Communication method and related device

By obtaining the identification information of the first network element and determining the data to be analyzed based on its token, the problem of being unable to perform fine-grained authorization management of the service network element data in the prior art is solved, and data security and management efficiency are improved.

WO2025113338A1PCT designated stage expired Publication Date: 2025-06-05HUAWEI TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/133781
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-29
Filing Date
2024-11-22
Publication Date
2025-06-05

AI Technical Summary

Technical Problem

The prior art cannot perform fine-grained authorization management on data used to evaluate service network elements, resulting in inadequate data security and management efficiency.

Method used

By acquiring the identification information of the first network element, determining the data to be analyzed to the first network element based on its token, the data from the second network element is implemented in fine-grained authorization management, and different data to be analyzed are allocated to different first network elements.

Benefits of technology

It realizes fine-grained authorization management of business network element evaluation data, improves data security and management efficiency, and ensures that data access rights of different network elements are allocated on demand.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024133781_05062025_PF_FP_ABST
    Figure CN2024133781_05062025_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of the present application relate to the field of communications, and provide a communication method and a related device. In the method, a fourth network element acquires identifier information of a first network element. On the basis of a token of the first network element, the fourth network element determines data to be analyzed from a second network element. The token corresponds to the identifier information of the first network element. The token comprises first information which indicates a type of data for which the first network element has reading permission. The data to be analyzed is used for evaluating a service network element. The fourth network element sends the data to be analyzed to the first network element. Thus, according to the present solution, tokens of first network elements are used to achieve fine-grained authorization management of data from a second network element, thereby allocating different data to be analyzed to different first network elements.
Need to check novelty before this filing date? Find Prior Art

Description

A communication method and related equipment

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of China on November 29, 2023, with application number 202311622819.7, and priority to the Chinese patent application entitled “A Communication Method and Related Equipment”, all contents of which are incorporated by reference into this application. Technical Field

[0002] The embodiments of the present application relate to the field of communications, and in particular to a communication method and related equipment. Background Art

[0003] The identification of malicious behavior-related data may be related to various events, such as predefined service operation violations (e.g., malformed messages), unexpected configuration changes, message requests that exceed configuration limits, and current resource utilization information (if resource utilization limits are exceeded). This information can be collected indirectly from the assessment target in the form of security logs or reports through Operation Administration and Maintenance (OAM) as inference data.

[0004] For new data related to malicious behavior, the collection scheme is shown in FIG1A , which is a schematic diagram of a multi-faceted process for collecting NF data according to an embodiment of the present application. FIG1A shows data collection and data disclosure for security assessment, including the following steps:

[0005] 1. The Network Data Analytics Function (NWDAF) collects data based on the operator's local policies. The NWDAF can collect data and provide functions to external operators to enable (or assist) security assessment and monitoring.

[0006] 2a. NWDAF collects network function (NF) load data. NF load data can be collected from the network repository function (NRF).

[0007] 2b. NWDAF collects NF resource utilization data from OAM. NF resource utilization data includes CPU, memory, and other data.

[0008] 2c. NWDAF collects NF abnormal event data from OAM. Specifically, NWDAF subscribes to OAM's management service and collects data on one or more assessed events related to the target NF and events related to various specific malicious behaviors.

[0009] NWDAF sends the collected data to enable security assessment and obtain a response. Refer to steps 3a and 3b for details.

[0010] 3a. The NWDAF acts as a data collection agent and provides the collected data to operator functions outside the 3GPP domain through the NEF, such as the External Operator Managed Function (EOMF), which is the network element that enables security assessment and detection.

[0011] 3b. The external operator function sends a security assessment response to the NWADF.

[0012] In the process shown in Figure 1A , NEF can only send all data to EOMF for analysis.

[0013] Therefore, how to solve the above problems has become a hot topic being studied by those skilled in the art. Summary of the Invention

[0014] The present application provides a communication method and related equipment, which can perform fine-grained authorization on data used to evaluate service network elements.

[0015] In a first aspect, a communication method is provided, which can be executed by a communication device or a chip in the communication device. Exemplarily, the communication device is a fourth network element.

[0016] The communication method includes the following steps: obtaining identification information of a first network element; determining data to be analyzed from a second network element based on a token of the first network element; the token corresponding to the identification information of the first network element, the token including first information indicating the type of data that the first network element has permission to read; the data to be analyzed is used to evaluate the service network element; and the data to be analyzed is sent to the first network element.

[0017] The above-mentioned service network element is a network element that carries terminal services.

[0018] It can be seen that in this solution, the identification information of the first network element is first obtained. Since the identification information of the first network element corresponds to the token, the token of the first network element can be determined based on the identification information of the first network element; then, the data to be analyzed sent to the first network element is determined based on the token of the first network element, so as to realize fine-grained authorization management of the data from the second network element and allocate different data to be analyzed to different first network elements.

[0019] In a possible implementation of the first aspect, the above-mentioned determination of the data to be analyzed from the second network element based on the token of the first network element specifically includes the following steps: determining the data to be analyzed based on the token and the collected data of the second network element, and the data type of the data to be analyzed is the data type of all or part of the collected data.

[0020] The second network element obtains data from the service network element to obtain the above-mentioned collected data.

[0021] In this solution, the data to be analyzed can be determined based on the token and the collected data of the second network element. The data type of the data to be analyzed is the data type of all or part of the collected data, that is, the data to be analyzed can be all or part of the collected data.

[0022] In a possible implementation of the first aspect, the obtaining of identification information of the first network element specifically includes the following steps: receiving a data analysis request from the second network element. The data analysis request includes the identification information of the first network element, and the data analysis request is used to trigger the first network element to perform data analysis.

[0023] In this solution, the identification information of the first network element can be obtained based on the data analysis request sent by the second network element.

[0024] In one possible implementation of the first aspect, the data analysis request further includes collected data from the second network element and second information indicating a data type of the collected data. Determining the data to be analyzed from the second network element based on the token of the first network element specifically includes the following steps: determining the data to be analyzed from the collected data based on the token and the second information. The data type of the data to be analyzed is a data type that is an intersection of the data type indicated by the token and the data type indicated by the second information.

[0025] In this solution, the data to be analyzed can be determined by comparing the data types based on the second information carried in the data analysis request and the token; the intersection data type can be the data type indicated by the token or part of the data type indicated by the token.

[0026] In a possible implementation of the first aspect, after receiving the data analysis request from the second network element, the communication method further includes the following steps: sending a token check request to the first network element, and receiving a token check response from the first network element, where the token check response includes the token of the first network element.

[0027] In this solution, the first network element sends a token check response in response to the token check request, so as to obtain the token of the first network element in the token check response.

[0028] In one possible implementation of the first aspect, after receiving the data analysis request from the second network element, the communication method further includes: sending the data analysis request to the first network element; and receiving a data analysis request response from the first network element. Determining the data to be analyzed from the second network element based on the token of the first network element specifically includes the following steps: when the data analysis request response indicates that the first network element accepts the data analysis request, determining the data to be analyzed based on the token of the first network element.

[0029] In this solution, when it is determined based on the data analysis request response that the first network element has accepted the data analysis request, the data to be analyzed sent to the first network element is determined based on the token of the first network element, and the data reading permission of the first network element is verified based on the token to ensure data security.

[0030] In a possible implementation of the first aspect, the data analysis request further includes the data type that the second network element expects to analyze. When the first network element does not support reading the data type that the second network element expects to analyze, the data analysis request response includes the data type that the first network element cannot read.

[0031] In this solution, the data type that cannot be read by the first network element is carried in the data analysis request response, so that the second network element can readjust the data type expected to be analyzed as needed.

[0032] In one possible implementation of the first aspect, determining the data to be analyzed from the second network element based on the token of the first network element specifically includes the following steps: verifying the token of the first network element. If the token verification result is a passed verification, sending a data analysis request response to the second network element. The data analysis request response includes identification information of the first network element and the first information. The data to be analyzed from the second network element is received, where the data type of the data to be analyzed is the data type indicated by the first information.

[0033] In this solution, when the token of the first network element passes the verification, the first information of the first network element is carried in the data analysis request response to instruct the second network element to collect data corresponding to the data type indicated by the first information, thereby realizing targeted data collection.

[0034] In a possible implementation of the first aspect, the sending of the data to be analyzed to the first network element specifically includes the following steps: verifying the token of the first network element again. When the token verification result is verification passed, sending the data to be analyzed to the first network element.

[0035] In this solution, before sending the data to be analyzed to the first network element, the token of the first network element is verified again to ensure that the first network element has the data reading authority for the data to be analyzed.

[0036] In a possible implementation of the first aspect, the above-mentioned acquisition of the identification information of the first network element specifically includes the following steps: receiving a data subscription request sent by the first network element, the data subscription request includes the identification information of the first network element, and the data subscription request is used to trigger the second network element to collect data.

[0037] In this solution, the identification information of the first network element is obtained through the data subscription request sent by the first network element.

[0038] In one possible implementation of the first aspect, determining the data to be analyzed based on the token of the first network element specifically includes the following steps: verifying the token of the first network element. If the token verification result is a passing verification, sending identification information of the first network element and the first information to the second network element. Receiving a data analysis request from the second network element, the data analysis request including the data to be analyzed and the identification information of the first network element, where the data type of the data to be analyzed is the data type indicated by the first information.

[0039] In this solution, when the token of the first network element passes the verification, the first information is sent to the second network element to indicate the data that the second network element needs to collect. The second network element collects data according to the first information to obtain the data to be analyzed, and then carries the data to be analyzed in the data analysis request.

[0040] In a possible implementation of the first aspect, the sending of the data to be analyzed to the first network element specifically includes the following steps: sending a data analysis request to the first network element.

[0041] In this solution, the data to be analyzed is carried in the data analysis request, so as to send the data to be analyzed to the first network element.

[0042] In one possible implementation of the first aspect, verifying the token of the first network element specifically includes the following steps: sending a data subscription request to a second network element; receiving a token query request from the second network element, the token query request including identification information of the first network element; and verifying the token of the first network element in response to the token query request.

[0043] In this solution, a data subscription request is sent to the second network element, including the identification information of the first network element. Based on the identification information, the second network element determines whether to check the first network element's token. If so, the second network element sends a token query request. In response to the token query request, the first network element's token is verified.

[0044] In a possible implementation of the first aspect, the communication method further includes the following steps: receiving a token registration request from the first network element, the token registration request including identification information of the first network element and a token of the first network element; and storing the identification information of the first network element and the token of the first network element.

[0045] In this solution, the first network element implements token registration by initiating a token registration request.

[0046] In a possible implementation of the first aspect, storing the identification information of the first network element and the token of the first network element specifically includes the following steps: performing a validity check on the token of the first network element. If the validity check results in a passing result, storing the identification information of the first network element and the token of the first network element.

[0047] In this solution, before storing the identification information and token of the first network element, the validity of the token of the first network element is checked. Only when the validity check passes are the identification information and token of the first network element stored to ensure the validity of the token required to be registered.

[0048] In a possible implementation of the first aspect, the above-mentioned data type includes at least one of the following: load data of the service network element, resource utilization data of the service network element, abnormal event data of the service network element, or energy consumption data of the service network element.

[0049] In a possible implementation of the first aspect, the load data comes from a network storage network element, or the resource utilization data and / or abnormal event data comes from an operation, maintenance and management network element.

[0050] In this solution, the load data of the service network element is obtained through the network storage network element, and the resource utilization data and / or abnormal event data of the service network element is obtained through the operation, maintenance and management network element.

[0051] In a second aspect, the present application further provides a communication method, which can be executed by a communication device or a chip in the communication device. Exemplarily, the communication device is an authentication server.

[0052] The communication method includes the following steps: receiving a token issuance request from a first network element, the token issuance request including identification information of the first network element; sending a token grant response to the first network element, the token grant response including a token of the first network element; the token corresponding to the identification information of the first network element, the token including first information indicating the type of data that the first network element has permission to read.

[0053] In this solution, in response to the token issuance request of the first network element, a token is granted to the first network element to indicate the type of data that the first network element has read permission.

[0054] In a possible implementation of the second aspect, after receiving the token issuance request from the first network element, the communication method further includes the following steps: sending a contract information query request to a third network element, the contract information query request including identification information of the first network element; receiving a contract information response from the third network element, the contract information response including the trust level and / or service type of the first network element; and determining the token of the first network element based on the identification information and / or the contract information response of the first network element.

[0055] In this solution, a contract information response is obtained from a third network element based on the identification information of the first network element. The contract information response includes the trust level and / or service type of the first network element, and then the token of the first network element is determined based on the identification information of the first network element and the contract information response.

[0056] In a possible implementation of the second aspect, the token issuance request further includes third information, where the third information indicates the type of data that the first network element prefers to read. The token of the first network element is determined based on at least one of the identification information of the first network element, the contract information response, and the third information.

[0057] On the third aspect, the present application also provides a communication method, which is applied to a first network element. The communication method can be executed by the first network element or by a chip in the first network element.

[0058] The communication method includes the following steps: sending a token issuance request to a verification server, the token issuance request including identification information of a first network element; receiving a token grant response from the verification server, the token grant response including a token of the first network element; the token corresponding to the identification information of the first network element, the token including first information indicating the type of data that the first network element has permission to read.

[0059] In this solution, the first network element sends a token issuance request to the verification server and receives a token grant response sent by the verification server to obtain a corresponding token.

[0060] In a possible implementation of the third aspect, the token of the above-mentioned first network element is determined based on the identification information of the first network element and / or the contract information response from the third network element, and the contract information response includes the trust level and / or service type of the first network element.

[0061] In a possible implementation of the third aspect, the token issuance request further includes third information, where the third information indicates a data type that the first network element prefers to read. The token of the first network element is determined based on at least one of the identification information of the first network element, the contract information response, and the third information.

[0062] In a fourth aspect, the present application also provides a communication method, which is applied to a first network element. The communication method can be executed by the first network element or by a chip in the first network element.

[0063] The communication method includes the following steps: receiving data to be analyzed from a fourth network element. The data to be analyzed is determined by the fourth network element based on a token of the first network element, and the data to be analyzed originates from the second network element. The token corresponds to identification information of the first network element and includes first information indicating the type of data that the first network element has permission to read. The data to be analyzed is used to evaluate the service network element.

[0064] In this solution, the data to be analyzed sent by the fourth network element is received, wherein the data to be analyzed is determined by the fourth network element based on the token of the first network element. This can implement fine-grained authorization management of data from the second network element and allocate different data to be analyzed to different first network elements.

[0065] In a possible implementation manner of the fourth aspect, the communication method further includes the following steps: receiving a token check request sent by a fourth network element, and sending a token check response to the fourth network element, where the token check response includes the token of the first network element.

[0066] In this solution, the first network element sends a token check response in response to the token check request of the fourth network element. The token check response carries the token of the first network element, so that the fourth network element can obtain the token of the first network element.

[0067] In one possible implementation of the fourth aspect, the communication method further includes the following steps: receiving a data analysis request sent by a fourth network element, the data analysis request including identification information of the first network element, the data analysis request being used to trigger the first network element to perform data analysis; and sending a data analysis request response to the fourth network element.

[0068] In this solution, the fourth network element determines whether to accept the data analysis request based on the identification information of the first network element, and carries information indicating whether to accept the data analysis request in the data analysis request response.

[0069] In a possible implementation of the fourth aspect, the data analysis request further includes the data type that the second network element expects to analyze. When the first network element does not support reading the data type that the first network element expects to analyze, the data analysis request response includes the data type that the first network element cannot read.

[0070] In this solution, the data type that cannot be read by the first network element is carried in the data analysis request response, so that the second network element can readjust the data type expected to be analyzed as needed.

[0071] In a possible implementation of the fourth aspect, the above-mentioned communication method also includes the following steps: sending a data subscription request to the fourth network element, the above-mentioned data subscription request includes identification information of the first network element, and the data subscription request is used to trigger the second network element to collect data.

[0072] In this solution, the fourth network element can obtain the identification information of the first network element through the data subscription request sent by the first network element.

[0073] In a possible implementation of the fourth aspect, the above-mentioned receiving of the data to be analyzed sent by the fourth network element specifically includes the following steps: receiving a data analysis request sent by the fourth network element, the above-mentioned data analysis request includes the data to be analyzed and identification information of the first network element, and the data type of the data to be analyzed is the data type indicated by the first information.

[0074] In this solution, the data to be analyzed is carried in the data analysis request so that the first network element obtains the data to be analyzed.

[0075] In a possible implementation of the fourth aspect, the communication method further includes the following steps: sending a token registration request to the fourth network element, where the token registration request includes identification information of the first network element and a token of the first network element.

[0076] In this solution, the first network element implements token registration by initiating a token registration request, so that the fourth network element can determine the data to be analyzed based on the token of the first network element.

[0077] In a possible implementation of the fourth aspect, the above-mentioned data type includes at least one of the following: load data of the service network element, resource utilization data of the service network element, abnormal event data of the service network element, or energy consumption data of the service network element.

[0078] In a possible implementation of the fourth aspect, the load data comes from a network storage network element, or the resource utilization data and / or abnormal event data comes from an operation, maintenance and management network element.

[0079] In a fifth aspect, the present application further provides a communication method, applied to a communication system, the communication system including a first network element and a fourth network element, the communication method including the following steps: the fourth network element obtains identification information of the first network element. The fourth network element determines data to be analyzed from the second network element based on a token of the first network element. The token corresponds to the identification information of the first network element. The token includes first information indicating the type of data that the first network element has read permission for. The data to be analyzed is used to evaluate the service network element. The fourth network element sends the data to be analyzed to the first network element. The first network element receives the data to be analyzed.

[0080] In a possible implementation of the fifth aspect, the above-mentioned fourth network element determines the data to be analyzed from the second network element based on the token of the first network element, which specifically includes the following steps: the fourth network element determines the data to be analyzed based on the token and the collected data of the second network element, and the data type of the data to be analyzed is the data type of all or part of the collected data.

[0081] In a possible implementation of the fifth aspect, the above-mentioned fourth network element obtains the identification information of the first network element, which specifically includes the following steps: the fourth network element receives a data analysis request from the second network element, the data analysis request includes the identification information of the first network element, and the data analysis request is used to trigger the first network element to perform data analysis.

[0082] In a possible implementation of the fifth aspect, the data analysis request further includes collected data from the second network element and second information indicating a data type of the collected data. The fourth network element determining the data to be analyzed from the second network element based on the token of the first network element specifically includes the following steps: the fourth network element determines the data to be analyzed from the collected data based on the token and the second information. The data type of the data to be analyzed is a data type that is an intersection of the data type indicated by the token and the data type indicated by the second information.

[0083] In a possible implementation of the fifth aspect, after the fourth network element receives the data analysis request from the second network element, the communication method further includes the following steps: the fourth network element sends a token check request to the first network element. The first network element sends a token check response to the fourth network element, where the token check response includes the token of the first network element.

[0084] In a possible implementation of the fifth aspect, after the fourth network element receives the data analysis request from the second network element, the communication method further includes the following steps: the fourth network element sends a data analysis request to the first network element. The first network element sends a data analysis request response to the fourth network element. The fourth network element determines the data to be analyzed from the second network element based on the token of the first network element, specifically including the following steps: when the data analysis request response indicates that the first network element accepts the data analysis request, the fourth network element determines the data to be analyzed based on the token of the first network element.

[0085] In a possible implementation of the fifth aspect, the data analysis request further includes the data type that the second network element desires to analyze. When the first network element does not support reading the data type that it desires to analyze, the data analysis request response includes the data type that the first network element cannot read.

[0086] In a possible implementation of the fifth aspect, the fourth network element determines the data to be analyzed from the second network element based on the token of the first network element, specifically including the following steps: the fourth network element verifies the token of the first network element. If the token verification result is a pass, the fourth network element sends a data analysis request response to the second network element, the data analysis request response including identification information of the first network element and the first information. The second network element sends the data to be analyzed to the fourth network element, where the data type of the data to be analyzed is the data type indicated by the first information.

[0087] In a possible implementation of the fifth aspect, the fourth network element sending the data to be analyzed to the first network element includes: the fourth network element re-verifying the token of the first network element. When the token verification result is verification passed, the fourth network element sends the data to be analyzed to the first network element.

[0088] In a possible implementation of the fifth aspect, the fourth network element obtains the identification information of the first network element, specifically comprising the following steps: the first network element sends a data subscription request to the fourth network element. The data subscription request includes the identification information of the first network element, and the data subscription request is used to trigger the second network element to collect data. The fourth network element receives the data subscription request.

[0089] In one possible implementation of the fifth aspect, the fourth network element determines the data to be analyzed based on the token of the first network element, specifically including the following steps: the fourth network element verifies the token of the first network element. If the token verification result is a pass, the fourth network element sends the identification information of the first network element and the first information to the second network element. The fourth network element receives a data analysis request from the second network element, the data analysis request including the data to be analyzed and the identification information of the first network element, and the data type of the data to be analyzed is the data type indicated by the first information.

[0090] In a possible implementation of the fifth aspect, the fourth network element sends the data to be analyzed to the first network element, which specifically includes the following steps: the fourth network element sends a data analysis request to the first network element.

[0091] In a possible implementation of the fifth aspect, the fourth network element verifies the token of the first network element, specifically including the following steps: the fourth network element sends a data subscription request to the second network element. The second network element sends a token query request to the fourth network element, the token query request including identification information of the first network element. In response to the token query request, the fourth network element verifies the token of the first network element.

