Communication method and communication apparatus
By verifying the validity of ID routing relationship information, the problem that NRF entities may find the wrong NF entities during service discovery in 5G mobile communication systems is solved, achieving higher service discovery accuracy and service reliability.
Patent Information
- Application Number
- PCT/CN2024/140102
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-22
- Filing Date
- 2024-12-17
- Publication Date
- 2025-06-26
AI Technical Summary
In the service-oriented architecture of the 5G mobile communication system, when the network storage function (NRF) entity performs service discovery based on the user ID, the wrong NF entity may be found, resulting in service failure.
A communication method and a communication device are provided to ensure the accuracy of the NRF entity when service discovery is checked by verifying the validity of ID routing relationship information. The specific method includes receiving routing relationship information from an NF entity, determining its validity, and saving the routing relationship information after determining validity.
By verifying the effectiveness of ID routing relationship information, the accuracy of NRF entities when service discovery is improved based on user ID is avoided, and business failure is avoided.
Smart Images

Figure CN2024140102_26062025_PF_FP_ABST
Abstract
Description
Communication method and communication device
[0001] This application claims priority to the Chinese patent application filed with the China Patent Office on December 22, 2023, with application number 202311787291.9 and application name “Communication Method and Communication Device”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of wireless communications, and in particular to a communication method and a communication device. Background Art
[0003] The service-based architecture (SBA) of the fifth-generation (5G) mobile communication system adopts a registration-based discovery model. For example, when a network function (NF) entity registers with a network repository function (NRF) entity, it can report the user identity (ID) of its service. The NRF entity can determine ID routing relationship information based on the user ID reported by the NF entity, allowing the NRF entity to perform service discovery based on the user ID and determine the NF entity that meets the service requirements. The ID routing relationship information can be understood as the relationship between the user ID and the NF entity.
[0004] However, this registration discovery method has the following problem: the NRF entity may find the wrong NF entity when performing service discovery based on the user ID, resulting in service failure. Summary of the Invention
[0005] The present application provides a communication method and a communication device. The present application provides a verification mechanism for determining the validity of identity (ID) routing relationship information to improve the accuracy of a network repository function (NRF) entity in performing service discovery based on a user ID.
[0006] In a first aspect, the present application provides a communication method, which is applied to a first functional entity, and the method includes: receiving first information from a second functional entity, the first information indicating a first routing relationship, the first routing relationship being the relationship between identification information of the second functional entity and first user identification information; and determining the validity of the first routing relationship.
[0007] As an example, the method may be performed by the first functional entity, or may be performed by a chip system, a hardware circuit and / or a software module applied to the first functional entity.
[0008] As an example, the first functional entity may be an ID access gateway, and the second functional entity may be an ID home server directly connected to the first functional entity.
[0009] In this technical solution, after the second functional entity completes configuration and the device joins the network, it can register and report its own capabilities and attributes to the first functional entity. For example, the second functional entity can send first information to the first functional entity, where the first information is used to indicate a first routing relationship, which is the relationship between the identification information of the second functional entity and the identification information of the first user.
[0010] As an example, the identification information of the second functional entity can be the host ID of the second functional entity. The host ID of the second functional entity can be represented by a common network entity identifier such as the fully qualified domain name (FQDN) of the second functional entity or other domain names. The first routing relationship can be understood as ID routing relationship information. The first user identification information can be understood as the user ID registered and reported by the second functional entity. The user ID can be represented by the user ID segment, the user ID prefix, and the user ID value. The user ID segment can also be called the user ID range or segment range. Among them, the user ID segment is, for example, 4600310000 to 4600320000, the user ID prefix is, for example, 4600 or 46003, and the user ID value can be any specific value from 4600310000 to 4600320000.
[0011] In this technical solution, after receiving the first information sent by the second functional entity, the first functional entity can determine the validity of the first routing relationship indicated by the first information, thereby avoiding the problem of conflicts in user IDs reported by different second functional entities due to errors in the user ID reported by the second functional entity. This ensures that the first functional entity can find the second functional entity with higher accuracy when performing service discovery based on the user ID. Determining the validity of the first routing relationship can also be referred to as determining the legitimacy of the first routing relationship, or verifying / checking / authenticating the validity of the first routing relationship, which is not specifically limited here.
[0012] In combination with the first aspect, in certain implementations of the first aspect, determining the validity of the first routing relationship includes: sending second information to a third functional entity, the second information being used to request determination of the validity of the first routing relationship; and receiving third information from the third functional entity, the third information indicating the validity of the first routing relationship.
[0013] In this implementation, the first functional entity may request the third functional entity to determine the validity of the first routing relationship. As an example, the third functional entity may be an ID routing authentication service directly connected to the first functional entity, or the third functional entity may be an ID routing authentication service located in the same routing domain as the first functional entity.
[0014] As an example, the second information may include the first routing relationship.
[0015] As an example, the third information may include a determination result of the validity of the first routing relationship, where the determination result may be any of the following: valid, invalid, or unknown. It should be understood that when the determination result is valid, it can be considered that the authentication of the first routing relationship is successful; when the determination result is invalid, it can be considered that the authentication of the first routing relationship has failed; and when the determination result is unknown, it can be considered that the authentication function of the third functional entity for determining the validity of the first routing relationship is not enabled.
[0016] As an example, when the determination result is valid, the first functional entity may save the first routing relationship to the local database; when the determination result is invalid, the first functional entity does not save the first routing relationship; when the determination result is unknown, the first functional entity may process the first routing relationship based on the local configuration policy. As an example, the local configuration policy may be that when the determination result of the validity of the first routing relationship is unknown, the first functional entity may save or not save the first routing relationship. If the first routing relationship is saved, it is necessary to indicate that the determination result of the validity of the saved first routing relationship is unknown. Optionally, the local configuration policy can be pre-configured in the first functional entity in advance.
[0017] In combination with the first aspect, in certain implementations of the first aspect, when the first routing relationship is valid, the third information further includes a routing validity domain of the first routing relationship.
[0018] In this implementation, when determining that the first routing relationship is valid, the third information may further include a routing validity domain of the first routing relationship. The routing validity domain of the first routing relationship may be understood as a publishing range or transmission range of the first routing relationship in the ID routing network.
[0019] Therefore, when the third information indicates that the determination result of the validity of the first routing relationship is valid, the first functional entity needs to further determine whether the third information includes the routing validity domain of the first routing relationship. As an example, if the third information does not include the routing validity domain of the first routing relationship, the first functional entity may consider the routing validity domain of the first routing relationship to be the entire ID routing network.
[0020] In this implementation, by carrying the routing validity domain of the first routing relationship in the third information, the first functional entity can determine the publication scope of the first routing relationship, so that the first functional entity can implement the function of hiding or publishing routing information according to the routing validity domain, thereby realizing the secure isolation and hiding of routing information.
[0021] In combination with the first aspect, in certain implementations of the first aspect, determining the validity of the first routing relationship includes: obtaining fourth information, the fourth information including information obtained by signing the second routing relationship with the key of the first certificate, the first certificate is the certificate of the second functional entity, and the second routing relationship is the relationship between the identification information of the second functional entity and the user identification information belonging to the second functional entity; determining the validity of the first routing relationship based on the fourth information.
[0022] In this implementation, the first functional entity can independently determine the validity of the first routing relationship. As an example, the first functional entity can periodically obtain a signed second routing relationship from the ID resource management center. The signed second routing relationship is obtained by signing the second routing relationship using a key of the second functional entity's certificate. The key can include a public key and a private key.
[0023] As an example, the second routing relationship is the relationship between the identification information of the second functional entity and the second user identification information. The second user identification information can be understood as the user ID resource allocated by the ID resource management center to the second functional entity. As an example, the second routing relationship can include one or more key values, and the key value can be expressed as <second user identification information, identification information of the second functional entity>. It should be understood that the number of key values is consistent with the number of second user identification information.
[0024] Therefore, the first functional entity can determine the validity of the first routing relationship based on the second routing relationship. As an example, when there is a key value in the second routing relationship that matches the first routing relationship, the first routing relationship can be considered valid. For example, if the first routing relationship matches the first key value in the second routing relationship, the identification information of the second functional entity in the first routing relationship is consistent with the identification information of the second functional entity in the first key value, and the first user identification information in the first routing relationship is a subset of the second user identification information in the first key value.
[0025] In this implementation, the second routing relationship may be signed by using a certificate signature, so that the first functional entity can determine the validity of the first routing relationship based on the signed second routing relationship.
[0026] In combination with the first aspect, in certain implementations of the first aspect, the fourth information also includes the first certificate, and determining the validity of the first routing relationship based on the fourth information includes: determining the validity of the first certificate; when the first certificate is valid, determining the validity of the first routing relationship based on the first certificate.
[0027] In this implementation method, if the validity of the first routing relationship is determined based on the second routing relationship, the signed second routing relationship needs to be decrypted. Therefore, the first functional entity also needs to obtain the certificate of the second functional entity from the ID resource management center, and when it is determined that the certificate of the second functional entity is valid, the key of the certificate of the second functional entity is used to decrypt the signed second routing relationship, thereby determining the validity of the first routing relationship.
[0028] In combination with the first aspect, in certain implementations of the first aspect, the fourth information also includes a second certificate, which is a certificate of the routing domain to which the second functional entity belongs; wherein, determining the validity of the first certificate includes: determining the validity of the second certificate; when the second certificate is valid, determining the validity of the first certificate based on the second certificate.
[0029] As an example, the certificate of the second functional entity can be signed by a second certificate, which can also be called a trust domain certificate. The trust domain certificate can be the certificate of the ID routing domain to which the second functional entity belongs. Therefore, the first functional entity needs to obtain the second certificate from the ID resource management center and decrypt the signer information in the certificate of the second functional entity based on the key of the second certificate to determine the validity of the certificate of the second functional entity.
[0030] In combination with the first aspect, in some implementations of the first aspect, determining the validity of the second certificate includes: determining the validity of the second certificate based on a root certificate, and the second certificate is signed by the root certificate.
[0031] As an example, the second certificate may be signed by a root certificate, and thus the first functional entity may decrypt the signer information in the second certificate based on a key of the root certificate, thereby determining the validity of the second certificate.
[0032] As an example, the first functional entity may obtain a root certificate from an ID resource management center.
[0033] As an example, the root certificate may be pre-configured in the first functional entity.
[0034] In combination with the first aspect, in some implementations of the first aspect, the second routing relationship further includes a routing validity domain of the second routing relationship.
[0035] As an example, the route validity domain of the second routing relationship can be understood as the route publishing range of each key value in the second routing relationship.
[0036] As an example, the routing valid domain may be represented by a common network domain identifier such as an FQDN format.
[0037] As an example, the routing validity domain of the first routing relationship can be determined based on the routing validity domain of the second routing relationship. For example, when the first key value in the first routing relationship matches the first key value in the second routing relationship, the routing validity domain of the first routing relationship is consistent with the routing validity domain of the first key value.
[0038] In combination with the first aspect, in some implementations of the first aspect, when the first routing relationship is valid, the method further includes: sending fifth information to a fourth functional entity, the fifth information including the first user identification information and identification information of the first functional entity.
[0039] As an example, the fourth functional entity may be understood as an ID router or an ID access gateway directly connected to the first functional entity.
[0040] In this implementation, upon determining that the first routing relationship is valid, the first functional entity may further send fifth information to the fourth functional entity. The fifth information may include the first user identification information and identification information of the first functional entity. It should be understood that the first user identification information included in the fifth information is the first user identification information included in the first routing relationship determined to be valid.
[0041] In combination with the first aspect, in certain implementations of the first aspect, the sending of the fifth information to the fourth functional entity includes: when the routing validity domain of the first routing relationship is larger than the service domain of the first functional entity, sending the fifth information to the fourth functional entity.
[0042] In this implementation, when determining that the first routing relationship is valid, the first functional entity may determine whether it is necessary to send the fifth information based on the routing validity domain of the first routing relationship. As an example, the first functional entity may determine the routing validity domain of the first routing relationship based on the third information or the routing validity domain of the second routing relationship.
[0043] As an example, if the routing validity domain of the first routing relationship is not larger than the service domain of the first functional entity, there is no need to send the fifth information to the fourth functional entity. If the routing validity domain of the first routing relationship is larger than the service domain of the first functional entity, the first functional entity can send the fifth information to the fourth functional entity. The service domain of the fourth functional entity is smaller than the routing validity domain of the first routing relationship, or the service domain of the fourth functional entity is included in the routing validity domain of the first routing relationship. Optionally, the service domain of the first functional entity or the fourth functional entity can be represented by a common network domain identifier such as the FQDN or domain name of the first functional entity or the fourth functional entity.
[0044] In combination with the first aspect, in some implementations of the first aspect, the fifth information further includes identification information of the second functional entity and / or the routing validity domain of the first routing relationship.
[0045] In this implementation, the fifth information may also include identification information of the second functional entity, so that the fourth functional entity can determine the validity of the first routing relationship contained in the fifth information, and when the fourth functional entity determines that the first routing relationship is invalid, it can trace the device of the second functional entity that reports the invalid first routing relationship based on the identification information of the second functional entity.
[0046] In this implementation, the fifth information may also include the routing validity domain of the first routing relationship, so that the fourth functional entity can determine whether to continue forwarding the routing information containing the first user identification information based on the routing validity domain, thereby enabling the fourth functional entity to implement the function of publishing or hiding the routing information, and realizing the secure isolation and hiding of the routing information.
[0047] In a second aspect, the present application provides a communication method, which is applied to a second functional entity, and the method includes: determining first information, where the first information indicates a first routing relationship, and the first routing relationship is the relationship between the identification information of the second functional entity and the first user identification information; and sending the first information to the first functional entity.
[0048] As an example, the method may be performed by the second functional entity, or may be performed by a chip system, a hardware circuit and / or a software module applied to the second functional entity.
[0049] As an example, the second functional entity may be an ID home server, and the first functional entity may be an ID access gateway directly connected to the second functional entity.
[0050] In this technical solution, after the second functional entity completes configuration and the device joins the network, it can register and report its own capabilities and attributes to the first functional entity. For example, the second functional entity can send first information to the first functional entity, where the first information is used to indicate a first routing relationship, which is the relationship between the identification information of the second functional entity and the identification information of the first user.
[0051] As an example, the identification information of the second functional entity can be the host ID of the second functional entity. The host ID of the second functional entity can be represented by a common network entity identifier such as the FQDN or other domain name of the second functional entity. The first routing relationship can be understood as ID routing relationship information. The first user identification information can be understood as the user ID registered and reported by the second functional entity. The user ID can be represented by the user ID number segment, the user ID prefix, and the user ID value. The user ID number segment can also be called the user ID range or number segment range. Among them, the user ID number segment is, for example, 4600310000 to 4600320000, the user ID prefix is, for example, 4600 or 46003, and the user ID value can be any specific value from 4600310000 to 4600320000.
[0052] In a third aspect, the present application provides a communication method, which is applied to a third functional entity, and the method includes: receiving second information from a first functional entity, the second information being used to request determination of the validity of a first routing relationship, the first routing relationship being the relationship between identification information of the second functional entity and first user identification information; and sending third information to the first functional entity, the third information indicating the validity of the first routing relationship.
[0053] As an example, the method may be performed by a third functional entity, or may be performed by a chip system, a hardware circuit and / or a software module applied to the third functional entity.
[0054] As an example, the third functional entity may be an ID routing authentication service, the first functional entity may be an ID access gateway directly connected to the third functional entity, or the first functional entity may be an ID access gateway located in the same routing domain as the third functional entity, and the second functional entity may be an ID home server directly connected to the first functional entity.
[0055] As an example, the identification information of the second functional entity can be the host ID of the second functional entity. The host ID of the second functional entity can be represented by a common network entity identifier such as the FQDN or other domain name of the second functional entity. The first routing relationship can be understood as ID routing relationship information. The first user identification information can be understood as the user ID registered and reported by the second functional entity to the first functional entity. The user ID can be represented by the user ID segment, the user ID prefix, and the user ID value. The user ID segment can also be called the user ID range or segment range. Among them, the user ID segment is, for example, 4600310000 to 4600320000, the user ID prefix is, for example, 4600 or 46003, and the user ID value can be any specific value from 4600310000 to 4600320000.
[0056] As an example, the second information may include the first routing relationship.
[0057] As an example, the third information may include a determination result of the validity of the first routing relationship, where the determination result may be any of the following: valid, invalid, or unknown. It should be understood that when the determination result is valid, it can be considered that the authentication of the first routing relationship is successful; when the determination result is invalid, it can be considered that the authentication of the first routing relationship has failed; and when the determination result is unknown, it can be considered that the authentication function of the third functional entity for determining the validity of the first routing relationship is not enabled.
[0058] In this technical solution, when the second functional entity completes the configuration and the device enters the network, it can register and report its own capabilities and attributes to the first functional entity. For example, the second functional entity can send first information to the first functional entity, and the first information is used to indicate a first routing relationship. The first routing relationship is the relationship between the identification information of the second functional entity and the first user identification information; after receiving the first information sent by the second functional entity, the first functional entity can determine the validity of the first routing relationship indicated by the first information. Therefore, the first functional entity can send second information to the third functional entity to request the third functional entity to determine the validity of the first routing relationship. Accordingly, the third functional entity can receive the second information, and after determining whether the first routing relationship is valid, send third information to the first functional entity to indicate the validity of the first routing relationship.
[0059] In combination with the third aspect, in certain implementations of the third aspect, when the first routing relationship is valid, the third information further includes a routing validity domain of the first routing relationship.
[0060] In this implementation, when determining that the first routing relationship is valid, the third information may further include a routing validity domain of the first routing relationship. The routing validity domain of the first routing relationship may be understood as a publishing range or transmission range of the first routing relationship in the ID routing network.
[0061] As an example, when the determination result of the validity of the first routing relationship is valid, but the third information does not include the routing validity domain of the first routing relationship, it can be considered that the routing validity domain of the first routing relationship is the entire ID routing network.
[0062] In this implementation, by carrying the routing validity domain of the first routing relationship in the third information, the first functional entity can determine the publication scope of the first routing relationship, so that the first functional entity can implement the function of hiding or publishing routing information according to the routing validity domain, thereby realizing the secure isolation and hiding of routing information.
[0063] In combination with the third aspect, in some implementations of the third aspect, the method further includes: determining the validity of the first routing relationship.
[0064] In this implementation, after receiving the second information, the third functional entity may determine the validity of the first routing relationship included in the second information.
[0065] In combination with the third aspect, in certain implementations of the third aspect, determining the validity of the first routing relationship includes: obtaining sixth information, the sixth information including information obtained by signing the second routing relationship with the key of the first certificate, the first certificate is the certificate of the second functional entity, and the second routing relationship is the relationship between the identification information of the second functional entity and the user identification information belonging to the second functional entity; determining the validity of the first routing relationship based on the sixth information.
[0066] As an example, the third functional entity may periodically obtain a signed second routing relationship from the ID resource management center. The signed second routing relationship is obtained by signing the second routing relationship with the key of the certificate of the second functional entity. The key may include a public key and a private key.
[0067] As an example, the second routing relationship is the relationship between the identification information of the second functional entity and the second user identification information. The second user identification information can be understood as the user ID resource allocated by the ID resource management center to the second functional entity. As an example, the second routing relationship can include one or more key values, and the key value can be expressed as <second user identification information, identification information of the second functional entity>. It should be understood that the number of key values is consistent with the number of second user identification information.
[0068] Therefore, the third functional entity can determine the validity of the first routing relationship based on the second routing relationship. As an example, when there is a key value in the second routing relationship that matches the first routing relationship, the first routing relationship can be considered valid. For example, if the first routing relationship matches the first key value in the second routing relationship, the identification information of the second functional entity in the first routing relationship is consistent with the identification information of the second functional entity in the first key value, and the first user identification information in the first routing relationship is a subset of the second user identification information in the first key value.
[0069] In this implementation, the second routing relationship may be signed by using a certificate signature, so that the third functional entity can determine the validity of the first routing relationship based on the signed second routing relationship.
[0070] In combination with the third aspect, in certain implementations of the third aspect, the sixth information also includes the first certificate, and determining the validity of the first routing relationship based on the sixth information includes: determining the validity of the first certificate; when the first certificate is valid, determining the validity of the first routing relationship based on the first certificate.
[0071] In this implementation method, if the validity of the first routing relationship is determined based on the second routing relationship, the signed second routing relationship needs to be decrypted. Therefore, the third functional entity also needs to obtain the certificate of the second functional entity from the ID resource management center, and when it is determined that the certificate of the second functional entity is valid, the key of the certificate of the second functional entity is used to decrypt the signed second routing relationship, thereby determining the validity of the first routing relationship.
[0072] In combination with the third aspect, in certain implementations of the third aspect, the sixth information also includes a second certificate, which is a certificate of the routing domain to which the second functional entity belongs; wherein, determining the validity of the first certificate includes: determining the validity of the second certificate; when the second certificate is valid, determining the validity of the first certificate based on the second certificate.
[0073] As an example, the certificate of the second functional entity can be signed by a second certificate, which can also be called a trust domain certificate. The trust domain certificate can be the certificate of the ID routing domain to which the second functional entity belongs. Therefore, the third functional entity needs to obtain the second certificate from the ID resource management center and decrypt the signer information in the certificate of the second functional entity based on the key of the second certificate to determine the validity of the certificate of the second functional entity.
[0074] In combination with the third aspect, in some implementations of the third aspect, determining the validity of the second certificate includes: determining the validity of the second certificate based on a root certificate, and the second certificate is signed by the root certificate.
[0075] As an example, the second certificate may be signed by a root certificate, and thus the third functional entity may decrypt the signer information in the second certificate based on a key of the root certificate, thereby determining the validity of the second certificate.
[0076] As an example, the third functional entity may obtain a root certificate from the ID resource management center.
[0077] As an example, the root certificate may be pre-configured in the third functional entity.
[0078] In combination with the third aspect, in some implementations of the third aspect, the second routing relationship further includes a routing validity domain of the second routing relationship.
[0079] As an example, the route validity domain of the second routing relationship can be understood as the route publishing range of each key value in the second routing relationship.
[0080] As an example, the routing valid domain may be represented by a common network domain identifier such as an FQDN format.
[0081] As an example, the routing validity domain of the first routing relationship can be determined based on the routing validity domain of the second routing relationship. For example, when the first key value in the first routing relationship matches the first key value in the second routing relationship, the routing validity domain of the first routing relationship is consistent with the routing validity domain of the first key value.
[0082] In this implementation, by carrying the routing validity domain in the second routing relationship, each functional entity in the ID routing network (such as the first functional entity, the fourth functional entity, etc.) can determine the publication scope of the routing information, so that each functional entity can implement the function of hiding or publishing the routing information according to the routing validity domain, thereby realizing the secure isolation and hiding of the routing information.
[0083] In a fourth aspect, the present application provides a communication method, which is applied to a fourth functional entity, and the method includes: receiving fifth information from a first functional entity, the fifth information indicating a first routing relationship, the first routing relationship being the relationship between the identification information of the second functional entity and the first user identification information; and determining the validity of the first routing relationship.
[0084] As an example, the method may be performed by a fourth functional entity, or may be performed by a chip system, a hardware circuit and / or a software module applied to the fourth functional entity.
[0085] As an example, the fourth functional entity may be an ID router or an ID access gateway, the first functional entity may be understood as an ID access gateway directly connected to the fourth functional entity, and the second functional entity may be an ID home server directly connected to the first functional entity.
[0086] In this technical solution, after receiving the first routing relationship registered and reported by the second functional entity, the first functional entity can determine the validity of the first routing relationship, and send fifth information to the fourth functional entity if it is determined that the first routing relationship is valid.
[0087] As an example, the identification information of the second functional entity can be the host ID of the second functional entity. The host ID of the second functional entity can be represented by a common network entity identifier such as the FQDN or other domain name of the second functional entity. The first routing relationship can be understood as ID routing relationship information. The first user identification information can be understood as the user ID registered and reported by the second functional entity. The user ID can be represented by the user ID number segment, the user ID prefix, and the user ID value. The user ID number segment can also be called the user ID range or number segment range. Among them, the user ID number segment is, for example, 4600310000 to 4600320000, the user ID prefix is, for example, 4600 or 46003, and the user ID value can be any specific value from 4600310000 to 4600320000.
[0088] As an example, the fifth information indicates the first routing relationship, which can be understood as the fifth information including the first routing relationship. It should be understood that the first user identification information included in the fifth information is the first user identification information included in the first routing relationship that is determined to be valid.
[0089] As an example, the fifth information may also include identification information of the first functional entity.
[0090] In this technical solution, after receiving the fifth information, the fourth functional entity can determine the validity of the first routing relationship contained in the fifth information, thereby avoiding receiving invalid first routing relationships from the first functional entity, and ensuring higher accuracy of the first routing relationships published / transmitted in the ID routing network. Determining the validity of the first routing relationship can also be referred to as determining the legitimacy of the first routing relationship, or verifying / checking / authenticating the validity of the first routing relationship, which is not specifically limited herein.
[0091] In combination with the fourth aspect, in certain implementations of the fourth aspect, the fifth information further includes a routing validity domain of the first routing relationship.
[0092] In this implementation, the fifth information may also include the routing validity domain of the first routing relationship, so that the fourth functional entity can determine whether to continue forwarding the routing information containing the first user identification information based on the routing validity domain, thereby enabling the fourth functional entity to implement the function of publishing or hiding the routing information, and realizing the secure isolation and hiding of the routing information.
[0093] In combination with the fourth aspect, in certain implementations of the fourth aspect, determining the validity of the first routing relationship includes: sending seventh information to a fifth functional entity, the seventh information being used to request determination of the validity of the first routing relationship; and receiving eighth information from the fifth functional entity, the eighth information indicating the validity of the first routing relationship.
[0094] In this implementation, the fourth functional entity may request the fifth functional entity to determine the validity of the first routing relationship. As an example, the fifth functional entity may be an ID routing authentication service directly connected to the fourth functional entity, or the fifth functional entity may be an ID routing authentication service located in the same routing domain as the fourth functional entity.
[0095] As an example, the seventh information may include the first routing relationship, and the first routing relationship included in the seventh information is valid.
[0096] As an example, the eighth information may include a determination result of the validity of the first routing relationship, where the determination result may be any of the following: valid, invalid, or unknown. It should be understood that when the determination result is valid, it can be considered that the authentication of the first routing relationship is successful; when the determination result is invalid, it can be considered that the authentication of the first routing relationship has failed; and when the determination result is unknown, it can be considered that the authentication function of the fifth functional entity for determining the validity of the first routing relationship is not enabled.
[0097] As an example, when the determination result is valid, the fourth functional entity may save the first routing relationship to the local database; when the determination result is invalid, the fourth functional entity does not save the first routing relationship; when the determination result is unknown, the fourth functional entity may process the first routing relationship based on the local configuration policy. As an example, the local configuration policy may be that when the determination result of the validity of the first routing relationship is unknown, the fourth functional entity may save or not save the first routing relationship. If the first routing relationship is saved, it is necessary to indicate that the determination result of the validity of the saved first routing relationship is unknown. Optionally, the local configuration policy can be pre-configured in the fourth functional entity in advance.
[0098] In combination with the fourth aspect, in certain implementations of the fourth aspect, when the first routing relationship is valid, the eighth information further includes a routing validity domain of the first routing relationship.
[0099] In this implementation, when determining that the first routing relationship is valid, the eighth information may further include a routing validity domain of the first routing relationship. The routing validity domain of the first routing relationship may be understood as a publishing range or transmission range of the first routing relationship in the ID routing network.
[0100] Therefore, when the eighth information indicates that the determination result of the validity of the first routing relationship is valid, the fourth functional entity needs to further determine whether the eighth information includes the routing validity domain of the first routing relationship. As an example, if the eighth information does not include the routing validity domain of the first routing relationship, the fourth functional entity may consider that the routing validity domain of the first routing relationship is the entire ID routing network.
[0101] In this implementation, by carrying the routing validity domain of the first routing relationship in the eighth information, the fourth functional entity can determine the publication scope of the first routing relationship, so that the fourth functional entity can implement the function of hiding or publishing routing information according to the routing validity domain, thereby realizing the secure isolation and hiding of routing information.
[0102] In combination with the fourth aspect, in certain implementations of the fourth aspect, determining the validity of the first routing relationship includes: obtaining ninth information, the ninth information including information obtained by signing the second routing relationship with the key of the first certificate, the first certificate is the certificate of the second functional entity, and the second routing relationship is the relationship between the identification information of the second functional entity and the user identification information belonging to the second functional entity; determining the validity of the first routing relationship based on the ninth information.
[0103] In this implementation, the fourth functional entity can independently determine the validity of the first routing relationship. As an example, the fourth functional entity can periodically obtain a signed second routing relationship from the ID resource management center. The signed second routing relationship is obtained by signing the second routing relationship using the key of the certificate of the second functional entity. The key can include a public key and a private key.
[0104] As an example, the second routing relationship is the relationship between the identification information of the second functional entity and the second user identification information. The second user identification information can be understood as the user ID resource allocated by the ID resource management center to the second functional entity. As an example, the second routing relationship can include one or more key values, and the key value can be expressed as <second user identification information, identification information of the second functional entity>. It should be understood that the number of key values is consistent with the number of second user identification information.
[0105] Therefore, the fourth functional entity can determine the validity of the first routing relationship based on the second routing relationship. As an example, when there is a key value in the second routing relationship that matches the first routing relationship, the first routing relationship can be considered valid. For example, if the first routing relationship matches the first key value in the second routing relationship, the identification information of the second functional entity in the first routing relationship is consistent with the identification information of the second functional entity in the first key value, and the first user identification information in the first routing relationship is a subset of the second user identification information in the first key value.
[0106] In this implementation, the second routing relationship may be signed by using a certificate signature, so that the fourth functional entity can determine the validity of the first routing relationship based on the signed second routing relationship.
[0107] In combination with the fourth aspect, in certain implementations of the fourth aspect, the ninth information also includes the first certificate, and determining the validity of the first routing relationship based on the ninth information includes: determining the validity of the first certificate; when the first certificate is valid, determining the validity of the first routing relationship based on the first certificate.
[0108] In this implementation method, if the validity of the first routing relationship is determined based on the second routing relationship, the signed second routing relationship needs to be decrypted. Therefore, the fourth functional entity also needs to obtain the certificate of the second functional entity from the ID resource management center, and when it is determined that the certificate of the second functional entity is valid, the key of the certificate of the second functional entity is used to decrypt the signed second routing relationship, thereby determining the validity of the first routing relationship.
[0109] In combination with the fourth aspect, in certain implementations of the fourth aspect, the ninth information also includes a second certificate, which is a certificate of the routing domain to which the second functional entity belongs; wherein, determining the validity of the first certificate includes: determining the validity of the second certificate; when the second certificate is valid, determining the validity of the first certificate based on the second certificate.
[0110] As an example, the certificate of the second functional entity can be signed by a second certificate, which can also be called a trust domain certificate. The trust domain certificate can be the certificate of the ID routing domain to which the second functional entity belongs. Therefore, the fourth functional entity needs to obtain the second certificate from the ID resource management center and decrypt the signer information in the certificate of the second functional entity based on the key of the second certificate to determine the validity of the certificate of the second functional entity.
[0111] In combination with the fourth aspect, in certain implementations of the fourth aspect, determining the validity of the second certificate includes: determining the validity of the second certificate based on a root certificate, and the second certificate is signed by the root certificate.
[0112] As an example, the second certificate may be signed by a root certificate, and thus the fourth functional entity may decrypt the signer information in the second certificate based on a key of the root certificate, thereby determining the validity of the second certificate.
[0113] As an example, the fourth functional entity may obtain a root certificate from the ID resource management center.
[0114] As an example, the root certificate may be pre-configured in the fourth functional entity.
[0115] In combination with the fourth aspect, in some implementations of the fourth aspect, the second routing relationship further includes a routing validity domain of the second routing relationship.
[0116] As an example, the route validity domain of the second routing relationship can be understood as the route publishing range of each key value in the second routing relationship.
[0117] As an example, the routing valid domain may be represented by a common network domain identifier such as an FQDN format.
[0118] As an example, the routing validity domain of the first routing relationship can be determined based on the routing validity domain of the second routing relationship. For example, when the first key value in the first routing relationship matches the first key value in the second routing relationship, the routing validity domain of the first routing relationship is consistent with the routing validity domain of the first key value.
[0119] In a fifth aspect, the present application provides a communication method, which is applied to a fifth functional entity, and the method includes: receiving seventh information from a fourth functional entity, the seventh information being used to request determination of the validity of a first routing relationship, the first routing relationship being the relationship between the identification information of the second functional entity and the first user identification information; and sending eighth information to the fourth functional entity, the eighth information indicating the validity of the first routing relationship.
[0120] As an example, the method may be performed by a fifth functional entity, or may be performed by a chip system, a hardware circuit and / or a software module applied to the fifth functional entity.
[0121] As an example, the fifth functional entity may be an ID routing authentication service, the fourth functional entity may be an ID access gateway directly connected to the fifth functional entity, or the fourth functional entity may be an ID access gateway located in the same routing domain as the fifth functional entity, and the second functional entity may be an ID home server directly connected to the fourth functional entity.
[0122] As an example, the identification information of the second functional entity can be the host ID of the second functional entity. The host ID of the second functional entity can be represented by a common network entity identifier such as the FQDN or other domain name of the second functional entity. The first routing relationship can be understood as ID routing relationship information. The first user identification information can be understood as the user ID registered and reported by the second functional entity to the first functional entity. The user ID can be represented by the user ID segment, the user ID prefix, and the user ID value. The user ID segment can also be called the user ID range or segment range. Among them, the user ID segment is, for example, 4600310000 to 4600320000, the user ID prefix is, for example, 4600 or 46003, and the user ID value can be any specific value from 4600310000 to 4600320000.
[0123] As an example, the seventh information may include the first routing relationship.
[0124] As an example, the eighth information may include a determination result of the validity of the first routing relationship, where the determination result may be any of the following: valid, invalid, or unknown. It should be understood that when the determination result is valid, it can be considered that the authentication of the first routing relationship is successful; when the determination result is invalid, it can be considered that the authentication of the first routing relationship has failed; and when the determination result is unknown, it can be considered that the authentication function of the fifth functional entity for determining the validity of the first routing relationship is not enabled.
[0125] In this technical solution, after receiving the fifth information, the fourth functional entity can verify the validity of the first routing relationship contained in the fifth information. Therefore, the fourth functional entity can send the seventh information to the fifth functional entity to request the fifth functional entity to determine the validity of the first routing relationship. Correspondingly, the fifth functional entity can receive the seventh information and, after determining whether the first routing relationship is valid, send the eighth information to the fourth functional entity to indicate the validity of the first routing relationship.
[0126] In combination with the fifth aspect, in certain implementations of the fifth aspect, when the first routing relationship is valid, the eighth information further includes a routing validity domain of the first routing relationship.
[0127] In this implementation, when determining that the first routing relationship is valid, the eighth information may further include a routing validity domain of the first routing relationship. The routing validity domain of the first routing relationship may be understood as a publishing range or transmission range of the first routing relationship in the ID routing network.
[0128] As an example, when the determination result of the validity of the first routing relationship is valid, but the eighth information does not include the routing validity domain of the first routing relationship, it can be considered that the routing validity domain of the first routing relationship is the entire ID routing network.
[0129] In this implementation, by carrying the routing validity domain of the first routing relationship in the eighth information, the fourth functional entity can determine the publication scope of the first routing relationship, so that the fourth functional entity can implement the function of hiding or publishing routing information according to the routing validity domain, thereby realizing the secure isolation and hiding of routing information.
[0130] In combination with the fifth aspect, in some implementations of the fifth aspect, the method further includes: determining the validity of the first routing relationship.
[0131] In this implementation, after receiving the seventh information, the fifth functional entity may determine the validity of the first routing relationship included in the seventh information.
[0132] In combination with the fifth aspect, in certain implementations of the fifth aspect, determining the validity of the first routing relationship includes: obtaining tenth information, the tenth information including information obtained by signing the second routing relationship with the key of the first certificate, the first certificate is the certificate of the second functional entity, and the second routing relationship is the relationship between the identification information of the second functional entity and the user identification information belonging to the second functional entity; determining the validity of the first routing relationship based on the tenth information.
[0133] As an example, the fifth functional entity may periodically obtain a signed second routing relationship from the ID resource management center. The signed second routing relationship is obtained by signing the second routing relationship with the key of the certificate of the second functional entity. The key may include a public key and a private key.
[0134] As an example, the second routing relationship is the relationship between the identification information of the second functional entity and the second user identification information. The second user identification information can be understood as the user ID resource allocated by the ID resource management center to the second functional entity. As an example, the second routing relationship can include one or more key values, and the key value can be expressed as <second user identification information, identification information of the second functional entity>. It should be understood that the number of key values is consistent with the number of second user identification information.
[0135] Therefore, the fifth functional entity can determine the validity of the first routing relationship based on the second routing relationship. As an example, when there is a key value in the second routing relationship that matches the first routing relationship, the first routing relationship can be considered valid. For example, if the first routing relationship matches the first key value in the second routing relationship, the identification information of the second functional entity in the first routing relationship is consistent with the identification information of the second functional entity in the first key value, and the first user identification information in the first routing relationship is a subset of the second user identification information in the first key value.
[0136] In this implementation, the second routing relationship may be signed by using a certificate signature, so that the fifth functional entity can determine the validity of the first routing relationship based on the signed second routing relationship.
[0137] In combination with the fifth aspect, in certain implementations of the fifth aspect, the tenth information also includes the first certificate, and determining the validity of the first routing relationship based on the tenth information includes: determining the validity of the first certificate; when the first certificate is valid, determining the validity of the first routing relationship based on the first certificate.
[0138] In this implementation method, if the validity of the first routing relationship is determined based on the second routing relationship, the signed second routing relationship needs to be decrypted. Therefore, the fifth functional entity also needs to obtain the certificate of the second functional entity from the ID resource management center, and when it is determined that the certificate of the second functional entity is valid, the key of the certificate of the second functional entity is used to decrypt the signed second routing relationship, thereby determining the validity of the first routing relationship.
[0139] In combination with the fifth aspect, in certain implementations of the fifth aspect, the tenth information also includes a second certificate, which is a certificate of the routing domain to which the second functional entity belongs; wherein, determining the validity of the first certificate includes: determining the validity of the second certificate; when the second certificate is valid, determining the validity of the first certificate based on the second certificate.
[0140] As an example, the certificate of the second functional entity can be signed by a second certificate, which can also be called a trust domain certificate. The trust domain certificate can be the certificate of the ID routing domain to which the second functional entity belongs. Therefore, the fifth functional entity needs to obtain the second certificate from the ID resource management center and decrypt the signer information in the certificate of the second functional entity based on the key of the second certificate to determine the validity of the certificate of the second functional entity.
[0141] In combination with the fifth aspect, in certain implementations of the fifth aspect, determining the validity of the second certificate includes: determining the validity of the second certificate based on a root certificate, and the second certificate is signed by the root certificate.
[0142] As an example, the second certificate may be signed by a root certificate, and thus the fifth functional entity may decrypt the signer information in the second certificate based on a key of the root certificate, thereby determining the validity of the second certificate.
[0143] As an example, the fifth functional entity may obtain a root certificate from the ID resource management center.
[0144] As an example, the root certificate may be pre-configured in the fifth functional entity.
[0145] In combination with the fifth aspect, in certain implementations of the fifth aspect, the second routing relationship further includes a routing validity domain of the second routing relationship.
[0146] As an example, the route validity domain of the second routing relationship can be understood as the route publishing range of each key value in the second routing relationship.
[0147] As an example, the routing valid domain may be represented by a common network domain identifier such as an FQDN format.
