Communication method and apparatus

By providing users with attribute endorsement services and smart contracts for blockchain nodes, the problem of lack of attribute information for user identities in the telecommunications network is solved, and security and reliability are improved.

WO2025152988A1PCT designated stage expired Publication Date: 2025-07-24HUAWEI TECH CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/072584
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-17
Filing Date
2025-01-15
Publication Date
2025-07-24

AI Technical Summary

Technical Problem

The user identities in the telecommunications network lack attribute information and cannot apply for attribute information from third parties, resulting in insufficient identity security and the inability to use third-party credibility to enhance security.

Method used

By providing attribute endorsement services to users, assign attribute information and perform access control, blockchain nodes and smart contracts can be used to achieve attribute interoperability and security enhancement.

Benefits of technology

Enhanced the security of telecommunications network services and realize the reliability and security of data access and authorization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025072584_24072025_PF_FP_ABST
    Figure CN2025072584_24072025_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of the present application relate to the field of communications, and provide a communication method and apparatus, which can perform attribute endorsement for nodes, thereby achieving endorsed attribute-based data access control for the nodes. The method comprises: acquiring attribute information, and sending the attribute information to a second node, wherein the attribute information is used for indicating an attribute corresponding to the proved second node.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method and device

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on January 17, 2024, with application number 202410071582.6 and application name “Communication Method and Device”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of communications, and in particular to communication methods and devices. Background Art

[0003] In telecommunications network services, the profiles corresponding to user identifications (IDs) are all strongly related to the services and lack user attribute information. Furthermore, users are unable to request attribute information from the operator or a third party through the operator's network, making the user identity usable only within the telecommunications network. Consequently, the telecommunications network is unable to leverage the credibility of third parties to enhance the security of user identities. Summary of the Invention

[0004] The present application provides a communication method and apparatus, which allocates attribute information to users by providing attribute endorsement services for users, and can control user access based on the attribute information, thereby enhancing the security of telecommunications network services and realizing data access and authorization.

[0005] To achieve the above objectives, this application adopts the following technical solutions:

[0006] In a first aspect, a communication method is provided. The method can be executed by a first node, or by a component of the first node, such as a processor, chip, or chip system of the first node, or by a logic module or software that implements all or part of the first node. The method includes obtaining attribute information and sending the attribute information to a second node, wherein the attribute information indicates a certified attribute corresponding to the second node.

[0007] Based on this communication method, the first node can distribute the attribute information corresponding to the second node to the second node, so that the second node can obtain its attributes certified or endorsed by the first node. As a result, operators or third-party institutions (such as universities, enterprises, banks, functional departments, etc.) can use the credible characteristics to enhance the security of the second node's identity, thereby enhancing the security of telecommunications network services or facilitating the second node to perform related services, such as data access authorization. In this embodiment of the present application, the first node can be a blockchain node or a node for providing attribute endorsement or certification services (such as the fourth node described below).

[0008] In one possible design, obtaining attribute information may include receiving a first request from a second node. The first request is for obtaining the attribute. The attribute information is sent to the second node based on the first request. Based on this design, the first node can be triggered by the second node to obtain the attribute information for the second node. In other words, the second node can proactively request the corresponding certification attribute from the first node based on demand.

[0009] In one possible design, sending attribute information to a second node based on a first request may include: generating attribute information based on the first request using a smart contract, where the smart contract is associated with an attribute endorsement service. Sending the attribute information to the second node. In this design, the first node may be a blockchain node, on which a smart contract related to the attribute endorsement service may be deployed. The first node can then generate attribute information for the second node based on the deployed smart contract. Furthermore, deploying the smart contract related to the attribute endorsement service on a blockchain enables attribute interoperability between nodes providing different attribute endorsement or attestation services, different second nodes, and operator nodes.

[0010] In one possible design, the communication method described in the first aspect may further include: receiving a fifth request from a fourth node, wherein the first request is for requesting installation of a smart contract. Installing the smart contract in accordance with the fifth request. The fourth node is a node providing attribute endorsement or certification services. Thus, if the first node is a blockchain node, the blockchain node can deploy a smart contract related to the attribute endorsement service in accordance with the request of the fourth node.

[0011] In one possible design, installing a smart contract based on a fifth request may include: sending second information to a fourth node based on the fifth request, wherein the second information indicates whether the smart contract installation is supported; and receiving third information from the fourth node, wherein the third information indicates whether the smart contract installation is supported, and the third information is determined based on the second information corresponding to at least one blockchain node on the blockchain. Thus, after receiving the smart contract installation request, the blockchain node may share the installation request with other blockchain nodes on the blockchain. Each blockchain node may then provide feedback to the blockchain node indicating whether it supports the smart contract installation. This allows the fourth node to instruct the blockchain node on whether to install the smart contract based on whether each blockchain node supports the smart contract installation.

[0012] In one possible design, if the first node records the result of whether or not to support smart contract installation on the blockchain, the second information may include the address of the result on the blockchain. Thus, the blockchain node that participates in providing feedback on the second information can publish its feedback on the blockchain, allowing other blockchain nodes to learn whether or not to support smart contract installation.

[0013] In one possible design scheme, the third information may include the result of whether at least one blockchain node on the blockchain supports the installation of the smart contract, and / or the address on the blockchain of the result of whether at least one blockchain node supports the installation of the smart contract.

[0014] In one possible design, the communication method described in the first aspect may further include receiving fourth information from a fourth node, where the fourth information indicates usage information of the smart contract. Thus, after the blockchain node determines that the smart contract has been installed, it may also obtain the usage information of the smart contract from the fourth node, which may be understood as a configuration file corresponding to the smart contract, so that the blockchain node can complete the use of the smart contract based on the usage information.

[0015] In one possible design scheme, the fourth information may include at least one of the following: the attribute endorsement service corresponding to the smart contract, the address of the smart contract, the input parameters of the smart contract, the output parameters of the smart contract, or the application template for attribute information.

[0016] In one possible design, the communication method described in the first aspect may further include: sending attribute information to a blockchain node. Receiving first information from the blockchain node, where the first information indicates the address of the attribute information on the blockchain. Based on this design, the first node may be a node providing attribute endorsement or certification services. Thus, after generating the attribute information, the first node may publish the attribute information on the blockchain so that other nodes can also obtain the corresponding attribute information from the blockchain. Furthermore, the first node may store the address of the attribute information on the blockchain.

[0017] In one possible design, the first request may include at least one of the following: an identifier of the second node, information indicating the type of attribute requested, identity verification information corresponding to the second node, a signature of the third node on the identity verification information corresponding to the second node, or information indicating the content of the attribute requested. In this embodiment of the present application, the third node may be a node used to verify the identity of the second node, such as a device corresponding to a third-party authority.

[0018] In one possible design, the attribute information may include the attribute corresponding to the second node and the signature of a fourth node related to the attribute corresponding to the second node. Thus, the signed attribute of the second node is sent to the second node in the form of attribute information, so that the second node obtains credible attributes.

[0019] In one possible design scheme, the attribute information may also include at least one of the following: the issuance time of the attribute, the validity period of the attribute, the identifier of the second node, or the signature of the blockchain node on the attribute corresponding to the second node.

[0020] In one possible design, the communication method described in the first aspect may further include: sending first information to the second node, where the first information indicates the address of the attribute information on the blockchain. Thus, the first node may also send the address of its corresponding attribute information on the blockchain to the second node, so that the second node can query it or notify other nodes for query, thereby ensuring the authenticity and legitimacy of the attribute.

[0021] In a second aspect, a communication method is provided. This method can be performed by a second node, or by a component of the second node, such as a processor, chip, or chip system of the second node. It can also be implemented by a logic module or software that implements all or part of the second node. The method includes: receiving attribute information from a first node, where the attribute information indicates a certified attribute corresponding to the second node; and determining the attribute corresponding to the second node based on the attribute information.

[0022] In one possible design, the attribute information may include an attribute corresponding to the second node and a signature of a fourth node related to the attribute corresponding to the second node.

[0023] In one possible design scheme, the attribute information may also include at least one of the following: the issuance time of the attribute information, the validity period of the attribute information, the identifier of the second node, or the signature of the blockchain node on the attribute corresponding to the second node.

[0024] In one possible design scheme, the communication method described in the second aspect may also include: receiving first information from the first node, wherein the first information is used to indicate the address of the attribute information on the blockchain.

[0025] In a possible design scheme, the communication method described in the first aspect may further include: sending a first request to the first node, wherein the first request is used to request to obtain the attribute.

[0026] In a third aspect, a communication method is provided. This method can be executed by a blockchain node, or by a component of a blockchain node, such as a processor, chip, or chip system, or by a logic module or software that implements all or part of a blockchain node. The method includes receiving a fifth request from a fourth node, wherein the fifth request is for requesting installation of a smart contract corresponding to an attribute endorsement service supported by the fourth node, and installing the smart contract in accordance with the fifth request.

[0027] In one possible design, installing the smart contract according to the fifth request may include: sending second information to a fourth node according to the fifth request, wherein the second information indicates whether installation of the smart contract is supported; and receiving third information from the fourth node, wherein the third information indicates installation of the smart contract, and the third information is determined based on the second information corresponding to at least one blockchain node on the blockchain.

[0028] In one possible design, when the result of whether the installation of the smart contract is supported is recorded on the blockchain by the blockchain node, the second information may include the address of the result of whether the installation of the smart contract is supported on the blockchain.

[0029] In one possible design scheme, the third information may include the result of whether at least one blockchain node on the blockchain supports the installation of the smart contract, and / or the address on the blockchain of the result of whether at least one blockchain node supports the installation of the smart contract.

[0030] In one possible design scheme, the communication method described in the third aspect may further include: receiving fourth information from a fourth node, wherein the fourth information is used to indicate usage information of the smart contract.

[0031] In one possible design scheme, the fourth information may include at least one of the following: the attribute endorsement service corresponding to the smart contract, the address of the smart contract, the input parameters of the smart contract, the output parameters of the smart contract, or the application template for attribute information.

[0032] A fourth aspect provides a communication method. This method can be executed by a fourth node, or by a component of the fourth node, such as a processor, chip, or system-on-chip, or by a logic module or software that implements all or part of the fourth node. The method includes generating a fifth request and sending the fifth request to a blockchain node. The fifth request is used to request the installation of a smart contract corresponding to an attribute endorsement service supported by the fourth node.

[0033] In one possible design, the communication method described in the fourth aspect may further include: receiving second information from a blockchain node, wherein the second information indicates whether installation of the smart contract is supported; and sending third information to the blockchain node, wherein the third information indicates installation of the smart contract, the third information being determined based on the second information corresponding to at least one blockchain node on the blockchain.

[0034] In one possible design, when the result of whether the installation of the smart contract is supported is recorded on the blockchain by the blockchain node, the second information may include the address of the result of whether the installation of the smart contract is supported on the blockchain.

[0035] In one possible design scheme, the third information may include the result of whether at least one blockchain node on the blockchain supports the installation of the smart contract, and / or the address on the blockchain of the result of whether at least one blockchain node supports the installation of the smart contract.

[0036] In one possible design scheme, the communication method described in the fourth aspect may also include: fourth information to the blockchain node, wherein the fourth information is used to indicate the usage information of the smart contract.

[0037] In one possible design scheme, the fourth information may include at least one of the following: the attribute endorsement service corresponding to the smart contract, the address of the smart contract, the input parameters of the smart contract, the output parameters of the smart contract, or the application template for attribute information.

[0038] In one possible design, the communication method described in the fourth aspect may further include: receiving a first request from a second node, wherein the first request is for requesting to obtain an attribute, and sending attribute information to the second node according to the first request.

[0039] In one possible design, the attribute information may include an attribute corresponding to the second node and a signature of a fourth node related to the attribute corresponding to the second node.

[0040] In one possible design scheme, the attribute information may also include at least one of the following: the issuance time of the attribute, the validity period of the attribute, the identifier of the second node, or the signature of the blockchain node on the attribute corresponding to the second node.

[0041] In one possible design scheme, the communication method described in the fourth aspect may also include: receiving first information from a blockchain node, wherein the first information is used to indicate the address of the attribute information on the blockchain.

[0042] Among them, the description of the technical effects of the methods described in any of the second to fourth aspects can refer to the relevant description of the technical effects of the methods described in the first aspect, and will not be repeated here.

[0043] In a fifth aspect, a communication method is provided. This method can be executed by an operator node, or by a component of the operator node, such as a processor, chip, or chip system of the operator node. It can also be implemented by a logic module or software that implements all or part of the operator node. The method includes: determining whether a first terminal device and a second terminal device are connected to a network corresponding to the operator node. If it is determined that the first terminal device has received a call request from the second terminal device, attributes corresponding to the second terminal device are sent to the first terminal device.

[0044] Based on this communication method, the operator node can introduce the user's proven attributes during the call between users, such as displaying the caller's proven attributes in the user's incoming call interface, to achieve mutual communication of credibility and enhance the security of telecommunications network services.

[0045] In one possible design, the communication method described in aspect 5 may further include: sending a sixth request to the blockchain node, wherein the sixth request is for requesting to obtain attributes corresponding to the second terminal device. Attribute information corresponding to the second terminal device is received from the blockchain node, the attribute information corresponding to the second terminal device including the attributes corresponding to the second terminal device and a signature of a fourth node related to the attributes corresponding to the second terminal device. The operator node can thereby obtain the attribute information corresponding to the second terminal device from the blockchain, thereby displaying the verified attributes of the second terminal device during the call.

[0046] In one possible design scheme, the attribute information corresponding to the second terminal device may also include an identifier of the second terminal device and / or a signature of the blockchain node on the attributes corresponding to the second terminal device.

[0047] In a sixth aspect, a communication method is provided. The method can be executed by a fifth node, or by a component of the fifth node, such as a processor, chip, or chip system of the fifth node, or by a logic module or software that implements all or part of the fifth node. The method includes: receiving a second request from a second node, wherein the second request is for accessing data of the fifth node and includes attribute information corresponding to the second node. Based on the attribute information corresponding to the second node and certification information, determining whether the second node meets the requirements for accessing the data of the fifth node, the certification information being used to verify the attributes corresponding to the second node.

[0048] Based on this communication method, the fifth node can perform data access control on the second node according to the attribute information of the second node, thereby improving the reliability and security of data access and further enhancing the security of the business.

[0049] In one possible design, the second request may also include the blockchain address of the attribute information corresponding to the second node. Based on this address, the fifth node can query the blockchain for the corresponding attribute information and / or certification information to verify the attributes corresponding to the second node, ensuring their authenticity and legitimacy.

[0050] In one possible design, the communication method described in aspect 6 may further include: sending a third request to the blockchain node, wherein the third request is for requesting certification information; and receiving the certification information from the blockchain node.

[0051] In one possible design, the certification information may include credential information of a fourth node related to the attribute corresponding to the second node, for example, a certificate of the fourth node related to the attribute corresponding to the second node.

[0052] In a possible design solution, the certification information may further include: a hash of the attribute corresponding to the second node, and / or the attribute corresponding to the second node.

[0053] In one possible design, receiving the second request from the second node may include: receiving identification information from the second node, where the identification information includes the second node's identifier and a signature of the fourth node associated with the second node's identifier. If the second node's identifier is verified, determining to establish security authentication with the second node. If security authentication is complete, receiving the second request from the second node. Thus, the fifth node and the second node can perform security authentication based on the second node's identifier. Only if security authentication passes can a secure connection be established between the fifth node and the second node to exchange messages or information.

[0054] In one possible design, the communication method described in Aspect 6 may further include: sending data access information to a blockchain node, where the data access information includes information indicating requirements that must be met for the second node to access the fifth node's data and information indicating the need to obtain the fifth node's data. Based on this design, the fifth node may publish information related to its data access on the blockchain for easy access by the second node, thereby enabling data access.

[0055] In one possible design, the communication method described in aspect 6 may further include: if the second node meets requirements for accessing the fifth node's data, sending a first key to the second node, where the first key is determined based on an attribute corresponding to the second node and is used to decrypt the encrypted data of the fifth node. Based on this design, after the fifth node encrypts and stores its data, if it determines that the second node meets the data access requirements, the fifth node may further send a key to the second node to facilitate decryption of the encrypted data by the second node.

[0056] In a possible design, the information for indicating the acquisition of the data of the fifth node may include a storage address where the encrypted data of the fifth node is located, and / or information for indicating the encrypted data of the fifth node.

[0057] In a possible design, the data of the fifth node may be encrypted with a second key, and the information indicating the acquisition of the data of the fifth node may further include: the encrypted second key, and the first key is specifically used to decrypt the encrypted second key.

[0058] In one possible design, the communication method described in aspect 6 may further include: sending the encrypted data of the fifth node to the storage node corresponding to the storage address. Thus, the fifth node stores its encrypted data uniformly at the storage node, thereby reducing signaling overhead compared to the fifth node sending the encrypted data separately to multiple second nodes.

[0059] In one possible design, the communication method described in aspect 6 may further include: sending information indicating the second node's access history to the blockchain node. Thus, the fifth node may also record the second node's access information and publish it on the blockchain, thereby facilitating query access to the second node.

[0060] In one possible design, the attribute information corresponding to the second node may include the attribute corresponding to the second node and the signature of the fourth node associated with the attribute corresponding to the second node.

[0061] In a seventh aspect, a communication method is provided. The method can be executed by a second node, or by a component of the second node, such as a processor, chip, or chip system of the second node, or by a logic module or software that implements all or part of the second node. The method includes generating a second request and sending the second request to a fifth node. The second request is for requesting access to data of the fifth node, and the second request includes attribute information corresponding to the second node.

[0062] In one possible design scheme, the second request may also include the address of the attribute information corresponding to the second node on the blockchain.

[0063] In one possible design, sending the second request to the fifth node may include: establishing security authentication with the fifth node based on the identifier of the second node, and sending the second request to the fifth node after completing the security authentication.

[0064] In a possible design scheme, the communication method described in the seventh aspect may also include: receiving a first key from the fifth node, wherein the first key is determined according to the attribute corresponding to the second node, and the first key is used to decrypt the encrypted data of the fifth node.

[0065] In one possible design, the communication method described in aspect 7 may further include: sending a fourth request to the blockchain node, wherein the fourth request is for requesting information for accessing data of a fifth node; receiving data access information from the blockchain node, the data access information including information indicating requirements that must be met for the second node to access the data of the fifth node and information for instructing the second node to obtain the data of the fifth node; obtaining encrypted data of the fifth node based on the data access information; and decrypting the encrypted data of the fifth node using the first key.

[0066] In a possible design, the information for indicating the acquisition of the data of the fifth node may include a storage address where the encrypted data of the fifth node is located, and / or information for indicating the encrypted data of the fifth node.

[0067] In a possible design, the data of the fifth node may be encrypted with a second key, and the information indicating the acquisition of the data of the fifth node may further include: the encrypted second key, and the first key is specifically used to decrypt the encrypted second key.

[0068] In one possible design, obtaining the encrypted data of the fifth node based on the data access information may include: sending a seventh request to the storage node corresponding to the storage address, wherein the seventh request is for requesting the data of the fifth node; and receiving the encrypted data of the fifth node from the storage node.

[0069] In a possible design, decrypting the encrypted data of the fifth node according to the first key may include: decrypting the encrypted second key according to the first key, and decrypting the encrypted data of the fifth node according to the second key according to the second key.

[0070] In one possible design, the attribute information corresponding to the second node may include the attribute corresponding to the second node and the signature of a fourth node associated with the attribute corresponding to the second node.

[0071] In an eighth aspect, a communication method is provided. This method can be executed by a blockchain node, or by a component of a blockchain node, such as a processor, chip, or chip system of the blockchain node, or by a logic module or software that implements all or part of a blockchain node. The method includes receiving a fourth request from a second node, wherein the fourth request is for obtaining information for accessing data of a fifth node. Information for data access is sent to the second node, wherein the information for data access includes information indicating requirements that must be met for the second node to access the data of the fifth node and information for instructing the second node to obtain the data of the fifth node.

[0072] In one possible design scheme, the communication method described in the eighth aspect may also include: receiving information for data access from the fifth node.

[0073] In a possible design, the information for indicating the acquisition of the data of the fifth node may include a storage address where the encrypted data of the fifth node is located, and / or information for indicating the encrypted data of the fifth node.

[0074] In a possible design, the data of the fifth node may be encrypted using a second key, and the information indicating the acquisition of the data of the fifth node may further include: the encrypted second key.

[0075] In one possible design scheme, the communication method described in the eighth aspect may further include: receiving information from the fifth node for indicating the access record of the second node.

[0076] Among them, the technical effects of the method described in the seventh or eighth aspect can refer to the relevant description of the technical effects of the method described in the sixth aspect above, and will not be elaborated on here.

[0077] In a ninth aspect, a communication method is provided. This method can be executed by a blockchain node, or by a component of a blockchain node, such as a processor, chip, or chip system of the blockchain node, or by a logic module or software that implements all or part of a blockchain node. The method includes: receiving an eighth request from a second node, wherein the eighth request is for invoking a first smart contract, and the first smart contract is for determining whether the second node can access the data of a fifth node. Determining whether the second node can access the data of the fifth node based on the eighth request and the first smart contract.

[0078] Based on this communication method, a blockchain node can invoke a smart contract upon request from a second node and control data access to the second node, thereby improving the reliability and security of data access and, in turn, enhancing business security. The implementation process of deploying the first smart contract on the blockchain node can be found in the relevant implementation of the method described in the third aspect above and is not further elaborated here.

[0079] In one possible design solution, the eighth request may include attribute information corresponding to the second node.

[0080] In one possible design, the attribute information corresponding to the second node may include the attribute corresponding to the second node and a signature of a fourth node related to the attribute corresponding to the second node.

[0081] In a possible design scheme, the communication method described in the ninth aspect may also include: when the second node can access the data of the fifth node, sending a first key to the second node, and the first key is used to decrypt the encrypted data of the fifth node.

[0082] In one possible design scheme, the communication method described in the ninth aspect may also include: receiving information for data access from the fifth node, the information for data access includes information for indicating the requirements that the second node must meet to access the data of the fifth node and information for indicating the acquisition of the data of the fifth node.

[0083] In one possible design, the communication method of aspect 9 may further include: receiving a fourth request from the second node, wherein the fourth request is for requesting information for accessing data of the fifth node; and sending information for data access to the second node.

[0084] In a possible design, the information for indicating the acquisition of the data of the fifth node may include a storage address where the encrypted data of the fifth node is located, and / or information for indicating the encrypted data of the fifth node.

[0085] In a possible design, the data of the fifth node is encrypted with a second key, and the information indicating the acquisition of the data of the fifth node may further include: the encrypted second key.

[0086] In a possible design scheme, the communication method described in the ninth aspect may also include: generating and recording the access status of the fifth node when the second node is able to access the data of the fifth node.

[0087] In a tenth aspect, a communication method is provided. The method can be executed by a second node, or by a component of the second node, such as a processor, chip, or chip system of the second node, or by a logic module or software that implements all or part of the second node. The method includes generating an eighth request and sending the eighth request to a blockchain node. The eighth request is used to request the invocation of a first smart contract, and the first smart contract is used to determine whether the second node can access the data of the fifth node.

[0088] In one possible design solution, the eighth request may include attribute information corresponding to the second node.

[0089] In one possible design, the attribute information corresponding to the second node may include the attribute corresponding to the second node and a signature of a fourth node related to the attribute corresponding to the second node.

[0090] In one possible design scheme, the communication method described in the tenth aspect may also include: receiving a first key from a blockchain node, the first key being used to decrypt the encrypted data of the fifth node.

[0091] In one possible design, the communication method described in Aspect 10 may further include: sending a fourth request to the blockchain node, wherein the fourth request is for requesting information for accessing data of a fifth node. Receiving data access information from the blockchain node, the data access information including information indicating requirements that must be met for the second node to access data of the fifth node and information for instructing the user to obtain the data of the fifth node. Obtaining encrypted data of the fifth node based on the data access information. Decrypting the encrypted data of the fifth node using the first key.

[0092] In a possible design, the information for indicating the acquisition of the data of the fifth node may include a storage address where the encrypted data of the fifth node is located, and / or information for indicating the encrypted data of the fifth node.

[0093] In a possible design, the data of the fifth node is encrypted with a second key, and the information indicating the acquisition of the data of the fifth node may further include: the encrypted second key.

[0094] In one possible design, obtaining the encrypted data of the fifth node based on the data access information may include: sending a seventh request to the storage node corresponding to the storage address, wherein the seventh request is for requesting the data of the fifth node; and receiving the encrypted data of the fifth node from the storage node.

[0095] In a possible design, decrypting the encrypted data of the fifth node according to the first key may include: decrypting the encrypted second key according to the first key, and decrypting the encrypted data of the fifth node according to the second key according to the second key.

[0096] Among them, the technical effects of the method described in the ninth or tenth aspect can refer to the relevant description of the technical effects of the method described in the sixth aspect above, and will not be elaborated on here.

[0097] In an eleventh aspect, a communication device is provided for implementing the various methods described above. The communication device may be the first node described in the first aspect, or a device comprising the first node, or a device included in the first node, such as a chip. The communication device includes corresponding modules, units, or means for implementing the method described in the first aspect. The modules, units, or means may be implemented in hardware, software, or by executing corresponding software implementations in hardware. The hardware or software includes one or more modules or units corresponding to the above functions.

[0098] In some possible designs, the communication device includes: a processing module and a transceiver module. The processing module is configured to obtain attribute information. The transceiver module is configured to send the attribute information to the second node, wherein the attribute information indicates an attribute corresponding to the certified second node.

[0099] In one possible design, the processing module for obtaining attribute information may include: a processing module for controlling the transceiver module to receive a first request from the second node, wherein the first request is for obtaining the attribute; and a processing module for controlling the transceiver module to send the attribute information to the second node based on the first request.

[0100] In one possible design, the processing module, configured to control the transceiver module to send attribute information to the second node based on the first request, may include: a processing module configured to generate attribute information based on the first request using a smart contract, where the smart contract is associated with an attribute endorsement service; and a processing module configured to control the transceiver module to send the attribute information to the second node.

[0101] In one possible design, the transceiver module is further configured to receive a fifth request from the fourth node, the fifth request being for requesting installation of the smart contract. The processing module is further configured to install the smart contract according to the fifth request.

[0102] In one possible design, the processing module is further configured to install the smart contract based on the fifth request, and may include: a processing module configured to control the transceiver module to send second information to the first node based on the fifth request, wherein the second information indicates whether the installation of the smart contract is supported; and a processing module configured to control the transceiver module to receive third information from the fourth node, wherein the third information indicates the installation of the smart contract, and the third information is determined based on the second information corresponding to at least one blockchain node on the blockchain.

[0103] In one possible design, when the result of whether the installation of the smart contract is supported is recorded on the blockchain by the first node, the second information may include the address of the result of whether the installation of the smart contract is supported on the blockchain.

[0104] In one possible design scheme, the third information may include the result of whether at least one blockchain node on the blockchain supports the installation of the smart contract, and / or the address on the blockchain of the result of whether at least one blockchain node supports the installation of the smart contract.

[0105] In one possible design scheme, the transceiver module is also used to receive fourth information from the first node, where the fourth information is used to indicate usage information of the smart contract.

[0106] In one possible design scheme, the fourth information may include at least one of the following: the attribute endorsement service corresponding to the smart contract, the address of the smart contract, the input parameters of the smart contract, the output parameters of the smart contract, or the application template for attribute information.

[0107] In one possible design, the transceiver module is further configured to send attribute information to the blockchain node. The transceiver module is further configured to receive first information from the blockchain node, wherein the first information is configured to indicate an address of the attribute information on the blockchain.

[0108] In one possible design scheme, the first request may include at least one of the following: the identifier of the second node, information indicating the type of attribute requested, identity information corresponding to the second node, or the signature of the third node on the identity information corresponding to the second node.

[0109] In one possible design, the attribute information may include an attribute corresponding to the second node and a signature of a fourth node related to the attribute corresponding to the second node.

[0110] In one possible design scheme, the attribute information may also include at least one of the following: the issuance time of the attribute, the validity period of the attribute, the identifier of the second node, or the signature of the blockchain node on the attribute corresponding to the second node.

[0111] In one possible design scheme, the transceiver module is also used to send first information to the second node, where the first information is used to indicate the address of the attribute information on the blockchain.

[0112] In one possible design solution, the transceiver module may include a receiving module and a sending module, wherein the sending module is used to implement the sending function of the communication device described in the eleventh aspect, and the receiving module is used to implement the receiving function of the communication device described in the eleventh aspect.

[0113] In a possible design solution, the communication device described in the eleventh aspect may further include a storage module, wherein the storage module stores a program or instruction. When the processing module executes the program or instruction, the communication device described in the eleventh aspect may execute the method described in the first aspect.

[0114] In the twelfth aspect, a communication device is provided for implementing the various methods described above. The communication device may be the second node described in the second aspect, or a device comprising the second node, or a device included in the second node, such as a chip. The communication device includes corresponding modules, units, or means for implementing the method described in the second aspect. The modules, units, or means may be implemented in hardware, software, or by executing corresponding software implementations in hardware. The hardware or software includes one or more modules or units corresponding to the above functions.

[0115] In some possible designs, the communication device includes a processing module and a transceiver module. The transceiver module is configured to receive attribute information from a first node, wherein the attribute information indicates an attribute corresponding to a certified second node. The processing module is configured to determine an attribute corresponding to the second node based on the attribute information.

[0116] In one possible design, the attribute information may include an attribute corresponding to the second node and a signature of a fourth node related to the attribute corresponding to the second node.

[0117] In one possible design scheme, the attribute information may also include at least one of the following: the issuance time of the attribute, the validity period of the attribute, the identifier of the second node, or the signature of the blockchain node on the attribute corresponding to the second node.

[0118] In one possible design scheme, the transceiver module is also used to receive first information from the first node, wherein the first information is used to indicate the address of the attribute information on the blockchain.

[0119] In a possible design solution, the transceiver module is further configured to send a first request to the first node, where the first request is used to request to obtain an attribute.

[0120] In one possible design solution, the transceiver module may include a receiving module and a sending module, wherein the sending module is used to implement the sending function of the communication device described in aspect 12, and the receiving module is used to implement the receiving function of the communication device described in aspect 12.

[0121] In one possible design solution, the communication device described in aspect 12 may further include a storage module, wherein the storage module stores a program or instruction. When the processing module executes the program or instruction, the communication device described in aspect 12 may execute the method described in aspect 2.

[0122] In the thirteenth aspect, a communication device is provided for implementing the various methods described above. The communication device may be the blockchain node described in the third aspect, or a device comprising the blockchain node, or a device included in the blockchain node, such as a chip. The communication device includes corresponding modules, units, or means for implementing the method described in the third aspect. The modules, units, or means may be implemented in hardware, software, or by hardware executing corresponding software implementations. The hardware or software includes one or more modules or units corresponding to the above functions.

[0123] In some possible designs, the communication device includes a processing module and a transceiver module. The transceiver module is configured to receive a fifth request from a fourth node, wherein the fifth request is configured to request installation of a smart contract corresponding to an attribute endorsement service supported by the fourth node. The processing module is configured to install the smart contract according to the fifth request.

[0124] In one possible design, the processing module, configured to install the smart contract based on the fifth request, may include: a processing module configured to control the transceiver module to send second information to the fourth node based on the fifth request, wherein the second information indicates whether the smart contract installation is supported; and a processing module configured to control the transceiver module to receive third information from the fourth node, wherein the third information indicates the installation of the smart contract, and the third information is determined based on the second information corresponding to at least one blockchain node on the blockchain.

[0125] In one possible design, when the result of whether the installation of the smart contract is supported is recorded on the blockchain by the blockchain node, the second information may include the address of the result of whether the installation of the smart contract is supported on the blockchain.

[0126] In one possible design scheme, the third information may include the result of whether at least one blockchain node on the blockchain supports the installation of the smart contract, and / or the address on the blockchain of the result of whether at least one blockchain node supports the installation of the smart contract.

[0127] In one possible design scheme, the transceiver module is also used to receive fourth information from the first node, where the fourth information is used to indicate usage information of the smart contract.

[0128] In one possible design scheme, the fourth information may include at least one of the following: the attribute endorsement service corresponding to the smart contract, the address of the smart contract, the input parameters of the smart contract, the output parameters of the smart contract, or the application template for attribute information.

[0129] In one possible design solution, the transceiver module may include a receiving module and a sending module, wherein the sending module is used to implement the sending function of the communication device described in the thirteenth aspect, and the receiving module is used to implement the receiving function of the communication device described in the thirteenth aspect.

[0130] In one possible design solution, the communication device described in the thirteenth aspect may further include a storage module, wherein the storage module stores a program or instruction. When the processing module executes the program or instruction, the communication device described in the thirteenth aspect may execute the method described in the third aspect.

[0131] In a fourteenth aspect, a communication device is provided for implementing the various methods described above. The communication device may be the fourth node described in the fourth aspect, or a device comprising the fourth node, or a device included in the fourth node, such as a chip. The communication device includes corresponding modules, units, or means for implementing the method described in the fourth aspect. The modules, units, or means may be implemented in hardware, software, or by executing corresponding software implementations in hardware. The hardware or software includes one or more modules or units corresponding to the above functions.

[0132] In some possible designs, the communication device includes a processing module and a transceiver module. The processing module is configured to generate a fifth request. The fifth request is configured to request installation of a smart contract corresponding to an attribute endorsement service supported by a fourth node. The transceiver module is configured to send the fifth request to a blockchain node.

[0133] In one possible design, the transceiver module is further configured to receive second information from a blockchain node, where the second information indicates whether smart contract installation is supported. The transceiver module is further configured to send third information to the blockchain node, where the third information indicates the installation of the smart contract, and the third information is determined based on the second information corresponding to at least one blockchain node on the blockchain.

[0134] In one possible design, when the result of whether the installation of the smart contract is supported is recorded on the blockchain by the blockchain node, the second information may include the address of the result of whether the installation of the smart contract is supported on the blockchain.

[0135] In one possible design scheme, the third information may include the result of whether at least one blockchain node on the blockchain supports the installation of the smart contract, and / or the address on the blockchain of the result of whether at least one blockchain node supports the installation of the smart contract.

[0136] In one possible design scheme, the transceiver module is also used to send fourth information to the blockchain node, where the fourth information is used to indicate usage information of the smart contract.

[0137] In one possible design scheme, the fourth information may include at least one of the following: an attribute endorsement service corresponding to the smart contract, an address of the smart contract, an input parameter of the smart contract, or an output parameter of the smart contract.

[0138] In one possible design, the transceiver module is further configured to receive a first request from the second node, wherein the first request is for obtaining an attribute, and to send attribute information to the second node according to the first request.

[0139] In one possible design, the attribute information may include an attribute corresponding to the second node and a signature of a fourth node related to the attribute corresponding to the second node.

[0140] In one possible design scheme, the attribute information may also include at least one of the following: the issuance time of the attribute, the validity period of the attribute, the identifier of the second node, or the signature of the blockchain node on the attribute corresponding to the second node.

[0141] In one possible design scheme, the transceiver module is also used to receive first information from the blockchain node, wherein the first information is used to indicate the address of the attribute information on the blockchain.

[0142] In one possible design solution, the transceiver module may include a receiving module and a sending module, wherein the sending module is used to implement the sending function of the communication device described in aspect 14, and the receiving module is used to implement the receiving function of the communication device described in aspect 14.

[0143] In one possible design solution, the communication device described in aspect 14 may further include a storage module, wherein the storage module stores a program or instruction. When the processing module executes the program or instruction, the communication device described in aspect 14 may execute the method described in aspect 4.

[0144] In the fifteenth aspect, a communication device is provided for implementing the various methods described above. The communication device may be the operator node described in the fifth aspect, or a device comprising the operator node described above, or a device included in the operator node described above, such as a chip. The communication device includes corresponding modules, units, or means for implementing the method described in the fifth aspect. The modules, units, or means may be implemented in hardware, software, or by executing corresponding software implementations in hardware. The hardware or software includes one or more modules or units corresponding to the above functions.

[0145] In some possible designs, the communication device includes a processing module and a transceiver module. The processing module is configured to determine whether the first terminal device and the second terminal device access a network corresponding to an operator node. Upon determining that the first terminal device receives a call request from the second terminal device, the transceiver module is configured to send attributes corresponding to the second terminal device to the first terminal device.

[0146] In one possible design, the transceiver module is further configured to send a sixth request to the blockchain node, wherein the sixth request is configured to request to obtain attributes corresponding to the second terminal device. The transceiver module is further configured to receive attribute information corresponding to the second terminal device from the blockchain node, wherein the attribute information corresponding to the second terminal device includes the attributes corresponding to the second terminal device and a signature of a fourth node related to the attributes corresponding to the second terminal device.

[0147] In one possible design scheme, the attribute information corresponding to the second terminal device may also include an identifier of the second terminal device and / or a signature of the blockchain node on the attributes corresponding to the second terminal device.

[0148] In one possible design solution, the transceiver module may include a receiving module and a sending module, wherein the sending module is used to implement the sending function of the communication device described in aspect 15, and the receiving module is used to implement the receiving function of the communication device described in aspect 15.

[0149] In one possible design solution, the communication device described in aspect 15 may further include a storage module, wherein the storage module stores a program or instruction. When the processing module executes the program or instruction, the communication device described in aspect 15 may execute the method described in aspect 5.

[0150] In a sixteenth aspect, a communication device is provided for implementing the various methods described above. The communication device may be the fifth node described in the sixth aspect, or a device comprising the fifth node, or a device included in the fifth node, such as a chip. The communication device includes corresponding modules, units, or means for implementing the method described in the sixth aspect. The modules, units, or means may be implemented in hardware, software, or by hardware executing corresponding software implementations. The hardware or software includes one or more modules or units corresponding to the above functions.

[0151] In some possible designs, the communication device includes: a processing module and a transceiver module. The transceiver module is configured to receive a second request from a second node, wherein the second request is for accessing data of a fifth node and includes attribute information corresponding to the second node. The processing module is configured to determine whether the second node meets requirements for accessing the data of the fifth node based on the attribute information corresponding to the second node and certification information, wherein the certification information is used to verify the attributes corresponding to the second node.

[0152] In one possible design scheme, the second request may also include the address of the attribute information corresponding to the second node on the blockchain.

[0153] In one possible design, the transceiver module is further configured to send a third request to the blockchain node, wherein the third request is configured to request certification information. The certification information is received from the blockchain node.

[0154] In one possible design, the certification information may include credential information of a fourth node related to an attribute corresponding to the second node.

[0155] In a possible design solution, the certification information may further include: a hash of the attribute corresponding to the second node, and / or the attribute corresponding to the second node.

[0156] In one possible design, the transceiver module for receiving the second request from the second node may include: a transceiver module for receiving identification information from the second node, wherein the identification information includes the second node's identifier and a signature of the first node associated with the second node's identifier. If the second node's identifier is verified, the transceiver module is controlled by the processing module to determine whether to establish security authentication with the second node. If security authentication is complete, the transceiver module is configured to receive the second request from the second node.

[0157] In one possible design scheme, the transceiver module is also used to send information for data access to the blockchain node, wherein the information for data access includes information for indicating requirements that the second node must meet to access the data of the fifth node and information for indicating how to obtain the data of the fifth node.

[0158] In one possible design scheme, the transceiver module is also used to send a first key to the second node when the second node meets the requirements for accessing the data of the fifth node, wherein the first key is determined based on the attributes corresponding to the second node, and the first key is used to decrypt the encrypted data of the fifth node.

[0159] In a possible design, the information for indicating the acquisition of the data of the fifth node may include a storage address where the encrypted data of the fifth node is located, and / or information for indicating the encrypted data of the fifth node.

[0160] In a possible design, the data of the fifth node may be encrypted with a second key, and the information indicating the acquisition of the data of the fifth node may further include: the encrypted second key, and the first key is specifically used to decrypt the encrypted second key.

[0161] In a possible design solution, the transceiver module is further configured to send the encrypted data of the fifth node to the storage node corresponding to the storage address.

[0162] In one possible design scheme, the transceiver module is also used to send information indicating the access record of the second node to the blockchain node.

[0163] In one possible design, the attribute information corresponding to the second node may include the attribute corresponding to the second node and the signature of the fourth node associated with the attribute corresponding to the second node.

[0164] In one possible design solution, the transceiver module may include a receiving module and a sending module, wherein the sending module is used to implement the sending function of the communication device described in aspect 16, and the receiving module is used to implement the receiving function of the communication device described in aspect 16.

[0165] In one possible design solution, the communication device described in aspect 16 may further include a storage module, wherein the storage module stores a program or instruction. When the processing module executes the program or instruction, the communication device described in aspect 16 may execute the method described in aspect 6.

[0166] In the seventeenth aspect, a communication device is provided for implementing the various methods described above. The communication device may be the second node in the seventh aspect, or a device comprising the second node, or a device included in the second node, such as a chip. The communication device includes corresponding modules, units, or means for implementing the method described in the seventh aspect. The modules, units, or means may be implemented by hardware, software, or by hardware executing corresponding software implementations. The hardware or software includes one or more modules or units corresponding to the above functions.

[0167] In some possible designs, the communication device includes: a processing module and a transceiver module. The processing module is configured to generate a second request. The second request is configured to request access to data of a fifth node, and the second request includes attribute information corresponding to the second node. The transceiver module is configured to send the second request to the fifth node.

[0168] In one possible design scheme, the second request may also include the address of the attribute information corresponding to the second node on the blockchain.

[0169] In one possible design, the transceiver module, configured to send the second request to the fifth node, may include: a transceiver module, controlled by the processing module, configured to establish security authentication with the fifth node based on the identifier of the second node. Upon completion of security authentication, the transceiver module is configured to send the second request to the fifth node.

[0170] In one possible design, the transceiver module is further configured to receive a first key from the fifth node, wherein the first key is determined based on an attribute corresponding to the second node, and the first key is used to decrypt the encrypted data of the fifth node.

[0171] In one possible design, the transceiver module is further configured to send a fourth request to the blockchain node, wherein the fourth request is configured to request information for accessing data of a fifth node. The transceiver module is further configured to receive data access information from the blockchain node, wherein the data access information includes information indicating requirements that must be met for the second node to access the data of the fifth node and information for instructing the second node to obtain the data of the fifth node. The processing module is further configured to obtain the encrypted data of the fifth node based on the data access information. The processing module is further configured to decrypt the encrypted data of the fifth node using the first key.

[0172] In a possible design, the information for indicating the acquisition of the data of the fifth node may include a storage address where the encrypted data of the fifth node is located, and / or information for indicating the encrypted data of the fifth node.

[0173] In a possible design, the data of the fifth node may be encrypted with a second key, and the information indicating the acquisition of the data of the fifth node may further include: the encrypted second key, and the first key is specifically used to decrypt the encrypted second key.

[0174] In one possible design, the processing module is further configured to obtain the encrypted data of the fifth node based on the data access information, and may include: a processing module configured to control the transceiver module to send a seventh request to the storage node corresponding to the storage address, wherein the seventh request is for obtaining the data of the fifth node; and a processing module configured to control the transceiver module to receive the encrypted data of the fifth node from the storage node.

[0175] In one possible design scheme, the processing module, used to control the transceiver module to decrypt the encrypted data of the fifth node according to the first key, may include: a processing module, used to control the transceiver module to decrypt the encrypted second key according to the first key, and decrypt the data of the fifth node encrypted by the second key according to the second key.

[0176] In one possible design, the attribute information corresponding to the second node may include the attribute corresponding to the second node and the signature of a fourth node associated with the attribute corresponding to the second node.

[0177] In one possible design solution, the transceiver module may include a receiving module and a sending module, wherein the sending module is used to implement the sending function of the communication device described in aspect 17, and the receiving module is used to implement the receiving function of the communication device described in aspect 17.

[0178] In one possible design solution, the communication device described in aspect 17 may further include a storage module, wherein the storage module stores a program or instruction. When the processing module executes the program or instruction, the communication device described in aspect 17 may execute the method described in aspect 7.

[0179] In aspect 18, a communication device is provided for implementing the various methods described above. The communication device may be the blockchain node described in aspect 8 above, or a device comprising the blockchain node described above, or a device included in the blockchain node described above, such as a chip. The communication device includes corresponding modules, units, or means for implementing the method described in aspect 8 above. The modules, units, or means may be implemented in hardware, software, or by hardware executing corresponding software implementations. The hardware or software includes one or more modules or units corresponding to the above functions.

[0180] In some possible designs, the communication device includes: a processing module and a transceiver module. The processing module is configured to control the transceiver module to receive a fourth request from the second node, wherein the fourth request is for requesting information for accessing data of a fifth node. The processing module is configured to control the transceiver module to send information for data access to the second node, wherein the information for data access includes information indicating requirements that must be met for the second node to access the data of the fifth node and information for instructing the second node to obtain the data of the fifth node.

[0181] In one possible design, the transceiver module is configured to receive information for data access from the fifth node.

[0182] In a possible design, the information for indicating the acquisition of the data of the fifth node may include a storage address where the encrypted data of the fifth node is located, and / or information for indicating the encrypted data of the fifth node.

[0183] In a possible design, the data of the fifth node may be encrypted using a second key, and the information indicating the acquisition of the data of the fifth node may further include: the encrypted second key.

[0184] In one possible design, the transceiver module is further configured to receive information indicating an access record of the second node from a fifth node.

[0185] In one possible design solution, the transceiver module may include a receiving module and a sending module, wherein the sending module is used to implement the sending function of the communication device described in aspect 18, and the receiving module is used to implement the receiving function of the communication device described in aspect 18.

[0186] In one possible design solution, the communication device described in aspect 18 may further include a storage module, wherein the storage module stores a program or instruction. When the processing module executes the program or instruction, the communication device described in aspect 18 may execute the method described in aspect 8.

[0187] In the nineteenth aspect, a communication device is provided for implementing the various methods described above. The communication device may be the blockchain node described in the ninth aspect, or a device comprising the blockchain node, or a device contained in the blockchain node, such as a chip. The communication device includes corresponding modules, units, or means for implementing the method described in the ninth aspect. The modules, units, or means may be implemented in hardware, software, or by hardware executing corresponding software implementations. The hardware or software includes one or more modules or units corresponding to the above functions.

[0188] In some possible designs, the communication device includes: a processing module and a transceiver module. The transceiver module is configured to receive an eighth request from the second node, wherein the eighth request is configured to request the invocation of a first smart contract, and the first smart contract is configured to determine whether the second node can access the data of the fifth node. The processing module is configured to determine whether the second node can access the data of the fifth node based on the eighth request and the first smart contract.

[0189] In one possible design solution, the eighth request may include attribute information corresponding to the second node.

[0190] In one possible design, the attribute information corresponding to the second node may include the attribute corresponding to the second node and a signature of a fourth node related to the attribute corresponding to the second node.

[0191] In one possible design, the transceiver module is further configured to send a first key to the second node when the second node can access the data of the fifth node, where the first key is used to decrypt the encrypted data of the fifth node.

[0192] In one possible design scheme, the transceiver module is also used to receive information for data access from the fifth node, and the information for data access includes information for indicating requirements that the second node must meet to access the data of the fifth node and information for indicating how to obtain the data of the fifth node.

[0193] In one possible design, the transceiver module is further configured to receive a fourth request from the second node, wherein the fourth request is for requesting information for accessing data of the fifth node. The transceiver module is further configured to send information for data access to the second node.

[0194] In a possible design, the information for indicating the acquisition of the data of the fifth node may include a storage address where the encrypted data of the fifth node is located, and / or information for indicating the encrypted data of the fifth node.

[0195] In a possible design, the data of the fifth node is encrypted with a second key, and the information indicating the acquisition of the data of the fifth node may further include: the encrypted second key.

[0196] In a possible design solution, the processing module is further configured to generate and record access information of the fifth node when the second node is able to access data of the fifth node.

[0197] In one possible design solution, the transceiver module may include a receiving module and a sending module, wherein the sending module is used to implement the sending function of the communication device described in aspect 19, and the receiving module is used to implement the receiving function of the communication device described in aspect 19.

[0198] In one possible design solution, the communication device described in aspect 19 may further include a storage module, wherein the storage module stores a program or instruction. When the processing module executes the program or instruction, the communication device described in aspect 19 can execute the method described in aspect 9.

[0199] In the twentieth aspect, a communication device is provided for implementing the various methods described above. The communication device may be the second node described in the tenth aspect, or a device comprising the second node, or a device included in the second node, such as a chip. The communication device includes corresponding modules, units, or means for implementing the method described in the tenth aspect. The modules, units, or means may be implemented by hardware, software, or by executing corresponding software implementations in hardware. The hardware or software includes one or more modules or units corresponding to the above functions.

[0200] In some possible designs, the communication device includes: a processing module and a transceiver module. The processing module is configured to generate an eighth request. The eighth request is configured to request the invocation of a first smart contract, which is configured to determine whether the second node can access the data of the fifth node. The transceiver module is configured to send the eighth request to the blockchain node.

[0201] In one possible design solution, the eighth request may include attribute information corresponding to the second node.

[0202] In one possible design, the attribute information corresponding to the second node may include the attribute corresponding to the second node and a signature of a fourth node related to the attribute corresponding to the second node.

[0203] In one possible design scheme, the transceiver module is also used to receive a first key from a blockchain node, and the first key is used to decrypt the encrypted data of the fifth node.

[0204] In one possible design, the transceiver module is further configured to send a fourth request to the blockchain node, wherein the fourth request is configured to request information for accessing data of a fifth node. The transceiver module is further configured to receive data access information from the blockchain node, wherein the data access information includes information indicating requirements that must be met for the second node to access the data of the fifth node and information for instructing the second node to obtain the data of the fifth node. The processing module is further configured to obtain the encrypted data of the fifth node based on the data access information. The processing module is further configured to decrypt the encrypted data of the fifth node using the first key.

[0205] In a possible design, the information for indicating the acquisition of the data of the fifth node may include a storage address where the encrypted data of the fifth node is located, and / or information for indicating the encrypted data of the fifth node.

[0206] In a possible design, the data of the fifth node is encrypted with a second key, and the information indicating the acquisition of the data of the fifth node may further include: the encrypted second key.

[0207] In one possible design, the processing module is further configured to obtain the encrypted data of the fifth node based on the data access information, and may include: a processing module configured to control the transceiver module to send a seventh request to the storage node corresponding to the storage address, wherein the seventh request is for obtaining the data of the fifth node; and a processing module configured to control the transceiver module to receive the encrypted data of the fifth node from the storage node.

[0208] In one possible design, the processing module is further configured to decrypt the encrypted data of the fifth node using the first key, and may include: a processing module configured to decrypt the encrypted second key using the first key; and a processing module configured to decrypt the encrypted data of the fifth node using the second key using the second key.

[0209] In one possible design solution, the transceiver module may include a receiving module and a sending module, wherein the sending module is used to implement the sending function of the communication device described in aspect 20, and the receiving module is used to implement the receiving function of the communication device described in aspect 20.

[0210] In one possible design solution, the communication device described in aspect 20 may further include a storage module, wherein the storage module stores a program or instruction. When the processing module executes the program or instruction, the communication device described in aspect 20 may execute the method described in aspect 10.

[0211] In a twenty-first aspect, a communication device (for example, a chip or a chip system) is provided. The communication device includes a processor configured to implement the functions of any one of the first to tenth aspects.

[0212] In one possible design, the communication device may further include a memory for storing necessary program instructions and data. A processor is coupled to the memory, and the processor is configured to execute a computer program or instruction stored in the memory, causing the communication device to perform the method described in any one of aspects 1 to 10 above.

[0213] In one possible design solution, the communication device described in aspect 21 may further include a transceiver. The transceiver may be a transceiver circuit or an interface circuit. The transceiver may be used for the communication device described in aspect 21 to communicate with other communication devices.

[0214] In one possible design, the processor can be integrated with the memory.

[0215] In some possible designs, when the device is a chip system, it can be composed of a chip or include a chip and other discrete devices.

[0216] In aspect 22, a communication device is provided, which includes a processor and an interface circuit, the interface circuit being used to receive signals from other communication devices outside the communication device and transmit them to the processor or send signals from the processor to other communication devices outside the communication device, and the processor being used to implement the method described in any one of aspects 1 to 10 above through logic circuits or executing code instructions.

[0217] In aspect 23, a communication device is provided. The communication device may be a first node, or a module or unit (e.g., a chip, or a chip system, or a circuit) in the first node that corresponds to the method / operation / step / action described in aspect 1, or a communication device capable of being used in conjunction with the first node. Alternatively, the communication device may be a second node, or a module or unit (e.g., a chip, or a chip system, or a circuit) in the second node that corresponds to the method / operation / step / action described in aspect 2, aspect 7, or aspect 10, or a communication device capable of being used in conjunction with the second node. Alternatively, the communication device may be a first node, or a module or unit (e.g., a chip, or a chip system, or a circuit) in the first node that corresponds to the method / operation / step / action described in aspect 4, or a communication device capable of being used in conjunction with the first node. Alternatively, the communication device may be a blockchain node, or a module or unit (e.g., a chip, or a chip system, or a circuit) in the blockchain node that corresponds to the method / operation / step / action described in aspect 3, aspect 8, or aspect 9, or a communication device capable of being used in conjunction with the blockchain node. Alternatively, the communication device may be an operator node, or a module or unit (e.g., a chip, or a chip system, or a circuit) in an operator node that corresponds one-to-one to the method / operation / step / action described in the fifth aspect, or may be used in conjunction with an operator node. Alternatively, the communication device may be a fifth node, or a module or unit (e.g., a chip, or a chip system, or a circuit) in a fifth node that corresponds one-to-one to the method / operation / step / action described in the sixth aspect, or may be used in conjunction with a fifth node.

[0218] It can be understood that when the communication device provided in any one of aspects 21 to 23 is a chip, the above-mentioned sending action / function can be understood as output, and the above-mentioned receiving action / function can be understood as input.

[0219] In the twenty-fourth aspect, a communication chip is provided, in which instructions are stored. When the communication chip runs on a communication device, the method described in any one of the first to tenth aspects above is implemented.

[0220] In aspect 25, a computer-readable storage medium is provided, which stores a computer program or instruction. When the computer-readable storage medium is run on a communication device, the communication device can execute the method described in any one of aspects 1 to 10 above.

[0221] In aspect twenty-six, a computer program product comprising instructions is provided, including computer program code, which, when the computer program code is run on a communication device, enables the communication device to execute the method described in any one of aspects one to ten.

[0222] In aspect twenty-seven, a communication system is provided, comprising: a communication device for implementing the method described in the first aspect above and a communication device for implementing the method described in the second aspect above.

[0223] In aspect twenty-eight, a communication system is provided, comprising: a communication device for implementing the method described in aspect three and a communication device for implementing the method described in aspect four.

[0224] In the twenty-ninth aspect, a communication system is provided, comprising: a communication device for implementing the method described in the fifth aspect above.

[0225] In the 30th aspect, a communication system is provided, comprising: a communication device for implementing the method described in the sixth aspect above, a communication device for implementing the method described in the seventh aspect above, and a communication device for implementing the method described in the eighth aspect above.

[0226] In the thirty-first aspect, a communication system is provided, comprising: a communication device for implementing the method described in the ninth aspect and a communication device for implementing the method described in the tenth aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0227] FIG1 is a schematic diagram of the architecture of a communication system provided in an embodiment of the present application;

[0228] FIG2 is a flow chart of a communication method provided in an embodiment of the present application;

[0229] FIG3 is a flow chart of another communication method provided in an embodiment of the present application;

[0230] FIG4 is a flow chart of another communication method provided in an embodiment of the present application;

[0231] FIG5 is a flow chart of another communication method provided in an embodiment of the present application;

[0232] FIG6 is a flow chart of another communication method provided in an embodiment of the present application;

[0233] FIG7 is a flow chart of another communication method provided in an embodiment of the present application;

[0234] FIG8 is a schematic structural diagram of a communication device provided in an embodiment of the present application;

[0235] FIG9 is a schematic structural diagram of another communication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0236] The embodiments of the present application will present various aspects, embodiments, or features around a system that may include multiple devices, components, modules, etc. It should be understood and appreciated that each system may include additional devices, components, modules, etc., and / or may not include all of the devices, components, modules, etc. discussed in conjunction with the figures. Furthermore, combinations of these solutions may also be used.

[0237] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as wireless fidelity (Wi-Fi) systems, vehicle to everything (V2X) communication systems, device-to-device (D2D) communication systems, Internet of Vehicles communication systems, world-wide interoperability for microwave access (WiMAX) communication systems, fourth-generation (4G) mobile communication systems, such as long-term evolution (LTE) systems, world-wide interoperability for microwave access (WiMAX) communication systems, 5G (fifth generation, 5G) mobile communication systems, such as new radio (NR) systems, and future communication systems, such as sixth-generation (6G) mobile communication systems.

[0238] For ease of understanding, the technical terms involved in the embodiments of this application are first introduced below.

[0239] 1. Blockchain: A distributed ledger that integrates cryptography, peer-to-peer (P2P) networks, and distributed databases. As an open and transparent decentralized technology, blockchain transforms traditional authority and centralized trust into group consensus and decentralized trust, respectively, creating a tamper-proof distributed ledger secured by cryptography.

[0240] 2. Smart contracts: These use computers as the primary tool, embedding mathematical algorithms into programs to verify whether an event meets agreed-upon conditions and ensure that all parties reach an agreement within a specified timeframe and on agreed-upon terms. This ensures the verification and execution of contract terms. Simply put, a smart contract is a computer program that automatically executes contract terms without the need for third-party intervention.

[0241] Smart contracts use mathematical algorithms to verify whether a transaction meets the agreed conditions: for example, a contract stipulates a condition: "A car needs to be transported from place A to place B." In order to ensure that the transaction stipulated in this contract occurs when the condition is met, a function or an algorithm is required to verify whether this contract meets the agreed conditions.

[0242] 3. Consensus mechanism: It is one of the important mechanisms to ensure the security and reliability of blockchain. It is implemented through algorithms and protocols between network nodes to ensure the consistency of data and transactions on the blockchain among all nodes, thereby preventing double spending and other malicious behaviors. The consensus mechanism can prevent nodes in the network from tampering with data or performing other malicious behaviors, making the blockchain more secure and reliable. The implementation of the consensus mechanism requires collaboration between multiple nodes, thereby improving the degree of decentralization of the blockchain. Under the action of the consensus mechanism, there is no need for nodes to trust any centralized organization, which makes the blockchain more decentralized and democratic. The consensus mechanism can be applied to digital currency, smart contracts, supply chain management, medical record management and other fields, providing reliable technical support for the development and application of these fields. The implementation of the consensus mechanism requires the use of digital technologies such as computers and networks. Therefore, the development and application of the consensus mechanism has promoted the development of the digital economy. The continuous optimization and innovation of the consensus mechanism will provide more reliable and secure technical support for the development of the digital economy.

[0243] As described in the background technology, user profiles in telecommunications network services are strongly related to telecommunications network services and lack user attribute information, such as the user's social attributes identifying the user as an employee of a certain company. This means that the user's identity is only used within the telecommunications network, and the telecommunications network cannot leverage the credibility of third parties to enhance security. For example, in a user's caller ID, the caller's information displayed is "express delivery" or "harassment call." This type of information can be used as user attribute information, but this information is generated based on big data feedback, that is, based on feedback tags from other users. The user attribute information generated in this way has the following problems: 1. Poor authority: maliciously marked harassment calls may exist; 2. Poor real-time performance: multiple people are required to verify before the call is marked.

[0244] In addition, due to the lack of user attributes, users are unable to support complex upper-level applications, such as data access and authorization.

[0245] To this end, an embodiment of the present application provides a communication method and device, which allocates attribute information to users by providing attribute endorsement services for users, and can control access to users based on the attribute information, thereby enhancing the security of telecommunications network services and realizing data access and authorization.

[0246] In order to better understand the embodiments of the present application, the following explanations are made before introducing the embodiments of the present application.

[0247] First, in the embodiments of the present application, "used to indicate" can include being used for direct indication and being used for indirect indication. When describing a certain "indication information" as being used to indicate A, it can include the indication information directly indicating A or indirectly indicating A, and does not necessarily mean that the indication information carries A.

[0248] The information indicated by the indication information is called the information to be indicated. In the specific implementation process, there are many ways to indicate the information to be indicated, such as but not limited to, directly indicating the information to be indicated, such as the information to be indicated itself or the index of the information to be indicated. The information to be indicated can also be indirectly indicated by indicating other information, wherein there is an association between the other information and the information to be indicated. It is also possible to indicate only a part of the information to be indicated, while the other parts of the information to be indicated are known or agreed in advance. For example, it is also possible to use the arrangement order of each piece of information agreed in advance (such as specified in the protocol) to achieve the indication of specific information, thereby reducing the indication overhead to a certain extent. At the same time, it is also possible to identify the common parts of each piece of information and indicate them uniformly to reduce the indication overhead caused by indicating the same information separately.

[0249] In addition, the specific indication method can also be various existing indication methods, such as but not limited to the above-mentioned indication methods and various combinations thereof. The specific details of the various indication methods can be referred to the prior art and will not be repeated herein. As can be seen from the above, for example, when it is necessary to indicate multiple information of the same type, there may be a situation where the indication methods for different information are different. In the specific implementation process, the required indication method can be selected according to specific needs. The embodiment of the present application does not limit the selected indication method. In this way, the indication method involved in the embodiment of the present application should be understood to cover various methods that can enable the party to be indicated to obtain the information to be indicated.

[0250] The information to be indicated can be sent as a whole, or divided into multiple sub-information and sent separately, and the sending period and / or sending time of these sub-information can be the same or different. The specific sending method is not limited in this application. Among them, the sending period and / or sending time of these sub-information can be predefined, for example, predefined according to the protocol, or configured by the transmitting device by sending configuration information to the receiving device. Among them, the configuration information can, for example, but not limited to, include one or a combination of at least two of radio resource control (RRC) signaling, media access control (MAC) layer signaling and physical layer signaling. Among them, MAC layer signaling, for example, includes MAC-control element (CE); physical (PHY) layer signaling, for example, includes downlink control information (DCI).

[0251] Second, in the embodiments of the present application, the first, second, and various numerical numbers are merely distinctions for ease of description and are not intended to limit the scope of the embodiments of the present application. For example, different indication information is distinguished. For another example, the first information and the second information are merely for distinguishing different information and do not limit their order. Those skilled in the art will understand that words such as "first" and "second" do not limit the quantity and execution order, and words such as "first" and "second" do not necessarily limit them to be different.

[0252] Third, in the embodiments of the present application, descriptions such as "when...", "in the case of...", "if" and "if" all mean that the device (such as a terminal device or an access network device) will make corresponding processing under certain objective circumstances. It does not limit the time, and does not require the device (such as a terminal device or an access network device) to have a judgment action when implementing it, nor does it mean that there are other limitations.

[0253] At the same time, in the embodiments of this application, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described as "exemplary" or "for example" in the embodiments of this application should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Rather, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner to facilitate understanding.

[0254] Finally, the network architecture and business scenarios described in the embodiments of this application are intended to more clearly illustrate the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided in the embodiments of this application. Ordinary technicians in this field can know that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.

[0255] Please refer to Figure 1, which is a schematic diagram of the architecture of a communication system provided in an embodiment of the present application. As shown in Figure 1, the communication system includes: a distributed system 101 and at least one node 102a-102f that interacts with the distributed system. The distributed system includes a blockchain system, which includes one or more blockchain nodes, and the blockchain nodes can communicate with each other.

[0256] A blockchain node can be a terminal device, access network equipment, network element or device in the core network, server, personal computer (PC), virtual machine (VM), application container engine (dockor), or blockchain all-in-one machine, etc.

[0257] Nodes interacting with the distributed system may include nodes providing attribute endorsement or certification services, nodes requesting attribute retrieval, nodes providing operator services, nodes providing data services, nodes providing identity verification services, and nodes providing storage services. Nodes interacting with the distributed system may also communicate with each other, either directly or indirectly, without limitation. Nodes interacting with the distributed system may also be terminal devices, access network devices, network elements or devices in the core network, servers, PCs, VMs, application container engines (dockers), or blockchain all-in-one machines, etc.

[0258] Among them, the node that provides attribute endorsement or certification services can also be called attribute endorsement node, endorsement node, etc., which can be a device used to implement the business of an organization or institution (which can be simply referred to as the device corresponding to the organization or institution), a device used to provide the business of an operator (which can be simply referred to as the device corresponding to the operator), a device used to provide the business of an authoritative institution (which can be simply referred to as the device corresponding to the authoritative institution), a device used to provide the business of a third-party trusted institution (which can be simply referred to as the device corresponding to the third-party trusted institution), or other devices corresponding to organizations or institutions that can provide attribute endorsement services, etc.

[0259] The node that requests to obtain an attribute may also be called an attribute application node, an attribute ownership node, etc., and may be a device corresponding to a user, a device corresponding to an organization or institution, etc.

[0260] The node providing operator services may also be called an operator node, operator service node, etc., and may be the operator's corresponding equipment, such as the operator's server, network elements or equipment in the core network (such as operation administration and maintenance (OAM) network elements), or access network equipment, servers, etc.

[0261] The node that provides data services may also be called a data-owning node, a data node, etc., and may be a device such as a database, a server, etc. that can provide data services.

[0262] The node that provides identity verification services can also be called a verification node or an identity verification node. It can be a device corresponding to a third-party trusted organization, a device corresponding to an authoritative organization, or a device corresponding to other organizations or institutions that can provide identity verification.

[0263] Nodes that provide storage services can also be called storage nodes, off-chain storage nodes, etc., and can be devices that provide data storage functions such as servers and distributed storage systems.

[0264] It should be understood that blockchain nodes can be nodes that provide attribute endorsement or certification services, nodes that request to obtain attributes, nodes that provide operator services, nodes that provide data services, nodes that provide identity verification services, nodes that provide storage services, etc., or can be jointly set up with the above-mentioned nodes, without limitation.

[0265] The terminal device may be a terminal device with transceiver functions, or may be a chip or chip system provided in the terminal device. The terminal device may also be referred to as user equipment (UE), access terminal, subscriber unit, subscriber station, mobile station (MS), mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent or user device. The terminal device in the embodiments of the present application can be a mobile phone, a cellular phone, a smart phone, a tablet computer, a wireless data card, a personal digital assistant (PDA), a wireless modem, a handset, a laptop computer, a machine type communication (MTC) terminal, a computer with wireless transceiver function, a virtual reality (VR) terminal, an augmented reality (AR) terminal, a smart home device (for example, a refrigerator, a television, an air conditioner, an electric meter, etc.), an intelligent robot, a robotic arm, a workshop equipment, a wireless terminal in unmanned driving, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical care, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, a vehicle-mounted terminal, a road side unit with terminal function ... The terminal device of the present application may also be an onboard module, onboard module, onboard component, onboard chip or onboard unit built into a vehicle as one or more components or units. The terminal device may also be other devices with terminal functions, for example, a terminal device may also be a device that functions as a terminal in D2D communication.

[0266] The embodiments of this application do not limit the device form factor of the terminal device. The device used to implement the functions of the terminal device can be the terminal device; it can also be a device that supports the terminal device to implement the functions, such as a chip system. The device can be installed in the terminal device or used in conjunction with the terminal device. In the embodiments of this application, the chip system can be composed of a chip or include a chip and other discrete components.

[0267] The access network device may also be referred to as an access network node, a radio access network (RAN) node, a RAN entity or an access node, etc., which is located on the network side of the above-mentioned communication system to help the terminal device achieve wireless access, and has a device with wireless transceiver function or a chip or chip system that can be set in the device. The access network device includes but is not limited to: a base station, an evolved NodeB (eNodeB), an access point (AP), a transmission reception point (TRP or transmission point, TP), a next generation NodeB (gNB), a next generation base station in a 6G mobile communication system, a base station in a future mobile communication system, or an access node in a Wi-Fi system, etc. The access network device may be a macro base station, a micro base station or an indoor station, a relay node or a donor node, an open radio access network (ORAN) or a wireless controller in a centralized radio access network (CRAN) scenario. The access network device may also be one or a group of antenna panels (including multiple antenna panels) of a base station in 5G, or it may also be a network node constituting a gNB, TRP or TP or transmission measurement function (TMF), such as a centralized unit (CU), a distributed unit (DU), a CU-control plane (CP), a CU-user plane (UP), or a radio unit (RU), an RSU with base station functions. Optionally, the access network device may also be a server, a wearable device, a vehicle or an on-board device, etc. For example, the access network device in V2X technology may be an RSU. All or part of the functions of the network device in this application may also be implemented by software functions running on hardware, or by virtualization functions instantiated on a platform (such as a cloud platform). The access network device in this application may also be a logical node, a logical module or software that can implement all or part of the functions of the access network device.

[0268] Among them, the CU and DU can be set separately, or can also be included in the same network element, such as a baseband unit (BBU). The RU can be included in a radio frequency device or a radio frequency unit, for example, a remote radio unit (RRU), an active antenna unit (AAU) or a remote radio head (RRH). It can be understood that the access network device can be a CU node, a DU node, or a device including a CU node and a DU node. In addition, the CU can be divided into a network device in the access network RAN, or the CU can be divided into a network device in the CN, which is not limited here.

[0269] In different systems, CU (or CU-CP and CU-UP), DU or RU may also have different names, but those skilled in the art can understand their meanings. For example, in the ORAN system, CU may also be called O-CU (Open CU), DU may also be called O-DU, CU-CP may also be called O-CU-CP, CU-UP may also be called O-CU-UP, and RU may also be called O-RU. For the convenience of description, this application uses CU, CU-CP, CU-UP, DU and RU as examples for description. Any unit of CU (or CU-CP, CU-UP), DU and RU in this application can be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.

[0270] The embodiments of this application do not limit the form of the access network device. The device used to implement the functions of the access network device can be the access network device; it can also be a device that supports the access network device to implement the functions, such as a chip system. The device can be installed in the access network device or used in conjunction with the access network device.

[0271] A network element or device in a core network is a device deployed in the core network to provide services to terminal devices. In systems using different wireless access technologies, the names of core network elements with similar wireless communication functions may be different. For example, when the method of an embodiment of the present application is applied to a 5G system, the core network device may be an access and mobility management function (AMF), a session management function (SMF), a user plane function (UPF), etc. Among them, the UPF processes user plane data. The AMF and SMF process control plane signaling. When the method of an embodiment of the present application is applied to an LTE system, the core network device may be a mobility management entity (MME). For the convenience of description only, in the embodiment of the present application, the above-mentioned devices that can provide services to terminal devices may be collectively referred to as core network elements, core network devices, or network functions (NF), etc., without limitation.

[0272] In addition, it should be understood that the communication system shown in Figure 1 exemplarily shows nodes or devices of several functions or types. The communication system shown in Figure 1 can also include other types of nodes, such as devices or nodes used to implement the business of card merchants or terminal manufacturers, etc., and there is no limitation on this.

[0273] In the embodiments of the present application, the names of nodes, modules, devices or network elements in different scenarios, architectures or systems, as well as the names of communication interfaces between nodes, modules, devices or network elements are given by way of example, and the possibility of name changes in future communication systems, scenarios or architectures is not excluded.

[0274] The communication method provided in the embodiments of the present application will be described in detail below with reference to Figures 2 to 7.

[0275] For example, FIG2 is a flow chart of a communication method provided in an embodiment of the present application. This communication method is illustrated by taking the communication between the blockchain node shown in FIG1 and the node providing attribute endorsement or certification services (hereinafter referred to as node #1) as an example. Of course, the subject that executes the blockchain node action in this method can also be a device / module in the blockchain node, such as a chip, processor, processing unit, etc. in the blockchain node, without limitation; the subject that executes the node #1 action in this method can also be a device / module in node #1, such as a chip, processor, processing unit, etc. in node #1, without specific limitation.

[0276] As shown in FIG2 , the communication method includes:

[0277] S201: Node #1 sends request #1 to a blockchain node. In response, the blockchain node receives request #1 from node #1.

[0278] Request #1 is a request initiated by Node #1 to install a smart contract related to an attribute endorsement or attestation service. For example, Request #1 is used to request the installation of a smart contract corresponding to an attribute endorsement service supported by Node #1. In this embodiment of the present application, Request #1 may also be referred to as the fifth request, and Node #1 may also be referred to as the fourth node. In other words, Request #1 corresponds to the fifth request, and Node #1 corresponds to the fourth node.

[0279] Specifically, request #1 may include the identification of node #1, the attribute endorsement service corresponding to the smart contract, and the smart contract. Among them, the identification of node #1 is used to uniquely identify the identity information of node #1. For example, the identification of node #1 can be decentralized root credentials / credentials (DRC), or decentralized identity credentials / credentials (DIC), or decentralized self-control credentials (DSCC), or decentralized operator credentials (DOC), or self-control identity credentials (SCIC). Among them, DRC, DIC and DSCC can all be called self-control identity (scID). For another example, the identification of node #1 can be the identification of the authentication certificate of node #1.

[0280] Among them, DRC is preset in the card by the card vendor / equipment manufacturer when it leaves the factory or is the root ID of the organization; DIC is a number of temporary / derived identities derived from DRC; DSCC is generated by the user himself for the user's control of identity information, and is independent of DRC or DIC; DOC can be the credential information issued by the operator to the user; SCIC is derived based on DSCC. Each DRC, DIC, DSCC or SCIC corresponds to file information. In other words, the above-mentioned DRC and DIC can be shared by both users and organizations, and DOC, DSCC and SCIC can be unique to users. It should be understood that the node identification settings are different based on the different node types. The identification settings of the following nodes #2 to #4 are similar to the identification settings of node #1, and will not be repeated later.

[0281] In one possible implementation, the identifier of node #1 may reuse the embedded UICC (eUICC) format of the universal integrated circuit card (UICC) specified by the Global System for Mobile Communications Association (GSMA). For example, the identifier of node #1 may be "0x1234." This identifier is used for example only. In actual implementation, the identifier of node #1 may also be implemented in other possible ways, which are not further described here.

[0282] The attribute endorsement service is a service for providing attribute authentication or certification for nodes (such as node #2). The attribute certification may include social attribute certification and objective attribute certification of the node. For example, the social attribute certification may include certification of node #2's work, education, real-name authentication status, etc. The objective attribute certification may include certification of node #2's current location, current age, whether it has certain permissions, etc. Therefore, the certified attributes are considered to be trustworthy and safe. In an embodiment of the present application, node #1 may be a device that can provide attribute endorsement services, such as equipment corresponding to an operator, equipment corresponding to an authoritative agency, equipment corresponding to a third-party trusted agency, etc., and may provide certified attributes for the nodes it serves. In an embodiment of the present application, node #2 may also be referred to as the second node, or in other words, node #1 corresponds to the fourth node.

[0283] The smart contract corresponding to the attribute endorsement service refers to the attribute endorsement service provided by Node #1 installed or deployed in the form of a smart contract. A smart contract can correspond to one or more attribute endorsement services. In other words, Node #1 requests the installation of the attribute endorsement service it can provide on the blockchain node via Request #1 in the form of a smart contract, thereby enabling the blockchain node to provide the attribute endorsement service. It should be understood that a smart contract can be expressed in the form of code or a program.

[0284] Optionally, Request #1 may also include Node #1's signature on Request #1, Node #1's signature on the smart contract, etc., to prove the authenticity and validity of the information or message. It should be understood that Node #1 may use its private key to sign the information or message.

[0285] In one possible design, node #1 can send request #1 to a blockchain node. Based on the characteristics of blockchain, the blockchain node (e.g., the first blockchain node) that receives request #1 can communicate request #1 to other blockchain nodes on its blockchain through consensus. Some or all of the blockchain nodes on the blockchain can then install the smart contract based on request #1, thereby installing the smart contract on the blockchain.

[0286] In a possible design 2, node #1 can send request #1 to multiple blockchain nodes. As a result, the multiple blockchain nodes that receive request #1 can install the smart contract based on request #1, without having to communicate request #1 to other blockchain nodes through consensus.

[0287] S202. The blockchain node installs the smart contract according to request #1.

[0288] After receiving Request #1, the blockchain node can determine whether the smart contract can be installed based on Request #1 and then decide whether to install the smart contract based on the determination. For example, the blockchain node can determine whether it can currently support the installation of the smart contract indicated in Request #1 based on its own current installation resources and installation conditions. If the current installation resources are abundant and the installation conditions are favorable, the smart contract can be installed; otherwise, the smart contract may not be installed.

[0289] Optionally, the blockchain node can verify Request #1. If verification is successful, the node can then determine whether the smart contract can be installed. Conversely, if verification fails, the node no longer needs to determine whether the smart contract can be installed and can deem Request #1 invalid. For example, the node can verify the signature in Request #1 using the public key. If the signature verification is successful, the node can then determine whether the smart contract can be installed based on the installation resources and installation conditions.

[0290] In one possible design, after receiving Request #1 and verifying the signature in Request #1, the blockchain node can first vote / select / judge whether to support the installation of the smart contract based on Request #1. The voting / selection / judgment result is then returned to Node #1. Node #1 then instructs the blockchain node on whether to install the smart contract based on the voting / selection / judgment result fed back by the blockchain node. It should be understood that the voting / selection / judgment result can be determined by the blockchain node based on the installation resources and installation conditions described above.

[0291] In this design, in one possible implementation, a blockchain node may send information #1 to node #1 based on request #1, and node #1 accordingly receives information #1 from the blockchain node. Information #1 is used to indicate whether smart contract installation is supported. For example, information #1 may include a single bit of indication information (also referred to as an information element, field, or indication domain) to indicate whether smart contract installation is supported. A bit value of 1 indicates that the blockchain node supports smart contract installation, while a bit value of 0 indicates that the blockchain node does not support smart contract installation. Alternatively, a bit value of 0 indicates that the blockchain node supports smart contract installation, while a bit value of 1 indicates that the blockchain node does not support smart contract installation. Optionally, information #1 may also include a signature from the blockchain node confirming whether smart contract installation is supported, to verify the authenticity of the information.

[0292] Optionally, information #1 can be sent in the response corresponding to request #1, or can be sent in other messages, without limitation. In the embodiment of the present application, information #1 can also be referred to as second information, or in other words, information #1 corresponds to the second information.

[0293] In one possible implementation, the blockchain node may also trade, publish, or record the voting / selection / judgment results (including whether to support smart contract installation and / or the signature of the result) on the blockchain. In this implementation, information #1 may include the voting / selection / judgment results and / or the address of the voting / selection / judgment results on the blockchain (also known as the storage address, transaction address, etc.).

[0294] Thus, node #1 can determine information #2 based on information #1 of at least one blockchain node and send information #2 to the blockchain node. Accordingly, the blockchain node receives information #2 from node #1 and determines whether to install the smart contract based on information #2. In other words, information #2 is determined based on information #1 of at least one blockchain node. Among them, information #2 is used to indicate whether to install the smart contract. For example, information #2 can be similar to the above-mentioned information #1, or it can include 1 bit of indication information to indicate. For details, please refer to the relevant description of the above-mentioned information #1, which will not be repeated here. In the embodiment of the present application, information #2 can also be referred to as third information, or in other words, information #2 corresponds to the third information.

[0295] Exemplarily, node #1 receives information #1 corresponding to one or more blockchain nodes on the blockchain that participate in installing a smart contract, and counts the results of whether the information #1 corresponding to the one or more blockchain nodes supports the installation of the smart contract. If the number of results indicating support for the installation of the smart contract is greater than (or greater than or equal to) a first threshold, node #1 instructs the blockchain nodes to install the smart contract through information #2. Otherwise, node #1 instructs the blockchain nodes not to install the smart contract through information #2.

[0296] If information #1 only includes the address of the voting / selection / judgment result on the blockchain, node #1 can query the voting / selection / judgment result of each blockchain node based on the address and perform the above-mentioned statistics and threshold comparison on it. If information #1 includes both the voting / selection / judgment result and the address of the voting / selection / judgment result on the blockchain, node #1 can compare the voting / selection / judgment result of each blockchain node queried based on the address with the voting / selection / judgment result in information #1. If they match, the above-mentioned statistics and threshold comparison can be performed on them. Otherwise, the above-mentioned statistics and threshold comparison can be performed directly using the voting / selection / judgment result queried based on the address, or the above-mentioned statistics and threshold comparison can be directly cancelled.

[0297] Optionally, node #1 may also use a private key to sign the installation result obtained by the threshold comparison. In this case, information #2 may include the result of whether the smart contract is installed and node #1's signature on the result of whether the smart contract is installed.

[0298] In one possible implementation, node #1 can also instruct blockchain nodes on whether to install the smart contract by providing feedback on the results of each blockchain node's support for smart contract installation. In other words, information #2 can include the results of at least one blockchain node's support for smart contract installation and / or the addresses on the blockchain of at least one blockchain node's support for smart contract installation results.

[0299] Therefore, after the blockchain node receives information #2, if there is a signature in information #2, the blockchain node can verify the signature in information #2. If the verification passes, it determines whether to install the smart contract based on the installation result indicated in information #2.

[0300] If information #2 indicates that a smart contract should be installed, the blockchain node may, with respect to design 1 in S201 above, notify other blockchain nodes on its blockchain of information #2 through consensus, so that each participating blockchain node can install the smart contract requested by node #1 based on information #2. If information #2 indicates that a smart contract should not be installed, the blockchain node may not perform the smart contract installation operation.

[0301] Optionally, after the blockchain node completes the installation of the smart contract, the blockchain node may also feedback response information to node #1 to indicate that the smart contract installation is complete.

[0302] Based on S201 and S202 above, Node #1 publishes the attribute endorsement service to the blockchain in the form of a smart contract via Request #1. This allows nodes requesting the attribute (e.g., Node #2) to obtain the verified attribute by invoking the smart contract on the blockchain. This enables cross-domain attribute interoperability between nodes, ultimately achieving mutual trust.

[0303] Furthermore, the communication method provided in the embodiment of the present application may further include the following steps:

[0304] S203: Node #1 sends information #3 to the blockchain node. Accordingly, the blockchain node receives information #3 from node #1.

[0305] In this embodiment of the present application, information #3 is used to indicate usage information of the smart contract. Information #3 can serve as a configuration file (profile) corresponding to the smart contract. Information #3 can include at least one of the following: the attribute endorsement service corresponding to the smart contract, the address of the smart contract, the input parameters of the smart contract, the output parameters of the smart contract, or an application template for attribute information. In this embodiment of the present application, information #3 can also be referred to as the fourth information, or in other words, information #3 corresponds to the fourth information.

[0306] Among them, the attribute endorsement service corresponding to the smart contract is used to indicate the attribute endorsement service provided by the installed smart contract; the address information of the smart contract is used to indicate the location of the installed smart contract; the input parameters of the smart contract are used to indicate the parameter settings of the smart contract when the attribute endorsement service is completed using the smart contract; the output parameters of the smart contract are used to indicate the parameter settings of the smart contract when the attribute endorsement service is completed using the smart contract; the application template of the attribute information is used to indicate the filling template of the attribute content of the application, that is, to fill in the attribute content according to the template.

[0307] It should be understood that in addition to the several parameters shown above, information #3 may also include other usage information related to the smart contract, such as the validity period corresponding to the smart contract, the identifier of node #1 corresponding to the smart contract, the identifier of the smart contract, etc., without limitation to this.

[0308] For example, the smart contract installed on the blockchain node is a smart contract that provides an attribute endorsement service for a device corresponding to a social organization (i.e., node #1). The attribute endorsement service corresponding to the smart contract can be: proving that node #2 is an employee of the social organization; the address of the smart contract can be 0x1111; the input parameters of the smart contract can be at least one of the following: node #2's ID, node #2's ID + work number, node #2's ID + ID number, or node #2's ID + work certificate, etc.; the output result of the smart contract can be: node #2 is an employee of the social organization (the output result is signed by the device corresponding to the social organization).

[0309] As another example, the smart contract installed on the blockchain node is a smart contract that provides an attribute endorsement service for a device corresponding to a certain operator (i.e., node #1). Then the attribute endorsement service corresponding to the smart contract can be: proving the current location of node #2; the address of the smart contract can be 0x1280; the input parameters of the smart contract can be at least one of the following: the ID of node #2, or the access information related to node #2 and the device corresponding to the operator, etc., wherein the access information related to node #2 and the device corresponding to the operator can be such as the ID of the access network device accessed by node #2, the public land mobile network (PLMN) ID, etc.; the output result of the smart contract can be: the current location of node #2 is Beijing / Shanghai, etc. (the output result is signed by the device corresponding to the operator).

[0310] After receiving Information #3, the blockchain node can record the consensus on Information #3 on the blockchain and store the address of Information #3 on the blockchain. This allows the blockchain node to apply for endorsed or certified attributes corresponding to the node's attributes when invoking the smart contract. It should be understood that Information #3 can be included in Request #1, in which case S203 is optional.

[0311] Furthermore, embodiments of the present application also provide a communication method for issuing certified attributes for a node. This communication method is illustrated using the communication between the blockchain node shown in Figure 1 and a node requesting to obtain attributes (hereinafter referred to as node #2) as an example. Of course, the subject that executes the blockchain node action in this method can also be a device / module in the blockchain node, such as a chip, processor, or processing unit in the blockchain node, without limitation. The subject that executes the node #2 action in this method can also be a device / module in node #2, such as a chip, processor, or processing unit in node #2, without limitation.

[0312] As shown in FIG3 , the communication method includes:

[0313] S301: Node #2 sends request #2 to the blockchain node. Accordingly, the blockchain node receives request #2 from node #2.

[0314] Request #2 is an attribute request initiated by node #2. For example, request #2 is used to request the acquisition of an attribute. Request #2 may include the identifier of node #2, information indicating the type of attribute requested, information indicating the identity of node #2, and other information used to request the acquisition of the attribute. In this embodiment of the present application, request #2 may also be referred to as the first request, and node #2 may also be referred to as the second node. In other words, request #3 corresponds to the first request, and node #2 corresponds to the second node.

[0315] Among them, the specific description of the identification of node #2 can refer to the relevant description of the identification of node #1 in the above S201, which will not be repeated here; the information used to indicate the type of attribute requested to be obtained is used to indicate one or more attribute types requested to be obtained by node #2.

[0316] The information used to indicate the identity of node #2 is used to prove whether the identity of node #2 is legal and authentic. The information used to indicate the identity of node #2 may include the identity proof information corresponding to node #2 and / or the signature of node #3 on the identity proof information corresponding to node #2, wherein node #3 is a node corresponding to an institution or organization that can prove the identity of node #2, such as a device corresponding to a social authority, and the authentication of the identity information of node #2 has credibility. For example, node #2 is a terminal device, and the identity proof information corresponding to node #2 may be an ID card number, educational information, etc. The signature of node #3 on the identity proof information corresponding to node #2 is used to represent the third party's authentication of the identity of node #2. In the embodiment of the present application, node #3 may also be referred to as a third node, or in other words, node #3 corresponds to a third node.

[0317] Thus, node #2 obtains the attributes related to it through request #2.

[0318] In one possible implementation, the blockchain node may also proactively send the corresponding attribute information to node 2#, without the need for node #2 to request the information from the blockchain node. In this case, S301 may be considered an optional step.

[0319] S302: The blockchain node sends attribute information to node #2. In response, node #2 receives the attribute information from the blockchain node.

[0320] The attribute information is used to indicate the attributes corresponding to the certified node #2. The attribute information may include the attributes corresponding to node #2 and the signature of node #1 related to the attributes corresponding to node #2. Node #1 may use its private key to sign the attributes corresponding to node #2. The node #1 related to the attributes corresponding to node #2 refers to the node that provides attribute endorsement services for node #2, which may be one or more nodes, such as devices corresponding to social authoritative organizations or devices corresponding to third-party trusted organizations.

[0321] Exemplarily, the attribute information corresponding to node #2 can be expressed as the correspondence between the identifier of node #2 and the attribute and signature, such as scID2~{attribute, signature}, or {scID2, attribute, signature}, where scID2 represents the identifier of node #2, the attribute represents the attribute corresponding to node #2, and the signature represents the signature of node #1 on the attribute corresponding to node #2.

[0322] Optionally, the attribute information corresponding to node #2 may further include at least one of the following: the issuance time of the attribute, the validity period of the attribute, the identifier of node #2, or the blockchain node's signature on the attribute corresponding to node #2. The blockchain node may also use its private key to sign the attribute corresponding to node #2.

[0323] It should be understood that in an embodiment of the present application, node #1 can provide one or more proven attributes for node #2, and different attributes can also correspond to different nodes #1. Therefore, different attributes can correspond to different signatures, and different attributes can also correspond to the same signature. There is no limitation on this.

[0324] In one possible design, a blockchain node or the blockchain on which the blockchain node resides can pre-store attribute information corresponding to node #2, obtained from node #1 providing different attribute endorsement services. This attribute information has been verified by signature. For example, the blockchain node can query the attributes signed by node #2 based on the identifier of node #2 in request #2 and the attribute type requested by node #2, thereby obtaining the attribute information corresponding to node #2.

[0325] In one possible design, Design 2, blockchain nodes deploy smart contracts corresponding to different attribute endorsement services provided by Node #1. Based on Request #2, the blockchain nodes can invoke the corresponding smart contracts to generate attribute information. For example, based on the attribute type requested by Node #2 in Request #2, the blockchain node selects the smart contract corresponding to the attribute endorsement service and inputs relevant parameters, such as Node #2's identifier and / or its corresponding identity verification information, into the selected smart contract. The smart contract then retrieves the attribute information corresponding to Node #2. The detailed implementation of blockchain node deployment and usage of the smart contract corresponding to the attribute endorsement service can be found in the description of the smart contract installation interaction process shown in Figure 2 above, and is omitted here for brevity.

[0326] In a possible design 3, the blockchain node or other blockchain nodes on its blockchain are nodes that provide attribute endorsement / proof services. The blockchain node can generate attribute information locally or obtain it from the blockchain.

[0327] Thus, node #2 can obtain the attribute with credibility through the attribute information. Optionally, the attribute information corresponding to node #2 can be sent in the response corresponding to request #2, or can be sent in other messages, without limitation.

[0328] Optionally, after generating the attribute information corresponding to node #2, the blockchain node can record it on the blockchain and store the address of the attribute information corresponding to node #2 on the blockchain.

[0329] Furthermore, the blockchain node can also send the blockchain address of the attribute information corresponding to node #2 to node #2, so that node #2 can subsequently verify the authenticity of its attributes during attribute-based interactions with other nodes. In one possible implementation, the blockchain node can send information #4 to node #2, and node #2 will receive information #4 from the blockchain node. Information #4 indicates the blockchain address of the attribute information corresponding to node #2.

[0330] Optionally, information #4 can be sent in the same message as the attribute information, or can be sent separately in different messages, without limitation. In the embodiment of the present application, information #4 can also be referred to as the first information, or in other words, information #4 corresponds to the first information.

[0331] Based on the communication method shown in FIG3 , node #2 can obtain the endorsed attributes from node #1 that provides different attribute endorsement services from the blockchain, thereby obtaining credible attribute characteristics.

[0332] In addition to the communication method shown in FIG3 above, the embodiment of the present application also provides a communication method in which a node providing different attribute endorsement services (i.e., node #1) can proactively issue attributes to a node requesting to obtain attributes (i.e., node #2), without node #2 triggering the acquisition. As shown in FIG4, the communication method includes:

[0333] S401. Node #1 generates attribute information.

[0334] The attribute information indicates the endorsed / certified attributes of node #2. The attribute information may include the attributes of node #2 and node #1's signature on the attributes of node #2, where node #1 signs the attributes of node #2 using its private key. Exemplarily, the attribute information may be represented as {scID2, attribute, signature}. Optionally, the attribute information may also include node #2's identifier.

[0335] In this embodiment of the present application, node #1 can provide attribute endorsement / certification services to node #2, which it serves. That is, node #1 indicates the attributes of node #2, which have been endorsed by its signature, to node #2 in the form of attribute information. It should be understood that node #1 can provide corresponding attribute certificates for different nodes #2, and then send the certified attributes to the corresponding node #2 in the form of attribute information.

[0336] In addition to proactively sending attribute information to node #2, node #1 can also, in one possible implementation, send attribute information based on a trigger from node #2. For example, node #2 sends request #2 to node #1, and node #1 receives request #2 from node #2. Request #2 is used to request the acquisition of attributes. A detailed description of request #2 can be found in the description of request #2 in S301 above and is omitted here.

[0337] S402: Node #1 sends attribute information to node #2. Correspondingly, node #2 receives the attribute information from node #1.

[0338] After receiving the attribute information, node #1 sends it to node #2. Node #2 can then verify the signature in the attribute information using its public key. If the signature verification passes, it obtains the corresponding attributes. For example, the attributes corresponding to node #2 in the attribute information may include that node #2 is a full-time employee of the organization corresponding to node #1 and that node #2 has worked at the organization for three years.

[0339] In one possible design, node #1 can also send attribute information to the blockchain node, and the blockchain node in turn receives the attribute information from node #1. Thus, after receiving the attribute information, the blockchain node can also verify the signature in the attribute information using the public key. If the signature verification passes, the authenticity of the attribute is confirmed, and the attribute information can be recorded on the blockchain.

[0340] Optionally, the attribute information corresponding to node #2 may be carried in the response corresponding to request #2 or carried in other messages, and there is no limitation on this.

[0341] Optionally, the blockchain node can also provide node #1 with the address of the attribute information on the blockchain. In one possible implementation, the blockchain node sends message #4 to node #1, and node #1 receives message #4 from the blockchain node. Message #4 indicates the address of the attribute information on the blockchain. Thus, node #1 can determine the storage address or record address of the attribute information on the blockchain based on message #4.

[0342] Furthermore, after node #1 obtains information #4, it can also send information #4 to node #2 to inform node #2 of the location of its corresponding attribute information on the blockchain, so that node #2 can subsequently prove the authenticity of its attributes during attribute-based interactions with other nodes. Optionally, information #4 can be sent in the same message as the attribute information, or in separate messages, without limitation. In this embodiment of the present application, information #4 can also be referred to as first information, or in other words, information #4 corresponds to the first information.

[0343] Therefore, based on the communication method shown in FIG4 , node #1 can directly provide attribute proof to node #2 so that node #2 can obtain credible attributes.

[0344] It should be noted that Figures 3 and 4 above respectively show the process of node #2 obtaining corresponding attribute information in two scenarios. It can be seen from the above that both the blockchain node and node #1 can send corresponding attribute information to node #2 based on the request of node #2, or actively send corresponding attribute information to node #2. Therefore, in the embodiment of the present application, the blockchain node shown in Figure 3 and the node #1 shown in Figure 4 can be called the first node.

[0345] In addition, the embodiment of the present application also provides a communication method, which is applicable to the scenario where node #2 is a terminal device, and the operator stores the certified attributes of the terminal device in the UICC by writing the card over the air, such as displaying the certified attributes of the incoming call user in the user's incoming call interface. The communication method is illustrated by taking the communication between the node providing operator services (hereinafter referred to as the operator node) and the terminal device (node ​​#2) shown in Figure 1 as an example. As shown in Figure 5, the communication method includes:

[0346] S501: The operator node determines that a first terminal device and a second terminal device access a network corresponding to the operator node.

[0347] Regarding the specific implementation process of the terminal device accessing the operator network in S501, reference may be made to the relevant description of the process of the terminal device accessing the network in the existing implementation method, which will not be described in detail.

[0348] S502: When it is determined that the first terminal device has received a call request from the second terminal device, the operator node sends attributes corresponding to the second terminal device to the first terminal device. Accordingly, when the first terminal device has received a call request from the second terminal device, the first terminal device receives the attributes corresponding to the second terminal device from the operator node.

[0349] That is, when a first terminal device receives a call request, the operator node can inform the first terminal device of the attributes of the second terminal device with which the call is to be made, so that the first terminal device can identify the identity of the second terminal device by the attributes. For example, the operator node displays the attributes of the second terminal device on the incoming call interface of the first terminal device, such as the identity of the second terminal device is "courier" and the current location of the second terminal device is "Beijing".

[0350] In a possible scenario 1, the operator node may be the above-mentioned node #1, which may locally provide attribute endorsement services for the second terminal device, thereby generating attributes corresponding to the second terminal device.

[0351] In one possible scenario 2, the operator node can obtain attribute information corresponding to the second terminal device from the blockchain to obtain the endorsed / certified attributes of the second terminal device. The attribute information corresponding to the second terminal device may include the identifier of the second terminal device, the attributes corresponding to the second terminal device, and the signature of node #1 on the attributes corresponding to the second terminal device. For a detailed description of the attribute information, please refer to the description of the attribute information in S302 above and will not be repeated here.

[0352] In this scenario 2, in one possible implementation, the operator node may send request #3 to the blockchain node, and accordingly, the blockchain node receives request #3 from the operator node. Request #3 is used to request to obtain the attributes corresponding to the second terminal device. Thus, the blockchain node sends the attribute information corresponding to the second terminal device to the operator node according to request #3, and accordingly, the operator node receives the attribute information corresponding to the second terminal device from the blockchain node. For the specific description of request #3, please refer to the relevant description of request #2 in S301 or S401, which will not be elaborated on; the specific implementation process of the blockchain node obtaining the attribute information corresponding to the second terminal device can refer to the relevant description in Design 1 to Design 3 in S302, which will not be elaborated on. In the embodiment of the present application, request #3 can also be called the sixth request, or in other words, request #3 corresponds to the sixth request.

[0353] Based on the communication method shown in FIG5 , the operator node can introduce the user's proven attributes during the call between users to achieve mutual communication of credibility, which can enhance the security of telecommunications network services.

[0354] Figures 2 to 5 above describe in detail how node #2 acquires the credible attribute. Furthermore, based on the credible attribute, data access control for node #2 can be implemented, and the traceability of access records can be guaranteed. For example, Figure 6 is a flow chart of a communication method provided in an embodiment of the present application, which is applicable to the communication between the node requesting to obtain the attribute (i.e., the above-mentioned node #2), the node providing data services (hereinafter referred to as node #4), the blockchain node, and the node providing storage services (hereinafter referred to as the storage node) shown in Figure 1.

[0355] As shown in FIG6 , the communication method includes:

[0356] S601: Node #2 sends request #4 to node #4. Correspondingly, node #4 receives request #4 from node #2.

[0357] Request #4 is a request initiated by node #2 for accessing data. For example, request #4 is used to request access to the data of node #4. Request #4 includes the attribute information corresponding to node #2. The attribute information corresponding to node #2 includes the attributes corresponding to node #2 and the signature of node #1 on the attributes corresponding to node #2. The process for node #2 to obtain its corresponding attribute information can be obtained by referring to any of the implementation methods in Figures 2 to 5 above, and this will not be described in detail. The specific description of the attribute information corresponding to node #2 can also be referred to the above related description, and this will not be described in detail. