer of the second identifier, or information indicating the disclosure conditions of the credential information corresponding to the second identifier are carried in the file information corresponding to the second identifier. In this way, the identification information corresponding to the second identifier and other information can be stored independently or read separately, which can reduce information leakage, thereby enhancing privacy protection and making the release method more flexible.

[0013] In one possible implementation, the identification information corresponding to the second identifier includes a first field and one or more of the following: a second field or a third field, wherein the information carried by the first field is used to indicate the second identifier, the information carried by the second field is used to indicate the identification type of the second identifier, and the information carried by the third field is used to verify the information carried by fields other than the third field in the identification information corresponding to the second identifier. In this way, the node corresponding to the second identifier can be indicated by the first field. In addition, in the case where the identification information corresponding to the second identifier includes the second field, the type of the second identifier can be determined, and then the source, credibility or usage scenario of the second identifier can be determined based on the second identifier. In the case where the information corresponding to the second identifier includes the third field, verification of other fields, such as the first field, or the first field and the second field can be implemented to ensure the accuracy of the second identifier.

[0014] In one possible implementation, the method provided in the first aspect may further include: the first node sending third information to the terminal. The third information is used to indicate the second information, or the third information is used to indicate the second information and the storage location of the second information in the storage system. In this way, the terminal can obtain the second information, thereby enabling other nodes to authenticate the terminal using the second information.

[0015] In one possible implementation, if the first node is a terminal, the method provided in the first aspect may further include: the first node receiving fourth information from a device corresponding to a card vendor or terminal manufacturer. The fourth information is used to indicate the first identifier and the credential information corresponding to the first identifier. Alternatively, the fourth information is used to indicate the first identifier, the credential information corresponding to the first identifier, and the storage location of the first identifier and the credential information corresponding to the first identifier in a storage system. This allows the terminal to obtain the fourth information and use it for authentication.

[0016] In one possible implementation, the method provided in the first aspect may further include: the first node sending fifth information and / or a hash value of the fifth information to the storage node. The fifth information is used to indicate a third identifier of the first node and credential information corresponding to the third identifier, where the third identifier is different from the first identifier. In this way, the first node can indicate the different identifiers of the first node and the credential information corresponding to the different identifiers to the storage node, so that different services can be used for different identifiers, thereby improving privacy.

[0017] In one possible implementation, if the first node is a terminal, the method provided in the first aspect may further include: the first node sends a certification request message to a device corresponding to a card dealer or terminal manufacturer. The certification request message is used to request certification information corresponding to the first node, and the certification information corresponding to the first node is used to verify the attributes corresponding to the first node or the identifier of the first node. The first node receives the certification information corresponding to the first node. The certification information corresponding to the first node is generated by a device corresponding to the card dealer or terminal manufacturer. For example, the card dealer or terminal manufacturer can endorse the terminal, so that if the card dealer or device manufacturer is trustworthy, the terminal can be verified through the certification information.

[0018] In one possible implementation, if the first node is a device corresponding to a card vendor or terminal manufacturer, the method provided in the first aspect may further include: the first node receiving certification request information from the terminal. The certification request information is used to request certification information corresponding to the terminal, and the certification information corresponding to the terminal is used to verify the attributes corresponding to the terminal or its identifier. The first node sends the certification information corresponding to the terminal to the storage node. The first node sends the certification information corresponding to the terminal to the terminal. In this way, the card vendor or terminal manufacturer can endorse the terminal, and if the card vendor or device manufacturer is trustworthy, the terminal can be verified using the certification information on the blockchain.

[0019] In a second aspect, a communication method is provided. The communication method includes: a storage node receiving first information from a first node, wherein the first information includes a first identifier and service information corresponding to the first identifier. The storage node stores the first information.

[0020] Based on the method provided in the second aspect, the storage node can obtain the first identifier of the first node and the service information corresponding to the first identifier, so that other nodes can obtain the service information corresponding to the first identifier through the storage node, increasing the channels for obtaining service information and reducing dependence on the first node. Therefore, it can be applied to more scenarios.

[0021] In a possible implementation, the first node may include one or more of: equipment corresponding to a card vendor or terminal manufacturer, a terminal, equipment corresponding to an operator, equipment corresponding to an authority, equipment corresponding to a third-party trusted institution, or an air card writing server.

[0022] In one possible implementation, if the first node includes a device corresponding to a card vendor or terminal manufacturer, the method provided in the second aspect may further include: the storage node receiving second information from the first node. The second information is used to indicate a second identifier of the terminal and credential information corresponding to the second identifier, and the credential information corresponding to the second identifier is used to verify attributes corresponding to the terminal and / or the second identifier. The credential information corresponding to the second identifier and the second identifier is generated by the first node. The storage node stores fourth information.

[0023] In one possible implementation, the credential information corresponding to the second identifier includes authentication information corresponding to the second identifier and / or proof information corresponding to the second identifier, the authentication information corresponding to the second identifier is used to verify the terminal, and the proof information corresponding to the second identifier is used to verify the attribute corresponding to the second identifier.

[0024] In one possible implementation, the second information includes a second identifier, and one or more of the following: credential information corresponding to the second identifier, service information corresponding to the second identifier, information used to indicate the type of the terminal, information of the issuer of the second identifier, or information used to indicate the disclosure conditions of the credential information corresponding to the second identifier.

[0025] In one possible implementation, the second identifier and the credential information corresponding to the second identifier are carried in the identification information corresponding to the second identifier. In this case, the second information may also include file information, where the file information includes one or more of the following: service information corresponding to the second identifier, information indicating the type of terminal, information about the issuer of the second identifier, or information indicating the disclosure conditions of the credential information corresponding to the second identifier. In this way, the identification information of the second identifier includes the credential information used to authenticate the first node, allowing file information to be generated based on actual conditions, making the file information more accurate and reducing the amount of stored data. Alternatively, the second identifier is carried in the identification information corresponding to the second identifier, and one or more of the credential information corresponding to the second identifier, the service information corresponding to the second identifier, information indicating the type of terminal, information about the issuer of the second identifier, or information indicating the disclosure conditions of the credential information corresponding to the second identifier are carried in the file information corresponding to the second identifier. In this way, the identification information corresponding to the second identifier and other information can be stored independently or read separately, which can reduce information leakage, enhance privacy protection, and make the release method more flexible.

[0026] In one possible implementation, the identification information corresponding to the second identifier includes a first field and one or more of the following: a second field or a third field, wherein the information carried by the first field is used to indicate the second identifier, the information carried by the second field is used to indicate the identification type of the second identifier, and the information carried by the third field is used to verify the information carried by fields other than the third field in the identification information corresponding to the second identifier.

[0027] In one possible implementation, the method provided in the second aspect may further include: the storage node receiving fifth information from the first node, wherein the fifth information is used to indicate a third identifier of the first node and credential information corresponding to the third identifier.

[0028] In one possible implementation, if the first node includes a device corresponding to a card vendor or terminal manufacturer, the method provided in the second aspect may further include: the storage node receiving certification information corresponding to the terminal from the first node. The certification information corresponding to the terminal is used to verify attributes corresponding to the terminal or the terminal identifier.

[0029] In one possible implementation, the method provided in the second aspect may further include: the storage node receiving sixth information from the second node. The sixth information is used to indicate the fourth identifier of the second node and the credential information corresponding to the fourth identifier, and the credential information corresponding to the fourth identifier is used to verify the attributes corresponding to the second node and / or the fourth identifier. The fourth identifier and the credential information corresponding to the fourth identifier are generated by the first node. The storage node stores the sixth information.

[0030] In one possible implementation, the credential information corresponding to the fourth identifier includes authentication information corresponding to the fourth identifier and / or proof information corresponding to the fourth identifier, the authentication information corresponding to the fourth identifier is used to verify the second node, and the proof information corresponding to the fourth identifier is used to verify the attribute corresponding to the fourth identifier.

[0031] In one possible implementation, the sixth information includes the fourth identifier and one or more of the following: credential information corresponding to the fourth identifier, service information corresponding to the fourth identifier, information used to indicate the type of the second node, information of the issuer of the fourth identifier, or information used to indicate the disclosure conditions of the credential information corresponding to the fourth identifier.

[0032] In one possible implementation, the fourth identifier and the credential information corresponding to the fourth identifier are carried in the identification information corresponding to the fourth identifier. In this way, the identification information of the fourth identifier includes the credential information for authenticating the second node, so that file information can be generated according to actual conditions, thereby making the file information more accurate and reducing the amount of stored data. Alternatively, the fourth identifier is carried in the identification information corresponding to the second identifier, and one or more of the credential information corresponding to the fourth identifier, the service information corresponding to the fourth identifier, the information for indicating the type of the second node, the information of the issuer of the fourth identifier, or the information for indicating the disclosure conditions of the credential information corresponding to the fourth identifier are carried in the file information corresponding to the fourth identifier. In this way, the identification information corresponding to the fourth identifier and other information can be stored independently or read separately, which can reduce information leakage, thereby enhancing privacy protection and making the publishing method more flexible.

[0033] In one possible implementation, the identification information corresponding to the fourth identifier includes a fourth field and one or more of the following: a fifth field or a sixth field, wherein the information carried by the fourth field is used to indicate the fourth identifier, the information carried by the fifth field is used to indicate the identification type of the fourth identifier, and the information carried by the sixth field is used to verify the information carried by fields other than the sixth field in the identification information corresponding to the fourth identifier.

[0034] Regarding the technical effects of the second aspect, reference may be made to the technical effects of the method described in the first aspect, which will not be repeated here.

[0035] In combination with the solution of the first aspect or the second aspect, in one possible implementation, the service information corresponding to the first identifier is used to generate proof information of the third node and / or authentication information of the third node. And / or, the service information corresponding to the first identifier is used to verify the proof information of the third node and / or authentication information of the third node. And / or, the service information corresponding to the first identifier is used to provide the third node with one or more of the following services: contract service, network access service, or data sharing service; wherein, the third node is different from the first node, the credential information of the third node is used to verify the third node, and the proof information of the third node is used to verify the attributes corresponding to the identifier of the third node. In this way, the content of the service information can be more flexible. For example, the service information can be matched according to the specific usage scenario.

[0036] In a possible implementation, the first information is further used to indicate credential information corresponding to the first identifier, and the credential information corresponding to the first identifier is used to verify the first node and / or to verify the attribute corresponding to the first identifier.

[0037] In one possible implementation, the credential information corresponding to the first identifier includes authentication information corresponding to the first identifier and / or proof information corresponding to the first identifier. The authentication information corresponding to the first identifier is used to verify the first node, and the proof information corresponding to the first identifier is used to verify the attributes corresponding to the first node. In this way, the first information stored in the storage node can include the first identifier and the credential information corresponding to the first identifier. Because the first credential information can be used to verify the first identifier or the attributes corresponding to the first identifier, other nodes can verify the first identifier.

[0038] In one possible implementation, the first information includes the first identifier, service information corresponding to the first identifier, and one or more of the following: information indicating the type of the first node, information about the issuer of the first identifier, or information indicating disclosure conditions for the credential information corresponding to the first identifier. This allows for greater flexibility in the content of the first information.

[0039] In one possible implementation, the first identifier and the credential information corresponding to the first identifier are carried in the identification information corresponding to the first identifier. In this way, the identification information of the first identifier includes credential information for authenticating the first node, so that file information can be generated according to actual conditions, thereby making the file information more accurate and reducing the amount of stored data. Alternatively, the first identifier is carried in the identification information corresponding to the first identifier, and one or more of the credential information corresponding to the first identifier, the service information corresponding to the first identifier, the information indicating the type of the terminal, the information of the issuer of the first identifier, or the information indicating the disclosure conditions of the credential information corresponding to the first identifier are carried in the file information corresponding to the first identifier. In this way, the identification information corresponding to the first identifier and other information can be stored independently or read separately, which can reduce information leakage, thereby enhancing privacy protection and making the publishing method more flexible.

[0040] In one possible implementation, the certification information corresponding to the first identifier is generated by a fourth node based on service information corresponding to the fourth node, and the certification information corresponding to the first identifier is signed by a private key corresponding to the fourth node. The fourth node is different from the first node.

[0041] In one possible implementation, the service information corresponding to the fourth node is used to generate service result information, and the service result information includes credential information of a fifth node. The fifth node is different from the fourth node. The credential information of the fifth node is used to verify the fifth node and / or to verify the attributes corresponding to the identifier of the fifth node.

[0042] In a possible implementation, the identification information corresponding to the first identification is information signed by a private key corresponding to the identification of the first node, which is generated by a card vendor or a terminal manufacturer.

[0043] In one possible implementation, the storage node is one or more of the following: a blockchain node, a distributed storage node, or a communication device. The communication device is different from the first node.

[0044] According to a third aspect, a communication method is provided. The communication method includes: a second node obtaining sixth information. The sixth information is used to indicate a fourth identifier of the second node and credential information corresponding to the fourth identifier, and the credential information corresponding to the fourth identifier is used to verify attributes corresponding to the second node and / or the fourth identifier. The fourth identifier and the credential information corresponding to the fourth identifier are generated by the first node. The second node sends the sixth information and / or a hash value of the sixth information to a storage node.

[0045] Based on the method provided in the third aspect, the second node can obtain the sixth information and upload the sixth information by itself, which can improve the second node's control over its own identification and credential information.

[0046] In one possible implementation, the credential information corresponding to the fourth identifier includes authentication information corresponding to the fourth identifier and / or proof information corresponding to the fourth identifier, the authentication information corresponding to the fourth identifier is used to verify the second node, and the proof information corresponding to the fourth identifier is used to verify the attribute corresponding to the fourth identifier.

[0047] In one possible implementation, the sixth information includes the fourth identifier and one or more of the following: credential information corresponding to the fourth identifier, service information corresponding to the fourth identifier, information used to indicate the type of the second node, information of the issuer of the fourth identifier, or information used to indicate the disclosure conditions of the credential information corresponding to the fourth identifier.

[0048] In one possible implementation, the fourth identifier and the credential information corresponding to the fourth identifier are carried in the identification information corresponding to the fourth identifier; or, the fourth identifier is carried in the identification information corresponding to the second identifier, and one or more of the credential information corresponding to the fourth identifier, the service information corresponding to the fourth identifier, the information used to indicate the type of the second node, the information of the issuer of the fourth identifier, or the information used to indicate the disclosure conditions of the credential information corresponding to the fourth identifier are carried in the file information corresponding to the fourth identifier.

[0049] Optionally, the identification information corresponding to the fourth identifier includes a fourth field and one or more of the following: a fifth field or a sixth field, wherein the information carried by the fourth field is used to indicate the fourth identifier, the information carried by the fifth field is used to indicate the identification type of the fourth identifier, and the information carried by the sixth field is used to verify the information carried by fields other than the sixth field in the identification information corresponding to the fourth identifier.

[0050] In one possible implementation, the storage node is one or more of the following: a blockchain node, a distributed storage node, or a communication device. The communication device is different from the first node.

[0051] In a fourth aspect, a communication method is provided. The communication method includes: a device corresponding to an operator obtains seventh information. The seventh information is used to indicate a fifth identifier of the terminal and credential information corresponding to the fifth identifier, the credential information corresponding to the fifth identifier is used to verify attributes corresponding to the terminal and / or the fifth identifier, the fifth identifier is different from a user permanent identifier of the terminal in the device corresponding to the operator, and the fifth identifier corresponds to the user permanent identifier of the terminal, and the user permanent identifier is used for communication between the device corresponding to the operator and the terminal. The device corresponding to the operator sends the seventh information to the terminal.

[0052] Based on the method provided in the fourth aspect, the device corresponding to the operator can generate the fifth identification of the terminal and the credential information corresponding to the fifth identification. Since the fifth identification corresponds to the user permanent identification of the terminal, the device corresponding to the operator can centrally manage the information of the terminal.

[0053] In a fifth aspect, a communication method is provided. The communication method includes: a terminal receiving seventh information from a device corresponding to an operator. The seventh information is used to indicate a fifth identifier of the terminal and credential information corresponding to the fifth identifier, the credential information corresponding to the fifth identifier is used to verify attributes corresponding to the terminal and / or the fifth identifier, the fifth identifier is different from the user permanent identifier of the terminal, and the fifth identifier corresponds to the user permanent identifier of the terminal, and the user permanent identifier is used for communication between the device corresponding to the operator and the terminal. The terminal stores the seventh information.

[0054] In addition, the technical effects of the communication method described in the fifth aspect can refer to the technical effects of the communication method described in the fourth aspect, and will not be repeated here.

[0055] In one possible implementation, the credential information corresponding to the fifth identifier includes authentication information corresponding to the fifth identifier and / or proof information corresponding to the fifth identifier, the authentication information corresponding to the fifth identifier is used to verify the terminal, and the proof information corresponding to the fifth identifier is used to verify the attributes corresponding to the terminal.

[0056] In one possible implementation, the seventh information includes the fifth identifier, and one or more of the following: credential information corresponding to the fifth identifier, proof information corresponding to the fifth identifier, information used to indicate the type of the terminal, information of the issuer of the fifth identifier, and information used to indicate the disclosure conditions of the credential information corresponding to the fifth identifier.

[0057] In one possible implementation, the fifth identifier and the credential information corresponding to the fifth identifier are carried in the identification information corresponding to the fifth identifier; or, one or more of the credential information corresponding to the fifth identifier, the service information corresponding to the fifth identifier, the information used to indicate the type of the terminal, the information of the issuer of the fifth identifier, and the information used to indicate the disclosure conditions of the credential information corresponding to the fifth identifier are carried in the file information corresponding to the fifth identifier.

[0058] In one possible implementation, the identification information corresponding to the fifth identifier includes the seventh field and one or more of the following: the eighth field or the ninth field, wherein the information carried by the seventh field is used to indicate the fifth identifier, the information carried by the eighth field is used to indicate the identification type of the fifth identifier, and the information carried by the ninth field is used to verify the information carried by the fields other than the ninth field in the identification information corresponding to the fifth identifier. In this way, the node corresponding to the fifth identifier can be indicated by the seventh field. In addition, in the case where the identification information corresponding to the fifth identifier includes the eighth field, the type of the fifth identifier can be determined, and then the source, credibility or usage scenario of the fifth identifier can be determined based on the fifth identifier. In the case where the information corresponding to the fifth identifier includes the ninth field, verification of other fields, such as the seventh field, or the seventh field and the eighth field can be implemented to ensure the accuracy of the fifth identifier.

[0059] In a sixth aspect, a communication method is provided, which includes: the device corresponding to the card dealer or terminal manufacturer obtains the eighth information and the ninth information. The eighth information includes a seventh identifier for indicating the device corresponding to the card dealer or terminal manufacturer, and the credential information corresponding to the seventh identifier, and the credential information corresponding to the seventh identifier is used to verify the device corresponding to the card dealer or terminal manufacturer and / or for verifying the attribute corresponding to the seventh identifier. The ninth information is used to indicate the eighth identifier of the terminal and the credential information corresponding to the eighth identifier, and the credential information corresponding to the eighth identifier is used to verify the attribute corresponding to the terminal and / or the eighth identifier. The eighth identifier and the credential information corresponding to the eighth identifier are generated by the device corresponding to the card dealer or terminal manufacturer, that is, the credential information corresponding to the eighth identifier is signed by the private key of the device corresponding to the card dealer or terminal manufacturer. The device corresponding to the card dealer or terminal manufacturer sends the eighth information and the ninth information to the storage node.

[0060] Based on the method provided in the sixth aspect, the device corresponding to the card vendor or terminal manufacturer can send the eighth information and the ninth information to the storage node, and the eighth identifier and the credential information corresponding to the eighth identifier are generated by the device corresponding to the card vendor or terminal manufacturer, thereby enabling the device corresponding to the card vendor or terminal manufacturer to endorse the eighth identifier and the credential information corresponding to the eighth identifier. For example, the credential information corresponding to the eighth identifier is signed by the private key of the device corresponding to the card vendor or terminal manufacturer. Therefore, if the device corresponding to the card vendor or terminal manufacturer is trustworthy, the eighth identifier and the credential information corresponding to the eighth identifier can be trusted and communicated between different domains.

[0061] In a possible implementation manner, the method provided in the sixth aspect may further include: a device corresponding to the card vendor or the terminal manufacturer sends ninth information to the terminal.

[0062] In the seventh aspect, a communication method is provided, which includes: a storage node receives eighth information and ninth information. The eighth information includes a seventh identifier for indicating the device corresponding to the card dealer or terminal manufacturer, and credential information corresponding to the seventh identifier, and the credential information corresponding to the seventh identifier is used to verify the device corresponding to the card dealer or terminal manufacturer and / or for verifying the attribute corresponding to the seventh identifier. The ninth information is used to indicate the eighth identifier of the terminal and the credential information corresponding to the eighth identifier, and the credential information corresponding to the eighth identifier is used to verify the attribute corresponding to the terminal and / or the eighth identifier. The eighth identifier and the credential information corresponding to the eighth identifier are generated by the device corresponding to the card dealer or terminal manufacturer, that is, the credential information corresponding to the eighth identifier is signed by the private key of the device corresponding to the card dealer or terminal manufacturer. The storage node stores the eighth information and the ninth information.

[0063] Based on the method provided in the seventh aspect, the storage node can receive the eighth information and the ninth information, and the eighth identifier and the credential information corresponding to the eighth identifier are generated by the device corresponding to the card vendor or terminal manufacturer, which can enable the device corresponding to the card vendor or terminal manufacturer to endorse the eighth identifier and the credential information corresponding to the eighth identifier. For example, the credential information corresponding to the eighth identifier is signed by the private key of the device corresponding to the card vendor or terminal manufacturer. Therefore, if the device corresponding to the card vendor or terminal manufacturer is trustworthy, the eighth identifier and the credential information corresponding to the eighth identifier can be trusted and communicated between different domains.

[0064] In a possible implementation, the storage node receives the eighth information and the ninth information, including: the storage node receives the eighth information and the ninth information from a device corresponding to a card manufacturer or a terminal manufacturer.

[0065] In one possible implementation, the storage node receives the eighth information and the ninth information, including: the storage node receives the eighth information from a device corresponding to a card vendor or a terminal manufacturer, and receives the ninth information from a terminal. In some possible examples, the device corresponding to the card vendor or the terminal manufacturer may be a device corresponding to the card vendor or the terminal manufacturer, and the terminal may be a terminal.

[0066] In an eighth aspect, a communication device is provided, which is used to execute the communication method described in any one of the implementations of the first to seventh aspects.

[0067] In the present application, the communication device described in the eighth aspect can be a terminal or a network device, or a chip (system), or other parts or components or software modules that can be set in the terminal or network device, or a device that includes the terminal or network device.

[0068] It should be understood that the communication device described in the eighth aspect includes a module, unit, or means corresponding to the communication method described in any one of the first to seventh aspects above. The module, unit, or means can be implemented by hardware, software, or hardware executing the corresponding software implementation. The hardware or software includes one or more modules or units for performing the functions involved in the above-mentioned communication method.

[0069] In a ninth aspect, a communication device is provided, comprising: a processor configured to execute the communication method described in any possible implementation of the first to seventh aspects.

[0070] In one possible implementation, the communication device described in aspect 9 may further include a transceiver. The transceiver may be a transceiver circuit or an interface circuit. The transceiver may be used for the communication device described in aspect 9 to communicate with other communication devices.

[0071] In one possible implementation, the communication device described in aspect 9 may further include a memory. The memory may be integrated with the processor or provided separately. The memory may be used to store the computer program and / or data involved in the communication method described in any one of aspects 1 to 7.

[0072] The processor is coupled to the memory, and the processor is used to execute the computer program stored in the memory so that the communication device executes the communication method described in any possible implementation manner of the first aspect to the seventh aspect.

[0073] In the present application, the communication device described in the ninth aspect can be the first node, the second node, the equipment corresponding to the card manufacturer or the terminal manufacturer, the storage node, the terminal, the equipment corresponding to the card manufacturer or the device manufacturer, or a chip (system), other parts or components or software modules that can be set in the first node, the second node, the equipment corresponding to the card manufacturer or the terminal manufacturer, the storage node, the terminal, the equipment corresponding to the card manufacturer or the device manufacturer, or a device that includes the first node, the second node, the equipment corresponding to the card manufacturer or the terminal manufacturer, the storage node, the terminal, the equipment corresponding to the card manufacturer or the device manufacturer.

[0074] In a tenth aspect, a communication system is provided, which includes one or more terminals and one or more network devices.

[0075] In the eleventh aspect, a computer-readable storage medium is provided, comprising: a computer program or instructions; when the computer program or instructions are run on a computer, the computer executes the communication method described in any possible implementation method of the first to seventh aspects.

[0076] In the twelfth aspect, a computer program product is provided, comprising a computer program or instructions, which, when executed on a computer, enables the computer to execute the communication method described in any one of the possible implementations of the first to seventh aspects.

[0077] In addition, the technical effects of the communication devices described in the eighth to twelfth aspects above can refer to the technical effects of the communication methods described in the first to seventh aspects above, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0078] FIG1 is a schematic diagram of the architecture of a communication system provided in an embodiment of the present application;

[0079] FIG2 is a flow chart of a communication method according to an embodiment of the present application;

[0080] FIG3 is a schematic diagram of the structure of a first identifier provided in an embodiment of the present application;

[0081] FIG4 is a second flow chart of the communication method provided in an embodiment of the present application;

[0082] FIG5 is a schematic diagram of first information provided in an embodiment of the present application;

[0083] FIG6 is a schematic diagram of information stored in a terminal according to an embodiment of the present application;

[0084] FIG7 is a schematic diagram of the relationship between different identifiers and file information between different identifiers provided in an embodiment of the present application;

[0085] FIG8 is a third flow chart of the communication method provided in an embodiment of the present application;

[0086] FIG9 is a fourth flow chart of a communication method according to an embodiment of the present application;

[0087] FIG10 is a fifth flow chart of a communication method according to an embodiment of the present application;

[0088] FIG11 is a first structural diagram of a communication device provided in an embodiment of the present application;

[0089] FIG12 is a second structural diagram of the communication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0090] Users can identify themselves through identity identifiers, such as their decentralized identifiers (DIDs).

[0091] In information technology (IT) or communication technology (CT), a node can provide services to other nodes through the service information corresponding to the node, or in other words, the service of a node can be obtained by obtaining the service information of the node. The service information of a node can be obtained from the node, or from the node that generates the service information of the node. For example, the node corresponding to the card dealer or terminal manufacturer can generate the service information of the (node) corresponding to the terminal, and the node corresponding to the terminal can also store the service information of the node corresponding to the terminal. Therefore, if you need to obtain the service provided by the terminal, you need to obtain the service information of the terminal from the node corresponding to the terminal or the node corresponding to the card dealer or terminal manufacturer. In the above scheme, the acquisition of service information needs to rely on the node that provides the service or the node that generates the service information, and the application scenario is limited.

[0092] In addition, in a certain field or industry, if a user needs to obtain the services of a merchant, he or she must first provide the user's identity-related information and register an account with the merchant. The merchant will save the user's identity-related information and account. The user can obtain the merchant's services based on the user's registered account and password. For other merchants that do not store the user's identity-related information, account (i.e., user identification), and password, it is impossible to determine whether the user is trustworthy. In different fields, users need to use different identifications for verification. Therefore, there is no trust and intercommunication between different fields, that is, the same identification of the terminal cannot be used in different fields.

[0093] The technical solutions in the embodiments of the present application will be described below with reference to the accompanying drawings.

[0094] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as wireless fidelity (WiFi) systems, vehicle-to-everything (V2X) communication systems, device-to-device (D2D) communication systems, Internet of Vehicles communication systems, 4th generation (4G) mobile communication systems, such as long term evolution (LTE) systems, fifth generation (5G) mobile communication systems, such as new radio (NR) systems, and communication systems evolved after 5G, such as sixth generation (6G) mobile communication systems.

[0095] This application will present various aspects, embodiments, or features in the context of systems that may include multiple devices, components, modules, etc. It should be understood and appreciated that each system may include additional devices, components, modules, etc., and / or may not include all of the devices, components, modules, etc. discussed in conjunction with the figures. Furthermore, combinations of these aspects may also be used.

[0096] Additionally, in the embodiments of this application, words such as "exemplarily" and "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or implementation described in this application as "exemplary" should not be construed as preferred or advantageous over other embodiments or implementations. Rather, the use of the word "exemplary" is intended to present concepts in a concrete manner.

[0097] The network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Ordinary technicians in this field will know that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.

[0098] To facilitate understanding of the embodiments of the present application, a communication system applicable to the embodiments of the present application is first described in detail using the communication system shown in Figure 1 as an example. For example, Figure 1 is a schematic diagram of the architecture of a communication system applicable to the communication method provided in the embodiments of the present application.

[0099] As shown in FIG. 1 , the communication system includes at least one node (nodes 101 a to 101 i ) and a storage system 102 .

[0100] The storage system 102 may include one or more storage nodes.

[0101] The storage system 102 may include one or more of the following: a blockchain system (in which case, the storage node may be a blockchain node), a distributed storage system (a storage node is a node in a distributed system), or a communication device (a storage node is a communication device).

[0102] Among them, the blockchain system may include one or more blockchain nodes, the distributed storage system may include one or more distributed storage devices, and the communication equipment may include equipment corresponding to the operator.

[0103] It should be understood that a blockchain node can be a terminal or a network device, a storage device in a distributed storage system can be a terminal or a network device, and a communication device can be a terminal or a network device.

[0104] The nodes in at least one node (nodes 101a to 101i) can exchange information with the storage system. If the at least one node includes multiple nodes, then two nodes in the multiple nodes can directly exchange information. The nodes in at least one node (nodes 101a to 101i) can include terminals and network devices. Among them, the nodes in at least one node (nodes 101a to 101i) can be devices corresponding to users, and the network devices can be devices corresponding to card vendors or terminal manufacturers, devices corresponding to trusted third parties, air card writing servers, devices corresponding to operators, or devices corresponding to authoritative agencies. Terminal manufacturers can also be called equipment vendors, equipment providers, etc. It is understandable that card vendors, terminal manufacturers, trusted third parties, operators, or authoritative agencies are all used as examples. In actual implementation, other organizations or institutions may also exist.

[0105] The device corresponding to the card merchant or terminal manufacturer may be a device used to implement the business of the card merchant or terminal manufacturer, such as a card writing device of the card merchant or terminal manufacturer.

[0106] Operator-specific equipment is used to provide operator services, such as operator servers, network elements in the core network, or access network equipment. Authority-specific equipment is used to provide authority services, such as servers or hosts belonging to the authority.

[0107] The device corresponding to the third-party trusted organization can be used as a device for providing services of the third-party trusted organization, such as a server or host belonging to the third-party trusted organization.

[0108] The above-mentioned terminal is a terminal that accesses the above-mentioned communication system and has a transceiver function, or a chip or chip system that can be set in the terminal, or a unit or module with terminal function. The terminal can also be called a terminal device, and can also be called user equipment (UE), mobile station (MS), mobile terminal (MT), etc., or a device used to provide voice or data connectivity to users, or an Internet of Things device. For example, the terminal includes a handheld device with wireless connection function, a vehicle-mounted device, etc. Currently, terminals can be: mobile phones, tablets, laptops, PDAs, mobile internet devices (MIDs), wearable devices (such as smart watches, smart bracelets, pedometers, smart glasses, etc.), vehicle-mounted equipment (such as cars, bicycles, electric vehicles, airplanes, ships, trains, high-speed trains, etc.), satellite terminals, virtual reality (VR) devices, augmented reality (AR) devices, smart point of sale (POS) machines, customer-premises equipment (CPE), wireless terminals in industrial control, smart home devices (such as refrigerators, televisions, air conditioners, electricity meters, etc.), intelligent robots, robotic arms, workshop equipment, wireless terminals in unmanned driving, wireless terminals in telemedicine, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, or wireless terminals in smart homes, flying equipment (such as intelligent robots, hot air balloons, drones, airplanes), etc. The terminal can also be a vehicle device, such as a complete vehicle device, a vehicle-mounted module, a vehicle-mounted chip, an on-board unit (OBU) or a telematics box (T-BOX), etc. The terminal can also be other devices with terminal functions. For example, the terminal can also be a device that serves as a terminal in D2D communication.

[0109] The terminal of the present application may also be a module or unit that can be used to implement terminal functions. For example, the terminal may also be a universal integrated circuit card (UICC). It should be understood that the UICC card in the embodiments of the present application is for example only. In actual implementation, the UICC card may also be replaced by a device with the same functions as the UICC card. In addition, the UICC card also has other names, such as the blockchain universal integrated circuit card (B-UICC), which is not limited in the embodiments of the present application.

[0110] The embodiments of this application do not limit the device form factor of the terminal. The device used to implement the terminal's function can be a terminal; it can also be a device that supports the terminal in implementing the function, such as a chip system. The device can be installed in the terminal or used in conjunction with the terminal. In the embodiments of this application, the chip system can be composed of a chip or include a chip and other discrete components.

[0111] In one possible scenario, the network device may be a base station, an evolved NodeB (eNodeB), a transmitting and receiving point (TRP), a transmitting point (TP), a next-generation NodeB (gNB), a next-generation base station in a sixth-generation (6G) mobile communication system, a base station in a future mobile communication system, a satellite, an access point (AP) in a WiFi system, an integrated access and backhaul (IAB) node, a mobile switching center, or a network device in a non-terrestrial network (NTN) communication system, i.e., it may be deployed on a high-altitude platform or a satellite. The network device may be a macro base station (such as 110a in FIG. 1 ), a micro base station or an indoor station (such as 110b in FIG. 1 ), a relay node or a donor node, or a wireless controller in a cloud radio access network (CRAN) scenario. Network devices can also serve as base stations in device-to-device (D2D) communications, Internet of Vehicles (IoV) communications, drone communications, and machine-to-machine communications. Alternatively, network devices can be servers, wearable devices, vehicles, or onboard devices. For example, the access network device in vehicle-to-everything (V2X) technology can be a roadside unit (RSU).

[0112] In another possible scenario, multiple network devices collaborate to assist the terminal in achieving wireless access, and different network devices respectively implement part of the functions of the base station. For example, the network device can be a centralized unit (CU), a distributed unit (DU), a CU-control plane (CP), a CU-user plane (UP), or a radio unit (RU). The CU and DU can be set separately, or they can also be included in the same network element, such as a baseband unit (BBU). The RU can be included in a radio frequency device or a radio frequency unit, such as a remote radio unit (RRU), an active antenna unit (AAU), or a remote radio head (RRH). It can be understood that the network device can be a CU node, a DU node, or a device including a CU node and a DU node. In addition, the CU can be divided into a network device in the radio access network (RAN), or the CU can be divided into a network device in the core network (CN), without limitation here.

[0113] In different systems, CU (or CU-CP and CU-UP), DU or RU may also have different names, but those skilled in the art can understand their meanings. For example, in an open access network (open RAN, ORAN) system, CU may also be called O-CU (open CU), DU may also be called O-DU, CU-CP may also be called O-CU-CP, CU-UP may also be called O-CU-UP, and RU may also be called O-RU. For the convenience of description, this application uses CU, CU-CP, CU-UP, DU and RU as examples for description. Any unit of CU (or CU-CP, CU-UP), DU and RU in this application can be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.

[0114] In another possible scenario, the above-mentioned network device may also be a network element or device in the core network.

[0115] In some other possible scenarios, the above-mentioned network device may be a network element or device in a wired network, such as a server.

[0116] In the embodiments of the present application, there is no limitation on the form of the network device. The device used to implement the function of the network device can be a network device; it can also be a device that can support the network device to implement the function, such as a chip system. The device can be installed in the network device or used in conjunction with the network device. It should be understood that the nodes in the embodiments of the present application are only used as examples. In actual implementation, the nodes in the embodiments of the present application can also be devices corresponding to other organizations or institutions, which will not be repeated here. It should be understood that the blockchain node described in the embodiments of the present application can include multiple communication devices, and the distributed system described in the embodiments of the present application can include multiple communication devices.

[0117] It should be noted that the communication method provided in the embodiment of the present application can be applied between the node and the storage node shown in Figure 1. The specific implementation can refer to the following method embodiment, which will not be repeated here.

[0118] It should be noted that the solutions in the embodiments of the present application can also be applied to other communication systems, and the corresponding names can also be replaced by the names of corresponding functions in other communication systems.

[0119] It should be understood that FIG1 is only a simplified schematic diagram for ease of understanding, and the communication system may also include other network devices and / or other terminals, which are not shown in FIG1 .

[0120] The communication method provided in the embodiment of the present application will be described in detail below with reference to Figures 2 to 10.

[0121] For example, Figure 2 is a flow chart of a communication method according to an embodiment of the present application. The communication method can be applied to the communication between the node and the storage node shown in Figure 2 .

[0122] As shown in FIG2 , the communication method includes the following steps:

[0123] S201: A first node obtains first information.

[0124] The first information includes the first identifier and service information corresponding to the first identifier.