[0148] As an example, the routing validity domain of the first routing relationship can be determined based on the routing validity domain of the second routing relationship. For example, when the first key value in the first routing relationship matches the first key value in the second routing relationship, the routing validity domain of the first routing relationship is consistent with the routing validity domain of the first key value.
[0149] In this implementation, by carrying the routing validity domain in the second routing relationship, each functional entity in the ID routing network (such as the first functional entity, the fourth functional entity, etc.) can determine the publication scope of the routing information, so that each functional entity can implement the function of hiding or publishing the routing information according to the routing validity domain, thereby realizing the secure isolation and hiding of the routing information.
[0150] In a sixth aspect, the present application provides a communication device, which includes various modules for implementing the method in the first aspect or any one of the implementation methods, and each module can be implemented in the form of hardware and / or software.
[0151] For example, the apparatus may include: a receiving module and a processing module. The receiving module is configured to receive first information from a second functional entity, where the first information indicates a first routing relationship, where the first routing relationship is a relationship between identification information of the second functional entity and first user identification information; and the processing module is configured to determine the validity of the first routing relationship.
[0152] In conjunction with the sixth aspect, in some implementations of the sixth aspect, the apparatus may further include a sending module, configured to send second information to a third functional entity, the second information being used to request determination of the validity of the first routing relationship; and a receiving module, further configured to receive third information from the third functional entity, the third information indicating the validity of the first routing relationship.
[0153] In combination with the sixth aspect, in certain implementations of the sixth aspect, when the first routing relationship is valid, the third information further includes a routing validity domain of the first routing relationship.
[0154] In combination with the sixth aspect, in certain implementations of the sixth aspect, the processing module is further used to obtain fourth information, where the fourth information includes information obtained by signing the second routing relationship with the key of the first certificate, the first certificate is the certificate of the second functional entity, and the second routing relationship is the relationship between the identification information of the second functional entity and the user identification information belonging to the second functional entity; the processing module is also used to determine the validity of the first routing relationship based on the fourth information.
[0155] In combination with the sixth aspect, in certain implementations of the sixth aspect, the fourth information also includes the first certificate, and the processing module is also used to determine the validity of the first certificate; the processing module is also used to determine the validity of the first routing relationship based on the first certificate when the first certificate is valid.
[0156] In combination with the sixth aspect, in certain implementations of the sixth aspect, the fourth information also includes a second certificate, which is a certificate of the routing domain to which the second functional entity belongs; the processing module is also used to determine the validity of the second certificate; the processing module is also used to determine the validity of the first certificate based on the second certificate when the second certificate is valid.
[0157] In combination with the sixth aspect, in certain implementations of the sixth aspect, the processing module is further used to determine the validity of the second certificate based on a root certificate, and the second certificate is signed by the root certificate.
[0158] In combination with the sixth aspect, in some implementations of the sixth aspect, the second routing relationship further includes a routing validity domain of the second routing relationship.
[0159] In combination with the sixth aspect, in certain implementations of the sixth aspect, when the first routing relationship is valid, the sending module is further used to send fifth information, where the fifth information includes the first user identification information and the identification information of the first functional entity.
[0160] In combination with the sixth aspect, in some implementations of the sixth aspect, the sending module is further used to send the fifth information to the fourth functional entity when the routing validity domain of the first routing relationship is larger than the service domain of the first functional entity.
[0161] In combination with the sixth aspect, in some implementations of the sixth aspect, the fifth information further includes identification information of the second functional entity and / or the routing validity domain of the first routing relationship.
[0162] In a seventh aspect, the present application provides a communication device, which includes modules for implementing the method in the second aspect or any one of the implementation methods, and each module can be implemented in the form of hardware and / or software.
[0163] For example, the apparatus may include: a processing module and a sending module. The processing module is configured to determine first information, where the first information indicates a first routing relationship, where the first routing relationship is a relationship between identification information of the second functional entity and identification information of the first user; and the sending module is configured to send the first information to the first functional entity.
[0164] In an eighth aspect, the present application provides a communication device, which includes modules for implementing the method in the third aspect or any one of the implementation methods thereof, and each module can be implemented in the form of hardware and / or software.
[0165] For example, the apparatus may include: a receiving module and a sending module. The receiving module is configured to receive second information from a first functional entity, the second information being used to request determination of the validity of a first routing relationship, where the first routing relationship is a relationship between identification information of the second functional entity and identification information of a first user; and the sending module is configured to send third information to the first functional entity, the third information indicating the validity of the first routing relationship.
[0166] In combination with the eighth aspect, in certain implementations of the eighth aspect, when the first routing relationship is valid, the third information further includes a routing validity domain of the first routing relationship.
[0167] In conjunction with the eighth aspect, in certain implementations of the eighth aspect, the apparatus may further include: a processing module. The processing module is configured to determine the validity of the first routing relationship.
[0168] In combination with the eighth aspect, in certain implementations of the eighth aspect, the processing module is further used to obtain sixth information, where the sixth information includes information obtained by signing the second routing relationship with the key of the first certificate, where the first certificate is the certificate of the second functional entity, and the second routing relationship is the relationship between the identification information of the second functional entity and the user identification information belonging to the second functional entity; the processing module is also used to determine the validity of the first routing relationship based on the sixth information.
[0169] In combination with the eighth aspect, in certain implementations of the eighth aspect, the sixth information also includes the first certificate, and the processing module is also used to determine the validity of the first certificate; the processing module is also used to determine the validity of the first routing relationship based on the first certificate when the first certificate is valid.
[0170] In combination with the eighth aspect, in certain implementations of the eighth aspect, the sixth information also includes a second certificate, which is a certificate of the routing domain to which the second functional entity belongs; the processing module is also used to determine the validity of the second certificate; the processing module is also used to determine the validity of the first certificate based on the second certificate when the second certificate is valid.
[0171] In combination with the eighth aspect, in certain implementations of the eighth aspect, the processing module is further used to determine the validity of the second certificate based on the root certificate, and the second certificate is signed by the root certificate.
[0172] In combination with the eighth aspect, in certain implementations of the eighth aspect, the second routing relationship further includes a routing validity domain of the second routing relationship.
[0173] In a ninth aspect, the present application provides a communication device comprising modules for implementing the method in the fourth aspect or any one of the implementation methods thereof, and each module can be implemented in the form of hardware and / or software.
[0174] For example, the apparatus may include: a receiving module and a processing module. The receiving module is configured to receive fifth information from a first functional entity, where the fifth information indicates a first routing relationship, where the first routing relationship is a relationship between identification information of a second functional entity and identification information of a first user; and the processing module is configured to determine the validity of the first routing relationship.
[0175] In conjunction with the ninth aspect, in certain implementations of the ninth aspect, the fifth information further includes a routing validity domain of the first routing relationship. In conjunction with the ninth aspect, in certain implementations of the ninth aspect, the apparatus may further include a sending module. The sending module is configured to send seventh information to a fifth functional entity, the seventh information being used to request determination of the validity of the first routing relationship; and the receiving module is further configured to receive eighth information from the fifth functional entity, the eighth information indicating the validity of the first routing relationship.
[0176] In combination with the ninth aspect, in certain implementations of the ninth aspect, when the first routing relationship is valid, the eighth information further includes a routing validity domain of the first routing relationship.
[0177] In combination with the ninth aspect, in certain implementations of the ninth aspect, the processing module is further used to obtain ninth information, where the ninth information includes information obtained by signing the second routing relationship with the key of the first certificate, where the first certificate is the certificate of the second functional entity, and the second routing relationship is the relationship between the identification information of the second functional entity and the user identification information belonging to the second functional entity; the processing module is also used to determine the validity of the first routing relationship based on the ninth information.
[0178] In combination with the ninth aspect, in certain implementations of the ninth aspect, the ninth information also includes the first certificate, and the processing module is also used to determine the validity of the first certificate; the processing module is also used to determine the validity of the first routing relationship based on the first certificate when the first certificate is valid.
[0179] In combination with the ninth aspect, in certain implementations of the ninth aspect, the ninth information also includes a second certificate, which is a certificate of the routing domain to which the second functional entity belongs; the processing module is also used to determine the validity of the second certificate; the processing module is also used to determine the validity of the first certificate based on the second certificate when the second certificate is valid.
[0180] In combination with the ninth aspect, in certain implementations of the ninth aspect, the processing module is further used to determine the validity of the second certificate based on the root certificate, and the second certificate is signed by the root certificate.
[0181] In combination with the ninth aspect, in certain implementations of the ninth aspect, the second routing relationship further includes a routing validity domain of the second routing relationship.
[0182] In a tenth aspect, the present application provides a communication device, which includes modules for implementing the method in the fifth aspect or any one of the implementation methods thereof, and each module can be implemented in the form of hardware and / or software.
[0183] For example, the apparatus may include: a receiving module and a sending module. The receiving module is configured to receive seventh information from a fourth functional entity, the seventh information being used to request determination of the validity of a first routing relationship, where the first routing relationship is a relationship between identification information of the second functional entity and identification information of the first user; and the sending module is configured to send eighth information to the fourth functional entity, the eighth information indicating the validity of the first routing relationship.
[0184] In combination with the tenth aspect, in certain implementations of the tenth aspect, when the first routing relationship is valid, the eighth information further includes a routing validity domain of the first routing relationship.
[0185] In conjunction with the tenth aspect, in certain implementations of the tenth aspect, the apparatus may further include a processing module. The processing module is configured to determine the validity of the first routing relationship.
[0186] In combination with the tenth aspect, in certain implementations of the tenth aspect, the processing module is further used to obtain tenth information, where the tenth information includes information obtained by signing the second routing relationship with the key of the first certificate, the first certificate is the certificate of the second functional entity, and the second routing relationship is the relationship between the identification information of the second functional entity and the user identification information belonging to the second functional entity; the processing module is also used to determine the validity of the first routing relationship based on the tenth information.
[0187] In combination with the tenth aspect, in certain implementations of the tenth aspect, the tenth information also includes the first certificate, and the processing module is also used to determine the validity of the first certificate; the processing module is also used to determine the validity of the first routing relationship based on the first certificate when the first certificate is valid.
[0188] In combination with the tenth aspect, in certain implementations of the tenth aspect, the tenth information also includes a second certificate, which is a certificate of the routing domain to which the second functional entity belongs; the processing module is also used to determine the validity of the second certificate; the processing module is also used to determine the validity of the first certificate based on the second certificate when the second certificate is valid.
[0189] In combination with the tenth aspect, in certain implementations of the tenth aspect, the processing module is further used to determine the validity of the second certificate based on the root certificate, and the second certificate is signed by the root certificate.
[0190] In combination with the tenth aspect, in certain implementations of the tenth aspect, the second routing relationship further includes a routing validity domain of the second routing relationship.
[0191] In an eleventh aspect, the present application provides a communication device, comprising a processor, the processor being coupled to a memory and configured to call program code in the memory to execute the method described in the first aspect or any possible implementation thereof. Optionally, the device further comprises a memory. Optionally, the device further comprises a communication interface, the processor being coupled to the communication interface.
[0192] In a twelfth aspect, the present application provides a communication device, comprising a processor, the processor being coupled to a memory and configured to call program code in the memory to execute the method described in the second aspect or any possible implementation thereof. Optionally, the device further comprises a memory. Optionally, the device further comprises a communication interface, the processor being coupled to the communication interface.
[0193] In a thirteenth aspect, the present application provides a communication device, comprising a processor, the processor being coupled to a memory and configured to call program code in the memory to execute the method described in the third aspect or any possible implementation thereof. Optionally, the device further comprises a memory. Optionally, the device further comprises a communication interface, the processor being coupled to the communication interface.
[0194] In a fourteenth aspect, the present application provides a communication device, comprising a processor, the processor being coupled to a memory and configured to call program code in the memory to execute the method described in the fourth aspect or any possible implementation thereof. Optionally, the device further comprises a memory. Optionally, the device further comprises a communication interface, the processor being coupled to the communication interface.
[0195] In a fifteenth aspect, the present application provides a communication device, comprising a processor, the processor being coupled to a memory and configured to call program code in the memory to execute the method described in the fifth aspect or any possible implementation thereof. Optionally, the device further comprises a memory. Optionally, the device further comprises a communication interface, the processor being coupled to the communication interface.
[0196] In the sixteenth aspect, the present application provides a communication system, which includes the device in the sixth aspect or the eleventh aspect, the device in the seventh aspect or the twelfth aspect, the device in the eighth aspect or the thirteenth aspect, the device in the ninth aspect or the fourteenth aspect, and the device in the tenth aspect or the fifteenth aspect.
[0197] In the seventeenth aspect, the present application provides a computer program product comprising instructions, which, when run on a computer, enables the computer to execute the method described in the first aspect, the second aspect, the third aspect, the fourth aspect, the fifth aspect, or any possible implementation thereof.
[0198] In aspect 18, the present application provides a computer-readable medium storing program code for execution by a device, wherein the program code includes a method for executing the method described in aspect 1, aspect 2, aspect 3, aspect 4, aspect 5, or any possible implementation thereof.
[0199] For the technical effects that can be achieved by any of the above-mentioned aspects 6 to 18 and any possible design of any of them, please refer to the description of the technical effects that can be brought about by the above-mentioned aspects 1 to 5, and no further details will be given here. BRIEF DESCRIPTION OF THE DRAWINGS
[0200] FIG1 is an exemplary diagram illustrating a communication system;
[0201] FIG2 is a schematic diagram of an application scenario provided by an embodiment of the present application;
[0202] FIG3 is a schematic diagram illustrating a communication method provided by an embodiment of the present application;
[0203] FIG4 is a schematic diagram illustrating a certificate management and signature rule provided by an embodiment of the present application;
[0204] FIG5 is a schematic diagram illustrating a communication method provided in yet another embodiment of the present application;
[0205] FIG6 is a schematic diagram illustrating a communication method provided in another embodiment of the present application;
[0206] FIG7 is a schematic structural diagram of a communication device provided by one embodiment of the present application;
[0207] FIG8 is a schematic structural diagram of a communication device provided in another embodiment of the present application. DETAILED DESCRIPTION
[0208] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present application, as detailed in the appended claims.
[0209] To facilitate the clear description of the technical solutions of the embodiments of the present application, in the embodiments of the present application, the words "first" and "second" are used to distinguish between identical or similar items with substantially the same functions and effects. Those skilled in the art will understand that the words "first" and "second" do not limit the quantity or execution order, and the words "first" and "second" do not necessarily mean different.
[0210] It should be noted that in the embodiments of this application, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described in this application as "exemplary" or "for example" should not be construed as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.
[0211] In the embodiments of the present application, "at least one" refers to one or more, and "more" refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can represent: the existence of A alone, the existence of A and B at the same time, and the existence of B alone, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, c can be single or multiple.
[0212] The technical solution provided in the present application can be applied to various communication systems, including but not limited to: narrowband Internet of Things (NB-IoT), global system for mobile communications (GSM), enhanced data rate for GSM evolution (EDGE), wideband code division multiple access (WCDMA), code division multiple access 2000 (CDMA), time division-synchronization code division multiple access (TD-SCDMA), wireless fidelity (WIFI), third generation (3G) mobile communication system, long term evolution (LTE), advanced long term evolution (LTE-A), LTE frequency division duplex (FDD), LTE time division duplex (TDD), fourth generation (4G) mobile communication system, fifth generation (5G) The three major application scenarios of 5G (5th generation) mobile communication system and 5G new radio (NR) communication system are: enhanced mobile broadband (eMBB), ultra-reliable and low latency communications (URLLC) and massive machine type communication (mMTC), as well as the future sixth generation (6G) mobile communication system, such as high frequency, terahertz, optical communication, etc. This application does not impose specific restrictions on this.
[0213] The technical problem solved by this application is described below with reference to FIG1 .
[0214] The service-based architecture (SBA) of the 5G mobile communication system adopts a registration discovery model. As an example, when a network function (NF) entity joins the network, the NF entity reports its own capabilities and attributes to the network repository function (NRF) entity, such as which user identities (IDs), tracking area identities (TAIs), access point names (APNs) the NF entity can provide services or service-based interfaces (SBIs), as well as the interface addresses of the SBIs. After receiving the information reported by the NF entity, the NRF entity can store the received information according to certain rules. For example, the NRF entity can internally organize and store the ID routing relationship information between the user ID and the NF entity, so that the NRF entity can subsequently perform service discovery based on the user ID to determine the NF entity that meets the business needs. For example, in the session activation process of the terminal device, the session management function (SMF) entity can use the terminal device's subscription permanent identifier (SUPI) to query the NRF entity for the unified data management (UDM) entity serving the SUPI and the SBI interface address provided by the UDM entity. The NRF entity can determine the UDM entity and the SBI interface address of the UDM entity based on the SUPI and return it to the SMF entity. The SMF entity can call the SBI interface provided by the determined UDM entity to obtain the terminal device contract data. Among them, the user ID served by the NF entity can be allocated by the operator according to a certain area (such as province, city, district, etc.), that is, the operator can allocate the user ID to the NF entity.
[0215] FIG1 is an exemplary diagram illustrating a communication system. As shown in FIG1 , the communication system may include an NRF entity 1, an NRF entity 2, a NF entity 1, a NF entity 2, a NF entity 3, and a NF entity 4. It should be understood that the number of NF entities and NRF entities is only an example.
[0216] Among them, NRF entity 1, NF entity 1 and NF entity 2 are located in the same network, for example, they are located in network 1, and NF entity 1 and NF entity 2 are located in the management domain of NRF entity 1. NF entity 1 or NF entity 2 can register with NRF entity 1 and report the user ID served by NF entity 1 or NF entity 2. After receiving the user ID reported by NF entity 1 or NF entity 2, NRF entity 1 can internally organize and store the ID routing relationship information between the user ID and NF entity 1 or NF entity 2.
[0217] NRF entity 2, NF entity 3 and NF entity 4 are located in the same network, for example, in network 2, and NF entity 3 and NF entity 4 are located in the management domain of NRF entity 2. NF entity 3 or NF entity 4 can register with NRF entity 2 to report the user ID served by NF entity 3 or NF entity 4. After receiving the user ID reported by NF entity 3 or NF entity 4, NRF entity 2 can internally organize and store the ID routing relationship information between the user ID and NF entity 3 or NF entity 4.
[0218] In this communication system, assuming that NF entity 4 needs to call a service interface provided by another NF entity, NF entity 4 uses a user ID to query NRF entity 2 for the NF entity that serves the user ID. After receiving the user ID, NRF entity 2 can determine which NRF entity's management domain the NF entity to which the user ID belongs is located. Assuming that the NF entity to which the user ID belongs is located in the management domain of NRF entity 1, NRF entity 2 can use the user ID to query NRF entity 1 for the NF entity that serves the user ID. After receiving the user ID, NRF entity 1 can determine the NF entity that serves the user ID and the interface information of the NF entity in the stored ID routing relationship information based on the user ID, and return it to NRF entity 2, so that NF entity 4 can call the required service interface. It should be noted that each NRF entity is pre-configured with the user ID served by the NF entity in the management domain of other NRF entities.
[0219] However, this registration and discovery method has the following problems: when different NF entities independently report the user ID of their own services, the user ID reported by the NF entity may be incorrect, which may lead to conflicts in the user IDs reported by different NF entities, and then the NRF entity may find the wrong NF entity when performing service discovery based on the user ID, resulting in service failure.
[0220] In view of this, the present application provides a communication method and a communication device. The present application provides a verification process or mechanism for signing ID routing relationship information using certificate signature to determine the validity and legality of the ID routing relationship information. For example, the NRF entity can verify the ID routing relationship information stored by the organization, or the NRF entity can verify the ID routing relationship information received from other NRF entities, thereby improving the accuracy of the NRF entity when performing service discovery based on the user ID. In addition, the present application also provides a decision-making mechanism for determining whether the ID routing relationship information needs to be transmitted across networks or across ID routing domains through the routing validity domain of the ID routing relationship information. It should be noted that the communication method and communication device provided in the present application are based on the same technical concept. Since the principles of solving the problems of the method and the device are similar, the implementation of the method and the device can refer to each other, and the repeated parts will not be repeated.
[0221] Figure 2 is a schematic diagram of an application scenario provided by an embodiment of the present application. The application scenario or system architecture shown in Figure 2 can be called an ID routing network architecture or a network architecture based on ID routing. The system architecture can be defined based on the 5G core network (5Gcore, 5GC) SBA architecture and future network evolution (such as ID routing network evolution) scenarios. As shown in Figure 2, the system architecture can include an ID resource management center 210, an ID routing domain 220, an ID routing domain 230, and an ID routing domain 240. Among them, the ID resource management center 210 mainly includes two functional modules, such as a certificate issuance center and an ID resource allocation and signature management functional module, the ID routing domain 220 can include an ID routing authentication service 221, an ID access gateway 222, and an ID home server 223, the ID routing domain 230 can include an ID routing authentication service 231, an ID access gateway 232, and an ID home server 233, and the ID routing domain 240 can include an ID routing authentication service 241 and an ID router 242.
[0222] Among them, the ID resource management center 210 can be connected to the ID routing authentication service 221, the ID access gateway 222, the ID routing authentication service 231, the ID access gateway 232, the ID routing authentication service 241 and the ID router 242. The ID access gateway 222 can be connected to the ID routing authentication service 221, the ID home server 223, the ID access gateway 232 and the ID router 242 respectively. The ID access gateway 232 can be connected to the ID routing authentication service 231, the ID home server 233 and the ID router 242 respectively. The ID router 242 is connected to the ID routing authentication service 241. In the embodiment of the present application, the ID routing authentication service 221, the ID access gateway 222, the ID home server 223, the ID routing authentication service 231, the ID access gateway 232, the ID home server 233, the ID routing authentication service 241 and the ID router 242 can be referred to as functional entities, network elements, functional modules, devices, network entities, etc., and this application does not impose specific restrictions on this. It should be understood that the number of ID routing domains, functional modules or functional entities in the system architecture is only an example and not a limitation.
[0223] In some embodiments, the ID routing authentication service 221 and the ID access gateway 222 can be merged into one functional entity, and one functional entity can simultaneously implement the functions of the ID routing authentication service 221 and the ID access gateway 222; similarly, the ID routing authentication service 231 and the ID access gateway 232 can also be merged into one functional entity, and the ID routing authentication service 241 and the ID router 242 can also be merged into one functional entity.
[0224] It should be noted that the functional modules or functional entities included in the system architecture may be provided by different manufacturers or by the same manufacturer, and this application does not impose any specific restrictions on this. It should be understood that the naming of the ID routing domain, functional modules, or functional entities included in the system architecture is only an example and not a limitation. As long as the network element, device, module, or functional entity has the same function as the ID routing domain, functional module, or functional entity in the system architecture, it can be included in the scope of the ID routing domain, functional module, or functional entity in the system architecture.
[0225] As an example, the ID resource management center can be a first-level organization or a multi-level organization, and organizations at different levels perform ID resource management within their own scope.
[0226] The certificate issuing center can be used to complete the hierarchical issuance and signing of certificates. For example, the certificate issuing center can issue the same trust domain certificate for all ID routing domains in the system architecture, and issue a device certificate for each functional entity in the system architecture, and sign the certificate of each functional entity through the trust domain certificate; for another example, the certificate issuing center can issue a corresponding trust domain certificate for each ID routing domain in the system architecture, and issue a device certificate for each functional entity in each ID routing domain, and sign the certificate of each functional entity in each ID routing domain through the trust domain certificate of each ID routing domain, thereby realizing the hierarchical issuance of certificates. Therefore, each functional entity can communicate after mutually confirming the validity of the certificate to improve the communication security between each functional entity. In the embodiment of the present application, if functional entity A can use the key of the trust domain certificate to decrypt the certificate of functional entity B, then the certificate of functional entity B can be considered to be valid. Determining the validity of the certificate can also be called determining / verifying / checking / authenticating the legitimacy of the certificate, and the present application does not impose specific restrictions on this.
[0227] The ID resource allocation and signature management functional module can be used to complete ID resource allocation, such as allocating user IDs to each ID home server according to certain rules. It can also be used to sign and store the ID routing relationship information of each ID home server using the certificate of each ID home server. It can also be used to provide an interface for each functional entity connected to the ID resource management center. Each functional entity can obtain the signed ID routing relationship information and the notification information of the ID resource allocation and signature management functional module updating the signed ID routing relationship information based on the interface. The signed ID routing relationship information can also be referred to as ID routing relationship information signature data. As an example, the ID routing relationship information can be the relationship between the user ID and the ID home server host ID.
[0228] In some embodiments, the ID resource allocation and signature management functional module can implement ID resource allocation according to a certain user ID range or user ID prefix. Among them, the user ID range is, for example, 4600310000 to 4600320000, and the user ID prefix is, for example, 4600 or 46003. The user ID range can also be called a user ID segment.
[0229] The ID routing authentication service can periodically or periodically obtain the certificate issued by the certificate issuing center and the ID routing relationship information signature data from the ID resource management center. It can also determine the validity of the obtained certificate and, if the certificate of the ID home server is determined to be valid, decrypt the ID routing relationship information signature data corresponding to the ID home server based on the ID home server's certificate, thereby providing the ID access gateway and ID router with the legitimacy authentication of the ID routing relationship information of the ID home server. Among them, at least one ID routing authentication service can be deployed in each ID routing domain. It can be seen that in the system architecture shown in Figure 2, an ID routing authentication service is deployed in each ID routing domain.
[0230] The ID access gateway can obtain ID routing relationship information from the ID home server and complete the identity authentication of the ID home server. It can also determine the validity of the obtained ID routing relationship information through the ID routing authentication service located in the same ID routing domain as the ID access gateway. It can also be used to forward the confirmed valid ID routing relationship information to the surrounding directly connected ID routers or ID access gateways. Among them, each ID routing domain can deploy at least one ID access gateway. It can be seen that in the system architecture shown in Figure 2, each ID routing domain deploys an ID access gateway.
[0231] In some embodiments, the ID access gateway can also directly obtain the certificate issued by the certificate issuing center and the ID routing relationship information signature data from the ID resource management center; it can also determine the validity of the obtained certificate, and when it is determined that the certificate of the ID belonging server is valid, decrypt the ID routing relationship information signature data corresponding to the ID belonging server based on the certificate of the ID belonging server, thereby authenticating the validity of the obtained ID routing relationship information.
[0232] In some embodiments, such as in a 5GC network architecture, the ID access gateway may be an NRF entity, or the network element function of the ID access gateway may be implemented by the NRF entity.
[0233] The ID home server is used to receive user ID resources allocated by the ID resource allocation and signature management function module, and send or publish ID routing relationship information to the ID access gateway.