[0092] In a possible implementation of the fifth aspect, the communication method further includes the following steps: the fourth network element receives a token registration request from the first network element, the token registration request including identification information of the first network element and the token of the first network element. The fourth network element stores the identification information of the first network element and the token of the first network element.

[0093] In a possible implementation of the fifth aspect, the fourth network element stores the identification information of the first network element and the token of the first network element, specifically including the following steps: the fourth network element performs a validity check on the token of the first network element. If the validity check results in a pass, the fourth network element stores the identification information of the first network element and the token of the first network element.

[0094] In a possible implementation of the fifth aspect, the above-mentioned data type includes at least one of the following: load-related data of the service network element, resource utilization data of the service network element, abnormal event data of the service network element, or energy consumption data of the service network element.

[0095] In a possible implementation of the fifth aspect, the load data comes from a network storage network element, or the resource utilization data and / or abnormal event data comes from an operation, maintenance and management network element.

[0096] In a sixth aspect, the present application further provides a communication method, applied to a communication system, the communication system comprising a verification server and a first network element. The communication method comprises the following steps: the verification server receives a token issuance request from the first network element, the token issuance request including identification information of the first network element. The first network element receives a token grant response from the verification server, the token grant response including a token of the first network element. The token corresponds to the identification information of the first network element, the token including first information indicating the type of data that the first network element has permission to read.

[0097] In this solution, the verification server responds to the token issuance request of the first network element and grants a token to the first network element to indicate the type of data that the first network element has read permission.

[0098] In a possible implementation of the sixth aspect, after the verification server receives the token issuance request from the first network element, the communication method further includes the following steps: the verification server sends a contract information query request to a third network element, the contract information query request including identification information of the first network element. The verification server receives a contract information response from the third network element, the contract information response including the trust level and / or service type of the first network element. The token of the first network element is determined based on the identification information of the first network element and / or the contract information response.

[0099] In a possible implementation of the sixth aspect, the token issuance request further includes third information, where the third information indicates a data type that the first network element prefers to read. The token of the first network element is determined based on at least one of the identification information of the first network element, the contract information response, and the third information.

[0100] In a seventh aspect, the present application also provides a communication device comprising a module for executing the communication method as described in any one of the first to sixth aspects.

[0101] In the eighth aspect, the present application also provides a communication device, comprising a processor and an interface circuit, wherein the interface circuit is used to receive signals from other communication devices outside the communication device and transmit them to the processor or send signals from the processor to other communication devices outside the communication device, and the processor is used to implement the communication method as described in any one of the first to sixth aspects through a logic circuit or executing code instructions.

[0102] In the ninth aspect, the present application also provides a computer-readable storage medium, in which a computer program or instruction is stored. When the computer program or instruction is executed by a communication device, the communication method as described in any one of the first to sixth aspects is implemented.

[0103] In the tenth aspect, the present application also provides a computer program product comprising instructions, which, when run on a computer, enables the computer to execute the communication method described in any one of the first to sixth aspects.

[0104] In the eleventh aspect, the present application also provides a chip, which includes a processor and a data interface, and the processor reads instructions stored in the memory through the data interface to execute the communication method described in any one of the first to sixth aspects.

[0105] Optionally, as an implementation method, the chip may further include a memory, in which instructions are stored, and the processor is used to execute the instructions stored on the memory. When the instructions are executed, the processor is used to execute the communication method described in any one of the first to sixth aspects. BRIEF DESCRIPTION OF THE DRAWINGS

[0106] The following is an introduction to the drawings used in the embodiments of this application.

[0107] FIG1A is a schematic diagram of a process for collecting NF data from multiple aspects according to an embodiment of the present application;

[0108] FIG1B is a schematic diagram of a network architecture provided in an embodiment of the present application;

[0109] FIG1C is a schematic diagram of token generation and use provided by an embodiment of the present application;

[0110] FIG2 is a flow chart of a communication method provided in an embodiment of the present application;

[0111] FIG3 is a flow chart of another communication method provided in an embodiment of the present application;

[0112] FIG4 is a flow chart of another communication method provided in an embodiment of the present application;

[0113] FIG5 is a flow chart of another communication method provided in an embodiment of the present application;

[0114] FIG6 is a flow chart of another communication method provided in an embodiment of the present application;

[0115] FIG7 is a schematic structural diagram of a communication device provided in an embodiment of the present application;

[0116] FIG8 is a schematic structural diagram of another communication device provided in an embodiment of the present application;

[0117] FIG9 is a schematic structural diagram of another communication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0118] The technical solution in this application will be described below with reference to the accompanying drawings.

[0119] In the embodiments of this application, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described in this application as "exemplary" or "for example" should not be construed as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.

[0120] The “at least one” mentioned in the embodiments of this application refers to one or more, and “plurality” refers to two or more. “At least one of the following items” or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can represent: a, b, c, (a and b), (a and c), (b and c), or (a and b and c), where a, b, c can be single or multiple. “And / or” describes the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. The character “ / ” generally indicates that the previous and next associated objects are in an “or” relationship. The serial numbers of the steps in the embodiments of the present application (such as step S1, step S21, etc.) are only for distinguishing different steps. The size of the serial numbers of each step does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0121] Furthermore, unless otherwise specified, ordinal numbers such as "first" and "second" in the embodiments of this application are used to distinguish multiple objects and are not used to limit the order, timing, priority, or importance of multiple objects. For example, the first device and the second device are only for ease of description and do not indicate differences in structure, importance, etc. between the first and second devices. In some embodiments, the first device and the second device can also be the same device.

[0122] In the above embodiments, the term "when" can be interpreted to mean "if...", "after...", "in response to determining...", or "in response to detecting...", depending on the context. The above are merely optional embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent substitutions, improvements, etc. made within the concepts and principles of the present application shall be included in the scope of protection of the present application.

[0123] The method of the embodiment of the present application can be applied to future communication networks such as the Long Term Evolution (LTE) system, the Long Term Evolution-Advanced (LTE-A) system, the Enhanced Long Term Evolution-Advanced (eLTE), the fifth generation (5G) mobile communication system New Radio (NR) system, and the sixth generation (6G) mobile communication system, and can also be extended to similar wireless communication systems such as Wireless Fidelity (WiFi), Worldwide Interoperability for Microwave Access (WIMAX), and cellular systems related to the Third Generation Partnership Project (3GPP).

[0124] FIG1B is a network architecture applied to an embodiment of the present application, and each network element that may be involved in the network architecture is described separately.

[0125] 1. Terminal device: abbreviated as terminal, also known as user equipment (UE), which can include various handheld devices with wireless communication capabilities, vehicle-mounted devices, wearable devices, IoT terminal devices, computing devices, or other processing devices connected to a wireless modem, as well as various forms of terminals, mobile stations (MS), terminals, soft terminals, access terminals, subscriber units, terminal stations, mobile stations, mobile stations (MS), remote stations, remote terminals, mobile devices, terminal device agents, terminal device devices, etc. For example, water meters, electricity meters, sensors, etc.

[0126] 2. Radio Access Network (R)AN): This provides wireless access for terminal devices. For example, it consists of multiple (R)AN nodes, implementing wireless physical layer functions, resource scheduling and radio resource management, radio access control, and mobility management. The (R)AN connects to user-plane network elements via the user-plane interface N3 to transmit data from terminal devices. The (R)AN establishes a control-plane signaling connection with access and mobility management network elements via the control-plane interface N2 to implement functions such as radio access bearer control.

[0127] Specifically, it can be used to provide network access functions for authorized terminal devices in a specific area, and can use transmission tunnels of different qualities according to the level of the terminal device, business requirements, etc.

[0128] (R)AN can manage wireless resources, provide access services for terminal devices, and then complete the forwarding of control signals and terminal device data between terminal devices and the core network.

[0129] The wireless access network can have any of the following replacement terms: access network equipment, access network (AN), where the access network equipment can be a base station, a further evolved Node B (gNB), an evolved Node B (eNB), a transmission reception point (TRP), a centralized unit (CU) node, a distributed unit (DU) node, a transmission point (TP), a receiving point (RP), a wireless access point (AP) or a World Interoperability for Microwave Access (WiMAX) base station, etc., without limitation. In this application, the wireless access network is explained using a base station as an example, and the functions performed by the base station are also applicable to other replacement terms for the wireless access network.

[0130] 3. User-side network element: mainly responsible for processing user messages, such as forwarding and billing.

[0131] In a 5G communication system, the user plane network element may be a user plane function (UPF) network element. In future communication systems, the user plane network element may still be a UPF network element, or may have other names, which are not limited in this application.

[0132] Among them, UPF mainly provides business processing functions for the user plane. As the anchor point for the Protocol Data Units (PDU) session connection, UPF is responsible for data packet filtering, business routing, packet forwarding, anchoring functions, rate control, generation of billing information, Quality of Service (QoS) mapping and execution, uplink identification and routing to the data network, downlink packet caching and notification triggering of downlink data arrival, and connection to the external data network.

[0133] 4. Data network: a network used to provide data transmission.

[0134] In a 5G communication system, the data network may be a data network (DN). In future communication systems, the data network may still be a DN, or may have other names, which are not limited in this application.

[0135] Exemplarily, the UE accesses the data network by establishing a session from the UE to the RAN to the UPF to the DN.

[0136] 5. Network slice authentication and authorization network element: Mainly responsible for the authentication and authorization of network slices, and can interact with the authentication, authorization and accounting server (Authentication, Authorization, and Accounting Server, AAA-S) through the authentication, authorization and accounting proxy (Authentication, Authorization, and Accounting Proxy, AAA-P).

[0137] In a 5G communication system, the network slice authentication and authorization network element may be a network slice specific authentication and authorization function (NSSAAF) network element. In future communication systems, the network slice authentication and authorization network element may still be an NSSAAF network element, or may have other names, which are not limited in this application.

[0138] 6. Authentication service network element: used to perform security authentication on UE when UE accesses the network.

[0139] In a 5G communication system, the authentication service network element may be an authentication server function (AUSF) network element. In future communication systems, the authentication service network element may still be an AUSF network element, or may have other names, which are not limited in this application.

[0140] Taking the 5G communication system as an example, for example, AUSF receives the request from AMF to authenticate the UE, requests the key from UDM, and then forwards the key issued by UDM to AMF for authentication processing.

[0141] 7. Access and mobility management function network element: Mainly used for mobility management and access management, etc., and can be used to implement other functions of the Mobility Management Entity (MME) except session management, such as user location update, user registration network, user switching, etc.

[0142] In a 5G communication system, the access and mobility management function network element may be an access and mobility management function (AMF) network element. In future communication systems, the access and mobility management function network element may still be an AMF network element, or may have other names, which are not limited in this application.

[0143] Among them, AMF is mainly responsible for UE authentication, UE mobility management, network slice selection, session management network element selection and other functions; serves as the anchor point for N1 and N2 signaling connections and provides routing of N1 / N2 session management (Session Management, SM) messages for session management network elements; maintains and manages UE status information.

[0144] 8. Session Management NE: This element is primarily responsible for session management (such as session establishment, modification, and release), allocation and management of Internet Protocol (IP) addresses for terminal devices, selection of endpoints for interfaces that manage user plane functions, policy control, and charging functions, and downlink data notification. Specific functions include allocating IP addresses to users and selecting the UPF that provides packet forwarding capabilities.

[0145] In a 5G communication system, the session management network element may be a session management function (SMF) network element. In future communication systems, the session management network element may still be an SMF network element, or may have other names, which are not limited in this application.

[0146] Among them, SMF is mainly responsible for all control plane functions of UE session management, including user plane network element selection, IP address allocation, session QoS management, and obtaining policy and charging control (PCC) information (from policy control network element).

[0147] 9. Network Slice Selection Element: This element is used to select a set of slice instances for the UE, determine the set of AMFs, and allowable NSSAIs for the UE. (NSSAI stands for Network Slice Selection Assistance Information. A network slice is uniquely identified by a single S-NSSAI, while a collection of one or more S-NSSAIs is called NSSAI.)

[0148] In a 5G communication system, the network slice selection network element may be a network slice selection function (NSSF) network element. In future communication systems, the network slice selection network element may still be an NSSF network element, or may have other names, which are not limited in this application.

[0149] 10. Network capability exposure network element: used to connect the interaction between other internal network elements of the core network and the external application servers of the core network, so as to provide network capability information to the external application servers, or provide information of the external application servers to the core network elements.

[0150] In a 5G communication system, the network capability exposure network element may be a NEF network element. In future communication systems, the network capability exposure network element may still be a NEF, or may have other names, which are not limited in this application.

[0151] 11. Network Storage Element: Responsible for network function service registration and status monitoring, enabling automated management, selection, and scalability of network function services, and allowing each network function to discover the services provided by other network functions. This element is used to register, manage, and monitor the status of network functions (NFs), enabling automated management of all NFs. Upon startup, each NF must register with the NRF to provide services. Registration information includes NF type, address, and service list.

[0152] In a 5G communication system, the network storage network element may be an NRF network element. In future communication systems, the network storage network element may still be an NRF, or may have other names, which are not limited in this application.

[0153] 12. Policy control network element: A unified policy framework used to guide network behavior, provide configuration policy information for UE, and provide policy rule information for control plane functional network elements (such as AMF, SMF network elements, etc.).

[0154] In a 5G communication system, the policy control network element may be a policy control function (PCF) network element. In future communication systems, the policy control network element may still be a PCF network element, or may have other names, which are not limited in this application.

[0155] 13. Data management network element: used to process terminal device identification, access authentication, registration and mobility management, etc.

[0156] In a 5G communication system, the data management network element may be a unified data management (UDM) network element. In future communication systems, the data management network element may still be a UDM network element, or may have other names, which are not limited in this application.

[0157] The UDM network element primarily manages user data, such as subscription information and authentication / authorization information. This includes obtaining subscription information from the data repository and providing it to other network elements (such as the AMF); generating 3GPP authentication credentials for the UE; and registering and maintaining the network elements currently serving the UE.

[0158] 14. Application service network element: interacts with core network elements to provide some services, for example, interacts with policy control network elements to perform service policy control, interacts with network capability exposure network elements to obtain some network capability information or provide some application information to the network, and provides some data network access point information to the policy control network element to generate routing information for corresponding data services.

[0159] In a 5G communication system, the application service network element may be an application service function (AF) network element. In future communication systems, the application service network element may still be an AF network element, or may have other names, which are not limited in this application. For example, the application service network element may have any of the following alternative terms: application server (AS), AF, third party, third-party application, application (APP), etc.

[0160] It should be noted that the above-mentioned "network element" may also be referred to as an entity, device, apparatus, or module, etc., and this application does not specifically limit this. Moreover, in this application, for ease of understanding and explanation, the description of "network element" is omitted in some descriptions. For example, the AMF network element is referred to as AMF. In this case, the "AMF" should be understood as the AMF network element or AMF entity. The description of the same or similar situations will be omitted below.

[0161] This network architecture also includes a network data analysis element (NWEE) to analyze various network data, including network operation data collected from the NF, terminal and network-related statistics obtained from the OAM element, and application data obtained from third-party AFs. The analysis results generated by the NWDAF are also output to the NF, OAM, or third-party AF. The specific work steps of the NWEE can be categorized into several categories, including request analysis, subscription analysis, and data collection.

[0162] In a 5G communication system, the network data analysis network element may be a network data analysis function (NWDAF) network element. In future communication systems, the network data analysis network element may still be an NWDAF, or may have other names, which are not limited in this application.

[0163] This network architecture also includes Operation, Administration, and Maintenance (OAM) network elements. Based on the operator's actual network operation needs, OAM network elements divide network management tasks into three categories: Operation, Administration, and Maintenance. Operations primarily involve analysis, forecasting, planning, and configuration of daily network and service operations. Maintenance primarily involves day-to-day operational activities such as testing and fault management of the network and its services.

[0164] In a 5G communication system, the operation, maintenance and management network element may be an OAM network element, which generally refers to a network management device. In future communication systems, the operation, maintenance and management network element may still be OAM, or may have other names, which are not limited in this application.

[0165] The network architecture may also include an external operator management network element for evaluating whether the service network element is abnormal based on data.

[0166] In a 5G communication system, the external operator management network element may be an external operator managed function (EOMF) network element. In future communication systems, the external operator management network element may still be an EOMF network element, or may have other names, which are not limited in this application.

[0167] The network architecture may also include an authentication server, which may be a service function located inside the core network, such as an AUSF network element, an NRF network element, or a third-party authentication server; or it may be a network element outside the operator, such as an external AF.

[0168] It should be understood that the above-mentioned network architecture applied to the embodiments of the present application is only an example of a network architecture described from the perspective of a service-oriented architecture. The network architecture applicable to the embodiments of the present application is not limited to this. Any network architecture that can realize the functions of the above-mentioned network elements is applicable to the embodiments of the present application.

[0169] For example, in some network architectures, network function entities such as AMF, SMF, PCF and UDM are all called NF network elements; or, in other network architectures, the collection of network elements such as AMF, SMF, PCF and UDM can be called control plane function (CPF) network elements.

[0170] Next, we will use the network elements in a 5G system as an example to introduce the specific solution details. It is understandable that when this solution is used in an LTE system or future communication systems, the network elements in the solution can be replaced with other network elements with corresponding functions, and this application does not limit this.

[0171] It should be understood that Figure 1B is only an exemplary network architecture, and the network architecture applicable to the embodiments of the present application is not limited to this. Any network architecture that can realize the functions of the above-mentioned network elements is applicable to the embodiments of the present application.

[0172] The following is an introduction to the specific process of token generation and use.

[0173] Referring to FIG. 1C , FIG. 1C is a schematic diagram of a token generation and use provided by an embodiment of the present application; specifically, the following steps are included:

[0174] (A) The client requests authorization from the resource owner. The authorization request can be made directly to the resource owner (as shown in Figure 1C) or indirectly through the authentication server acting as an intermediary.

[0175] (B) The client receives an authorization grant, which is a token of authorization from the resource owner, illustratively expressed using one of the four grant types or extended grant types defined in the Internet Engineering Task Force (IETF) specification. The authorization grant type depends on the method used by the client to request authorization and the types supported by the authentication server.

[0176] (C) The client requests an access token by authenticating with the authentication server and providing an authorization grant.

[0177] (D) The authentication server authenticates the client and verifies the authorization grant, and if valid, issues an access token.

[0178] (E) The client requests a protected resource from the resource server and authenticates by providing an access token.

[0179] (F) The resource server validates the access token and, if valid, services the request.

[0180] Referring to the process shown in Figure 1A, the NWDAF acts as a data collection agent, providing the collected data to operator functions outside the 3GPP domain through the NEF. However, the NEF can only send all data to the EOMF for analysis and is unable to perform fine-grained analysis and authorization checks on data that the EOMF can read. Therefore, embodiments of the present application provide a communication method that can perform fine-grained authorization on data used to evaluate service network elements.

[0181] The communication method of the embodiment of the present application is described in detail below.

[0182] Referring to FIG. 2 , FIG. 2 is a flow chart of a communication method provided in an embodiment of the present application. The communication method in the embodiment of the present application includes the following steps:

[0183] 201. The fourth network element obtains identification information of the first network element.

[0184] Specifically, in the embodiment of the present application, the fourth network element is an intermediary or gateway device between the first network element and the second network element. For example, the fourth network element is an NEF network element, a Security Edge Protection Proxy (SEPP), or a Service Communication Proxy (SCP). In the embodiment of the present application, the fourth network element is described using the NEF network element as an example.

[0185] The first network element is used to evaluate the service network element. For example, the first network element is an external operator-managed network element. In the embodiment of the present application, the first network element is described using an external operator-managed network element as an example. The above-mentioned service network element is a network element that carries terminal services. For example, the service network element is an SMF network element or a (R)AN. The first network element can evaluate the security status of the SMF network element or evaluate the energy consumption of the (R)AN.

[0186] The second network element is used to collect data of the service network element, for example, the second network element is a network data analysis network element. In the embodiment of the present application, the second network element is described by taking the network data analysis network element as an example.

[0187] Exemplarily, the identification information of the first network element may be at least one of the following: the name of the first network element, the identifier of the network function instance of the first network element, the device number of the first network element, or the IP address of the first network element.

[0188] 202. The fourth network element determines the data to be analyzed from the second network element based on the token of the first network element.

[0189] Specifically, the token corresponds to the identification information of the first network element. Since the identification information of the first network element corresponds to the token, the fourth network element can determine the token of the first network element based on the identification information of the first network element. The specific process of determining the token is described in the following embodiments 1 to 4, which will not be repeated here.

[0190] The token of the first network element includes first information, and the first information indicates the type of data that the first network element has read permission. Therefore, the data to be analyzed sent to the first network element can be determined based on the token of the first network element.

[0191] Exemplarily, the first information may directly or indirectly indicate the data type that the first network element has read permission to. The first information may be at least one of the following: a data type indication, a data type description, or a data type tag (Tag). The above data types include at least one of the following: load data of the service network element, resource utilization data of the service network element, abnormal event data of the service network element, or energy consumption data of the service network element.

[0192] For example, the data type indication "0" corresponds to the load data of the service network element, the data type indication "1" corresponds to the resource utilization data of the service network element, the data type indication "2" corresponds to the abnormal event data of the service network element, and the data type indication "3" corresponds to the energy consumption data of the service network element.