[0125] In one possible implementation, the first node can include one or more of the following: a device corresponding to a card vendor or terminal manufacturer, a terminal, a device corresponding to an operator, a device corresponding to an authority, a device corresponding to a third-party trusted institution, or an over-the-air card writing server. This allows the first node to be determined based on the actual scenario, and each of the aforementioned devices can store their own identification and service information in the storage node, providing greater flexibility in application scenarios.

[0126] Regarding the implementation of the equipment and terminals corresponding to the card vendors or terminal manufacturers, the equipment corresponding to the operators, the equipment corresponding to the authoritative agencies, and the equipment corresponding to the third-party trusted agencies, please refer to the relevant introduction in the communication system provided in Figure 1, which will not be repeated here.

[0127] The first identifier is information for identifying the first node, or the first identifier is information for identifying the attribute corresponding to the first identifier. The first identifier can reuse the embedded universal integrated circuit card (eUICC) form of the UICC specified by the Global System for Mobile Communications Association (groupe speciale mobile association, GSMA). For example, the first identifier can be "0x12345678", where the first identifier is only used as an example. In actual implementation, the first identifier can also be other possible implementation methods, which are not repeated here. It should be understood that the first identifier can be a decentralized root certificate / credential (DRC), or a decentralized identity certificate / credential (DIC), or a decentralized self-control identity (DSCC). Among them, DRC, DIC and DSCC can all be referred to as self-control identity (scID). It can be understood that in the embodiment of the present application, the attribute corresponding to the node's identifier also corresponds to the node, that is, the attribute corresponding to the node's identifier can also be said to be the attribute corresponding to the node. A node can have multiple identifiers, and different identifiers can have their own corresponding attributes.

[0128] In some possible implementations, the first identifier may be information generated by a trusted node other than the first node for identifying the first node. For example, if the first identifier is a DRC, the DRC may be generated by a trusted node other than the first node. In other possible embodiments, the first identifier may be information generated by the first node based on a root credential for identifying the first node or identifying the corresponding attribute of the node, such as a decentralized identity credential (DIC).

[0129] In some other possible implementations, the first identifier may be information generated by the first node to identify the first node or an attribute of the first node, such as decentralized self-control credentials (DSCC). In this way, different types of first identifiers can be used according to different business scenarios. For example, in business scenarios with high requirements for confidentiality of personal information, DIC can be used to complete the business. For another example, in scenarios with low requirements for trust in the first node, DSCC can be used to complete the business.

[0130] In some possible implementations, the attributes corresponding to the first node may include social attributes, such as the first node is a legal citizen, the first node has completed real-name authentication, the first node's academic qualifications, the first node's job, etc.

[0131] In some possible implementations, the attributes corresponding to the first node may further include other objective attributes, such as the location, age, and certain permissions of the first node.

[0132] In one possible implementation, the service information corresponding to the first identifier includes information about services that the first node can provide, such as the location of the service (for example, if the service is implemented through a smart contract, the location of the service can be the address of the smart contract that implements the service's functionality) or parameters required to call the service (such as parameters for calling a contract service or identity verification service). This is explained below in conjunction with Scenarios 1 to 4.

[0133] Scenario 1: The service information corresponding to the first identifier is used to generate proof information of the third node and / or authentication information of the third node.

[0134] Scenario 2: The service information corresponding to the first identifier is used to verify the proof information of the third node and / or the authentication information of the third node.

[0135] In scenario 3, the third node can call the service in the service information using the service corresponding to the first identifier. In other words, the service information corresponding to the first identifier can be used to provide the service in the service information to the third node. For example, the service information corresponding to the first identifier is used to provide the third node with one or more of the following services: contract service, network access service, or data sharing service. The third node is different from the first node, the credential information of the third node is used to verify the third node, and the certification information of the third node is used to verify the attributes corresponding to the identifier of the third node.

[0136] If the first node is a card dealer, the service information corresponding to the first identifier is the card dealer's service information. This service information can be used to implement the functionality of the service information in Scenario 1 or Scenario 2. For example, if the third node is a terminal, where the terminal is a card, the card dealer can use the card dealer's service information to generate certification information for the card, used to verify the card's security level. Alternatively, the card dealer can use the card dealer's service information to generate authentication information for the card, that is, to generate a certificate for the card. This certificate can be used to endorse the card's public key. Alternatively, the card dealer can use the card dealer's service information to complete card verification. That is, when other nodes verify the card, they can use the card dealer's service information for verification.

[0137] Similarly, if the first node is a carrier, the service information corresponding to the first identifier is the card vendor's service information, which can be used to implement the functions of the service information in scenario 1 or scenario 2. Furthermore, the service information can be used to implement the functions of the service information in scenario 3. For example, the second node can run the service in the service information to verify the user's identity or to verify the location.

[0138] The attributes corresponding to the third node's identifier refer to conditions satisfied by the third node and / or its owner (user), such as the region in which the third node is located or the identity of the third node's owner (user). Alternatively, the implementation principles of the attributes corresponding to the third node's identifier can be found in the description of the attributes corresponding to the first identifier, and will not be further elaborated on.

[0139] In the following embodiments, regarding the implementation of the attributes corresponding to the identifier and the attributes corresponding to the node, reference may be made to the relevant introduction to the attributes corresponding to the first identifier, which will not be repeated here.

[0140] The identifier of the third node is information used to identify the third node. The identifier of the third node may be one or more, wherein each identifier of the third node has a corresponding attribute.

[0141] Verifying a third node refers to verifying whether a node is a third node, or verifying the legitimacy or validity of the third node, etc. Verifying an attribute corresponding to the identifier of the third node refers to verifying whether the attribute corresponding to the identifier of the third node is true.

[0142] Optionally, the first information is further used to indicate credential information corresponding to the first identifier, and the credential information corresponding to the first identifier is used to verify the first node and / or to verify the attribute corresponding to the first identifier. In other words, the credential information corresponding to the first identifier includes information used to verify the first node, i.e., authentication information corresponding to the first identifier, and / or information used to verify the attribute corresponding to the first identifier, i.e., certification information corresponding to the first identifier. It is understandable that the authentication information corresponding to the first identifier is used to verify the first node, and the certification information corresponding to the first identifier is used to verify the attribute corresponding to the first node.

[0143] Verifying the first node refers to verifying whether a node is the first node, or verifying the legitimacy or validity of the third node. The implementation principle of verifying the first node can be referred to the relevant introduction of verifying the third node, which will not be repeated here.

[0144] For verifying the attributes corresponding to the first identifier, please refer to the relevant introduction of verifying the attributes corresponding to the third identifier, which will not be repeated here.

[0145] In some possible examples, the authentication information corresponding to the first identifier may include: the public key corresponding to the first identifier, information of the subject corresponding to the first identifier, the signature corresponding to the first identifier, the cryptographic algorithm corresponding to the first identifier, information of the issuer of the first identifier, the validity period of the authentication information corresponding to the first identifier, and information used to indicate whether the authentication information corresponding to the first identifier has been revoked.

[0146] Among them, the public key corresponding to the first identifier can be used to verify whether the information is signed by the private key corresponding to the first identifier. The subject corresponding to the first identifier refers to the object to which the first identifier belongs. The signature corresponding to the first identifier refers to the information obtained by signing the first identifier. The cryptographic algorithm corresponding to the first identifier, which may also be referred to as the cryptographic suite corresponding to the first identifier, includes one or more of the following: key length, encryption algorithm, decryption algorithm, signature algorithm, or public parameters, etc. The information of the issuer of the first identifier can be used to verify the information of the issuer of the first identifier. For example, the information of the issuer of the first identifier can be the public key of the issuer of the first identifier. The information used to indicate whether the authentication information corresponding to the first identifier has been revoked can be information indicating all authentication information that has been revoked, such as a revocation list (including the identifiers of all authentication information that has been revoked).

[0147] The certification information corresponding to the first identifier may also be referred to as a certificate corresponding to the first identifier, a verifiable credential corresponding to the first identifier, a verifiable credential (VC) corresponding to the first identifier, etc., which will not be repeated here.

[0148] The certification information corresponding to the first identifier is generated based on the service information of the fourth node.

[0149] In one possible design, the certification information corresponding to the first identifier is generated by a fourth node based on service information corresponding to the fourth node. If the first identifier is generated by the fourth node, the certification information corresponding to the first identifier is signed by a private key corresponding to the fourth node. The fourth node is different from the first node.

[0150] In one possible implementation, when the storage node is a blockchain node, the fourth node may store service information corresponding to the fourth node in the blockchain system. The service information may be used to indicate the service that generated the node's certification information.

[0151] In one possible implementation, the service indicating the node's certification information in the service information is implemented via a smart contract. In this case, the certification information of the first identifier can be obtained by the fourth node invoking the smart contract. It is understood that in this case, the certification information of the first identifier can also be obtained by other nodes other than the fourth node invoking the smart contract.

[0152] In one possible implementation, the service information of the fourth information may indicate the address of a website used to generate the certification information corresponding to the identifier. In this case, the certification information corresponding to the first identifier may be obtained by the fourth node by accessing the website according to the website address. In this case, the certification information corresponding to the first identifier may be signed by the fourth node's private key.

[0153] If the first identifier is generated by another identifier of the first node, the first identifier may be signed by a private key corresponding to the identifier that generates the first identifier.

[0154] The service information corresponding to the fourth node may be the service information corresponding to the identifier of the fourth node. For the service information corresponding to the fourth node, reference may be made to the service information corresponding to the first identifier, which will not be repeated here.

[0155] Optionally, the service information corresponding to the fourth node is used to generate service result information, which includes the credential information of the fifth node. The fifth node is different from the fourth node. The credential information of the fifth node is used to verify the fifth node and / or to verify the attributes corresponding to the identifier of the fifth node. The implementation of the service information corresponding to the fourth node can refer to the implementation principles of the service information corresponding to the first identifier and will not be repeated here.

[0156] In one possible implementation, the first information includes a first identifier, service information corresponding to the first identifier, and one or more of the following: authentication information corresponding to the first identifier, proof information corresponding to the first identifier, information indicating the type of the first node, information of the issuer of the first identifier, or information indicating the disclosure conditions of the credential information corresponding to the first identifier.

[0157] It can be understood that in the embodiment of the present application, information A including information B may mean that information A includes information used to indicate information B.

[0158] The type of the first node may be determined based on the owner of the device corresponding to the first node. For example, the type of the first node may indicate whether the first node is a terminal, a device corresponding to an operator, or a device corresponding to another merchant. It is understood that the type of the first node may also be determined in other ways, for example, based on the services or functions implemented by the first node, which is not limited in the embodiments of the present application.

[0159] The issuer of the first identification can also be said to be the subject that generates the first identification, such as an individual, organization or institution. The information of the issuer of the first identification can be information used to identify the issuer of the first identification, such as the identifier of the issuer of the first identification.

[0160] The disclosure conditions for the credential information corresponding to the first identifier, i.e., the conditions under which the credential information corresponding to the first identifier may be displayed or provided (disclosed). For example, the disclosure conditions for the credential information corresponding to the first identifier may include: the time period (e.g., time period) during which the credential information corresponding to the first identifier may be displayed or provided, the scope (e.g., network domain) within which the credential information corresponding to the first identifier may be displayed or provided, the scenarios in which the credential information corresponding to the first identifier may be displayed or provided, etc.

[0161] For ease of understanding, the first information is explained below in conjunction with different implementations of the first information.

[0162] Implementation method 1: The first information includes identification information corresponding to the first identifier, and the identification information corresponding to the first identifier includes the first identifier and credential information corresponding to the first identifier.

[0163] Optionally, the first information may further include one or more of the following: information indicating the type of the first node, information about the issuer of the first identifier, or information indicating disclosure conditions for the credential information corresponding to the first identifier. For example, the first information may further include profile information corresponding to the first identifier, where the profile information corresponding to the first identifier includes information indicating the type of the first node, information about the issuer of the first identifier, or information indicating disclosure conditions for the credential information corresponding to the first identifier.

[0164] It is understood that the file information corresponding to the first identifier may include the service information corresponding to the first identifier. In addition, if the credential information corresponding to the first identifier includes the authentication information corresponding to the first identifier, the first information may also include the certification information corresponding to the first identifier. For example, if the first information also includes the file information corresponding to the first identifier, the file information corresponding to the first identifier may also include the certification information corresponding to the first identifier.

[0165] The following example further illustrates the first information, using the identification information corresponding to the first identifier as an example, including the first authentication information. Assuming the first node is a device corresponding to an operator, and the first identifier is DRC1 of the device corresponding to the operator, then, as shown in (a) of Figure 3 , the identification information corresponding to DRC1 includes: DRC1, the public key corresponding to DRC1, the validity period corresponding to DRC1 (also called a timestamp), the signature corresponding to DRC1, the cryptographic algorithm corresponding to DRC1 (also called a verification algorithm), information indicating whether the authentication information corresponding to DRC1 has been revoked, and the like. The file information corresponding to DRC1 includes: the subject corresponding to the first identifier, such as the name of the operator; the service area corresponding to the first identifier; and service information corresponding to DRC1 (i.e., information about the services provided by the operator). The services in the service information corresponding to DRC1 can include contract services, business services, and certification services. Contract services are services used to provide users with package or business processing services, and business services are services used to provide users with one or more of the following services: call record query, rate query, or location query.

[0166] For another example, assuming that the first node is a terminal and the first identifier is DRC2 of the terminal, then, as shown in (b) in Figure 3, the identification information corresponding to the first identifier includes: DRC2, the public key corresponding to DRC2, the validity period corresponding to DRC2, the signature corresponding to DRC2, the cryptographic algorithm corresponding to DRC2, information used to indicate whether the authentication information corresponding to DRC2 has been revoked, etc. The file information corresponding to DRC2 includes: the certification information corresponding to DRC2 and the attributes corresponding to DRC2. For example, the certification information of DRC2 may include one or more of the following: age certificate, identity certificate, academic certificate, and operator access certificate. The age certificate is used to prove the user's age, the identity certificate is used to prove the user's identity, the academic certificate is used to prove the user's academic qualifications, and the operator access certificate is used to prove that the user has the right to access the operator. The attributes corresponding to the first identifier are used to indicate whether the user is an individual user, an organization or institution.

[0167] In a second implementation method, the first information includes identification information corresponding to the first identifier and file information corresponding to the first identifier, the identification information corresponding to the first identifier includes the first identifier, and the file information corresponding to the first identifier includes credential information corresponding to the first identifier.

[0168] The file information corresponding to the first identifier also includes one or more of the following: information indicating the type of the first node, information about the issuer of the first identifier, or information indicating disclosure conditions for the credential information corresponding to the first identifier. It is understood that the file information corresponding to the first identifier also includes service information of the first identifier.

[0169] It should be understood that in Implementation Methods 1 and 2, if the credential information corresponding to the first identifier includes authentication information corresponding to the first identifier, then the file information corresponding to the first identifier may also include proof information corresponding to the first identifier. If the credential information corresponding to the first identifier includes proof information corresponding to the first identifier, then the file information corresponding to the first identifier may also include authentication information corresponding to the first identifier. The first information in Implementation Methods 1 and 2 above is for example only. In actual implementation, the first information may also be implemented in other ways, which will not be described in detail here.

[0170] In one possible implementation, if the first node is a terminal, the identification information corresponding to the first identifier is information signed by a private key corresponding to the identifier of the first node (e.g., DRC) generated by a card dealer or terminal manufacturer. The card dealer or terminal manufacturer may also generate a public key corresponding to the identifier of the first node, and the card dealer or terminal manufacturer may also upload the public key or public key hash corresponding to the identifier of the first node to a storage node. In this way, a verification node (such as node 101i in FIG. 1 ) may obtain the public key or public key hash corresponding to the identifier of the first node from the storage node, and verify the identification information corresponding to the first identifier based on the public key corresponding to the identifier of the first node, thereby verifying the first node or the attribute corresponding to the first identifier.

[0171] S202: The first node sends first information to the storage node. Correspondingly, the storage node receives the first information from the first node.

[0172] In the embodiment of the present application, the storage node is one or more of the following: a blockchain node, a distributed storage node, or a communication device. The communication device is different from the first node.

[0173] The implementation principles of storage nodes can be found in the communication system described in FIG1 above and will not be further elaborated here. Taking a blockchain node as an example, in this case, S202 may include: a first node sending first information to a blockchain node. In response, the blockchain node receives the first information from the first node.

[0174] Taking a distributed storage node as an example, in this case, S202 may include: the first node sends first information to a node in the distributed storage node. Correspondingly, the node in the distributed storage node receives the first information from the first node.

[0175] S203: The storage node stores the first information.

[0176] If the storage node for the first information is a blockchain node, the first information may be stored in a node within the blockchain node in a block-like manner. If the storage node is a distributed storage node, the first information may be stored in a node within the distributed storage node. In some possible scenarios, the distributed storage node may be a blockchain node.

[0177] Based on the method provided in Figure 2, the first node can send the first identifier and the service information corresponding to the first identifier to the storage node. In this way, the storage node can obtain the first identifier of the first node and the service information corresponding to the first identifier, so that other nodes can obtain the service information corresponding to the first identifier through the storage node, which increases the channels for obtaining service information and reduces dependence on the first node. Therefore, it can be applied to more scenarios.

[0178] For ease of understanding, the following uses the equipment corresponding to the card merchant or terminal manufacturer, the equipment corresponding to the operator, the equipment corresponding to the authoritative agency, the equipment corresponding to the third-party trusted agency, or the air card writing server and terminal as examples to illustrate the communication method provided in Figure 2 above in combination with different scenarios.

[0179] In some scenarios, the card dealer or terminal manufacturer generates the terminal identification and the credential information corresponding to the terminal identification for the terminal. The first node in the method provided in Figure 2 can be a device corresponding to the card dealer or terminal manufacturer, a device corresponding to the operator, a device corresponding to the authority, a device corresponding to a third-party trusted institution, an air card writing server (not shown in Figure 4), or a terminal. In this case, the communication method provided in the embodiment of the present application is shown in Figure 4 below. It should be understood that in actual implementation, the first node can also be other devices, which will not be repeated here. Figure 4 is a communication method provided in an embodiment of the present application. The communication method includes:

[0180] S401, the device corresponding to the card vendor or terminal manufacturer obtains information #1.

[0181] Among them, information #1 includes the identification #1 of the device corresponding to the card merchant or terminal manufacturer and the service information corresponding to identification #1. For the implementation principle of identification #1, please refer to the relevant introduction of the first identification in the method provided in Figure 2 above. For the service information corresponding to identification #1, please refer to the relevant introduction of the service information corresponding to the first identification in the method provided in Figure 2 above. For the implementation principle of information #1, please refer to the relevant introduction of the first information in the method provided in Figure 2 above. No further details will be given here.