[0234] In some embodiments, the ID home server can directly obtain the allocated user ID resources from the ID resource allocation and signature management function module and store them, or after the ID resource allocation and signature management function module allocates user ID resources to the ID home server, the allocated user ID resources can be pre-configured in the ID home server by manual means. This application does not impose specific restrictions on this.
[0235] In some embodiments, such as in a 5GC network architecture, the ID home server may be an NF entity, or it can be said that the network element function of the ID home server may be implemented by the NF entity.
[0236] The ID router can be used to determine the validity of the certificate of the ID access gateway or ID router directly connected to the ID router to complete identity authentication, and receive ID routing relationship information sent by the ID access gateway or ID router directly connected to the ID router; it can also be used to determine the validity of the received ID routing relationship information through the ID routing authentication service located in the same routing domain as the ID router; it can also be used to forward the determined valid ID routing relationship information to the surrounding directly connected ID routers or ID access gateways.
[0237] In some embodiments, the ID router may also directly obtain the certificate issued by the certificate issuing center and the ID routing relationship information signature data from the ID resource management center; it may also determine the validity of the obtained certificate, and when it is determined that the certificate of the ID belonging server is valid, decrypt the ID routing relationship information signature data corresponding to the ID belonging server based on the certificate of the ID belonging server, thereby authenticating the validity of the received ID routing relationship information.
[0238] In some embodiments, such as in a 5GC network architecture, the ID router may be an NRF entity, or it can be said that the network element function of the ID router may be implemented by the NRF entity.
[0239] In some embodiments, the ID routing relationship information may also include a routing validity domain, which may be used to indicate the routing publication range of the ID routing relationship information. The routing publication range is understood as the (valid) publication range or transmission range of the ID routing relationship information in the ID routing network.
[0240] In some embodiments, the routing validity domain can be represented by a common network domain identifier such as a fully qualified domain name (FQDN) format. As an example, if the routing validity domain of the ID routing relationship information is<E.F> , and the service domain of the ID home server in the ID routing relationship information is<E.F.G.H> The service domain of the ID access gateway in the same ID routing domain as the ID home server is<E.F.G> When the routing effective domain of the ID routing relationship information is larger than the service domain of the ID access gateway, the ID access gateway needs to forward the ID routing relationship information to the ID router or ID access gateway directly connected to the ID access gateway. If the service domain of the ID router directly connected to the ID access gateway is<E.F> When the ID routing relationship information is transmitted to the ID router, it is no longer transmitted. The service domain of the functional entities such as the ID home server, ID access gateway, and ID router can be the host ID of each functional entity. The host ID of each functional entity can be represented by a common network entity identifier such as the FQDN or domain name of each functional entity.
[0241] As an example, the ID routing relationship information may be expressed as <user ID, ID home server host ID, routing valid domain (optional)>.
[0242] The present application provides an autonomous security solution within the ID routing domain, which implements hierarchical certificate issuance and allocation of user ID resources through the ID resource management center, and centrally signs and stores the ID routing relationship information corresponding to each ID home server, so that functional entities such as the ID access gateway, ID routing authentication service, and ID router can determine the validity of the ID routing relationship information published in the ID routing network through the certificate issued by the ID resource management center.
[0243] In some implementations, the security domain of the ID routing network can be divided into a trusted domain and an untrusted domain. As an example, the trusted domain may include the ID routing authentication service, the ID access gateway, and the ID router. Within the trusted domain, the trustworthiness of each functional entity can be determined through certificates. The untrusted domain may include the ID resource management center and the ID home server. In addition to determining the trustworthiness of the functional entities through certificates, the untrusted domain also requires certificates to verify the validity of the ID routing relationship information published in the ID routing network.
[0244] Figure 3 is a schematic diagram illustrating a communication method provided by an embodiment of the present application. As shown in Figure 3, the method may include S301, S302 and S303.
[0245] S301: A first functional entity receives first information from a second functional entity, where the first information indicates a first routing relationship, and the first routing relationship is a relationship between identification information of the second functional entity and identification information of a first user.
[0246] In an embodiment of the present application, after the second functional entity completes configuration and the device joins the network, it can register and report its own capabilities and attributes to the first functional entity. For example, the second functional entity can send first information to the first functional entity, where the first information is used to indicate a first routing relationship, which is the relationship between the identification information of the second functional entity and the identification information of the first user. The first information can also be referred to as a routing advertisement message, and the second functional entity sending the first information to the first functional entity can also be referred to as the second functional entity issuing a routing advertisement message to the first functional entity.
[0247] As an example, the first functional entity may be an ID access gateway, and the second functional entity may be an ID home server.
[0248] As an example, the identification information of the second functional entity can be understood as the host ID of the second functional entity, and the host ID of the second functional entity can be represented by a common network entity identifier such as the FQDN or other domain name of the second functional entity; the first routing relationship can be understood as ID routing relationship information, and the first user identification information can be understood as the user ID registered and reported by the second functional entity. The user ID can be represented by the prefix of the user ID, the segment of the user ID, and the value of the user ID. The segment of the user ID can also be called the range of the user ID or the segment range.
[0249] As an example, the first routing relationship may be expressed as <first user identification information, second functional entity identification information>.
[0250] It should be understood that the number of the first routing relationships may be one or more. When the number of the first routing relationships is multiple, the first routing relationships may be represented in the form of a list.
[0251] S302: The first functional entity sends second information to the third functional entity, where the second information is used to request to determine the validity of the first routing relationship.
[0252] In an embodiment of the present application, after receiving the first information sent by the second functional entity, the first functional entity needs to determine the validity of the first routing relationship indicated by the first information, so that the second functional entity determined by the first functional entity when performing service discovery based on the user ID can meet the business requirements.
[0253] In one implementable manner, the first functional entity may send second information to the third functional entity to request the third functional entity to determine the validity of the first routing relationship. The second information may include the first routing relationship.
[0254] As an example, when the first functional entity is an ID access gateway and the second functional entity is an ID home server, the third functional entity may be an ID routing authentication service located in the same ID routing domain as the ID access gateway and the ID home server.
[0255] In one achievable manner, after receiving the second information, the third functional entity may match the first routing relationship with a local cache of the third functional entity, thereby determining the validity of the first routing relationship.
[0256] As an example, the third functional entity can periodically obtain the certificate issued by the certificate issuing center and the signed second routing relationship from the ID resource management center, decrypt the signed second routing relationship through the certificate management and signature rules, and save the decrypted second routing relationship, thereby establishing a local cache of the second routing relationship. The second routing relationship can be understood as the relationship between the identification information of the second functional entity and the second user identification information belonging to the second functional entity, and the second user identification information can be understood as the user ID resource allocated to the second functional entity by the ID resource allocation and signature management function module.
[0257] For example, Figure 4 is a schematic diagram illustrating certificate management and signature rules provided in one embodiment of the present application. As shown in Figure 4 , the certificates issued by the certificate issuance center may include a root certificate, a trust domain certificate, a certificate for a first functional entity, and a certificate for a second functional entity. It should be understood that the certificates issued by the certificate issuance center are not limited to the certificates shown in Figure 4 .
[0258] As shown in Figure 4, the root certificate can be understood as a trusted certificate or a self-signed certificate. The root certificate can include a root certificate signature, a root certificate key, and root certificate extension information. The key can include a public key and a private key. As an example, the root certificate can be a root certificate authority (CA) certificate.
[0259] The trust domain certificate can be a certificate issued by the certificate issuance center of the ID resource management center for the ID routing domain to which the first functional entity and the second functional entity belong. The trust domain certificate can be the same as or different from the trust domain certificates of other ID routing domains, and this application does not impose specific restrictions on this. The trust domain certificate may include a certificate signature, a certificate key, signer information, and root certificate extension information. As an example, the trust domain certificate can be a trust domain CA certificate.
[0260] The certificate of the first functional entity may be a certificate issued by a certificate issuing center of an ID resource management center to the first functional entity. The certificate of the first functional entity may include a certificate signature, a certificate key, signer information, and root certificate extension information. As an example, the certificate of the first functional entity may be a CA certificate of the first functional entity.
[0261] The certificate of the second functional entity may be a certificate issued by a certificate issuing center of an ID resource management center to the second functional entity. The certificate of the second functional entity may include a certificate signature, a certificate key, signer information, and root certificate extension information. As an example, the certificate of the second functional entity may be a CA certificate of the second functional entity.
[0262] In this embodiment, the trust domain certificate can be signed by a root certificate, so the signer information in the trust domain certificate points to the root certificate. As an example, the root certificate signs the trust domain certificate, which can be understood as signing the trust domain certificate with the root certificate's key. Therefore, the root certificate can be called the superior certificate of the trust domain certificate. Similarly, the certificate of the first functional entity can be signed by a trust domain certificate, so the signer information in the certificate of the first functional entity points to the trust domain certificate, and the certificate of the second functional entity can be signed by a trust domain certificate, so the signer information in the certificate of the second functional entity points to the trust domain certificate. Therefore, the trust domain certificate can be called the superior certificate of the certificate of the first functional entity and the certificate of the second functional entity.
[0263] After the ID resource allocation and signature management functional module allocates user ID resources to the second functional entity, it can use the second functional entity's certificate to sign the second routing relationship and store it in the database. It should be noted that this application does not limit the algorithm used for signature. For example, the signature algorithm can use one or more algorithms such as encryption and decryption, integrity protection, etc.
[0264] In some embodiments, the second routing relationship may further include a routing validity domain of the second routing relationship, and the routing validity domain may be used to indicate a routing publication scope of the second routing relationship.
[0265] In some embodiments, the root certificate may be pre-configured in the third functional entity.
[0266] Based on the certificate management and signature rules shown in Figure 4, after the third functional entity periodically obtains the certificate issued by the certificate issuing center and the signed second routing relationship from the ID resource management center, it can use the key of the root certificate to decrypt the trust domain certificate to determine the validity of the trust domain certificate; if the trust domain certificate is valid, the key of the trust domain certificate is used to decrypt the certificate of the second functional entity to determine the validity of the certificate of the second functional entity; if the certificate of the second functional entity is valid, the key of the certificate of the second functional entity can be used to decrypt the signed second routing relationship, and establish cache data of the second routing relationship to facilitate subsequent query and authentication.
[0267] As an example, the second routing relationship may include one or more key values, which may be expressed as <second user identification information, identification information of the second functional entity>. It should be understood that the number of key values is consistent with the number of second user identification information.
[0268] Therefore, after receiving the second information, the third functional entity can match the first routing relationship with the second routing relationship stored in the third functional entity, thereby determining the validity of the first routing relationship. As an example, when there is a key value in the second routing relationship that matches the first routing relationship, the first routing relationship can be considered valid. For example, if the first routing relationship matches the first key value in the second routing relationship, the identification information of the second functional entity in the first routing relationship is consistent with the identification information of the second functional entity in the first key value, and the first user identification information in the first routing relationship is a subset of the second user identification information in the first key value.
[0269] It should be understood that the routing validity domain of the second routing relationship is the routing publication range of each key value in the second routing relationship.
[0270] S303: The first functional entity receives third information from the third functional entity, where the third information indicates the validity of the first routing relationship.
[0271] In this embodiment, after determining the validity of the first routing relationship, the third functional entity may send third information to the first functional entity to indicate the validity of the first routing relationship.
[0272] In one possible implementation, the third information may include a determination result of the validity of the first routing relationship, and the determination result may be any of the following: valid, invalid, or unknown. It should be understood that when the determination result is valid, it can be considered that the authentication of the first routing relationship is successful; when the determination result is invalid, it can be considered that the authentication of the first routing relationship has failed; when the determination result is unknown, it can be considered that the authentication function of the third functional entity for determining the validity of the first routing relationship is not enabled. Optionally, when there are multiple first routing relationships, the third functional entity may send multiple third information to the first functional entity, and each third information may include a determination result of the validity of each first routing relationship, or the third information may include a determination result of the validity of each first routing relationship. This application does not impose any restrictions on this.
[0273] Accordingly, the first functional entity can receive the third information. If the determination result of the validity of the first routing relationship is valid, the first functional entity can save the first routing relationship to the local database; if the determination result of the validity of the first routing relationship is invalid, the first functional entity does not save the first routing relationship; if the determination result of the validity of the first routing relationship is unknown, the first functional entity can process the first routing relationship based on the local configuration policy. As an example, the local configuration policy may be that when the determination result of the validity of the first routing relationship is unknown, the first functional entity may save or not save the first routing relationship. If the first routing relationship is saved, it is necessary to indicate that the determination result of the validity of the saved first routing relationship is unknown. Optionally, the local configuration policy can be pre-configured in the first functional entity in advance.
[0274] In this embodiment, the first functional entity can authenticate the validity of the first routing relationship registered and reported by the second functional entity through the third functional entity, and save the valid first routing relationship, thereby avoiding the problem of conflict of user IDs reported by different second functional entities, so that the first functional entity has a higher accuracy in finding the second functional entity when performing service discovery based on the user ID; in addition, in this embodiment, the first routing relationship is signed to verify the validity of the first routing relationship, thereby avoiding tampering of the first routing relationship by middlemen, and improving communication efficiency.
[0275] For example, Figure 5 is a schematic diagram illustrating a communication method provided by another embodiment of the present application. As shown in Figure 5 , the method may include S301, S302, and S303, and may also include S304, S305, and S306.
[0276] S304: The first functional entity sends fourth information to the fourth functional entity, where the fourth information includes the first user identification information and identification information of the first functional entity.
[0277] As an example, the fourth functional entity may be understood as an ID router or an ID access gateway directly connected to the first functional entity.