[0193] The data type description is the description content of the data type. For example, the load data of the service network element can be described as "service load", and the "resource utilization data of the service network element" can be described as "resource utilization", the "abnormal event data of the service network element" can be described as "abnormal event", and the "energy consumption data of the service network element" can be described as "energy consumption".

[0194] The data type tag is used to directly or indirectly indicate the data type. Indirect indication means that the data type can only be determined by reading the data itself. For example, the data type tag can be an event ID, which is a specific collection task indicator. For example, if NWDAF collects data using event subscriptions, the result data of one or more events can be aggregated, and the event ID is carried on the data.

[0195] For example, Event ID 10001 collects data about the network element's central processing unit (CPU), while Event ID 10003 collects data about the network element's graphics processing unit (GPU). CPU and GPU data are resource utilization data. Collection tasks using event IDs can implicitly correspond to a data type.

[0196] For another example, when EventID is 10001, user plane load data is collected, and when EventID is 10003, signaling plane load data is collected. They may implicitly correspond to data type indication 0 and data type description "service load".

[0197] For another example, when EventID is 10004, user plane energy consumption data is collected, and when EventID is 10005, signaling plane energy consumption data is collected. They may implicitly correspond to data type indication 3 and data type description "energy consumption".

[0198] For example, when EventID is 10004, the energy consumption data collected is the Data Radio Bearer (DRB), and when EventID is 10005, the energy consumption data collected is the Signaling Radio Bearer (SRB). These data can implicitly correspond to the data type indication 3 and the data type description "energy consumption".

[0199] The data to be analyzed is used to evaluate the service network element and is collected by the second network element.

[0200] In one possible implementation, the load data is from a network storage network element, or the resource utilization data and / or abnormal event data is from an operation, maintenance, and management network element. For example, the second network element collects the load data of the service network element from the network storage network element, or the second network element collects the resource utilization data and / or abnormal event data of the service network element from the operation, maintenance, and management network element.

[0201] 203. The fourth network element sends the data to be analyzed to the first network element.

[0202] Correspondingly, the first network element receives the data to be analyzed.

[0203] In an embodiment of the present application, the fourth network element first obtains the identification information of the first network element. Since the identification information of the first network element corresponds to the token, the token of the first network element can be determined based on the identification information of the first network element; then, based on the token of the first network element, the data to be analyzed sent to the first network element is determined, thereby realizing fine-grained authorization management of the data from the second network element and allocating different data to be analyzed to different first network elements.

[0204] The following describes in detail possible communication methods of the embodiments of the present application using Examples 1 to 4.

[0205] Example 1

[0206] Referring to FIG3 , FIG3 is a flow chart of another communication method provided in an embodiment of the present application; the communication method includes the following steps:

[0207] 0a. The second network element collects data.

[0208] Specifically, the target of the second network element to collect data can be a service network element (for example, an AMF network element instance), or multiple service network elements, such as multiple network elements of the same type (such as multiple AMF network elements), or all types of network elements in an area, without limitation.

[0209] In addition, the second network element can obtain the collected data from NF (ie, service network element), NRF network element or OAM network element.

[0210] 0b. The second network element sends a data analysis request to the fourth network element.

[0211] In one possible implementation, the data analysis request includes identification information of the first network element, and the data analysis request is used to trigger the first network element to perform data analysis.

[0212] Correspondingly, the fourth network element receives the data analysis request. The fourth network element can obtain the identification information of the first network element based on the data analysis request.

[0213] In another possible implementation, the data analysis request further includes the collected data of the second network element and second information, wherein the second information indicates the data type of the collected data.

[0214] Specifically, the data analysis request carries the collected data, so that the collected data can be made available to an external network element, such as the first network element, through the fourth network element. The data type indicated by the second information includes at least one of the following: load data of the service network element, resource utilization data of the service network element, abnormal event data of the service network element, or energy consumption data of the service network element. Exemplarily, the second information can be a data type and / or a data type tag. The first information and the second information indicate the data type in the same manner, for example, both are data type tags.

[0215] 0c. The fourth network element and the authentication server pre-configure authentication information.

[0216] Specifically, the verification information includes a certificate or a key, etc. The verification server is used to issue a token to the first network element. The fourth network element has the ability to verify the token of the first network element, and verifying the token requires the use of the verification information, so the verification information needs to be configured in advance.

[0217] Step 0c has no order relationship with the previous steps and can be executed before, between, or after steps 0a and 0b. Other steps can also be inserted between step 0c, step 0a, and step 0b.

[0218] 1. The first network element sends a token issuance request to the authentication server.

[0219] Specifically, in a possible implementation manner, the token issuance request includes identification information of the first network element. Accordingly, the verification server receives the token issuance request from the first network element.

[0220] In another possible implementation, the token issuance request further includes third information, where the third information indicates the data type that the first network element prefers to read. The third information may directly or indirectly indicate the data type that the first network element prefers to read. For example, the third information may be in at least one of the following forms: a data type indication, a description of the preferred data type to be read, or a data type tag (such as EventID). The specific form of the third information is the same as the specific form of the second information in 0b. The following Table 1 is taken as an example:

[0221] Table 1 Data type indication table

[0222] For example, referring to Table 1, when Event ID is 10001, CPU data is collected, and when Event ID is 10003, GPU data is collected. Therefore, the data type indication 1 and the data type description "resource utilization" can be implicitly corresponded. 2. The verification server sends a contract information query request to the third network element.

[0223] Correspondingly, the third network element receives the subscription information query request. The third network element may be a data management network element.

[0224] Specifically, the contract information query request includes the identification information of the first network element, and the query content is, for example, the scope of work contracted by the first network element or the trust level. The verification server can determine the type of token issued to the first network element based on these contents.

[0225] Step 2 is optional. If the verification server itself does not need contract information to assist in judgment, or has a contract information cache of the first network element, it is not necessary to send a contract information query request.

[0226] 3. The third network element sends a signing information response to the verification server.

[0227] Corresponding to step 2, step 3 is optional. The subscription information response includes the trust level and / or service type of the first network element.

[0228] 4. The authentication server determines the token of the first network element.

[0229] Specifically, the verification server determines the token of the first network element based on at least one of the identification information of the first network element, the contract information response, and the third information. The verification server determines the type and scope of the token issued to the first network element, where the token contains a first information field that can directly or indirectly indicate the type of data that the first network element has read permission.

[0230] In one possible implementation, the verification server may determine the token of the first network element based on the identification information of the first network element. Furthermore, the verification server may determine the name of the first network element based on the identification information of the first network element, and the verification server may determine the token of the first network element based on the name of the first network element. The verification server may determine the token of the first network element based on the contract information response. The verification server may also determine the token of the first network element based on third information, for example, directly issuing a token to the first network element based on the preferred data type indicated by the third information. The verification server may also determine the token of the first network element based on the identification information of the first network element and the contract information response. The verification server may also determine the token of the first network element based on the identification information of the first network element and the third information. The verification server may also determine the token of the first network element based on the contract information response and the third information. The verification server may also determine the token of the first network element based on the identification information of the first network element, the contract information response, and the third information.

[0231] In another possible implementation, the verification server may also determine the token of the first network element based on preconfigured rules. For example, a token may be issued as long as there is a token issuance request. The data type that the token indicates has read permission may be preset. The preset data type of the token may be, for example, load-related data of the service network element.

[0232] In another possible implementation, the verification server determines the token of the first network element based on at least one of the identification information of the first network element, the contract information response, and the third information, and a preconfigured rule. For example, the verification server determines the token of the first network element based on the third information and the preconfigured rule, and the third information indicates that the first network element prefers to read data types such as load-related data of the service network element, resource utilization-related data of the service network element, and abnormal event-related data of the service network element. The preconfigured rule is to not issue a token with read permission for the data type of abnormal event-related data of the service network element. In this case, the verification server issues a token to the first network element indicating read permission for load-related data of the service network element and resource utilization-related data of the service network element.

[0233] 5. The authentication server sends a token grant response to the first network element.

[0234] Correspondingly, the first network element receives the token grant response sent by the verification server.

[0235] The token grant response includes a token of the first network element. The token corresponds to identification information of the first network element and includes first information indicating a type of data that the first network element has read permission.

[0236] Exemplarily, the token may be one or more of the following: an open authentication (Oauth) token (such as an Oauth 2.0 token), a certificate, or a one-time code, etc. The token may also be in other forms, and this application does not impose the sole limitation thereto.

[0237] The tokens in different embodiments may be in different forms. For example, the token in the first embodiment is an Oauth token, the token in the second embodiment is a certificate, and the tokens in the third and fourth embodiments are one-time codes, etc., without any unique limitation.

[0238] 6. The fourth network element determines whether to check the token.

[0239] Specifically, the fourth network element determines whether there is a local token check record for the first network element based on the identification information of the first network element in the data analysis request. In one possible implementation, if there is a historical token check record for the first network element, the token of the first network element is not checked, and step 10b is executed. In another possible implementation, if there is a historical token check record for the first network element and the token has not expired, the token of the first network element is not checked, and step 10b is executed. In another possible implementation, if there is no token check record for the first network element, step 7 is triggered.

[0240] 7. The fourth network element sends a token check request to the first network element.

[0241] Optionally, the token check request includes second information.

[0242] 8. The first network element checks the token.

[0243] Specifically, in one possible implementation, if step 7 does not include the second information, the first network element determines whether to report the token in the token check response based on its own configuration rules. For example, the first network element only needs to check whether the token is locally available, without considering the type correspondence. If the first network element has the token locally, the token check response includes the token of the first network element.

[0244] In another possible implementation, if step 7 carries the second information, the first network element determines whether it has a token of the data type indicated by the second information. If so, it includes the corresponding token in the token check response. If not, the first network element is triggered to execute steps 1 to 5, and then step 8. It can be seen that the above token issuance process (i.e., steps 1 to 5) can be executed before step 8, or can be triggered to execute at step 8.

[0245] In another implementation, the token check response may carry the first information in addition to the token.

[0246] 9. The first network element sends a token check response to the fourth network element.

[0247] Accordingly, the fourth network element receives a token check response.

[0248] In one possible implementation, the fourth network element may obtain the token of the first network element in the token check response. In another possible implementation, the fourth network element may obtain the first information in the token check response.

[0249] 10a. The fourth network element checks the validity of the token.

[0250] Specifically, the fourth network element checks the validity of the token of the first network element using the verification information preconfigured in step 0c. In one possible embodiment, if the validity check passes, step 10b is executed. In another possible embodiment, if the validity check fails, the fourth network element sends a failure response to the first network element, where the failure response includes a failure reason.

[0251] For example, if the token of the first network element is protected by a signature from a verification server, the fourth network element may perform an integrity check on the token, such as by reusing the certificate to verify the signature. If the signature verification passes, the token is considered complete and valid. For another example, the fourth network element may decrypt the token using a key. If the decryption succeeds, the token is considered complete and valid.