[0182] S402: The card vendor or terminal manufacturer's device sends information #1 to the blockchain node. In response, the blockchain node receives information #1 from the card vendor or terminal manufacturer's device.

[0183] S403, blockchain node stores information #1.

[0184] It is understood that information #1 can be stored in the form of blocks. It should be understood that in the embodiments of the present application, unless otherwise specified, blockchain node storage information can be stored in the form of blocks.

[0185] S404, the device corresponding to the card vendor or terminal manufacturer obtains information #2.

[0186] Information #2 is used to indicate the terminal's identifier #2 and the credential information corresponding to identifier #2. Information #2 is used to indicate the terminal's identifier #2 and the credential information corresponding to identifier #2. The credential information corresponding to identifier #2 is used to verify the terminal and / or the attributes corresponding to identifier #2. Identifier #2 and the credential information corresponding to identifier #2 are generated by the first node.

[0187] In one possible implementation, the credential information corresponding to identifier #2 includes authentication information corresponding to identifier #2 and / or proof information corresponding to identifier #2. The authentication information corresponding to identifier #2 is used to verify the terminal, and the proof information corresponding to identifier #2 is used to verify the attribute corresponding to identifier #2. The proof information corresponding to identifier #2 is signed by the private key of the device corresponding to the card vendor or terminal manufacturer. In this way, when the credential information corresponding to identifier #2 includes authentication information corresponding to identifier #2, the identity of the terminal can be verified. When the credential information corresponding to identifier #2 includes proof information corresponding to identifier #2, the attribute corresponding to identifier #2 can be verified.

[0188] In one possible implementation, information #2 may also include one or more of the following: service information corresponding to identifier #2, information indicating the type of terminal, information about the issuer of identifier #2, or information indicating the disclosure conditions of the credential information corresponding to identifier #2. That is, information #2 may include identifier #2, the credential information corresponding to identifier #2, and one or more of the following: service information corresponding to identifier #2, information indicating the type of terminal, information about the issuer of identifier #2, or information indicating the disclosure conditions of the credential information corresponding to identifier #2. In this way, the aforementioned one or more types of information may be stored in a storage node, allowing other devices to obtain or provide corresponding services based on the aforementioned information in the storage node.

[0189] For the authentication information corresponding to identifier #2, please refer to the relevant introduction to the authentication information corresponding to the first identifier in the method provided in Figure 2. For the proof information corresponding to identifier #2, please refer to the relevant introduction to the proof information corresponding to the first identifier in the method provided in Figure 2. For the service information corresponding to identifier #2, please refer to the relevant introduction to the service information corresponding to the first identifier in the method provided in Figure 2. For the information indicating the type of the terminal, please refer to the relevant introduction to the information indicating the type of the first node in the method provided in Figure 2. For the information of the issuer of identifier #2, please refer to the relevant introduction to the information of the issuer of the first identifier in the method provided in Figure 2. For the information indicating the disclosure conditions of the credential information corresponding to identifier #2, please refer to the relevant introduction to the information indicating the disclosure conditions of the credential information corresponding to the first identifier in the method provided in Figure 2.

[0190] For ease of understanding, information #2 is explained below in conjunction with implementation method three and implementation method four.

[0191] In implementation method three, information #2 includes identification information corresponding to identifier #2, and the identification information corresponding to identifier #2 includes identifier #2 and the credential information corresponding to identifier #2. In this way, the identification information of identifier #2 includes authentication information, so that file information can be constructed according to actual conditions, thereby making the file information more accurate.

[0192] Optionally, information #2 further includes one or more of the following: service information corresponding to identification #2, information indicating the type of terminal, information about the issuer of identification #2, or information indicating disclosure conditions for the credential information corresponding to identification #2. It is understood that the service information corresponding to identification #2, information indicating the type of terminal, information about the issuer of identification #2, or information indicating disclosure conditions for the credential information corresponding to identification #2 may all be located in the file information of identification #2.

[0193] In this way, the identification information of the second identification #2 includes the credential information for authenticating the terminal, so that the file information can be generated according to the actual situation, thereby making the file information more accurate and reducing the amount of stored data.

[0194] Implementation method four, information #2 includes identification information corresponding to identification #2 and file information corresponding to identification #2, the identification information corresponding to identification #2 includes identification #2, and the file information corresponding to identification #2 includes credential information corresponding to identification #2.

[0195] For example, the file information corresponding to ID #2 may also include one or more of the following: service information corresponding to ID #2, information indicating the terminal type, information about the issuer of ID #2, or information indicating the disclosure conditions for the credential information corresponding to ID #2. Thus, the identification information for ID #2 only includes ID #2, which can reduce the data size of the identification information corresponding to ID #2 and lower transmission resource overhead. The identification information corresponding to the second identifier can be stored or read separately from other information, reducing information leakage, thereby enhancing privacy protection and providing more flexible publishing methods.

[0196] As shown in Figure 5, the identification information corresponding to identifier #2 includes a first field and one or more of the following: a second field or a third field, wherein the information carried by the first field is used to indicate identifier #2, the information carried by the second field is used to indicate the identification type of identifier #2, and the information carried by the third field is used to verify the information carried by fields other than the third field in the identification information corresponding to identifier #2.

[0197] Among them, there is a corresponding relationship between identifier #2 and the hash value of the public key corresponding to identifier #2 (also referred to as a public key hash), or there is a corresponding relationship between identifier #2 and a randomly generated character. The information carried by the first field may include the hash value of the public key corresponding to identifier #2 (referred to as the public key hash), or the information carried by the first field may include randomly generated characters, thereby indicating identifier #2. It should be understood that the public key hash and randomly generated characters here are only used for example. In actual embodiments, the information carried by the first field may also include other information that can be used to indicate identifier #2, or the information carried by the first field may include a combination of multiple information used to indicate identifier #2, which will not be repeated here.

[0198] In this way, the node corresponding to the second identifier can be indicated through the first field. In addition, when the identification information corresponding to the second identifier includes the second field, the type of the second identifier can be determined, and then the source, credibility or usage scenario of the second identifier can be determined based on the second identifier. When the information corresponding to the second identifier includes the third field, verification of other fields, such as the first field, or the first field and the second field can be implemented to ensure the accuracy of the second identifier. The identification type refers to the method used to indicate the generation method of the identifier. For example, the identification type can include DRC, DIC, and DSCC. Different identification types can be represented by different numerical values ​​or character strings. Taking numerical values ​​as an example, DRC can be represented by the numerical value "0x1101", DIC can be represented by the numerical value "0x1111", and DSCC can be represented by the numerical value "0x1001". Here, the identification type of identifier #2 can be DRC, in which case the second field includes the numerical value "0x1101".

[0199] The information carried in the third field may be the check values ​​of the other fields except the third field in the information of identifier #2 obtained according to the check method. The check method may be a cyclic redundancy check or other possible check methods, which will not be described here.

[0200] In addition, the identification information corresponding to identification #2 may also include fields for indicating other information. For example, the identification information corresponding to identification #2 may also include a field for indicating the region to which identification #2 belongs, or a field for indicating the card vendor or device vendor that generated identification #2.

[0201] It should be understood that in Implementation Methods 3 and 4, if the credential information corresponding to identifier #2 only includes the authentication information corresponding to identifier #2, then the file information corresponding to identifier #2 may also include the certification information corresponding to identifier #2. If the credential information corresponding to identifier #2 only includes the certification information corresponding to identifier #2, then the file information corresponding to identifier #2 may also include the authentication information corresponding to identifier #2. In addition, Implementation Methods 3 and 4 are merely examples. In actual implementation, information #2 may also be implemented in other ways, which will not be further described here.

[0202] In this way, the device corresponding to the card merchant or terminal manufacturer can send information #2 to the storage node. Since the service information of the device corresponding to the card merchant or terminal manufacturer will also be uploaded to the storage node, and identification #2 and the credential information corresponding to identification #2 are generated by the device corresponding to the card merchant or terminal manufacturer, the endorsement of identification #2 and the credential information corresponding to identification #2 by the device corresponding to the card merchant or terminal manufacturer can be achieved. For example, identification #2 and the credential information corresponding to identification #2 are signed by the private key of the device corresponding to the card merchant or terminal manufacturer. Therefore, when the device corresponding to the card merchant or terminal manufacturer is trustworthy, the trust and mutual communication between identification #2 and the credential information corresponding to identification #2 can be achieved between different fields.

[0203] S405: The card vendor or terminal manufacturer's device sends information #2 to the blockchain node. Correspondingly, the blockchain node receives information #2 from the card vendor or terminal manufacturer's device.

[0204] S406, blockchain node stores information #2.

[0205] S407, the device corresponding to the operator obtains information #3.

[0206] Among them, information #3 includes the identification #3 of the device corresponding to the card merchant or terminal manufacturer and the service information corresponding to identification #3. For the implementation principle of identification #3, please refer to the relevant introduction of the first identification in the method provided in Figure 2 above. For the service information corresponding to identification #3, please refer to the relevant introduction of the service information corresponding to the first identification in the method provided in Figure 2 above. For the implementation principle of information #3, please refer to the relevant introduction of the first information in the method provided in Figure 2 above. No further details will be given here.

[0207] S408: The device corresponding to the operator sends information #3 to the blockchain node. In response, the blockchain node receives information #3 from the device corresponding to the operator.

[0208] S409, blockchain node stores information #3.

[0209] S410, the device corresponding to the authority obtains information #4.

[0210] Among them, information #4 includes the identification #4 of the device corresponding to the card merchant or terminal manufacturer and the service information corresponding to identification #4. For the implementation principle of identification #4, please refer to the relevant introduction of the first identification in the method provided in Figure 2 above. For the service information corresponding to identification #4, please refer to the relevant introduction of the service information corresponding to the first identification in the method provided in Figure 2 above. For the implementation principle of information #4, please refer to the relevant introduction of the first information in the method provided in Figure 2 above. No further details will be given here.

[0211] S411: The device corresponding to the authority sends information #4 to the blockchain node. In response, the blockchain node receives information #4 from the device corresponding to the authority.

[0212] S412, blockchain node stores information #4.

[0213] S413, the device corresponding to the third-party trusted institution obtains information #5.

[0214] Among them, information #5 includes the identification #5 of the device corresponding to the card merchant or terminal manufacturer and the service information corresponding to identification #5. For the implementation principle of identification #5, please refer to the relevant introduction of the first identification in the method provided in Figure 2 above. For the service information corresponding to identification #5, please refer to the relevant introduction of the service information corresponding to the first identification in the method provided in Figure 2 above. For the implementation principle of information #5, please refer to the relevant introduction of the first information in the method provided in Figure 2 above. No further details will be given here.

[0215] S414: The device corresponding to the third-party trusted institution sends information #5 to the blockchain node. Accordingly, the blockchain node receives information #5 from the device corresponding to the third-party trusted institution.

[0216] S415, the blockchain node stores information #5.

[0217] In addition, the method provided in FIG4 may further include:

[0218] In step S416, the card vendor or terminal manufacturer's corresponding device obtains the storage location of information #2 in the blockchain system, i.e., the on-chain address. This can also be considered the location in the storage system. It is understood that in this embodiment of the present application, a storage node can store information to other storage nodes in the storage system. For example, a blockchain node can store information to other blockchain nodes in the blockchain. The information can be stored in blocks, i.e., on-chain.

[0219] It is understandable that the storage location of information #2 in the blockchain system can be the location where the blockchain system sends information #2 to the corresponding device of the card merchant or terminal manufacturer after receiving and storing information #2.

[0220] S417, the card vendor or the terminal manufacturer's corresponding device sends information #2 to the terminal. Correspondingly, the terminal receives information #2 from the card vendor or the terminal manufacturer's corresponding device.

[0221] It is understandable that what is sent together with information #2 in S417 may also include the storage location of information #2 in the blockchain system.

[0222] Among them, information #2 and the storage location of information #2 in the blockchain system can be carried in the same message or different messages.

[0223] Additionally, the terminal may store information #6.

[0224] S418, the terminal obtains information #6 based on information #2.

[0225] Information #6 includes identifier #6 and service information corresponding to identifier #6.

[0226] Taking DRC and DIC as an example, in one possible implementation, the terminal can generate the public and private keys of DIC by itself, and then use the private key of DRC to sign and endorse the information of DIC. The endorsement content includes information such as DIC ID, public key, and validity period.

[0227] In a possible implementation, the terminal may generate a public key corresponding to the DIC, use the public key hash corresponding to the DIC as the DIC identifier, and then generate the DIC private key from the system key corresponding to the DRC and the DIC public key.

[0228] For the implementation principle of information #6, please refer to the relevant introduction of the first information. Here, identification #6 can be the DIC of the terminal. The DIC is generated by the terminal according to identification #2.

[0229] In S418, the terminal can generate multiple terminal identifiers based on identifier #2. For example, as shown in Figure 6, identifier #2 is a DRC. Then, based on this DRC, the terminal can generate multiple DICs, such as DIC1 and DIC2, as well as file information corresponding to DIC1 through DIC2. In this case, the terminal can store the DRC, the file information corresponding to the DRC (file information 1), DIC1 through DIC3, and the file information corresponding to DIC1 (file information 2) and the file information corresponding to DIC2 (file information 3). Each file information can include a certification identifier (used to identify the certification information and has a corresponding relationship with the certification information), certification information, and verification information (used to indicate a verification method for the certification information, such as an algorithm for verifying the certification information) (not shown in the figure). For example, file information 1 can include certification information 11, file information 2 can include certification information 21, file information 3 can include certification information 31 and certification information 32, file information 4 can include certification information 41 and certification information 42, and file information 5 can include certification information 51. In this case, identifier # can be DIC1 or DIC2.

[0230] The relationship between the terminal's DRC, DIC1, DIC2, and file information 1 through file information 3 is shown in Figure 7. The certification information in the file information corresponding to the terminal's DRC can be signed by the private key corresponding to the card vendor or terminal manufacturer. The terminal's DIC can also be signed by the private key corresponding to the terminal's DRC.

[0231] In a possible design solution, information #6 may be information #2. In this case, S418 may be that the terminal reads information #2 from its own stored information.

[0232] In some possible implementations, when the verification node needs to verify the terminal, as shown in FIG7 , the terminal may present (display) proof information through an application (APP) interface, such as presenting one or more of proof information 11, proof information 21, proof information 31, and proof information 32. The verification node may obtain the proof information displayed by the terminal (e.g., by scanning a code). After obtaining the proof information displayed by the terminal, the verification node may obtain a public key from the blockchain node, thereby verifying the proof information based on the public key.

[0233] S419: The terminal sends information #6. Correspondingly, the blockchain node receives information #6.

[0234] S420, the blockchain system stores information #6.

[0235] For ease of understanding, the following describes the correspondence between the first node and the first identifier in conjunction with the identifier and information in the method provided in Figure 4. The correspondence between the identifier in the method provided in Figure 4 and the first identifier in Figure 2, and the correspondence between the information in the method provided in Figure 4 and the first information can be referred to as shown in Table 1.

[0236] Table 1

[0237] The following describes each of these in detail. Regarding the solution presented in Figure 2, in some possible implementations, the first node can be a device corresponding to a card vendor or terminal manufacturer. In this case, information #1 is the first information, identifier #1 is the first identifier, information #2 is the second information, identifier #2 is the second identifier, and the storage location of information #2, or information #2 and information #2 together, in the blockchain system is the third information. In S417, the device corresponding to the card vendor or terminal manufacturer sends information #2, or information #2 and information #2 together, to the terminal on the blockchain node. Alternatively, the first node can be said to send the third information to the terminal. Because the third information can indicate information #2, the terminal can obtain and use the second information for authentication by other nodes. This allows the terminal to obtain the second information and use it to authenticate the terminal by other nodes.

[0238] In this case, the device corresponding to the card merchant or terminal manufacturer can also send the hash value of information #2 to the blockchain node (the hash value of information #2 can be carried in the same message or a different message as information #2), or, information #2 can be replaced by the hash value of information #2.

[0239] In this way, the device corresponding to the card merchant or terminal manufacturer can send the second information to the storage node. Since the service information of the device corresponding to the card merchant or terminal manufacturer will also be uploaded to the storage node, and identification #2 and the credential information corresponding to identification #2 are generated by the device corresponding to the card merchant or terminal manufacturer, the endorsement of identification #2 and the credential information corresponding to identification #2 by the device corresponding to the card merchant or terminal manufacturer can be realized. For example, identification #2 and the credential information corresponding to identification #2 can be signed by the private key corresponding to the device corresponding to the card merchant or terminal manufacturer, and the endorsement of identification #2 and the credential information corresponding to identification #2 by the device corresponding to the card merchant or terminal manufacturer can be realized. Therefore, when the device corresponding to the card merchant or terminal manufacturer is trustworthy, the trust and mutual communication between identification #2 and the credential information corresponding to identification #2 in different fields can be realized.

[0240] In some possible implementations, the first node is a device corresponding to an operator. In this case, the first information is information #3, and identifier #3 is the first identifier.

[0241] In some possible implementations, the first node is a device corresponding to an authoritative organization. In this case, the first information is information #4, and identifier #4 is the first identifier.

[0242] In some possible implementations, the first node is a device corresponding to a third-party trusted organization. In this case, the first information is information #5, and identifier #5 is the first identifier.

[0243] In some possible implementations, the first node is a terminal. In this case, the first information is information #6, identifier #6 is the first identifier, and the fourth information is information #2 and / or the storage location of information #2 on the blockchain system. In S417, the terminal receives information #2 and / or the storage location of information #2 on the blockchain system from the device corresponding to the card vendor or terminal manufacturer. That is, the first node receives the fourth information from the device corresponding to the card vendor or terminal manufacturer. This allows the terminal to obtain information #6 and use it for authentication.

[0244] It is understandable that the above-mentioned blockchain nodes can be replaced by any possible implementation of storage nodes, which will not be described here.

[0245] Regarding the technical effects of the method provided in FIG. 4 , reference may be made to the technical effects of the method provided in FIG. 2 above, which will not be repeated here.

[0246] It should be understood that the execution order of each step is not limited in the embodiments of the present application, as long as it is logical. For example, the process of storing information in a blockchain node is located after the blockchain node receives the information, and the process of sending information is located after the process of obtaining the information.