[0278] In some implementations, when the first routing relationship is valid, the third information may further include a routing validity domain of the first routing relationship. The routing validity domain of the first routing relationship may be determined by the routing validity domain of the second routing relationship. For example, when the first key value in the first routing relationship matches the first key value in the second routing relationship, the routing validity domain of the first routing relationship is consistent with the routing validity domain of the first key value.
[0279] Therefore, when the third information indicates that the determination result of the validity of the first routing relationship is valid, the first functional entity also needs to determine whether the third information contains the routing validity domain of the first routing relationship. As an example, if the third information does not contain the routing validity domain of the first routing relationship, the first functional entity may deem that the routing validity domain of the first routing relationship is the entire ID routing network, and the first functional entity may send the fourth information to the fourth functional entity; if the third information contains the routing validity domain of the first routing relationship, and the scope of the routing validity domain is larger than the service domain of the first functional entity, the first functional entity may send the fourth information to the fourth functional entity, and the service domain of the fourth functional entity should be smaller than the routing validity domain of the first routing relationship, or in other words, the service domain of the fourth functional entity is included in the routing validity domain of the first routing relationship; if the third information contains the routing validity domain of the first routing relationship, and the scope of the routing validity domain is not larger than the service domain of the first functional entity, then the first functional entity does not send the fourth information to the fourth functional entity.
[0280] In this embodiment, the fourth information may also be referred to as routing advertisement information, and the fourth information may include the first user identification information and the identification information of the first functional entity. The identification information of the first functional entity may be the host ID of the first functional entity, and the host ID of the first functional entity may be represented by a common network entity identifier such as the FQDN or domain name of the first functional entity.
[0281] As an example, the fourth information may be expressed as <first user identification information, identification information of the first functional entity>. It should be understood that the first user identification information included in the fourth information is the first user identification information used in determining a valid first routing relationship.
[0282] In some implementations, the first functional entity may send the fourth information in a direct forwarding manner or an aggregate forwarding manner.
[0283] As an example, if the first user identification information in the determined valid first routing relationship includes: 460031000 to 460031500, 460031600 to 460031799, and 460031800, when the first functional entity sends the fourth information by direct forwarding, the fourth information may include: <4600310>00 to 460031500, identification information of the first functional entity>, <4600316>00 to 460031799, identification information of the first functional entity>, and <4600318>00, identification information of the first functional entity>, when the first functional entity sends the fourth information by aggregated forwarding, the fourth information may include: <4600310>00 to 460031500, identification information of the first functional entity> and <4600316>00 to 460031800, identification information of the first functional entity>. It should be understood that 460031600 to 460031799 and 460031800 can be aggregated into 460031600 to 460031800.
[0284] In this example, when the first functional entity sends the fourth information by direct forwarding, the fourth information may also include the identification information of the second functional entity, and / or, the routing valid domain of the first routing relationship; when the first functional entity sends the fourth information by aggregated forwarding, the fourth information may also include the routing valid domain of the first routing relationship.
[0285] Correspondingly, the fourth functional entity can receive and save the fourth information. Among them, if the fourth information only includes the first user identification information and the identification information of the first functional entity, the fourth functional entity can forward the received first user identification information, and can carry the identification information of the fourth functional entity when forwarding. It should be understood that the fourth functional entity can forward the information to other functional entities directly connected to the fourth functional entity; if the fourth information includes the routing valid domain of the first routing relationship, and the routing valid domain of the first routing relationship is larger than the service domain of the fourth functional entity, then the fourth functional entity can forward the received first user identification information, and can carry the identification information of the fourth functional entity when forwarding, or can carry the identification information of the fourth functional entity and the routing valid domain of the first routing relationship. The service domain of the functional entity receiving the information forwarded by the fourth functional entity should be smaller than the routing valid domain of the first routing relationship; if the fourth information includes the identification information of the second functional entity, the fourth functional entity needs to authenticate the validity of the first routing relationship included in the fourth information, and then execute S305. Among them, the identification information of the fourth functional entity can be the host ID of the fourth functional entity, and the host ID of the fourth functional entity can be represented by common network entity identifiers such as the FQDN or domain name of the fourth functional entity.
[0286] In some embodiments, if the fourth information does not include the identification information of the second functional entity, the fourth functional entity considers that the first user identification information in the received fourth information is an aggregated route, and thus does not perform authentication.
[0287] S305: The fourth functional entity sends fifth information to the fifth functional entity, where the fifth information is used to indicate a request to determine the validity of the first routing relationship.
[0288] In this embodiment, the fourth functional entity may request the fifth functional entity to determine the validity of the first routing relationship included in the fourth information, and the fifth information may carry the first routing relationship included in the fourth information.
[0289] As an example, the fifth functional entity may be understood as an ID routing authentication service located in the same ID routing domain as the fourth functional entity.
[0290] In one achievable manner, after receiving the fifth information, the fifth functional entity may match the first routing relationship with a local cache of the fifth functional entity, thereby determining the validity of the first routing relationship.
[0291] In this embodiment, the manner in which the fifth functional entity determines the validity of the first routing relationship may refer to the manner in which the third functional entity determines the validity of the first routing relationship in S302, and will not be described in detail here.
[0292] S306: The fourth functional entity receives sixth information from the fifth functional entity, where the sixth information indicates the validity of the first routing relationship.
[0293] In this embodiment, after determining the validity of the first routing relationship, the fifth functional entity may send sixth information to the third functional entity to indicate the validity of the first routing relationship.
[0294] In this embodiment, the description of the sixth information can refer to the description of the third information in S303. The description of the fourth functional entity after receiving the sixth information can refer to the description of the first functional entity after receiving the third information in S303 and S304, which are not repeated here. The fourth functional entity needs to carry its identification information when forwarding the information.
[0295] In some embodiments, the fourth functional entity may also carry identification information of the first functional entity when forwarding information.
[0296] In this embodiment, the fourth functional entity can judge the validity of the received first routing relationship, thereby improving the accuracy of the first routing relationship when it is transmitted across ID routing domains or across ID routing networks, and improving communication efficiency; in addition, in the future 6G network that realizes ID routing autonomy, when the functional entities in the ID routing autonomous network perform ID routing discovery and learning within and between autonomous domains, this solution can be used to judge the validity of the ID routing relationship information, thereby avoiding man-in-the-middle attacks to tamper with the ID routing relationship information.
[0297] In some feasible methods, the first functional entity and the fourth functional entity can directly obtain the certificate issued by the certificate issuing center and the signed second routing relationship from the ID resource management center, decrypt the signed second routing relationship through certificate management and signature rules, and save the decrypted second routing relationship, establish a local cache of the second routing relationship, so as to independently determine the validity of the first routing relationship.
[0298] Figure 6 is a schematic diagram illustrating a communication method provided by another embodiment of the present application. As shown in Figure 6, the method may include S601, S602, S603, S604 and S605.
[0299] S601: A first functional entity receives first information from a second functional entity, where the first information indicates a first routing relationship, and the first routing relationship is a relationship between identification information of the second functional entity and identification information of a first user.
[0300] In this embodiment, the specific implementation of S601 can refer to S301 and will not be repeated here.
[0301] S602: The first functional entity determines the validity of the first routing relationship.
[0302] In this embodiment, the first functional entity can periodically obtain the certificate issued by the certificate issuing center and the signed second routing relationship from the ID resource management center, and use the root certificate to determine the validity of the trust domain certificate. If the trust domain certificate is valid, the trust domain certificate is used to determine the validity of the certificate of the second functional entity. If the certificate of the second functional entity is valid, the certificate of the second functional entity is used to decrypt the signed second routing relationship, so that the cached data of the second routing relationship can be determined to facilitate subsequent query and authentication.
[0303] In some embodiments, the root certificate may be pre-configured in the first functional entity.
[0304] In this embodiment, the specific implementation of S602 can refer to S302 and S303 and will not be repeated here. For example, the way in which the first functional entity determines that the first routing relationship is valid based on the cached data of the second routing relationship can refer to the way in which the third functional entity determines that the first routing relationship is valid in S302. The related operations of the first functional entity after determining the validity of the first routing relationship can refer to the relevant description in S303.
[0305] S603: The first functional entity sends fourth information to the fourth functional entity, where the fourth information includes the first user identification information and identification information of the first functional entity.
[0306] In this embodiment, the specific implementation of S603 can refer to S304 and will not be repeated here.
[0307] S604: The fourth functional entity determines the validity of the first routing relationship.
[0308] In this embodiment, the fourth functional entity can periodically obtain the certificate issued by the certificate issuing center and the signed second routing relationship from the ID resource management center, and use the root certificate to determine the validity of the trust domain certificate. If the trust domain certificate is valid, the trust domain certificate is used to determine the validity of the certificate of the second functional entity. If the certificate of the second functional entity is valid, the certificate of the second functional entity is used to decrypt the signed second routing relationship, so that the cached data of the second routing relationship can be determined to facilitate subsequent query and authentication.
[0309] In some embodiments, the root certificate may be pre-configured in the fourth functional entity.
[0310] In this embodiment, the specific implementation of S604 can refer to S302, S303, S305 and S306, which will not be repeated here. For example, the fourth functional entity determines the validity of the first routing relationship based on the cached data of the second routing relationship in the same manner as the third functional entity or the fifth functional entity determines the validity of the first routing relationship. The relevant operations of the fourth functional entity after determining the validity of the first routing relationship can refer to the relevant description in S306.
[0311] This embodiment provides a communication method for a first functional entity and a fourth functional entity to autonomously determine the validity of a first routing relationship, so that the first functional entity and the fourth functional entity do not need to request other functional entities to assist in determining the validity of the first routing relationship, thereby reducing signaling loss.
[0312] FIG7 is a schematic diagram of the structure of a communication device provided in one embodiment of the present application. As shown in FIG7 , the communication device 700 may include: a receiving module 710 , a processing module 720 , and a sending module 730 .
[0313] In a possible implementation, the apparatus 700 may be used to implement the various steps / operations performed by the first functional entity in the method shown in FIG. 3 , FIG. 5 , or FIG. 6 .
[0314] As an example, when the device 700 is used to implement the method implemented by the first functional entity in Figure 3, the receiving module 710 can be used to implement the operations performed by the first functional entity in S301 and S303; the sending module 730 can be used to implement the operations performed by the first functional entity in S302.
[0315] When the device 700 is used to implement the method implemented by the first functional entity in Figure 5, the receiving module 710 can be used to implement the operations performed by the first functional entity in S301 and S303; the sending module 730 can be used to implement the operations performed by the first functional entity in S302 and S304.
[0316] When the device 700 is used to implement the method implemented by the first functional entity in Figure 6, the receiving module 710 can be used to implement the operation performed by the first functional entity in S601; the sending module 730 can be used to implement the operation performed by the first functional entity in S603, and the processing module 720 can be used to implement S602.
[0317] In a possible implementation, the apparatus 700 may be used to implement the various steps / operations performed by the second functional entity in the method shown in FIG. 3 , FIG. 5 , or FIG. 6 .
[0318] As an example, when the apparatus 700 is used to implement the method implemented by the second functional entity in FIG. 3 , the sending module 730 may be used to implement the operation performed by the second functional entity in S301 .
[0319] When the apparatus 700 is used to implement the method implemented by the second functional entity in FIG. 5 , the sending module 730 may be used to implement the operation performed by the second functional entity in S301 .
[0320] When the apparatus 700 is used to implement the method implemented by the second functional entity in FIG. 6 , the sending module 730 may be used to implement the operation performed by the second functional entity in S601 .
[0321] In a possible implementation, the apparatus 700 may be used to implement the various steps / operations performed by the third functional entity in the method shown in FIG. 3 or FIG. 5 .
[0322] As an example, when the apparatus 700 is used to implement the method implemented by the third functional entity in FIG. 3 , the receiving module 710 can be used to implement the operation performed by the third functional entity in S302 ; the sending module 730 can be used to implement the operation performed by the third functional entity in S303 .
[0323] When the apparatus 700 is used to implement the method implemented by the third functional entity in FIG. 5 , the receiving module 710 may be used to implement the operation performed by the third functional entity in S302 ; the sending module 730 may be used to implement the operation performed by the third functional entity in S303 .
[0324] In a possible implementation, the apparatus 700 may be used to implement the various steps / operations performed by the fourth functional entity in the method shown in FIG. 5 or FIG. 6 .
[0325] As an example, when the device 700 is used to implement the method implemented by the fourth functional entity in Figure 5, the receiving module 710 can be used to implement the operations performed by the fourth functional entity in S304 and S306; the sending module 730 can be used to implement the operations performed by the fourth functional entity in S305.
[0326] When the apparatus 700 is used to implement the method implemented by the fourth functional entity in FIG. 6 , the receiving module 710 may be used to implement the operation performed by the fourth functional entity in S603 ; and the processing module 720 may be used to implement S604 .
[0327] In a possible implementation, the apparatus 700 may be used to implement the various steps / operations performed by the fifth functional entity in the method shown in FIG. 5 .
[0328] As an example, when the apparatus 700 is used to implement the method implemented by the fifth functional entity in FIG. 5 , the receiving module 710 may be used to implement the operation performed by the fifth functional entity in S305 ; the sending module 730 may be used to implement the operation performed by the fifth functional entity in S306 .
[0329] Figure 8 is a schematic diagram of the structure of a communication device provided by another embodiment of the present application. The device 800 shown in Figure 8 can be used to implement the method performed by the first functional entity, the second functional entity, the third functional entity, the fourth functional entity, or the fifth functional entity in any of the aforementioned embodiments.
[0330] As shown in Figure 8 , the apparatus 800 of this embodiment includes a memory 810, a processor 820, a communication interface 830, and a bus 840. The memory 810, the processor 820, and the communication interface 830 are connected to each other via the bus 840.
[0331] The memory 810 may be a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 810 may store programs. When the program stored in the memory 810 is executed by the processor 820, the processor 820 is configured to execute the steps / operations performed by the first functional entity, the second functional entity, the third functional entity, the fourth functional entity, or the fifth functional entity in any of the aforementioned embodiments.
[0332] The processor 820 can be a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits to execute relevant programs to implement the communication method shown in the method embodiment of the present application.
[0333] The processor 820 may also be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the communication method shown in the embodiment of the present application may be completed by hardware integrated logic circuits in the processor 820 or software instructions.
[0334] The processor 820 may also be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component. The processor 820 may implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor.
[0335] The steps of the method disclosed in conjunction with the embodiments of the present application can be directly embodied as being executed by a hardware decoding processor, or can be executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium mature in the art, such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory 810, and the processor 820 reads the information in the memory 810 and, in combination with its hardware, completes the functions required to be performed by the units included in the communication device of the present application. For example, the various steps / functions performed by the first functional entity, the second functional entity, the third functional entity, the fourth functional entity, or the fifth functional entity in Figures 3, 5, or 6 can be executed.
[0336] Optionally, the memory 810 and the processor 820 may be integrated together.
[0337] The communication interface 830 may use, but is not limited to, a transceiver or other transceiver device to implement communication between the apparatus 800 and other devices or apparatuses.
[0338] The bus 840 may include a path for transmitting information between the various components of the device 800 (eg, the memory 810 , the processor 820 , and the communication interface 830 ).
[0339] Some embodiments of the present application also provide a computer program product that, when executed on a processor, can implement the methods described in the aforementioned embodiments. Some embodiments of the present application also provide a computer-readable storage medium that contains computer instructions that, when executed on a processor, can implement the methods described in the aforementioned embodiments.
[0340] It should be noted that the modules or components shown in the above embodiments may be one or more integrated circuits configured to implement the above methods, such as one or more application specific integrated circuits (ASICs), one or more microprocessors (digital signal processors (DSPs), or one or more field programmable gate arrays (FPGAs). For another example, when a module is implemented by a processing element calling a program code, the processing element may be a general-purpose processor, such as a central processing unit (CPU) or other processor that can call a program code, such as a controller. For another example, these modules may be integrated together and implemented in the form of a system-on-a-chip (SOC).
[0341] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, software modules or any combination thereof. When software is used for implementation, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function according to the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from a website, computer, server or data center to another website, computer, server or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrations. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive (SSD)).
[0342] The term "plurality" in this article refers to two or more. The term "and / or" in this article is merely a description of the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can represent three situations: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in this article generally indicates that the previous and next associated objects are in an "or" relationship; in the formula, the character " / " indicates that the previous and next associated objects are in a "division" relationship. In addition, it should be understood that in the description of this application, words such as "first" and "second" are only used for the purpose of distinguishing the description, and cannot be understood as indicating or implying relative importance, nor can they be understood as indicating or implying order.
[0343] It will be understood that the various numerical numbers involved in the embodiments of the present application are merely distinctions for the convenience of description and are not intended to limit the scope of the embodiments of the present application.
[0344] It can be understood that in the embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
Claims
1. A communication method, characterized in that: The method is applied to a first functional entity, and the method comprises: receiving first information from a second functional entity, where the first information indicates a first routing relationship, where the first routing relationship is a relationship between identification information of the second functional entity and identification information of a first user; The validity of the first routing relationship is determined.
2. The method according to claim 1, characterized in that The determining the validity of the first routing relationship includes: Sending second information to a third functional entity, where the second information is used to request to determine the validity of the first routing relationship; Third information is received from the third functional entity, where the third information indicates the validity of the first routing relationship.
3. The method according to claim 2, characterized in that When the first routing relationship is valid, the third information further includes a routing validity field of the first routing relationship.
4. The method according to claim 1, characterized in that The determining the validity of the first routing relationship includes: Acquire fourth information, where the fourth information includes information obtained by signing the second routing relationship with a key of the first certificate, where the first certificate is a certificate of the second functional entity, and the second routing relationship is a relationship between identification information of the second functional entity and user identification information belonging to the second functional entity; The validity of the first routing relationship is determined based on the fourth information.
5. The method according to claim 4, characterized in that The fourth information also includes the first certificate, and determining the validity of the first routing relationship based on the fourth information includes: determining the validity of the first certificate; When the first certificate is valid, the validity of the first routing relationship is determined based on the first certificate.
6. The method according to claim 5, characterized in that The fourth information also includes a second certificate, where the second certificate is a certificate of the routing domain to which the second functional entity belongs; Wherein, determining the validity of the first certificate includes: determining the validity of the second certificate; When the second certificate is valid, the validity of the first certificate is determined based on the second certificate.
7. The method according to claim 6, characterized in that The determining the validity of the second certificate comprises: The validity of the second certificate is determined based on a root certificate, the second certificate being signed by the root certificate.
8. The method according to any one of claims 4 to 7, characterized in that The second routing relationship further includes a routing validity domain of the second routing relationship.
9. The method according to any one of claims 2 to 8, characterized in that When the first routing relationship is valid, the method further includes: Send fifth information to the fourth functional entity, where the fifth information includes the first user identification information and identification information of the first functional entity.
10. The method according to claim 9, characterized in that The sending the fifth information to the fourth functional entity includes: When the routing validity domain of the first routing relationship is larger than the service domain of the first functional entity, the fifth information is sent to the fourth functional entity.
11. The method according to claim 9 or 10, characterized in that: The fifth information further includes identification information of the second functional entity and / or a routing validity domain of the first routing relationship.
12. A communication method, characterized in that: The method is applied to a second functional entity, and the method comprises: Determine first information, where the first information indicates a first routing relationship, where the first routing relationship is a relationship between identification information of the second functional entity and first user identification information; The first information is sent to a first functional entity.
13. A communication method, characterized in that: The method is applied to a third functional entity, and the method comprises: receiving second information from the first functional entity, where the second information is used to request to determine the validity of a first routing relationship, where the first routing relationship is a relationship between identification information of the second functional entity and identification information of the first user; Sending third information to the first functional entity, where the third information indicates the validity of the first routing relationship.
14. The method according to claim 13, characterized in that When the first routing relationship is valid, the third information further includes a routing validity field of the first routing relationship.
15. The method according to claim 13 or 14, characterized in that The method further comprises: The validity of the first routing relationship is determined.
16. The method according to claim 15, characterized in that The determining the validity of the first routing relationship includes: Acquire sixth information, where the sixth information includes information obtained by signing the second routing relationship with a key of the first certificate, where the first certificate is a certificate of the second functional entity, and the second routing relationship is a relationship between identification information of the second functional entity and user identification information belonging to the second functional entity; The validity of the first routing relationship is determined based on the sixth information.
17. The method according to claim 16, characterized in that The sixth information further includes the first certificate, and determining the validity of the first routing relationship based on the sixth information includes: determining the validity of the first certificate; When the first certificate is valid, the validity of the first routing relationship is determined based on the first certificate.
18. The method according to claim 17, characterized in that The sixth information also includes a second certificate, where the second certificate is a certificate of the routing domain to which the second functional entity belongs; Wherein, determining the validity of the first certificate includes: determining the validity of the second certificate; When the second certificate is valid, the validity of the first certificate is determined based on the second certificate.
19. The method according to claim 18, characterized in that The determining the validity of the second certificate comprises: The validity of the second certificate is determined based on a root certificate, the second certificate being signed by the root certificate.
20. The method according to any one of claims 16 to 19, characterized in that The second routing relationship further includes a routing validity domain of the second routing relationship.
21. A communication method, characterized in that: The method is applied to a fourth functional entity, and the method comprises: receiving fifth information from the first functional entity, where the fifth information indicates a first routing relationship, where the first routing relationship is a relationship between identification information of the second functional entity and identification information of the first user; The validity of the first routing relationship is determined.
22. The method according to claim 21, characterized in that The fifth information also includes a routing validity domain of the first routing relationship.
23. The method according to claim 21 or 22, characterized in that The determining the validity of the first routing relationship includes: Sending seventh information to the fifth functional entity, where the seventh information is used to request to determine the validity of the first routing relationship; Eighth information is received from the fifth functional entity, where the eighth information indicates the validity of the first routing relationship.
24. The method according to claim 23, characterized in that When the first routing relationship is valid, the eighth information further includes a routing validity domain of the first routing relationship.
25. The method according to claim 21 or 22, characterized in that The determining the validity of the first routing relationship includes: Acquire ninth information, where the ninth information includes information obtained by signing the second routing relationship with a key of the first certificate, where the first certificate is a certificate of the second functional entity, and the second routing relationship is a relationship between identification information of the second functional entity and user identification information belonging to the second functional entity; The validity of the first routing relationship is determined based on the ninth information.
26. The method according to claim 25, characterized in that The ninth information further includes the first certificate, and determining the validity of the first routing relationship based on the ninth information includes: determining the validity of the first certificate; When the first certificate is valid, the validity of the first routing relationship is determined based on the first certificate.
27. The method according to claim 26, characterized in that The ninth information also includes a second certificate, where the second certificate is a certificate of the routing domain to which the second functional entity belongs; Wherein, determining the validity of the first certificate includes: determining the validity of the second certificate; When the second certificate is valid, the validity of the first certificate is determined based on the second certificate.
28. The method according to claim 27, characterized in that The determining the validity of the second certificate comprises: The validity of the second certificate is determined based on a root certificate, the second certificate being signed by the root certificate.
29. The method according to any one of claims 25 to 28, characterized in that The second routing relationship further includes a routing validity domain of the second routing relationship.
30. A communication method, characterized in that: The method is applied to a fifth functional entity, and the method comprises: receiving seventh information from the fourth functional entity, where the seventh information is used to request to determine the validity of the first routing relationship, where the first routing relationship is a relationship between the identification information of the second functional entity and the first user identification information; Sending eighth information to the fourth functional entity, where the eighth information indicates the validity of the first routing relationship.
31. The method according to claim 30, characterized in that When the first routing relationship is valid, the eighth information further includes a routing validity domain of the first routing relationship.
32. The method according to claim 30 or 31, characterized in that The method further comprises: The validity of the first routing relationship is determined.
33. The method according to claim 32, characterized in that The determining the validity of the first routing relationship includes: Obtaining tenth information, the tenth information including information obtained by signing the second routing relationship with a key of the first certificate, the first certificate being a certificate of the second functional entity, and the second routing relationship being a relationship between identification information of the second functional entity and user identification information belonging to the second functional entity; The validity of the first routing relationship is determined based on the tenth information.
34. The method according to claim 33, characterized in that The tenth information further includes the first certificate, and determining the validity of the first routing relationship based on the tenth information includes: determining the validity of the first certificate; When the first certificate is valid, the validity of the first routing relationship is determined based on the first certificate.
35. The method according to claim 34, characterized in that The tenth information also includes a second certificate, where the second certificate is a certificate of the routing domain to which the second functional entity belongs; Wherein, determining the validity of the first certificate includes: determining the validity of the second certificate; When the second certificate is valid, the validity of the first certificate is determined based on the second certificate.
36. The method according to claim 35, characterized in that The determining the validity of the second certificate comprises: The validity of the second certificate is determined based on a root certificate, the second certificate being signed by the root certificate.
37. The method according to any one of claims 33 to 36, characterized in that The second routing relationship further includes a routing validity domain of the second routing relationship.
38. A communication system, characterized in that: The invention comprises a communication device for executing the method according to any one of claims 1 to 11 and a communication device for executing the method according to claim 12.
39. The system according to claim 38, characterized in that The system further comprises at least one of the following: A communication device for performing the method according to any one of claims 13 to 20; A communication device for performing the method as claimed in any one of claims 21 to 29; or A communication device for performing the method as claimed in any one of claims 30 to 37.
40. A communication device, characterized in that: The method comprises various functional modules for implementing the method according to any one of claims 1 to 11, claim 12, any one of claims 13 to 20, any one of claims 21 to 29 or any one of claims 30 to 37.
41. A communication device, characterized in that: include: A processor, the processor being coupled to a memory, the memory being used to store a computer program, and when the processor calls the computer program, the device executes the method according to any one of claims 1 to 11, claim 12, any one of claims 13 to 20, any one of claims 21 to 29, or any one of claims 30 to 37.
42. A computer program product, characterized in that The method comprises a computer program code, which, when executed on a computer, causes the computer to implement the method as claimed in any one of claims 1 to 11, claim 12, any one of claims 13 to 20, any one of claims 21 to 29, or any one of claims 30 to 37.
43. A computer readable medium, characterized in that The computer-readable medium stores a program code for computer execution, the program code comprising instructions for executing the method of any one of claims 1 to 11, claim 12, any one of claims 13 to 20, any one of claims 21 to 29, or any one of claims 30 to 37.
Citation Information
Patent Citations
Communication method and communication device
CN120201507A
Secure communication method and device
CN113645621A
Service authorization method, communication device and system
CN114528540A
Methods and apparatus for providing information associated with network function (NF) instances of a 5g mobile network
US20200028920A1
Method and apparatus for authentication between core network devices in mobile communication system
US20220338104A1