[0252] 10b. The fourth network element checks the content of the token.

[0253] Specifically, the fourth network element checks the content of the token and determines the data to be analyzed based on the token and the collected data of the second network element. The data type of the data to be analyzed is the data type of all or part of the collected data. That is, the data to be analyzed can be all or part of the collected data.

[0254] In one possible implementation, the fourth network element determines the data to be analyzed to be sent to the first network element based on the token, the second information and pre-configured rules of the first network element. The first network element, based on the pre-configured rules, trims the collected data and only sends part of the data corresponding to the intersection data type if there is an intersection between the data types indicated by the token and the second information; or if the data types indicated by the token and the second information do not completely match, the content verification is considered to have failed.

[0255] Among them, the fourth network element determines the data to be analyzed from the collected data based on the token and the second information. The data type of the data to be analyzed is the intersection data type of the data type indicated by the token and the data type indicated by the second information. The data type can be determined by comparing the data types based on the second information carried in the data analysis request and the token; the intersection data type can be the data type indicated by the token or part of the data type indicated by the token. If there is no intersection data type, the content verification result is failure. For example, if it is determined according to Table 1 and the token that the first network element has read permission for data of data type indications 0, 1, and 2, but the second information in step 0b indicates that the collected data contains data of data type indications 1, 2, and 3, then the fourth network element retains the data of data type indications 1 and 2, and trims the other data in the collected data to obtain the data to be analyzed.

[0256] For another example, if it is determined according to Table 1 and the token that the first network element has read permission for data with data type indications of 0, 1, and 2, but the second information in step 0b indicates that the collected data includes data with data type indications of 1, 2, and 3, then the fourth network element determines that the verification result of the content of the token is failure.

[0257] In another possible implementation, when step 6 determines that the token does not need to be checked, the fourth network element determines the data to be analyzed based on the token and the collected data in the historical check result. The method for determining the data to be analyzed based on the token and the collected data is described above.

[0258] 11. Send data or respond with failure based on the inspection results.

[0259] Specifically, when step 6 determines that the token needs to be checked, the fourth network element determines whether to send the data to be analyzed or a failure response to the first network element based on the check results of steps 10a and 10b. In one possible embodiment, when the check results of steps 10a and 10b are both passed, the fourth network element sends the data to be analyzed to the first network element. In another possible embodiment, when the check result of steps 10a or 10b is failed, the fourth network element sends a failure response to the first network element, the failure response including the failure reason.

[0260] If step 6 does not require token checking, the decision to send the data to be analyzed or a failure response to the first network element is made based on the check result of step 10b. In one possible embodiment, if the check result of step 10b is a pass, the fourth network element sends the data to be analyzed to the first network element. In another possible embodiment, if the check result of step 10b is a fail, the fourth network element sends a failure response to the first network element, the failure response including the failure reason.

[0261] In embodiment one, for first network elements with different trust levels, the fourth network element cuts the collected data of the second network element based on the token of the first network element, and only opens part of the data to the first network element for processing. For different first network elements, the fourth network element can perform fine-grained authorization control to ensure the security of the communication network.

[0262] Example 2

[0263] Referring to FIG4 , FIG4 is a flow chart of another communication method provided in an embodiment of the present application; the communication method includes the following steps:

[0264] 0. The first network element obtains a token.

[0265] Specifically, before step 1, the first network element obtains its own token, and the specific method for obtaining the token is not limited. For example, the token of the first network element can be obtained according to steps 0c to 5 in embodiment 1.

[0266] 1. The first network element sends a token registration request to the fourth network element.

[0267] Correspondingly, the fourth network element receives the token registration request of the first network element.

[0268] In one implementation, the token registration request includes identification information of the first network element and the token of the first network element.

[0269] In another implementation, the token registration request includes identification information of the first network element and token information of the first network element. The token information is related information of the token of the first network element, such as identification information of the token.

[0270] 2a. The fourth network element checks the validity of the token.

[0271] Specifically, in one possible implementation, refer to step 10a in Example 1 to check the validity of the token. The fourth network element performs a validity check on the token of the first network element. If the validity check passes, step 2b is executed. In another possible implementation, if the validity check fails, the token registration result is a failure, and the fourth network element sends a registration request response to the first network element, where the registration request response includes the reason for the registration failure.

[0272] In one implementation, the fourth network element can obtain the token of the first network element based on the token information of the first network element and then check the validity of the token. For example, the first network element obtains the token from the verification server, sends the identification information of the token to the fourth network element for registration, and after receiving the identification information of the token, the fourth network element can obtain the token of the first network element from the verification server based on the identification information.

[0273] 2b. The fourth network element stores the identification information of the first network element and the token of the first network element.

[0274] Specifically, in one implementation, the fourth network element records the identification information of the first network element and the token of the first network element (such as 2b in Figure 4). In another implementation, the fourth network element records the identification information of the first network element and the token information of the first network element.

[0275] In an embodiment of the present application, before storing the identification information and token (or token information) of the first network element, a validity check is performed on the token of the first network element. Only when the validity check passes, the identification information of the first network element and the token (or token information) of the first network element are stored to ensure the validity of the token (or token information) required to be registered.

[0276] 3. The fourth network element sends a registration request response to the first network element.

[0277] Correspondingly, the first network element receives the registration request response.

[0278] Specifically, the registration request response indicates the token registration result. When registration fails, the registration request response includes the registration failure reason.

[0279] 4. The second network element sends a data analysis request to the fourth network element.

[0280] Correspondingly, the fourth network element receives the data analysis request from the second network element.

[0281] In one possible implementation, the data analysis request includes identification information of the first network element, and the data analysis request is used to trigger the first network element to perform data analysis. The fourth network element can obtain the identification information of the first network element through the data analysis request.

[0282] The data analysis request may be sent once or periodically. When the data analysis request is sent periodically, the data analysis request is an analysis subscription request.

[0283] In another possible implementation, the data analysis request further includes the type of data that the second network element desires to analyze.

[0284] Furthermore, the fourth network element sends a data analysis request to the first network element. Correspondingly, the first network element receives the data analysis request sent by the fourth network element.

[0285] Steps 1 to 3 and step 4 are not necessarily connected. Steps 1 to 3 can be performed before or after the data analysis request is sent. For example, steps 1 to 3 can be performed before step 5, and step 4 can trigger the execution of steps 1 to 3.

[0286] 5. The first network element sends a data analysis request response to the fourth network element.

[0287] Correspondingly, the fourth network element receives the data analysis request response.

[0288] Specifically, in one possible implementation, when the first network element determines that it cannot respond to the second network element's data analysis request based on preconfigured rules and / or the type of data the second network element desires to analyze, the first network element includes the reason for the inability to respond in the data analysis request response. For example, the preconfigured rules determine whether to respond to the second network element's data analysis request based on the first network element's identification information and / or name. The fourth network element forwards the data analysis request response to the second network element.

[0289] In another possible implementation, when the data analysis request carries a data type that the second network element desires to analyze, and the first network element determines that it does not support reading the desired data type, the data analysis request response includes the data type that the first network element cannot read. In this case, the fourth network element forwards the data analysis request response to the second network element, instructing the second network element to readjust the desired data type carried in the data analysis request as needed.

[0290] In another possible implementation, when the first network element determines that it can respond to the data analysis request of the second network element based on preconfigured rules and / or the type of data that the second network element expects to analyze, the first network element carries the identification information of the first network element in the data analysis request response; execute step 6a.

[0291] 6a. The fourth network element checks the validity period of the token.

[0292] When the data analysis request response indicates that the first network element accepts the data analysis request, the fourth network element determines the data to be analyzed based on the token of the first network element; and verifies the data reading authority of the first network element according to the token to ensure data security.

[0293] Specifically, the token registration record is first checked based on the identification information of the first network element. In one possible implementation, if a token registration record for the first network element exists and the token of the first network element has not expired, step 6b is triggered. In another possible implementation, if no token registration record for the first network element exists and / or the token of the first network element has expired, step 0 is triggered, and then step 6a is executed.

[0294] In a possible embodiment, when the fourth network element determines that there is a token registration record of the first network element, it can obtain the token of the first network element based on the token information of the first network element, and then determine whether the token of the first network element has expired.

[0295] 6b. The fourth network element verifies the token.

[0296] Specifically, the fourth network element first checks the validity of the token using the same method as step 10a in Example 1. In one possible implementation, if the token validity check results in a pass, the fourth network element checks the contents of the token to determine fourth information, where the fourth information indicates the type of data that the second network element needs to collect. In another possible implementation, if the token validity check results in a fail, the fourth network element sends a data analysis request response to the second network element, where the data analysis request response includes a reason for the failure.

[0297] In one possible implementation, the fourth information may be the same as the first information. For example, referring to Table 1, the fourth network element checks the content of the token to determine that the data type indications for which the first network element has read permission are 1, 2, and 3, and then determines that the data type indication indicated by the fourth information is 1, 2, or 3.

[0298] In another possible implementation, the fourth network element generates fourth information based on the first information, and the fourth information is the same as or different from the first information. Exemplarily, the fourth network element generates the fourth information based on a preconfigured rule and the first information. For example, if the preconfigured rule prohibits the collection of information of a first data type, and the data type indicated by the first information includes the first data type, the fourth network element modifies the first information by removing the first data type from the first information to obtain the fourth information.

[0299] In another possible implementation, when the fourth information generated by the fourth network element based on the first information is empty, the fourth network element sends a data analysis request response to the first network element, where the response includes a failure reason.

[0300] 7. The fourth network element sends the identification information of the first network element and the fourth information to the second network element.

[0301] In one possible implementation, when the inspection results of both step 6a and step 6b are passed, the fourth network element sends the identification information and fourth information of the first network element to the second network element. The specific manner in which the fourth network element sends the identification information and fourth information of the first network element is not limited. For example, the identification information and fourth information of the first network element may be carried in a data analysis request response, and the data analysis request response may be sent to the second network element to instruct the second network element to collect data corresponding to the data type indicated by the fourth information, thereby implementing targeted data collection.

[0302] 8. The second network element sends the data to be analyzed to the fourth network element.

[0303] Specifically, the second network element collects data according to the instruction of the fourth information to obtain the data to be analyzed. The second network element sends the data to be analyzed to the fourth network element, and the specific manner in which the second network element sends the data to be analyzed is not limited. Exemplarily, the second network element may send a data analysis request to the fourth network element, where the data analysis request includes identification information of the second network element and the data to be analyzed. Optionally, the data analysis request also includes information indicating the data type of the data to be analyzed (such as a data type indication and / or a data type tag, etc.).

[0304] 9a. The fourth network element checks the validity of the token.

[0305] 9b. The fourth network element checks the content of the token.

[0306] Before sending the data to be analyzed to the first network element, the fourth network element verifies the token of the first network element again.

[0307] Specifically, steps 9a and 9b are optional. For details, please refer to steps 10a and 10b in Example 1. For example, before steps 9a and 9b, if it is found that the token of the first network element has expired or does not exist, step 0 may be triggered again. If it has not expired, steps 9a and 9b are directly executed.

[0308] 10. Send data or respond with failure based on the inspection results.

[0309] Specifically, based on the check results of step 9a and step 9b, it is determined whether to send the data to be analyzed or a failure response to the first network element. In one possible implementation, when the check results of step 9a and step 9b are both passed, the fourth network element sends the data to be analyzed to the first network element to ensure that the first network element has data read permission for the data to be analyzed.

[0310] In another possible implementation, when the check result of step 9a or step 9b is failure, the fourth network element sends a failure response to the first network element, where the failure response includes a failure reason.

[0311] If step 9a and step 9b are not performed, the fourth network element directly forwards the data to be analyzed (or the data analysis request in step 8) to the first network element.

[0312] In embodiment two, the second network element actively sends a data analysis request to the first network element. The fourth network element does not need to check the data type indication in the token of the first network element. The fourth network element determines the fourth information based on the token of the first network element to instruct the second network element to collect the corresponding data, thereby solving the problem from the source.

[0313] Example 3

[0314] Referring to FIG5 , FIG5 is a flow chart of another communication method provided in an embodiment of the present application; the communication method includes the following steps:

[0315] 0. Same as step 0 to step 3 in embodiment 2.

[0316] The first network element registers the token or token information in the fourth network element.

[0317] 1a. The first network element sends a data subscription request to the fourth network element.

[0318] The data subscription request includes identification information of the first network element, and the data subscription request is used to trigger the second network element to collect data.

[0319] Correspondingly, the fourth network element receives the data subscription request and obtains the identification information of the first network element through the data subscription request sent by the first network element.

[0320] 1b. The fourth network element forwards the data subscription request to the second network element.

[0321] 2. The second network element determines whether to check the token.

[0322] Specifically, in one possible implementation, the second network element determines that it does not need to check the token of the first network element, then the second network element collects data according to the data subscription request and / or preconfigured rules to obtain data to be analyzed, and executes step 5.

[0323] The above pre-configured rules can be set according to actual conditions without limitation. For example, the pre-configured rules stipulate that data with data type indications of 2 and 3 are collected. When the second network element determines that only data needs to be collected based on the pre-configured rules, the second network element needs to collect data with data type indications of 2 and 3.

[0324] When the second network element determines the data to be collected based solely on the data subscription request, the second network element illustratively determines the data to be collected based on the name of the data subscription request. For example, if the name of the data subscription request is "load data subscription request," the data to be collected by the second network element is the load data of the service network element.

[0325] For example, if the second network element locally caches the token or token information of the first network element, then there is no need to send a token query request. Alternatively, if the second network element determines that the security of the first network element does not require a token check, then there is no need to send a token query request. For example, if the first network element and the second network element are managed by the same operator, then the security of the first network element is determined to be high, and no token check is required.

[0326] In another possible implementation, the second network element determines that the token of the first network element needs to be checked, then the second network element sends a token query request to the fourth network element and executes step 3a, where the token query request includes identification information of the first network element.

[0327] 3a. The fourth network element checks the validity period of the token.

[0328] In response to the token query request, the fourth network element verifies the token of the first network element. The fourth network element first checks the token's validity period. Specifically, the fourth network element checks the token registration record based on the identification information of the first network element. In one possible implementation, if the token of the first network element is registered and has not expired, the fourth network element executes step 3b. In another possible implementation, if the token of the first network element is not registered and / or has expired, step 0 is triggered, followed by step 3a.

[0329] 3b. The fourth network element verifies the token.

[0330] Specifically, the fourth network element first checks the validity of the token using the same method as step 10a in Example 1. In one possible implementation, when the token validity check result is a pass, the fourth network element checks the content of the token to determine the fourth information. For details, please refer to the description of step 6b, which will not be repeated here. In another possible implementation, when the token validity check result is a fail, the fourth network element sends a data subscription request response to the first network element, where the response includes a failure reason.

[0331] 4. The fourth network element sends the identification information of the first network element and the fourth information to the second network element.

[0332] Specifically, the specific manner in which the fourth network element sends the identification information of the first network element and the fourth information to the second network element is not limited. In one possible implementation, when both step 3a and step 3b pass the check, the fourth network element returns verification result information to the second network element, where the verification result information includes the identification information of the first network element, the token verification result, and the fourth information.

[0333] 5. The second network element sends the data to be analyzed to the first network element.

[0334] Specifically, in a possible implementation, the second network element receives the identification information and fourth information of the first network element, collects data according to the fourth information to obtain data to be analyzed, and sends the data to be analyzed to the first network element.

[0335] There is no limitation on the specific manner in which the second network element sends the data to be analyzed. For example, similar to steps 8 to 10 of the second embodiment, the second network element may send the data to be analyzed to the first network element via the fourth network element, and the fourth network element may perform a secondary verification on the token of the first network element before forwarding the data to be analyzed, or directly forward the data to be analyzed (or the data analysis request) to the first network element.

[0336] In the third embodiment, the first network element actively requests data from the second network element, the second network element queries the token status through the fourth network element, and the fourth network element determines fourth information according to the token to instruct the second network element to collect data.

[0337] Example 4

[0338] Referring to FIG6 , FIG6 is a flow chart of another communication method provided in an embodiment of the present application; the communication method includes the following steps:

[0339] 0. Same as step 0 to step 3 in embodiment 2.

[0340] 1. The first network element sends a data subscription request to the fourth network element.

[0341] The data subscription request includes identification information of the first network element, and the data subscription request is used to trigger the second network element to collect data.

[0342] Correspondingly, the fourth network element receives the data subscription request and obtains the identification information of the first network element through the data subscription request sent by the first network element.

[0343] 2a. The fourth network element checks the validity period of the token.

[0344] In response to the data subscription request, the fourth network element verifies the token of the first network element. The fourth network element first checks the token's validity period. Specifically, the fourth network element checks the token registration record based on the identification information of the first network element. In one possible implementation, if the token of the first network element is registered and has not expired, step 2b is executed. In another possible implementation, if the token of the first network element is not registered and / or has expired, step 0 is triggered, followed by step 2a.

[0345] 2b. The fourth network element verifies the token.

[0346] Specifically, the fourth network element first checks the validity of the token using the same method as step 10a in Example 1. In one embodiment, when the validity check result of the token passes, the fourth network element checks the content of the token to determine the fourth information. For details, please refer to the description of step 6b, which will not be repeated here. In another possible embodiment, when the validity check result of the token fails, the fourth network element sends a data subscription request response to the first network element, where the response includes the reason for the failure.

[0347] 3. The fourth network element sends the identification information of the first network element and the fourth information to the second network element.

[0348] Specifically, in one possible implementation, when both step 2a and step 2b pass the check, the fourth network element sends the identification information of the first network element and the fourth information to the second network element. The specific manner in which the fourth network element sends the identification information and the fourth information of the first network element is not limited. For example, the fourth network element returns verification result information to the second network element, the verification result information including the identification information of the first network element, the token verification result, and the fourth information.

[0349] In another possible implementation, when the check result of step 2a and / or step 2b is failure, the fourth network element returns a subscription failure response to the first network element, where the subscription failure response includes a failure reason.

[0350] 4. The second network element sends the data to be analyzed to the first network element.

[0351] Specifically, the second network element receives the identification information and the fourth information of the first network element, collects data according to the fourth information to obtain the data to be analyzed, and sends the data to be analyzed to the first network element.

[0352] There is no limitation on the specific manner in which the second network element sends the data to be analyzed. Similar to steps 8 to 10 of Example 2, the second network element may send the data to be analyzed to the first network element via the fourth network element. The fourth network element may perform a secondary verification on the token of the first network element before forwarding the data to be analyzed, or may directly forward the data to be analyzed (or the data analysis request) to the first network element.

[0353] In the fourth embodiment, the first network element actively requests data, the fourth network element queries the token status and instructs the second network element to collect data according to the token.

[0354] Figures 7, 8, and 9 are schematic diagrams of the structures of possible communication devices provided in embodiments of the present application. These communication devices can be used to implement the functions of the first network element, the fourth network element, or the verification server in the above-mentioned method embodiments, and thus can also achieve the beneficial effects possessed by the above-mentioned method embodiments. In the embodiments of the present application, the communication device can be the first network element, the fourth network element, or the verification server, and can also be a module (such as a chip) applied to the first network element, the fourth network element, or the verification server.

[0355] As shown in Figure 7 , a communication device 700 includes a processing unit 710 and a transceiver unit 720. The communication device 700 is configured to implement the functions of the fourth network element in the method embodiment shown in Figure 2 . Alternatively, the communication device 700 may include a module configured to implement any function or operation of the fourth network element in the method embodiment shown in Figure 2 . The module may be implemented in whole or in part via software, hardware, firmware, or any combination thereof.

[0356] When the communication device 700 is used to implement the function of the fourth network element in the method embodiment shown in Figure 2: the processing unit 710 is used to obtain the identification information of the first network element. The processing unit 710 is also used to determine the data to be analyzed from the second network element based on the token of the first network element. The above-mentioned token corresponds to the identification information of the first network element, and the token includes first information, which indicates the type of data that the first network element has read permission. The above-mentioned data to be analyzed is used to evaluate the service network element. The transceiver unit 720 is used to send the data to be analyzed to the first network element.

[0357] A more detailed description of the processing unit 710 and the transceiver unit 720 can be directly obtained by referring to the relevant description in any method embodiment of Figures 2 to 6, and will not be repeated here.

[0358] As shown in Figure 8 , the communication device 800 includes a transceiver unit 810. The communication device 800 is configured to implement the functions of the authentication server or the first network element in the method embodiment shown in Figure 3 . Alternatively, the communication device 800 may include a module configured to implement any function or operation of the authentication server or the first network element in the method embodiment shown in Figure 3 . The module may be implemented in whole or in part via software, hardware, firmware, or any combination thereof.

[0359] When the communication device 800 is used to implement the verification server functionality of the method embodiment shown in FIG3 , the transceiver unit 810 is configured to receive a token issuance request from a first network element, the token issuance request including the identification information of the first network element. The transceiver unit 810 is further configured to send a token grant response to the first network element, the token grant response including the token of the first network element. The token corresponds to the identification information of the first network element and includes first information indicating the type of data that the first network element has permission to read.

[0360] When communication device 800 is used to implement the functions of the first network element in the method embodiment shown in FIG3 , transceiver unit 810 is configured to send a token issuance request to a verification server, the token issuance request including identification information of the first network element. Transceiver unit 810 is further configured to receive a token grant response from the verification server, the token grant response including a token for the first network element. The token corresponds to the identification information of the first network element and includes first information indicating the type of data that the first network element has permission to read.