[0247] In some possible scenarios, information #2 in the method provided in FIG. 4 above can be stored in the terminal. For example, it can be provided to the terminal by a device corresponding to a card vendor or terminal manufacturer. The first node in the method provided in FIG. 2 can be a device corresponding to a card vendor or terminal manufacturer, a device corresponding to a carrier, a device corresponding to an authority, a device corresponding to a third-party trusted institution, an over-the-air card writing server, or a terminal. In this case, the communication method provided in the embodiment of the present application can also include the steps of the method provided in FIG. 4 above, with the difference that, in one possible implementation, the communication method further includes: the device corresponding to the card vendor or terminal manufacturer can send information #2. Accordingly, the terminal can receive information #2 from the device corresponding to the card vendor or terminal manufacturer. In one possible implementation, S405 can be replaced with: the terminal sends information #2. Accordingly, the blockchain node receives information #2. In other words, information #2 can be sent from the terminal to the blockchain node. It should be understood that in this scenario, S404 can be omitted. That is, information #2 is generated by the terminal. If the first node is a terminal, information #2 is the first information, identification #2 is the first identification, information #6 is the fifth information, and identification #6 is the third identification. In this way, the first node can send different identifiers indicating the first node and the credential information corresponding to the different identifiers to the storage node, so that different services can be used for different identifiers, thereby improving privacy. In addition, regarding the technical effects of the communication method in this scenario, reference can be made to the technical effects of the method provided in Figure 2, which will not be repeated here. In addition, the terminal can also send a hash value of information #6 to the storage node. At this time, the hash value of information #6 and information #6 can be carried in the same message or different messages. Alternatively, information #6 in S419 and S420 can also be replaced by the hash value of information #6.

[0248] It is understandable that the above-mentioned blockchain nodes can be replaced by any possible implementation of storage nodes, which will not be described here.

[0249] In some possible scenarios, the first node in the method provided in FIG. 4 may be a terminal. In this case, the communication method provided in the embodiment of the present application is as shown in the method provided in FIG. 4 , except that information #2 in S403 and S404 is replaced with information #7, i.e., the sixth information. Information #7 may be implemented with reference to information #2. Information #7 differs from the first information in that service information may not be included. Information #7 indicates the terminal's identifier #7, i.e., the fourth identifier and the credential information corresponding to identifier #7. The credential information corresponding to identifier #7 is used to verify the attributes corresponding to the terminal and / or identifier #7. Identifier #7 and the credential information corresponding to identifier #7 are generated by the device corresponding to the card vendor or terminal manufacturer. Furthermore, the terminal may also send a hash value of information #7 to the storage node. In this case, the hash value of information #7 and information #7 may be carried in the same message or in different messages. Alternatively, information #7 in S403 and S404 may be replaced with the hash value of information #7.

[0250] Information #7 is used to indicate the terminal, that is, the identifier #7 of the second node and the credential information corresponding to identifier #7. The credential information corresponding to identifier #7 is used to verify the terminal and / or the attributes corresponding to identifier #7. Identifier #7 and the credential information corresponding to identifier #7 are generated by the device corresponding to the card vendor or terminal manufacturer. Information #7 is used to indicate the identifier #7 of the terminal and the credential information corresponding to identifier #7. The credential information corresponding to identifier #7 is used to verify the terminal and / or the attributes corresponding to identifier #7. Identifier #7 and the credential information corresponding to identifier #7 are generated by the first node.

[0251] Optionally, the credential information corresponding to identification #7 includes authentication information and / or proof information corresponding to identification #7, the authentication information corresponding to identification #7 is used to verify the terminal, and the proof information corresponding to identification #7 is used to verify the attribute corresponding to identification #7.

[0252] In one possible implementation, information #6 may further include one or more of the following: service information corresponding to identifier #7, information indicating the type of terminal, information about the issuer of identifier #7, or information indicating disclosure conditions for the credential information corresponding to identifier #7. In other words, information #6 may include identifier #7, the credential information corresponding to identifier #7, and one or more of the following: service information corresponding to identifier #7, information indicating the type of terminal, information about the issuer of identifier #7, or information indicating disclosure conditions for the credential information corresponding to identifier #7.

[0253] For the authentication information corresponding to identifier #7, please refer to the relevant introduction to the authentication information corresponding to the first identifier in the method provided in Figure 2. For the certification information corresponding to identifier #7, please refer to the relevant introduction to the certification information corresponding to the first identifier in the method provided in Figure 2. For the service information corresponding to identifier #7, please refer to the relevant introduction to the service information corresponding to the first identifier in the method provided in Figure 2. For the information indicating the type of the terminal, please refer to the relevant introduction to the information indicating the type of the first node in the method provided in Figure 2. For the information of the issuer of identifier #7, please refer to the relevant introduction to the information of the issuer of the first identifier in the method provided in Figure 2. For the information indicating the disclosure conditions of the credential information corresponding to identifier #7, please refer to the relevant introduction to the information indicating the disclosure conditions of the credential information corresponding to the first identifier in the method provided in Figure 2.

[0254] In a possible implementation, information #7 includes identification information corresponding to identifier #7, and the identification information corresponding to identifier #7 includes identifier #7 and credential information corresponding to identifier #7.

[0255] Furthermore, information #7 is used to indicate one or more of the following: information indicating the type of terminal, information about the issuer of identification #7, or information indicating disclosure conditions for the credential information corresponding to identification #7. In other words, the file information corresponding to identification #7 includes one or more of the following: information indicating the type of terminal, information about the issuer of identification #7, or information indicating disclosure conditions for the credential information corresponding to identification #7.

[0256] Regarding the implementation principle of information #7, please refer to the relevant introduction in the above implementation method three. The difference is that information #7 does not include the service information corresponding to identifier #7.

[0257] In one possible implementation, information #7 includes identification information corresponding to identifier #7 and file information corresponding to identifier #7, the identification information corresponding to identifier #7 includes identifier #7, and the file information corresponding to identifier #7 includes credential information corresponding to identifier #7.

[0258] Optionally, the file information corresponding to identification #7 also includes one or more of the following: information indicating the type of the terminal, information about the issuer of identification #7, and information indicating disclosure conditions for the credential information corresponding to identification #7. For the implementation principle of information #7, please refer to the relevant description of implementation method 4 above, except that information #7 does not include the service information corresponding to identification #7.

[0259] Optionally, the identification information corresponding to identifier #7 includes a fourth field and one or more of the following: a fifth field or a sixth field, wherein the information carried by the fourth field is used to indicate identifier #7, the information carried by the fifth field is used to indicate the identification type of identifier #7, and the information carried by the sixth field is used to verify the information carried by fields other than the sixth field in the identification information corresponding to identifier #7.

[0260] For the implementation principle of the fifth field, please refer to the relevant introduction of the first field. For the implementation principle of the sixth field, please refer to the relevant introduction of the second field. For the implementation principle of the seventh field, please refer to the relevant introduction of the third field. For the identification information corresponding to identification #7, please refer to the identification information corresponding to information #2. No further details will be given here.

[0261] Optionally, information #7 includes identification #7 and one or more of the following: service information corresponding to identification #7, information indicating the type of terminal, information of the issuer of identification #7, or information indicating disclosure conditions of credential information corresponding to identification #7.

[0262] It should be understood that in this scenario, when the first node is the device corresponding to the card merchant or terminal manufacturer, the device corresponding to the operator, the device corresponding to the authoritative agency, the device corresponding to the third-party trusted agency, or the air card writing server, the implementation principle of the first information can correspond to the relevant introduction when the first node is the device corresponding to the card merchant or terminal manufacturer, the device corresponding to the operator, the device corresponding to the authoritative agency, the device corresponding to the third-party trusted agency, or the air card writing server in reference Figure 2, and will not be repeated here.

[0263] In some scenarios, the first node may be a terminal that generates its own terminal identification and credential information corresponding to the terminal identification. The first node in the method provided in FIG2 may be a terminal. In this case, the communication method provided in the embodiment of the present application is shown in FIG8 below. As shown in FIG8, the communication method includes:

[0264] S801, the card vendor or terminal manufacturer's corresponding device generates information #1.

[0265] For the implementation principle of information #1, please refer to the relevant introduction of information #1 in the method provided in Figure 4 above.

[0266] S802: The card vendor or terminal manufacturer's device sends information #1 to the blockchain node. In response, the blockchain node receives information #1 from the card vendor or terminal manufacturer's device.

[0267] S803, the device corresponding to the operator obtains information #3.

[0268] For the implementation principle of information #3, please refer to the relevant introduction of information #3 in the method provided in Figure 4 above.

[0269] S804: The device corresponding to the operator sends information #3 to the blockchain node. In response, the blockchain node receives information #3 from the device corresponding to the operator.

[0270] S805, the device corresponding to the social authority obtains information #4.

[0271] For the implementation principle of information #4, please refer to the relevant introduction of information #4 in the method provided in Figure 4 above.

[0272] S806: The device corresponding to the social authority sends information #4 to the blockchain node. In response, the blockchain node receives information #4 from the device corresponding to the authority.

[0273] S807, the device corresponding to the third-party trusted institution obtains information #5.

[0274] For the implementation principle of information #5, please refer to the relevant introduction of information #5 in the method provided in Figure 4 above.

[0275] S808: The device corresponding to the third-party trusted institution sends information #5 to the blockchain node. In response, the blockchain node receives information #5 from the device corresponding to the third-party trusted institution.

[0276] S809, the terminal obtains information #8.

[0277] Information #8 includes identifier #8 and service information corresponding to identifier #8.

[0278] Regarding the implementation principle of information #8, reference may be made to the relevant introduction to the first information in the method provided in FIG2 . Here, identifier #8 may be an identifier generated by the terminal itself, such as DSCC.

[0279] S810: The terminal sends information #8 to the blockchain node. In response, the blockchain node receives information #8 from the terminal.

[0280] S811: The terminal sends a certification request message to the card vendor or the device corresponding to the terminal manufacturer. Correspondingly, the card vendor or the device corresponding to the terminal manufacturer receives the certification request message from the terminal.

[0281] The certification request information is used to request certification information corresponding to the terminal, and the certification information corresponding to the terminal is used to verify attributes corresponding to the terminal or the terminal identifier.

[0282] In some possible designs, the certification request information may carry information used to prove the identity of the terminal to the card vendor or terminal manufacturer, such as a whitelist provided by the terminal vendor (including information used to identify devices produced by the card vendor or terminal manufacturer) or a purchase receipt, etc. For example, the card vendor or terminal manufacturer may endorse the terminal, so that if the card vendor or device manufacturer is trustworthy, the terminal can be verified using the certification information.

[0283] S812: The card vendor or terminal manufacturer's corresponding device sends the terminal's corresponding certification information to the blockchain node. In response, the blockchain node receives the terminal's corresponding certification information.

[0284] The certification information corresponding to the terminal is obtained by the device corresponding to the card vendor or terminal manufacturer according to the certification request information.

[0285] S813: The card vendor or the terminal manufacturer's corresponding device sends the terminal's corresponding certification information. Correspondingly, the terminal receives the terminal's corresponding certification information.

[0286] For ease of understanding, the following describes the correspondence between the first node and the first identifier in conjunction with the identifier and information in the method provided in Figure 8. The correspondence between the identifier in the method provided in Figure 8 and the first identifier in Figure 2, and the correspondence between the information in the method provided in Figure 4 and the first information can be referred to as shown in Table 2 below.

[0287] Table 2

[0288] The following describes each of them in detail. For the solution provided in FIG2 , if the first node is a device corresponding to a card vendor or a terminal manufacturer, information #1 is the first information, identification #1 is the first identification, and the certification request information is the certification request information.

[0289] If the first node is a device corresponding to an operator, the first information is information #3, and identifier #3 is the first identifier.

[0290] If the first node is a device corresponding to an authoritative organization, the first information is information #4, and identifier #4 is the first identifier.

[0291] If the first node is a device corresponding to a third-party trusted organization, the first information is information #5, and identifier #5 is the first identifier.

[0292] If the first node is a terminal, the first information is information #8, and identifier #8 is the first identifier. The certification information corresponding to the terminal is the certification information corresponding to the first node.

[0293] In the solution provided in Figure 8, identifier #8 can be one or more. For example, as shown in Figure 6, identifier #8 can include DSCC1 and DSCC2. As shown in Figure 6, the terminal can store DSCC1, file information 4 corresponding to DSCC1, and file information 5 corresponding to DSCC2 and DSCC2. File information 4 can include certification information 41 and certification information 42, and file information 5 can include certification information 51. It should be understood that the file information and certification information shown in Figure 6 are for example purposes only. In actual implementation, more or less certification information may be included. It is understandable that, as shown in Figure 7, the terminal can display the certification information in file information 5 and file information 4 through the app.

[0294] It can be understood that the solution provided in Figure 8 can also include S416 and S417 in the solution provided in Figure 4. The solution provided in Figure 8 can also include S418 to S420 in the solution provided in Figure 4. For specific implementation, please refer to the relevant introduction in Figure 4 and will not be repeated here. In this case, the terminal can store the terminal's DRC, DIC1, DIC2, DSCC1, DSCC1 and the file information corresponding to the terminal's DRC, DIC1, DIC2, DSCC1, DSCC1. The technical effects of the method provided in Figure 8 can refer to the technical effects of the method provided in Figure 2 above and will not be repeated here. In addition, based on the solution provided in Figure 8, the second node can obtain the sixth information and upload the sixth information by itself, which can improve the second node's control over its own identification and credential information, such as the sixth information.

[0295] In one possible embodiment, the operator's corresponding device can obtain another identifier corresponding to the terminal's existing identifier and send the other identifier corresponding to the terminal's existing identifier to the terminal. In this case, the embodiment of the present application also provides a communication method, which is described below in conjunction with Figure 9. As shown in Figure 9, the communication method includes:

[0296] S901: The device corresponding to the operator obtains the seventh information.

[0297] Among them, the seventh information is used to indicate the fifth identifier of the terminal and the credential information corresponding to the fifth identifier, the credential information corresponding to the fifth identifier is used to verify the attributes corresponding to the terminal and / or the fifth identifier, the fifth identifier is different from the user permanent identifier of the terminal in the device corresponding to the operator, such as the user permanent identifier (SUPI), and the fifth identifier corresponds to the user permanent identifier of the terminal, and the user permanent identifier is used for communication between the device corresponding to the operator and the terminal.

[0298] The device corresponding to the operator may be a device corresponding to the operator. For example, the device corresponding to the operator may be a device in the core network of the operator (core network element), or the device corresponding to the operator may be an access network device of the operator.

[0299] The terminal may be a terminal. For the implementation principle of the terminal, reference may be made to the relevant introduction of the communication system provided in FIG1 , which will not be repeated here.

[0300] The fifth identifier of the terminal is information used to identify the terminal. For example, the fifth identifier of the terminal can be the DSCC of the terminal. It is understood that in the embodiments of the present application, the fifth identifier DSCC is used only as an example. In actual implementation, the fifth identifier can also have other names, which will not be repeated here.

[0301] The fifth identifier of the terminal may be generated according to the root certificate of the terminal, such as DRC. The credential information corresponding to the fifth identifier may include authentication information corresponding to the fifth identifier and / or certification information corresponding to the fifth identifier.

[0302] The authentication information corresponding to the fifth identifier is used to verify the terminal, and the certification information corresponding to the fifth identifier is used to verify the attributes corresponding to the terminal.

[0303] The user permanent identifier of the terminal is used to identify the terminal during communication with the operator's corresponding device. For example, if the operator's corresponding device is a device corresponding to the card manufacturer or terminal manufacturer, and the terminal is a terminal, the user permanent identifier can be the terminal's SUPI generated by the card manufacturer or terminal manufacturer's device based on the DRC.

[0304] In one possible implementation, the seventh information may further include one or more of the following: service information corresponding to the fifth identifier, information indicating the type of the terminal, information about the issuer of the fifth identifier, or information indicating the disclosure conditions of the credential information corresponding to the fifth identifier. In other words, the seventh information may include the fifth identifier, the credential information corresponding to the fifth identifier, and one or more of the following: service information corresponding to the fifth identifier, information indicating the type of the terminal, information about the issuer of the fifth identifier, or information indicating the disclosure conditions of the credential information corresponding to the fifth identifier.

[0305] For the authentication information corresponding to the fifth identifier, please refer to the relevant introduction to the authentication information corresponding to the first identifier in the method provided in Figure 2. For the proof information corresponding to the fifth identifier, please refer to the relevant introduction to the proof information corresponding to the first identifier in the method provided in Figure 2. For the service information corresponding to the fifth identifier, please refer to the relevant introduction to the service information corresponding to the first identifier in the method provided in Figure 2. For the information indicating the type of the terminal, please refer to the relevant introduction to the information indicating the type of the first node in the method provided in Figure 2. For the information of the issuer of the fifth identifier, please refer to the relevant introduction to the information of the issuer of the first identifier in the method provided in Figure 2. For the information indicating the disclosure conditions of the credential information corresponding to the fifth identifier, please refer to the relevant introduction to the information indicating the disclosure conditions of the credential information corresponding to the first identifier in the method provided in Figure 2.

[0306] In one possible implementation, the seventh information includes identification information corresponding to the fifth identifier, and the identification information corresponding to the fifth identifier includes the fifth identifier and the credential information corresponding to the fifth identifier. In addition, the seventh information may also include one or more of the following: information about the service corresponding to the fifth identifier, information indicating the type of terminal, information about the issuer of the fifth identifier, or information indicating the disclosure conditions of the credential information corresponding to the fifth identifier. In this case, the implementation of the seventh information can refer to the relevant introduction of implementation method three and will not be repeated here.

[0307] In one possible implementation, the seventh information includes identification information corresponding to the fifth identifier and file information corresponding to the fifth identifier, the identification information corresponding to the fifth identifier includes the fifth identifier, and the file information corresponding to the fifth identifier includes credential information corresponding to the fifth identifier.

[0308] Optionally, the file information corresponding to the fifth identifier also includes one or more of the following: information about the service corresponding to the fifth identifier, information indicating the type of the terminal, information about the issuer of the fifth identifier, and information indicating disclosure conditions for the credential information corresponding to the fifth identifier. In this case, the implementation of the seventh information can refer to the relevant description of Implementation Method 4 and is not further described here.

[0309] Optionally, the identification information corresponding to the fifth identifier includes the seventh field and one or more of the following: the eighth field or the ninth field, wherein the information carried by the seventh field is used to indicate the fifth identifier, the information carried by the eighth field is used to indicate the identification type of the fifth identifier, and the information carried by the ninth field is used to verify the information carried by fields other than the ninth field in the identification information corresponding to the fifth identifier.

[0310] For the implementation principle of the seventh field, please refer to the relevant introduction of the first field in the method provided in Figure 2. For the introduction of the eighth field, please refer to the relevant introduction of the second field in the method provided in Figure 2. For the introduction of the ninth field, please refer to the relevant introduction of the third field in the method provided in Figure 2. No further details will be given here.

[0311] S902: The device corresponding to the operator sends seventh information to the terminal. Correspondingly, the terminal receives the seventh information from the device corresponding to the operator.

[0312] S903: The terminal stores the seventh information.

[0313] It should be understood that the terminal can store the seventh information in the memory of the terminal.

[0314] Based on the communication method provided in Figure 9 above, the device corresponding to the operator can generate the fifth identification of the terminal and the credential information corresponding to the fifth identification. Since the fifth identification corresponds to the user's permanent identification of the terminal, the device corresponding to the operator can centrally manage the terminal information.

[0315] In some possible embodiments, a node can upload its own information as well as information about other nodes generated by the node. The following is an explanation of the communication method in conjunction with FIG10. As shown in FIG10, the communication method includes:

[0316] S1001: The card vendor or the terminal manufacturer's corresponding device obtains the eighth information and the ninth information.

[0317] The eighth information includes a seventh identifier for indicating the device corresponding to the card vendor or terminal manufacturer, and credential information corresponding to the seventh identifier. The credential information corresponding to the seventh identifier is used to verify the device corresponding to the card vendor or terminal manufacturer and / or to verify the attributes corresponding to the seventh identifier. The ninth information is used to indicate the eighth identifier of the terminal and the credential information corresponding to the eighth identifier. The credential information corresponding to the eighth identifier is used to verify the terminal and / or the attributes corresponding to the eighth identifier. The eighth identifier and the credential information corresponding to the eighth identifier are generated by the device corresponding to the card vendor or terminal manufacturer, i.e., the credential information corresponding to the eighth identifier is signed by the private key of the device corresponding to the card vendor or terminal manufacturer. The device corresponding to the card vendor or terminal manufacturer sends the eighth and ninth information to the storage node.

[0318] The equipment corresponding to the card vendor or terminal manufacturer may be the equipment corresponding to the operator. For example, the equipment corresponding to the card vendor or terminal manufacturer may be the equipment in the operator's core network (core network element), or the equipment corresponding to the card vendor or terminal manufacturer may be the operator's access network equipment.

[0319] The implementation principle of the terminal can refer to the relevant introduction of the communication system provided in Figure 1, and will not be repeated here. The implementation principle of the eighth information and the ninth information can refer to the relevant introduction of information #2 in the solution provided in Figure 4 above, and will not be repeated here.

[0320] It is understandable that the corresponding devices of the card vendor or the terminal manufacturer can obtain the eighth information and the ninth information respectively.

[0321] S1002: The card vendor or terminal manufacturer's corresponding device sends the eighth and ninth information to the blockchain node.

[0322] It is understandable that the eighth information and the ninth information can be sent together or separately. In other words, the eighth information and the ninth information can be carried in the same message or signaling or in different messages or signalings.

[0323] S1003, the blockchain node stores the eighth information and the ninth information.

[0324] The eighth information and the ninth information may be stored in blocks.

[0325] S1004: The card vendor or the terminal manufacturer's corresponding device sends ninth information to the terminal.

[0326] Optionally, the device corresponding to the card vendor or terminal manufacturer may also send the storage location of the ninth information to the terminal. The storage location of the ninth information and the ninth information may be carried in the same message or in a different message. The storage location of the ninth information is determined after executing S1003. For example, the blockchain node may provide feedback to the device corresponding to the card vendor or terminal manufacturer, indicating the storage location of the ninth information, which may be a location within the blockchain system.

[0327] S1005: The terminal stores the ninth information.

[0328] It should be understood that the device corresponding to the card vendor or terminal manufacturer in the solution provided in FIG10 can also be other devices that can generate the ninth information, such as the device corresponding to the operator. The terminal can also be other devices that can receive the ninth information, which will not be repeated here.

[0329] Based on the method provided in Figure 10, the device corresponding to the card merchant or terminal manufacturer can send the eighth information and the ninth information to the storage node, the storage node can store the eighth information and the ninth information, and the eighth identification and the credential information corresponding to the eighth identification are generated by the device corresponding to the card merchant or terminal manufacturer, and the eighth identification and the credential information corresponding to the eighth identification are generated by the device corresponding to the card merchant or terminal manufacturer, and the credential information corresponding to the eighth identification is signed by the private key of the device corresponding to the card merchant or terminal manufacturer. Therefore, when the device corresponding to the card merchant or terminal manufacturer is trustworthy, the eighth identification and the credential information corresponding to the eighth identification can be trusted between different fields.

[0330] It is understood that the solution provided in FIG10 may also include S407 to S415 and / or S418 to S420 in the solution provided in FIG4. When the solution provided in FIG10 includes S407 to S415 in the solution provided in FIG4, the implementation principles of information #1, information #3, information #4, and information #5 can refer to the relevant introduction of information #2 in the solution provided in FIG4. In other words, information #1, information #3, information #4, or information #5 may not include the service information corresponding to the identifier.

[0331] The communication method provided by the embodiment of the present application is described in detail above in conjunction with Figures 3 to 10. The communication device for executing the communication method provided by the embodiment of the present application is described in detail below in conjunction with Figures 11 and 12.

[0332] The communication method provided by the embodiment of the present application is described in detail above in conjunction with Figures 2 to 10. The communication device for executing the communication method provided by the embodiment of the present application is described in detail below in conjunction with Figures 11 and 12.

[0333] For example, Figure 11 is a schematic diagram of the structure of a communication device provided in an embodiment of the present application. As shown in Figure 11, the communication device 1100 includes: a processing module 1101 and a transceiver module 1102. For ease of illustration, Figure 11 only shows the main components of the communication device 1100.

[0334] In some embodiments, the communication device 1100 may be applicable to the communication system shown in FIG. 1 , and perform the function of the first node in the communication method shown in FIG. 2 or FIG. 4 .

[0335] The processing module 1101 is configured to obtain first information, wherein the first information includes a first identifier and service information corresponding to the first identifier. The transceiver module 1102 is configured to send the first information to a storage node.

[0336] In a possible implementation, the first node may include one or more of: equipment corresponding to a card vendor or terminal manufacturer, a terminal, equipment corresponding to an operator, equipment corresponding to an authority, equipment corresponding to a third-party trusted institution, or an air card writing server.

[0337] In one possible implementation, if the first node is a device corresponding to a card vendor or terminal manufacturer, processing module 1101 is further configured to obtain second information. The second information is used to indicate a second identifier of the terminal and credential information corresponding to the second identifier. The credential information corresponding to the second identifier is used to verify attributes corresponding to the terminal and / or the second identifier. The second identifier and the credential information corresponding to the second identifier are generated by the first node. Transceiver module 1102 is further configured to send the second information and / or a hash value of the second information to a storage node.

[0338] In one possible implementation, the credential information corresponding to the second identifier includes authentication information corresponding to the second identifier and / or proof information corresponding to the second identifier, the authentication information corresponding to the second identifier is used to verify the terminal; the proof information corresponding to the second identifier is used to verify the attributes corresponding to the second identifier.

[0339] In one possible implementation, the second information includes a second identifier, and one or more of the following: credential information corresponding to the second identifier, service information corresponding to the second identifier, information used to indicate the type of the terminal, information of the issuer of the second identifier, or information used to indicate the disclosure conditions of the credential information corresponding to the second identifier.

[0340] In one possible implementation, the second identifier and the credential information corresponding to the second identifier are carried in the identification information corresponding to the second identifier; or, the second identifier is carried in the identification information corresponding to the second identifier, and one or more of the credential information corresponding to the second identifier, the service information corresponding to the second identifier, the information indicating the type of the terminal, the information of the issuer of the second identifier, or the information indicating the disclosure conditions of the credential information corresponding to the second identifier are carried in the file information corresponding to the second identifier.

[0341] In one possible implementation, the identification information corresponding to the second identifier includes a first field and one or more of the following: a second field or a third field, wherein the information carried by the first field is used to indicate the second identifier, the information carried by the second field is used to indicate the identification type of the second identifier, and the information carried by the third field is used to verify the information carried by fields other than the third field in the identification information corresponding to the second identifier.

[0342] In a possible implementation, the transceiver module 1102 is further configured to send third information to the terminal. The third information is used to indicate the second information, or the third information is used to indicate the second information and the storage location of the second information in the storage system.

[0343] In one possible implementation, if the first node is a terminal, the transceiver module 1102 is further configured to receive fourth information from a device corresponding to a card vendor or terminal manufacturer. The fourth information is configured to indicate the first identifier and the credential information corresponding to the first identifier; or the fourth information is configured to indicate the first identifier, the credential information corresponding to the first identifier, and the storage location of the first identifier and the credential information corresponding to the first identifier in a storage system.

[0344] In one possible implementation, the transceiver module 1102 is further configured to send fifth information and / or a hash value of the fifth information to the storage node, wherein the fifth information is used to indicate a third identifier of the first node and credential information corresponding to the third identifier, the third identifier being different from the first identifier.

[0345] In one possible implementation, if the first node is a terminal, transceiver module 1102 is further configured to send a certification request message to a device corresponding to the card vendor or terminal manufacturer. The certification request message is used to request certification information corresponding to the first node, and the certification information corresponding to the first node is used to verify the attributes corresponding to the first node or the first node's identifier. Transceiver module 1102 is further configured to receive the certification information corresponding to the first node. The certification information corresponding to the first node is generated by a device corresponding to the card vendor or terminal manufacturer.

[0346] In one possible implementation, if the first node is a device corresponding to a card vendor or terminal manufacturer, transceiver module 1102 is further configured to receive certification request information from the terminal. The certification request information is used to request certification information corresponding to the terminal, and the certification information corresponding to the terminal is used to verify attributes corresponding to the terminal or its identifier. Transceiver module 1102 is further configured to send the certification information corresponding to the terminal to the storage node. Transceiver module 1102 is further configured to send the certification information corresponding to the terminal to the terminal.

[0347] Optionally, the transceiver module 1102 may include a receiving module and a sending module (not shown in FIG11 ). The transceiver module 1102 is configured to implement the sending function and the receiving function of the communication device 1100 .

[0348] Optionally, the communication device 1100 may further include a storage module (not shown in FIG11 ) storing a program or instruction. When the processing module 1101 executes the program or instruction, the communication device 1100 may perform the function of the first node in the communication method shown in FIG2 or FIG4 .

[0349] It should be understood that the processing module 1101 involved in the communication device 1100 can be implemented by a processor or a processor-related circuit component, which can be a processor or a processing unit; the transceiver module 1102 can be implemented by a transceiver or a transceiver-related circuit component, which can be a transceiver or a transceiver unit.

[0350] It should be noted that the communication device 1100 can be a terminal or a network device, or a chip (system) that can be set in a terminal or a network device, or other parts or components or software modules, or a device that includes a terminal or a network device. This application does not limit this.

[0351] In addition, the technical effects of the communication device 1100 can refer to the technical effects of the communication method shown in either Figure 2 or Figure 4, and will not be repeated here.

[0352] In some embodiments, the communication device 1100 may be applicable to the communication system shown in FIG. 1 , and perform the function of a storage node in the communication method shown in FIG. 2 , FIG. 4 , or FIG. 8 .

[0353] The processing module 1101 is configured to receive first information from a first node via the transceiver module 1102. The first information includes a first identifier and service information corresponding to the first identifier. The processing module 1101 is configured to store the first information.

[0354] In a possible implementation, the first node may include one or more of: equipment corresponding to a card vendor or terminal manufacturer, a terminal, equipment corresponding to an operator, equipment corresponding to an authority, equipment corresponding to a third-party trusted institution, or an air card writing server.

[0355] In one possible implementation, if the first node includes a device corresponding to a card vendor or terminal manufacturer, the transceiver module 1102 is further configured to receive second information from the first node. The second information is used to indicate a second identifier of the terminal and credential information corresponding to the second identifier. The credential information corresponding to the second identifier is used to verify attributes corresponding to the terminal and / or the second identifier. The credential information corresponding to the second identifier is generated by the first node. The processing module 1101 is further configured to store fourth information.

[0356] In one possible implementation, the credential information corresponding to the second identifier includes authentication information corresponding to the second identifier and / or proof information corresponding to the second identifier, and the authentication information corresponding to the second identifier is used to verify the terminal; the proof information corresponding to the second identifier is used to verify the attributes corresponding to the second identifier.

[0357] In one possible implementation, the second information includes a second identifier, and one or more of the following: credential information corresponding to the second identifier, service information corresponding to the second identifier, information used to indicate the type of the terminal, information of the issuer of the second identifier, or information used to indicate the disclosure conditions of the credential information corresponding to the second identifier.

[0358] In one possible implementation, the second identifier and the credential information corresponding to the second identifier are carried in the identification information corresponding to the second identifier; or, the second identifier is carried in the identification information corresponding to the second identifier, and one or more of the credential information corresponding to the second identifier, the service information corresponding to the second identifier, the information indicating the type of the terminal, the information of the issuer of the second identifier, or the information indicating the disclosure conditions of the credential information corresponding to the second identifier are carried in the file information corresponding to the second identifier.

[0359] In one possible implementation, the identification information corresponding to the second identifier includes a first field and one or more of the following: a second field or a third field, wherein the information carried by the first field is used to indicate the second identifier, the information carried by the second field is used to indicate the identification type of the second identifier, and the information carried by the third field is used to verify the information carried by fields other than the third field in the identification information corresponding to the second identifier.

[0360] In a possible implementation, the storage node receives fifth information from the first node, wherein the fifth information is used to indicate a third identifier of the first node and credential information corresponding to the third identifier.

[0361] In one possible implementation, if the first node includes equipment corresponding to a card vendor or terminal manufacturer, the transceiver module 1102 is further configured to receive certification information corresponding to the terminal from the first node, wherein the certification information corresponding to the terminal is used to verify attributes corresponding to the terminal or the terminal identifier.

[0362] In one possible implementation, the transceiver module 1102 is further configured to receive sixth information from the second node. The sixth information indicates the second node's fourth identifier and credential information corresponding to the fourth identifier. The credential information corresponding to the fourth identifier is used to verify attributes corresponding to the second node and / or the fourth identifier. The fourth identifier and the credential information corresponding to the fourth identifier are generated by the first node. The processing module 1101 is further configured to store the sixth information.

[0363] In one possible implementation, the credential information corresponding to the fourth identifier includes authentication information corresponding to the fourth identifier and / or proof information corresponding to the fourth identifier, the authentication information corresponding to the fourth identifier is used to verify the second node, and the proof information corresponding to the fourth identifier is used to verify the attribute corresponding to the fourth identifier.

[0364] In one possible implementation, the sixth information includes the fourth identifier and one or more of the following: credential information corresponding to the fourth identifier, service information corresponding to the fourth identifier, information used to indicate the type of the second node, information of the issuer of the fourth identifier, or information used to indicate the disclosure conditions of the credential information corresponding to the fourth identifier.

[0365] In one possible implementation, the fourth identifier and the credential information corresponding to the fourth identifier are carried in the identification information corresponding to the fourth identifier. Alternatively, the fourth identifier is carried in the identification information corresponding to the second identifier, and one or more of the credential information corresponding to the fourth identifier, service information corresponding to the fourth identifier, information indicating the type of the second node, information about the issuer of the fourth identifier, or information indicating disclosure conditions for the credential information corresponding to the fourth identifier are carried in the file information corresponding to the fourth identifier.

[0366] In one possible implementation, the identification information corresponding to the fourth identifier includes a fourth field and one or more of the following: a fifth field or a sixth field, wherein the information carried by the fourth field is used to indicate the fourth identifier, the information carried by the fifth field is used to indicate the identification type of the fourth identifier, and the information carried by the sixth field is used to verify the information carried by fields other than the sixth field in the identification information corresponding to the fourth identifier.

[0367] Optionally, the transceiver module 1102 may include a receiving module and a sending module (not shown in FIG11 ). The transceiver module 1102 is configured to implement the sending function and the receiving function of the communication device 1100 .

[0368] Optionally, the communication device 1100 may further include a storage module (not shown in FIG11 ) that stores a program or instruction. When the processing module 1101 executes the program or instruction, the communication device 1100 may perform the function of a storage node in the communication method shown in FIG2 , FIG4 , or FIG8 .

[0369] It should be understood that the processing module 1101 involved in the communication device 1100 can be implemented by a processor or a processor-related circuit component, which can be a processor or a processing unit; the transceiver module 1102 can be implemented by a transceiver or a transceiver-related circuit component, which can be a transceiver or a transceiver unit.

[0370] It should be noted that the communication device 1100 can be a terminal or a network device, or a chip (system) that can be set in a terminal or a network device, or other parts or components or software modules, or a device that includes a terminal or a network device. This application does not limit this.

[0371] In addition, the technical effects of the communication device 1100 can refer to the technical effects of the communication method shown in any one of Figures 2, 4 or 8, and will not be repeated here.

[0372] In one possible implementation, the service information corresponding to the first identifier is used to generate proof information and / or authentication information for the third node. Furthermore, the service information corresponding to the first identifier is used to verify the proof information and / or authentication information of the third node. Furthermore, the service information corresponding to the first identifier is used to provide the third node with one or more of the following services: a contract service, a network access service, or a data sharing service; wherein the third node is different from the first node, the third node's credential information is used to verify the third node, and the third node's proof information is used to verify the attributes corresponding to the third node's identifier.

[0373] In a possible implementation, the first information is further used to indicate credential information corresponding to the first identifier, and the credential information corresponding to the first identifier is used to verify the first node and / or to verify the attribute corresponding to the first identifier.

[0374] In one possible implementation, the credential information corresponding to the first identifier includes authentication information corresponding to the first identifier and / or proof information corresponding to the first identifier, the authentication information corresponding to the first identifier is used to verify the first node, and the proof information corresponding to the first identifier is used to verify the attributes corresponding to the first node.

[0375] In one possible implementation, the first information includes the first identifier and service information corresponding to the first identifier, and one or more of the following: information indicating the type of the first node, information of the issuer of the first identifier, or information indicating the disclosure conditions of the credential information corresponding to the first identifier.

[0376] In one possible implementation, the first identifier and the credential information corresponding to the first identifier are carried in the identification information corresponding to the first identifier. Alternatively, the first identifier is carried in the identification information corresponding to the first identifier, and one or more of the credential information corresponding to the first identifier, service information corresponding to the first identifier, information indicating the type of the terminal, information indicating the issuer of the first identifier, or information indicating disclosure conditions for the credential information corresponding to the first identifier are carried in the file information corresponding to the first identifier.

[0377] In one possible implementation, the certification information corresponding to the first identifier is generated by a fourth node based on service information corresponding to the fourth node, and the certification information corresponding to the first identifier is signed by a private key corresponding to the fourth node. The fourth node is different from the first node.

[0378] In one possible implementation, the service information corresponding to the fourth node is used to generate service result information, and the service result information includes credential information of a fifth node. The fifth node is different from the fourth node. The credential information of the fifth node is used to verify the fifth node and / or to verify the attributes corresponding to the identifier of the fifth node.

[0379] In a possible implementation, the identification information corresponding to the first identification is information signed by a private key corresponding to the identification of the first node, which is generated by a card vendor or a terminal manufacturer.

[0380] In one possible implementation, the storage node is one or more of the following: a blockchain node, a distributed storage node, or a communication device. The communication device is different from the first node.

[0381] In some embodiments, the communication device 1100 may be applicable to the communication system shown in FIG. 1 and perform the function of a terminal in the communication method shown in FIG. 8 .

[0382] Processing module 1101 is configured to obtain sixth information. The sixth information indicates the fourth identifier of the second node and the credential information corresponding to the fourth identifier. The credential information corresponding to the fourth identifier is used to verify the attributes corresponding to the second node and / or the fourth identifier. The fourth identifier and the credential information corresponding to the fourth identifier are generated by the first node. Transceiver module 1102 is configured to send the sixth information and / or a hash value of the sixth information to a storage node.

[0383] In one possible implementation, the credential information corresponding to the fourth identifier includes authentication information corresponding to the fourth identifier and / or proof information corresponding to the fourth identifier, the authentication information corresponding to the fourth identifier is used to verify the second node, and the proof information corresponding to the fourth identifier is used to verify the attribute corresponding to the fourth identifier.

[0384] In one possible implementation, the sixth information includes the fourth identifier and one or more of the following: credential information corresponding to the fourth identifier, service information corresponding to the fourth identifier, information used to indicate the type of the second node, information of the issuer of the fourth identifier, or information used to indicate the disclosure conditions of the credential information corresponding to the fourth identifier.

[0385] In one possible implementation, the fourth identifier and the credential information corresponding to the fourth identifier are carried in the identification information corresponding to the fourth identifier; or, the fourth identifier is carried in the identification information corresponding to the second identifier, and one or more of the credential information corresponding to the fourth identifier, the service information corresponding to the fourth identifier, the information used to indicate the type of the second node, the information of the issuer of the fourth identifier, or the information used to indicate the disclosure conditions of the credential information corresponding to the fourth identifier are carried in the file information corresponding to the fourth identifier.

[0386] Optionally, the identification information corresponding to the fourth identifier includes a fourth field and one or more of the following: a fifth field or a sixth field, wherein the information carried by the fourth field is used to indicate the fourth identifier, the information carried by the fifth field is used to indicate the identification type of the fourth identifier, and the information carried by the sixth field is used to verify the information carried by fields other than the sixth field in the identification information corresponding to the fourth identifier.

[0387] In one possible implementation, the storage node is one or more of the following: a blockchain node, a distributed storage node, or an electronic device. The electronic device is different from the first node.

[0388] Optionally, the transceiver module 1102 may include a receiving module and a sending module (not shown in FIG11 ). The transceiver module 1102 is configured to implement the sending function and the receiving function of the communication device 1100 .

[0389] Optionally, the communication device 1100 may further include a storage module (not shown in FIG11 ) that stores a program or instruction. When the processing module 1101 executes the program or instruction, the communication device 1100 may perform the function of the storage node in the communication method shown in FIG8 .

[0390] It should be understood that the processing module 1101 involved in the communication device 1100 can be implemented by a processor or a processor-related circuit component, which can be a processor or a processing unit; the transceiver module 1102 can be implemented by a transceiver or a transceiver-related circuit component, which can be a transceiver or a transceiver unit.

[0391] It should be noted that the communication device 1100 can be a terminal, or a chip (system) or other parts, components or software modules that can be set in the terminal, or a device including a terminal, which is not limited in this application.

[0392] In addition, the technical effects of the communication device 1100 can refer to the technical effects of the communication method shown in any one of Figure 8, and will not be repeated here.

[0393] In some embodiments, the communication device 1100 may be applicable to the communication system shown in FIG. 1 , and perform the functions of the equipment corresponding to the operator in the communication method shown in FIG. 9 .

[0394] Processing module 1101 is configured to obtain seventh information. The seventh information indicates the terminal's fifth identifier and the credential information corresponding to the fifth identifier. The credential information corresponding to the fifth identifier is used to verify the attributes corresponding to the terminal and / or the fifth identifier. The fifth identifier is different from the user permanent identifier of the terminal in the operator's device, and the fifth identifier corresponds to the user permanent identifier of the terminal. The user permanent identifier is used for communication between the operator's device and the terminal. Transceiver module 1102 is configured to send the seventh information to the terminal.

[0395] Optionally, the transceiver module 1102 may include a receiving module and a sending module (not shown in FIG11 ). The transceiver module 1102 is configured to implement the sending function and the receiving function of the communication device 1100 .

[0396] Optionally, the communication device 1100 may further include a storage module (not shown in FIG11 ) that stores a program or instruction. When the processing module 1101 executes the program or instruction, the communication device 1100 may perform the function of the storage node in the communication method shown in FIG9 .

[0397] It should be understood that the processing module 1101 involved in the communication device 1100 can be implemented by a processor or a processor-related circuit component, which can be a processor or a processing unit; the transceiver module 1102 can be implemented by a transceiver or a transceiver-related circuit component, which can be a transceiver or a transceiver unit.

[0398] It should be noted that the communication device 1100 can be a network device, or other parts or components or software modules of a chip (system) that can be set in the network device, or a device that includes a network device. This application does not limit this.

[0399] In addition, the technical effects of the communication device 1100 can refer to the technical effects of the communication method shown in any one of Figure 9, and will not be repeated here.

[0400] In some embodiments, the communication device 1100 may be applicable to the communication system shown in FIG. 1 and perform the function of a terminal in the communication method shown in FIG. 9 .

[0401] The transceiver module 1102 is configured to receive seventh information from a device corresponding to an operator. The seventh information indicates the terminal's fifth identifier and credential information corresponding to the fifth identifier. The credential information corresponding to the fifth identifier is used to verify attributes corresponding to the terminal and / or the fifth identifier. The fifth identifier is different from the terminal's permanent user identifier, and the fifth identifier corresponds to the terminal's permanent user identifier. The permanent user identifier is used for communication between the operator's device and the terminal. The processing module 1101 is configured to store the seventh information.

[0402] Optionally, the transceiver module 1102 may include a receiving module and a sending module (not shown in FIG11 ). The transceiver module 1102 is configured to implement the sending function and the receiving function of the communication device 1100 .

[0403] Optionally, the communication device 1100 may further include a storage module (not shown in FIG11 ) that stores a program or instruction. When the processing module 1101 executes the program or instruction, the communication device 1100 may perform the function of the storage node in the communication method shown in FIG9 .

[0404] It should be understood that the processing module 1101 involved in the communication device 1100 can be implemented by a processor or a processor-related circuit component, which can be a processor or a processing unit; the transceiver module 1102 can be implemented by a transceiver or a transceiver-related circuit component, which can be a transceiver or a transceiver unit.

[0405] It should be noted that the communication device 1100 can be a terminal, or a chip (system) that can be set in a terminal, or other parts or components or software modules, or a device including a terminal, which is not limited in this application.

[0406] In addition, the technical effects of the communication device 1100 can refer to the technical effects of the communication method shown in any one of Figure 9, and will not be repeated here.

[0407] In one possible implementation, the credential information corresponding to the fifth identifier includes authentication information corresponding to the fifth identifier and / or proof information corresponding to the fifth identifier, the authentication information corresponding to the fifth identifier is used to verify the terminal, and the proof information corresponding to the fifth identifier is used to verify the attributes corresponding to the terminal.

[0408] In one possible implementation, the seventh information includes the fifth identifier, and one or more of the following: credential information corresponding to the fifth identifier, proof information corresponding to the fifth identifier, information used to indicate the type of the terminal, information of the issuer of the fifth identifier, and information used to indicate the disclosure conditions of the credential information corresponding to the fifth identifier.

[0409] In one possible implementation, the fifth identifier and the credential information corresponding to the fifth identifier are carried in the identification information corresponding to the fifth identifier; or, one or more of the credential information corresponding to the fifth identifier, the service information corresponding to the fifth identifier, the information used to indicate the type of the terminal, the information of the issuer of the fifth identifier, and the information used to indicate the disclosure conditions of the credential information corresponding to the fifth identifier are carried in the file information corresponding to the fifth identifier.

[0410] In one possible implementation, the identification information corresponding to the fifth identifier includes the seventh field and one or more of the following: the eighth field or the ninth field, wherein the information carried by the seventh field is used to indicate the fifth identifier, the information carried by the eighth field is used to indicate the identification type of the fifth identifier, and the information carried by the ninth field is used to verify the information carried by the fields other than the ninth field in the identification information corresponding to the fifth identifier.

[0411] In some embodiments, the communication device 1100 may be applicable to the communication system shown in FIG. 1 , and execute the functions of the equipment corresponding to the card vendor or terminal manufacturer in the communication method shown in FIG. 2 .

[0412] Among them, the processing module 1101 is used to obtain the eighth information and the ninth information. Among them, the eighth information includes the seventh identifier for indicating the device corresponding to the card merchant or terminal manufacturer, and the credential information corresponding to the seventh identifier, and the credential information corresponding to the seventh identifier is used to verify the device corresponding to the card merchant or terminal manufacturer and / or for verifying the attribute corresponding to the seventh identifier. The ninth information is used to indicate the eighth identifier of the terminal and the credential information corresponding to the eighth identifier, and the credential information corresponding to the eighth identifier is used to verify the attribute corresponding to the terminal and / or the eighth identifier. The eighth identifier and the credential information corresponding to the eighth identifier are generated by the device corresponding to the card merchant or terminal manufacturer, that is, the credential information corresponding to the eighth identifier is signed by the private key of the device corresponding to the card merchant or terminal manufacturer. The transceiver module 1102 is used to send the eighth information and the ninth information to the storage node.

[0413] In a possible implementation, the transceiver module 1102 is further configured to send ninth information to the terminal.

[0414] Optionally, the transceiver module 1102 may include a receiving module and a sending module (not shown in FIG11 ). The transceiver module 1102 is configured to implement the sending function and the receiving function of the communication device 1100 .

[0415] Optionally, the communication device 1100 may further include a storage module (not shown in FIG11 ) that stores a program or instruction. When the processing module 1101 executes the program or instruction, the communication device 1100 may perform the function of the storage node in the communication method shown in FIG10 .

[0416] It should be understood that the processing module 1101 involved in the communication device 1100 can be implemented by a processor or a processor-related circuit component, which can be a processor or a processing unit; the transceiver module 1102 can be implemented by a transceiver or a transceiver-related circuit component, which can be a transceiver or a transceiver unit.

[0417] It should be noted that the communication device 1100 can be a terminal or a network device, or a chip (system) that can be set in a terminal or a network device, or other parts or components or software modules, or a device that includes a terminal or a network device. This application does not limit this.

[0418] In addition, the technical effects of the communication device 1100 can refer to the technical effects of the communication method shown in any one of Figure 10, and will not be repeated here.

[0419] In some embodiments, the communication device 1100 may be applicable to the communication system shown in FIG. 1 , and perform the function of a storage node in the communication method shown in FIG. 10 .

[0420] The transceiver module 1102 is used to receive the eighth information and the ninth information. The eighth information includes the seventh identifier for indicating the device corresponding to the card dealer or terminal manufacturer, and the credential information corresponding to the seventh identifier. The credential information corresponding to the seventh identifier is used to verify the device corresponding to the card dealer or terminal manufacturer and / or for verifying the attribute corresponding to the seventh identifier. The ninth information is used to indicate the eighth identifier of the terminal and the credential information corresponding to the eighth identifier. The credential information corresponding to the eighth identifier is used to verify the attribute corresponding to the terminal and / or the eighth identifier. The eighth identifier and the credential information corresponding to the eighth identifier are generated by the device corresponding to the card dealer or terminal manufacturer, that is, the credential information corresponding to the eighth identifier is signed by the private key of the device corresponding to the card dealer or terminal manufacturer. The processing module 1101 is used to store the eighth information and the ninth information.

[0421] In a possible implementation, the transceiver module 1102 is further configured to receive the eighth information and the ninth information from a device corresponding to a card vendor or a terminal manufacturer.

[0422] In a possible implementation, the transceiver module 1102 is further configured to receive the eighth information from a device corresponding to a card vendor or a terminal manufacturer, and receive the ninth information from the terminal.

[0423] Optionally, the transceiver module 1102 may include a receiving module and a sending module (not shown in FIG11 ). The transceiver module 1102 is configured to implement the sending function and the receiving function of the communication device 1100 .

[0424] Optionally, the communication device 1100 may further include a storage module (not shown in FIG11 ) that stores a program or instruction. When the processing module 1101 executes the program or instruction, the communication device 1100 may perform the function of the storage node in the communication method shown in FIG10 .

[0425] It should be understood that the processing module 1101 involved in the communication device 1100 can be implemented by a processor or a processor-related circuit component, which can be a processor or a processing unit; the transceiver module 1102 can be implemented by a transceiver or a transceiver-related circuit component, which can be a transceiver or a transceiver unit.

[0426] It should be noted that the communication device 1100 can be a terminal or a network device, or a chip (system) that can be set in a terminal or a network device, or other parts or components or software modules, or a device that includes a terminal or a network device. This application does not limit this.

[0427] In addition, the technical effects of the communication device 1100 can refer to the technical effects of the communication method shown in any one of Figure 10, and will not be repeated here.

[0428] 12 is a schematic diagram of the structure of a communication device provided in an embodiment of the present application. The communication device may be a terminal or a network device, or a chip (system), or other components or assemblies or software modules that can be provided in a terminal or a network device. As shown in FIG12 , the communication device 1200 may include a processor 1201. Optionally, the communication device 1200 may further include a memory 1202 and / or a transceiver 1203. The processor 1201 is coupled to the memory 1202 and the transceiver 1203, such as by a communication bus.

[0429] The following is a detailed introduction to the various components of the communication device 1200 in conjunction with FIG12 :

[0430] The processor 1201 is the control center of the communication device 1200 and can be a single processor or a collective term for multiple processing elements. For example, the processor 1201 can be one or more central processing units (CPUs), an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application, such as one or more digital signal processors (DSPs) or one or more field programmable gate arrays (FPGAs).

[0431] Optionally, the processor 1201 may execute various functions of the communication device 1200 by running or executing a software program stored in the memory 1202 and calling data stored in the memory 1202 .

[0432] In a specific implementation, as an embodiment, the processor 1201 may include one or more CPUs, such as CPU0 and CPU1 shown in FIG12 .

[0433] In a specific implementation, as an embodiment, the communication device 1200 may also include multiple processors, such as the processor 1201 and the processor 1204 shown in FIG12 . Each of these processors may be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). The processor herein may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).

[0434] Among them, the memory 1202 is used to store the software program for executing the solution of this application, and the execution is controlled by the processor 1201. The specific implementation method can refer to the above method embodiment and will not be repeated here.

[0435] Alternatively, the memory 1202 may be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, an optical disc storage (including a compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 1202 may be integrated with the processor 1201 or exist independently and be coupled to the processor 1201 via an interface circuit (not shown in FIG. 12 ) of the communication device 1200. This embodiment of the present application does not specifically limit this.

[0436] Transceiver 1203 is used for communication with other communication devices. For example, if communication device 1200 is a terminal, transceiver 1203 can be used to communicate with a network device or another terminal. For another example, if communication device 1200 is a network device, transceiver 1203 can be used to communicate with a terminal or another network device.

[0437] Optionally, the transceiver 1203 may include a receiver and a transmitter (not shown separately in FIG12 ), wherein the receiver is used to implement a receiving function, and the transmitter is used to implement a sending function.

[0438] Optionally, the transceiver 1203 can be integrated with the processor 1201, or can exist independently and be coupled to the processor 1201 through the interface circuit of the communication device 1200 (not shown in Figure 12). This embodiment of the present application does not specifically limit this.

[0439] It should be noted that the structure of the communication device 1200 shown in FIG12 does not constitute a limitation on the communication device. An actual communication device may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.

[0440] In addition, the technical effects of the communication device 1200 can refer to the technical effects of the communication method described in the above method embodiment, and will not be repeated here.

[0441] An embodiment of the present application provides a communication system, which includes one or more terminals as described above, and one or more network devices.

[0442] It should be understood that the processor in the embodiments of the present application may be a CPU, but may also be other general-purpose processors, DSPs, ASICs, FPGAs, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor.

[0443] It should also be understood that the memory in the embodiments of the present application can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a ROM, a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an EEPROM, or a flash memory. The volatile memory can be a RAM, which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).

[0444] The above embodiments can be implemented in whole or in part by software, hardware (such as circuits), firmware or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer program are loaded or executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired (such as infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more available media sets. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a tape), an optical medium (for example, a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.

[0445] It should be understood that the term "and / or" as used herein simply describes a relationship between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A alone, A and B together, or B alone. A and B can be singular or plural. Furthermore, the character " / " as used herein generally indicates an "or" relationship between the associated objects, but it may also indicate an "and / or" relationship. For specific understanding, please refer to the context.

[0446] In this application, "at least one" means one or more, and "plurality" means two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or plural.

[0447] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0448] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0449] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0450] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0451] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0452] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0453] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a ROM, a RAM, a magnetic disk, or an optical disk.

[0454] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. A communication method, characterized in that: Applied to the first node, the method comprises: Acquire first information; wherein the first information is used to indicate a first identifier and service information corresponding to the first identifier; The first information is sent to the storage node.

2. The method according to claim 1, characterized in that The first node may include one or more of: Devices and terminals corresponding to card vendors or terminal manufacturers, devices corresponding to operators, devices corresponding to authoritative institutions, devices corresponding to third-party trusted institutions, or air card writing servers.

3. The method according to claim 2, characterized in that If the first node is a device corresponding to the card manufacturer or terminal manufacturer, the method further includes: Acquire second information; the second information is used to indicate a second identifier of the terminal and credential information corresponding to the second identifier, the credential information corresponding to the second identifier is used to verify the attributes corresponding to the terminal and / or the second identifier; the second identifier and the credential information corresponding to the second identifier are generated by the first node; Send the second information and / or the hash value of the second information to a storage node.

4. The method according to claim 3, characterized in that The credential information corresponding to the second identifier includes authentication information corresponding to the second identifier and / or proof information corresponding to the second identifier, the authentication information corresponding to the second identifier is used to verify the terminal; the proof information corresponding to the second identifier is used to verify the attribute corresponding to the second identifier.

5. The method according to claim 3 or 4, characterized in that: The second information includes the second identifier, and one or more of the following: The credential information corresponding to the second identifier, the service information corresponding to the second identifier, the information indicating the type of the terminal, the information of the issuer of the second identifier, or the information indicating the disclosure condition of the credential information corresponding to the second identifier.

6. The method according to claim 5, characterized in that The second identifier and the credential information corresponding to the second identifier are carried in the identification information corresponding to the second identifier; or, the second identifier is carried in the identification information corresponding to the second identifier, and one or more of the credential information corresponding to the second identifier, the service information corresponding to the second identifier, the information used to indicate the type of the terminal, the information of the issuer of the second identifier, or the information used to indicate the disclosure conditions of the credential information corresponding to the second identifier are carried in the file information corresponding to the second identifier.

7. The method according to claim 6, characterized in that The identification information corresponding to the second identifier includes a first field and one or more of the following: a second field or a third field, wherein the information carried by the first field is used to indicate the second identifier, the information carried by the second field is used to indicate the identification type of the second identifier, and the information carried by the third field is used to verify the information carried by fields other than the third field in the identification information corresponding to the second identifier.

8. The method according to any one of claims 3 to 7, characterized in that: The method further comprises: Sending third information to the terminal; the third information is used to indicate the second information, or the third information is used to indicate the second information and the storage location of the second information in the storage system.

9. The method according to claim 2, characterized in that: If the first node is a terminal, the method further includes: Receive fourth information from a device corresponding to a card merchant or a terminal manufacturer; wherein the fourth information is used to indicate the first identifier and the credential information corresponding to the first identifier; or, the fourth information is used to indicate the storage location of the first identifier, the credential information corresponding to the first identifier, and the first identifier and the credential information corresponding to the first identifier in a storage node.

10. The method according to claim 1, 2 or 9, characterized in that: The method further comprises: Sending fifth information and / or a hash value of the fifth information to a storage node; wherein the fifth information is used to indicate a third identifier of the first node and credential information corresponding to the third identifier; and the third identifier is different from the first identifier.

11. The method according to claim 2, characterized in that If the first node is the terminal, the method further includes: Sending a certification request message to a device corresponding to the card vendor or terminal manufacturer; wherein the certification request message is used to request certification information corresponding to the first node, and the certification information corresponding to the first node is used to verify the attribute corresponding to the first node or the identifier of the first node; The certification information corresponding to the first node is received, where the certification information corresponding to the first node is generated by a device corresponding to the card manufacturer or the terminal manufacturer.

12. The method according to claim 2, characterized in that: If the first node is a device corresponding to the card manufacturer or terminal manufacturer, the method further includes: Receiving certification request information from the terminal; wherein the certification request information is used to request certification information corresponding to the terminal, and the certification information corresponding to the terminal is used to verify the attribute corresponding to the terminal or the identifier of the terminal; Sending certification information corresponding to the terminal to the storage node; Send certification information corresponding to the terminal to the terminal.

13. A communication method, characterized in that: Applied to a storage node, the method comprises: The storage node receives first information from the first node; wherein the first information includes a first identifier and service information corresponding to the first identifier; The storage node stores the first information.

14. The method according to claim 13, characterized in that The first node may include one or more of: Devices and terminals corresponding to card vendors or terminal manufacturers, devices corresponding to operators, devices corresponding to authoritative institutions, devices corresponding to third-party trusted institutions, or air card writing servers.

15. The method according to claim 14, characterized in that If the first node includes a device corresponding to the card manufacturer or terminal manufacturer, the method further includes: The storage node receives second information from the first node; the second information is used to indicate a second identifier of the terminal and credential information corresponding to the second identifier, and the credential information corresponding to the second identifier is used to verify the attributes corresponding to the terminal and / or the second identifier; the second identifier and the credential information corresponding to the second identifier are generated by the first node; The storage node stores the second information.

16. The method according to claim 15, characterized in that The credential information corresponding to the second identifier includes authentication information corresponding to the second identifier and / or proof information corresponding to the second identifier, the authentication information corresponding to the second identifier is used to verify the terminal; the proof information corresponding to the second identifier is used to verify the attribute corresponding to the second identifier.

17. The method according to claim 15 or 16, characterized in that The second information includes the second identifier, and one or more of the following: The credential information corresponding to the second identifier, the service information corresponding to the second identifier, the information indicating the type of the terminal, the information of the issuer of the second identifier, or the information indicating the disclosure condition of the credential information corresponding to the second identifier.

18. The method according to claim 17, characterized in that The second identifier and the credential information corresponding to the second identifier are carried in the identification information corresponding to the second identifier; or, the second identifier is carried in the identification information corresponding to the second identifier, and one or more of the credential information corresponding to the second identifier, the service information corresponding to the second identifier, the information indicating the type of the terminal, the information of the issuer of the second identifier, or the information indicating the disclosure conditions of the credential information corresponding to the second identifier are carried in the file information corresponding to the second identifier.

19. The method according to claim 18, characterized in that The identification information corresponding to the second identifier includes a first field and one or more of the following: a second field or a third field, wherein the information carried by the first field is used to indicate the second identifier, the information carried by the second field is used to indicate the identification type of the second identifier, and the information carried by the third field is used to verify the information carried by fields other than the third field in the identification information corresponding to the second identifier.

20. The method according to claim 13 or 14, characterized in that The method further comprises: The storage node receives fifth information from the first node, wherein the fifth information is used to indicate a third identifier of the first node and credential information corresponding to the third identifier.

21. The method according to claim 14, characterized in that If the first node includes a device corresponding to a card manufacturer or a terminal manufacturer, the method further includes: Receive certification information corresponding to the terminal from the first node; wherein the certification information corresponding to the terminal is used to verify an attribute corresponding to the terminal or an identifier of the terminal.

22. The method according to claim 13, characterized in that The method further comprises: The storage node receives sixth information from the second node; wherein the sixth information is used to indicate a fourth identifier of the second node and credential information corresponding to the fourth identifier, and the credential information corresponding to the fourth identifier is used to verify an attribute corresponding to the second node and / or the fourth identifier; the fourth identifier and the credential information corresponding to the fourth identifier are generated by the first node; The storage node stores the sixth information.

23. The method according to claim 22, characterized in that The credential information corresponding to the fourth identifier includes authentication information corresponding to the fourth identifier and / or proof information corresponding to the fourth identifier, the authentication information corresponding to the fourth identifier is used to verify the second node, and the proof information corresponding to the fourth identifier is used to verify the attribute corresponding to the fourth identifier.

24. The method according to claim 22 or 23, characterized in that The sixth information includes the fourth identifier and one or more of the following: The credential information corresponding to the fourth identifier, the service information corresponding to the fourth identifier, the information used to indicate the type of the second node, the information of the issuer of the fourth identifier, or the information used to indicate the disclosure condition of the credential information corresponding to the fourth identifier.

25. The method according to claim 24, characterized in that The fourth identifier and the credential information corresponding to the fourth identifier are carried in the identification information corresponding to the fourth identifier; or, the fourth identifier is carried in the identification information corresponding to the fourth identifier, and one or more of the credential information corresponding to the fourth identifier, the service information corresponding to the fourth identifier, the information indicating the type of the second node, the information of the issuer of the fourth identifier, or the information indicating the disclosure conditions of the credential information corresponding to the fourth identifier are carried in the file information corresponding to the fourth identifier.

26. The method according to claim 25, characterized in that The identification information corresponding to the fourth identifier includes a fourth field and one or more of the following: a fifth field or a sixth field, wherein the information carried by the fourth field is used to indicate the fourth identifier, the information carried by the fifth field is used to indicate the identification type of the fourth identifier, and the information carried by the sixth field is used to verify the information carried by fields other than the sixth field in the identification information corresponding to the fourth identifier.

27. The method according to any one of claims 1 to 26, characterized in that The service information corresponding to the first identifier is used to generate proof information of the third node and / or authentication information of the third node; and / or, The service information corresponding to the first identifier is used to verify the proof information of the third node and / or the authentication information of the third node; and / or, The service information corresponding to the first identifier is used to provide the third node with one or more of the following services: a contract service, a network access service, or a data sharing service; The third node is different from the first node, the credential information of the third node is used to verify the third node, and the certification information of the third node is used to verify the attribute corresponding to the identifier of the third node.

28. The method according to any one of claims 1 to 27, characterized in that The first information is further used to indicate credential information corresponding to the first identifier, and the credential information corresponding to the first identifier is used to verify the first node and / or to verify an attribute corresponding to the first identifier.

29. The method according to claim 28, characterized in that The credential information corresponding to the first identifier includes authentication information corresponding to the first identifier and / or proof information corresponding to the first identifier, the authentication information corresponding to the first identifier is used to verify the first node, and the proof information corresponding to the first identifier is used to verify the attributes corresponding to the first node.

30. The method according to claim 29, characterized in that The first identifier and the credential information corresponding to the first identifier are carried in the identification information corresponding to the first identifier; or, the first identifier is carried in the identification information corresponding to the first identifier, and one or more of the credential information corresponding to the first identifier, the service information corresponding to the first identifier, the information indicating the type of the terminal, the information of the issuer of the first identifier, or the information indicating the disclosure conditions of the credential information corresponding to the first identifier are carried in the file information corresponding to the first identifier.

31. The method according to claim 29 or 30, characterized in that The certification information corresponding to the first identifier is generated by a fourth node based on service information corresponding to the fourth node, and the certification information corresponding to the first identifier is signed by a private key corresponding to the fourth node; the fourth node is different from the first node.

32. The method according to claim 31, characterized in that The service information corresponding to the fourth node is used to generate service result information, and the service result information includes the credential information of the fifth node; the fifth node is different from the fourth node; the credential information of the fifth node is used to verify the fifth node and / or to verify the attributes corresponding to the identifier of the fifth node.

33. The method according to claim 30, characterized in that The identification information corresponding to the first identification is information signed by a private key corresponding to the identification of the first node generated by a card merchant or a terminal manufacturer.

34. The method according to any one of claims 1 to 33, characterized in that The first information further includes one or more of the following: information indicating the type of the first node, information about the issuer of the first identifier, or information indicating a disclosure condition of the credential information corresponding to the first identifier.

35. The method according to any one of claims 1 to 34, characterized in that The storage node is one or more of the following: a blockchain node, a distributed storage node, or a communication device; the communication device is different from the first node.

36. A communication method, characterized in that: Applied to the second node, the method comprises: Acquire sixth information; wherein the sixth information is used to indicate the fourth identifier of the second node and the credential information corresponding to the fourth identifier, and the credential information corresponding to the fourth identifier is used to verify the attributes corresponding to the second node and / or the fourth identifier; the fourth identifier and the credential information corresponding to the fourth identifier are generated by the first node; Send the sixth information and / or the hash value of the sixth information to a storage node.

37. The method according to claim 36, characterized in that The credential information corresponding to the fourth identifier includes authentication information corresponding to the fourth identifier and / or proof information corresponding to the fourth identifier, the authentication information corresponding to the fourth identifier is used to verify the second node, and the proof information corresponding to the fourth identifier is used to verify the attribute corresponding to the fourth identifier.

38. The method according to claim 36 or 37, characterized in that The sixth information includes the fourth identifier and one or more of the following: credential information corresponding to the fourth identifier, service information corresponding to the fourth identifier, information used to indicate the type of the second node, information of the issuer of the fourth identifier, or information used to indicate a disclosure condition of the credential information corresponding to the fourth identifier.

39. The method according to any one of claims 36 to 38, characterized in that The fourth identifier and the credential information corresponding to the fourth identifier are carried in the identification information corresponding to the fourth identifier; or, the fourth identifier is carried in the identification information corresponding to the fourth identifier, and one or more of the credential information corresponding to the fourth identifier, the service information corresponding to the fourth identifier, the information indicating the type of the second node, the information of the issuer of the fourth identifier, or the information indicating the disclosure condition of the credential information corresponding to the fourth identifier are carried in the file information corresponding to the fourth identifier.

40. The method according to claim 39, characterized in that The identification information corresponding to the fourth identifier includes the fourth field and one or more of the following: a fifth field or a sixth field, wherein the information carried by the fourth field is used to indicate the fourth identifier, the information carried by the fifth field is used to indicate the identification type of the fourth identifier, and the information carried by the sixth field is used to verify the information carried by fields other than the sixth field in the identification information corresponding to the fourth identifier.

41. The method according to any one of claims 36 to 40, characterized in that The storage node is one or more of the following: a blockchain node, a distributed storage node, or a communication device, and the communication device is different from the first node.

42. A communication method, characterized in that: Applied to equipment corresponding to an operator, the method includes: Acquire seventh information; wherein the seventh information is used to indicate a fifth identifier of the terminal and credential information corresponding to the fifth identifier, the credential information corresponding to the fifth identifier is used to verify the attributes corresponding to the terminal and / or the fifth identifier, the fifth identifier is different from the user permanent identifier of the terminal in the device corresponding to the operator, and the fifth identifier corresponds to the user permanent identifier of the terminal, and the user permanent identifier is used for communication between the device corresponding to the operator and the terminal; Sending the seventh information to the terminal.

43. A communication method, characterized in that: Applied to a terminal, the method comprises: Receive seventh information from a device corresponding to an operator; wherein the seventh information is used to indicate a fifth identifier of the terminal and credential information corresponding to the fifth identifier, the credential information corresponding to the fifth identifier is used to verify an attribute corresponding to the terminal and / or the fifth identifier, the fifth identifier is different from a user permanent identifier of the terminal, and the fifth identifier corresponds to the user permanent identifier of the terminal, and the user permanent identifier is used for communication between the device corresponding to the operator and the terminal; The seventh information is stored.

44. The method according to claim 42 or 43, characterized in that The credential information corresponding to the fifth identification includes authentication information corresponding to the fifth identification and / or proof information corresponding to the fifth identification, the authentication information corresponding to the fifth identification is used to verify the terminal, and the proof information corresponding to the fifth identification is used to verify the attributes corresponding to the terminal.

45. The method according to any one of claims 42 to 44, characterized in that The seventh information includes the fifth identifier, and one or more of the following: The credential information corresponding to the fifth identification, the certification information corresponding to the fifth identification, the information used to indicate the type of the terminal, the information of the issuer of the fifth identification, and the information used to indicate the disclosure conditions of the credential information corresponding to the fifth identification.

46. ​​The method according to claim 45, characterized in that The fifth identifier and the credential information corresponding to the fifth identifier are carried in the identification information corresponding to the fifth identifier; or, the fifth identifier is carried in the identification information corresponding to the fifth identifier, and one or more of the credential information corresponding to the fifth identifier, the service information corresponding to the fifth identifier, the information indicating the type of the terminal, the information of the issuer of the fifth identifier, and the information indicating the disclosure conditions of the credential information corresponding to the fifth identifier are carried in the file information corresponding to the fifth identifier.

47. The method according to claim 46, characterized in that The identification information corresponding to the fifth identifier includes a seventh field and one or more of the following: an eighth field or a ninth field, wherein the information carried by the seventh field is used to indicate the fifth identifier, the information carried by the eighth field is used to indicate the identification type of the fifth identifier, and the information carried by the ninth field is used to verify the information carried by fields other than the ninth field in the identification information corresponding to the fifth identifier.

48. A communication method, characterized in that: Applied to the equipment corresponding to the card vendor or terminal manufacturer, the method includes: Acquire the eighth information and the ninth information; wherein the eighth information includes the seventh identification for indicating the device corresponding to the card merchant or the terminal manufacturer, and the credential information corresponding to the seventh identification, the credential information corresponding to the seventh identification is used to verify the device corresponding to the card merchant or the terminal manufacturer and / or to verify the attribute corresponding to the seventh identification; the ninth information is used to indicate the eighth identification of the terminal and the credential information corresponding to the eighth identification, the credential information corresponding to the eighth identification is used to verify the terminal and / or the attribute corresponding to the eighth identification; the eighth identification and the credential information corresponding to the eighth identification are generated by the device corresponding to the card merchant or the terminal manufacturer; The eighth information and the ninth information are sent to a storage node.

49. The method according to claim 48, characterized in that The method further comprises: The ninth information is sent to the terminal.

50. A communication method, characterized in that: Applied to a storage node, the method comprises: Receive the eighth information and the ninth information; wherein the eighth information includes the seventh identification for indicating the device corresponding to the card dealer or the terminal manufacturer, and the credential information corresponding to the seventh identification, the credential information corresponding to the seventh identification is used to verify the device corresponding to the card dealer or the terminal manufacturer and / or to verify the attribute corresponding to the seventh identification; the ninth information is used to indicate the eighth identification of the terminal and the credential information corresponding to the eighth identification, the credential information corresponding to the eighth identification is used to verify the terminal and / or the attribute corresponding to the eighth identification; the eighth identification and the credential information corresponding to the eighth identification are generated by the device corresponding to the card dealer or the terminal manufacturer; The eighth information and the ninth information are stored.

51. The method according to claim 50, characterized in that The receiving of the eighth information and the ninth information comprises: The eighth information and the ninth information are received from a device corresponding to the card vendor or the terminal manufacturer.

52. The method according to claim 50, characterized in that Receive the eighth and ninth messages, including: The eighth information is received from the device corresponding to the card vendor or the terminal manufacturer, and the ninth information is received from the terminal.

53. A communication device, characterized in that: The communication device is used to execute the communication method as described in any one of claims 1-52.

54. A communication device, characterized in that: It comprises a processor, wherein the processor is used to execute the communication method as described in any one of claims 1-52.

55. A communication device, characterized in that: include: a processor coupled to the memory; The processor is used to execute the computer program stored in the memory so that the communication device executes the communication method as described in any one of claims 1-52.

56. A communication device, characterized in that: include: processor and interface circuit; wherein, The interface circuit is used to receive code instructions and transmit them to the processor; The processor is configured to execute the code instructions to perform the method according to any one of claims 1-52.

57. A communication device, characterized in that: The communication device includes a processor and a transceiver, the transceiver is used for information exchange between the communication device and other communication devices, and the processor executes program instructions to perform the communication method as described in any one of claims 1-52.

58. A communication system, characterized in that: The communication system includes one or more terminal devices and one or more network devices.

59. A computer-readable storage medium, characterized in that The computer-readable storage medium includes a computer program or instructions, and when the computer program or instructions are executed on a computer, the computer is caused to execute the communication method according to any one of claims 1 to 52.

60. A computer program product, characterized in that The computer program product comprises: a computer program or instructions, and when the computer program or instructions are executed on a computer, the computer is caused to execute the communication method according to any one of claims 1 to 52.

Citation Information

Patent Citations

  • Communication method and communication device

    CN120021188A

  • Blockchain-based information verification method, device, equipment and storage medium

    CN110493007A

  • Private cloud networking method, device and system, computer equipment and storage medium

    CN113489695A

  • Equipment security authentication method based on attribute encryption and related device thereof

    CN115348076A

  • Data sharing method and device based on identification analysis and medium

    CN116614471A