[0361] A more detailed description of the transceiver unit 810 can be directly obtained by referring to the relevant description in the method embodiment shown in FIG3 , and is not repeated here.

[0362] As shown in Figure 8 , a communication device 800 includes a transceiver unit 810. The communication device 800 is configured to implement the functions of the first network element in the method embodiment shown in Figure 2 . Alternatively, the communication device 800 may include a module configured to implement any function or operation of the first network element in the method embodiment shown in Figure 2 . The module may be implemented in whole or in part via software, hardware, firmware, or any combination thereof.

[0363] When the communication device 800 is used to implement the functions of the first network element in the method embodiment shown in Figure 2, the transceiver unit 810 is configured to receive data to be analyzed from a fourth network element. The data to be analyzed is determined by the fourth network element based on the token of the first network element, and the data to be analyzed originates from the second network element. The token corresponds to the identification information of the first network element and includes first information indicating the type of data that the first network element has permission to read. The data to be analyzed is used to evaluate the service network element.

[0364] A more detailed description of the transceiver unit 810 can be directly obtained by referring to the relevant description in any method embodiment of FIG. 2 to FIG. 6 , and is not repeated here.

[0365] Exemplarily, an embodiment of the present application further provides a communication system, including the fourth network element and the first network element shown in FIG. 2 .

[0366] Exemplarily, an embodiment of the present application further provides a communication system, including the first network element and the verification server shown in FIG3 .

[0367] As shown in Figure 9, communication device 900 includes a processor 910 and an interface circuit 920. Processor 910 and interface circuit 920 are coupled to each other. It will be appreciated that interface circuit 920 may be a transceiver or an input / output interface. Optionally, communication device 900 may further include a memory 930 for storing instructions executed by processor 910, input data required by processor 910 to execute instructions, or data generated after processor 910 executes instructions. There may be one or more memories 930, and there may be one or more processors 910.

[0368] When the communication device 900 is used to implement the functions of the fourth network element in the method shown in FIG2 , the processor 910 is used to implement the functions of the processing unit 710, and the interface circuit 920 is used to implement the functions of the transceiver unit 720. When the communication device 900 is used to implement the functions of the first network element in the method shown in FIG2 , the interface circuit 920 is used to implement the functions of the transceiver unit 810. When the communication device 900 is used to implement the method shown in FIG3 , the interface circuit 920 is used to implement the functions of the transceiver unit 810.

[0369] When the communication device is a chip used in a network device, the network device chip implements the network device functions of the above method embodiments. The network device chip receives information from other modules in the network device (such as a radio frequency module or antenna), and the information is sent by the terminal device to the network device; or the network device chip sends information to other modules in the network device (such as a radio frequency module or antenna), and the information is sent by the network device to the terminal device.

[0370] Exemplarily, the communication device 900 may be a chip or a chip system.

[0371] It is understood that the processor 910 in the embodiments of the present application may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.

[0372] The memory 930 may be a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 930 may store programs. When the program stored in the memory 930 is executed by the processor 910, the processor 910 is configured to execute the steps of the communication method described in any of the above embodiments.

[0373] The method steps in the embodiments of the present application can be implemented by hardware or by a processor executing software instructions. The software instructions can be composed of corresponding software modules, and the software modules can be stored in a random access memory, a flash memory, a read-only memory, a programmable read-only memory, an erasable programmable read-only memory, an electrically erasable programmable read-only memory, a register, a hard disk, a mobile hard disk, a CD-ROM or any other form of storage medium well known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be an integral part of the processor. The processor and the storage medium can be located in an ASIC. In addition, the ASIC can be located in a network device or a terminal device. Of course, the processor and the storage medium can also be present in a network device or a terminal device as discrete components.

[0374] In the above embodiments, all or part of the embodiments may be implemented using software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments may be implemented in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are performed in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, or other programmable device. The computer program or instructions may be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program or instructions may be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium, such as a floppy disk, hard disk, or magnetic tape; an optical medium, such as a digital video disk; or a semiconductor medium, such as a solid-state drive.

[0375] In the various embodiments of the present application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.

Claims

1. A communication method, characterized in that: The method comprises: Obtaining identification information of the first network element; Determine the data to be analyzed from the second network element based on the token of the first network element, the token corresponds to the identification information of the first network element, the token includes first information, the first information indicates the type of data that the first network element has the permission to read; the data to be analyzed is used to evaluate the service network element; Sending the data to be analyzed to the first network element.

2. The method according to claim 1, characterized in that The determining the data to be analyzed from the second network element based on the token of the first network element includes: The data to be analyzed is determined based on the token and the collected data of the second network element, and the data type of the data to be analyzed is the data type of all or part of the collected data.

3. The method according to claim 1 or 2, characterized in that: The obtaining the identification information of the first network element includes: A data analysis request from the second network element is received, where the data analysis request includes identification information of the first network element, and the data analysis request is used to trigger the first network element to perform data analysis.

4. The method according to claim 3, characterized in that The data analysis request further includes the collected data of the second network element, and second information, wherein the second information indicates a data type of the collected data; The determining the data to be analyzed from the second network element based on the token of the first network element includes: The data to be analyzed is determined from the collected data based on the token and the second information, and the data type of the data to be analyzed is an intersection data type of a data type indicated by the token and a data type indicated by the second information.

5. The method according to claim 3 or 4, characterized in that: After receiving the data analysis request of the second network element, the method further includes: Sending a token check request to the first network element; A token check response from the first network element is received, where the token check response includes a token of the first network element.

6. The method according to claim 3, characterized in that: After receiving the data analysis request of the second network element, the method further includes: Sending the data analysis request to the first network element; Receiving a data analysis request response from the first network element; The determining the data to be analyzed from the second network element based on the token of the first network element includes: When the data analysis request response indicates that the first network element accepts the data analysis request, the data to be analyzed is determined based on the token of the first network element.

7. The method according to claim 6, characterized in that The data analysis request also includes the type of data that the second network element expects to analyze; When the first network element does not support reading the data type desired to be analyzed, the data analysis request response includes the data type that the first network element cannot read.

8. The method according to claim 3, 6 or 7, characterized in that: The determining the data to be analyzed from the second network element based on the token of the first network element includes: Verifying the token of the first network element; When the verification result of the token is verification passed, sending the data analysis request response to the second network element, the data analysis request response including the identification information of the first network element and the first information; The data to be analyzed is received from the second network element, where the data type of the data to be analyzed is the data type indicated by the first information.

9. The method according to claim 8, characterized in that The sending the data to be analyzed to the first network element includes: Verifying the token of the first network element again; When the verification result of the token is verification passed, the data to be analyzed is sent to the first network element.

10. The method according to claim 1, characterized in that The obtaining the identification information of the first network element includes: A data subscription request sent by the first network element is received, where the data subscription request includes identification information of the first network element, and the data subscription request is used to trigger the second network element to collect data.

11. The method according to claim 10, characterized in that The determining the data to be analyzed based on the token of the first network element includes: Verifying the token of the first network element; When the verification result of the token is verification passed, sending the identification information of the first network element and the first information to the second network element; A data analysis request from the second network element is received, where the data analysis request includes the data to be analyzed and identification information of the first network element, and the data type of the data to be analyzed is the data type indicated by the first information.

12. The method according to claim 11, characterized in that The sending the data to be analyzed to the first network element includes: Sending the data analysis request to the first network element.

13. The method according to claim 11 or 12, characterized in that: The verifying the token of the first network element includes: Sending the data subscription request to the second network element; receiving a token query request sent by the second network element, wherein the token query request includes identification information of the first network element; In response to the token query request, the token of the first network element is verified.

14. The method according to any one of claims 1 to 13, characterized in that: The method further comprises: receiving a token registration request from the first network element, wherein the token registration request includes identification information of the first network element and a token of the first network element; The identification information of the first network element and the token of the first network element are stored.

15. The method according to claim 14, characterized in that The storing the identification information of the first network element and the token of the first network element includes: Performing validity check on the token of the first network element; When the result of the validity check is that the check is passed, the identification information of the first network element and the token of the first network element are stored.

16. The method according to any one of claims 1 to 15, characterized in that The data type includes at least one of the following: The load data of the service network element, the resource utilization data of the service network element, the abnormal event data of the service network element or the energy consumption data of the service network element.

17. The method according to claim 16, characterized in that The load data comes from a network storage network element, or the resource utilization data and / or abnormal event data comes from an operation maintenance management network element.

18. A communication method, characterized in that: The method comprises: receiving a token issuance request from a first network element, wherein the token issuance request includes identification information of the first network element; A token grant response is sent to the first network element, wherein the token grant response includes a token of the first network element, wherein the token corresponds to identification information of the first network element, and wherein the token includes first information indicating the type of data that the first network element has read permission for.

19. The method according to claim 18, characterized in that After receiving the token issuance request from the first network element, the method further includes: Sending a contract information query request to a third network element, where the contract information query request includes identification information of the first network element; receiving a signing information response sent by the third network element, wherein the signing information response includes a trust level and / or a service type of the first network element; The token of the first network element is determined according to the identification information of the first network element and / or the contract information response.

20. The method according to claim 19, characterized in that The token issuance request further includes third information, where the third information indicates the type of data that the first network element prefers to read; The token of the first network element is determined based on at least one of the identification information of the first network element, the contract information response and the third information.

21. A communication method, characterized in that: Applied to a first network element, the method includes: Sending a token issuance request to a verification server, wherein the token issuance request includes identification information of the first network element; Receive a token grant response sent by the verification server, where the token grant response includes a token of the first network element, where the token corresponds to identification information of the first network element, and where the token includes first information indicating a data type that the first network element has read permission for.

22. The method according to claim 21, characterized in that The token of the first network element is determined based on the identification information of the first network element and / or a contract information response from a third network element, and the contract information response includes the trust level and / or service type of the first network element.

23. The method according to claim 22, characterized in that The token issuance request further includes third information, where the third information indicates the type of data that the first network element prefers to read; The token of the first network element is determined based on at least one of the identification information of the first network element, the contract information response and the third information.

24. A communication device comprising means for executing the method as claimed in any one of claims 1 to 23.

25. A communication device, characterized in that: It includes a processor and an interface circuit, wherein the interface circuit is used to receive signals from other communication devices outside the communication device and transmit them to the processor or send signals from the processor to other communication devices outside the communication device, and the processor is used to implement the method as described in any one of claims 1 to 23 through a logic circuit or executing code instructions.

26. A computer-readable storage medium, characterized in that: The storage medium stores a computer program or an instruction, and when the computer program or the instruction is executed by the communication device, the method according to any one of claims 1 to 23 is implemented.

Citation Information

Patent Citations

  • Communication method and related equipment

    CN120075801A

  • Authorization verification method and device

    CN115706997A

  • Communication method and communication device

    CN116033407A

  • Verification method, communication device and communication system

    CN116506810A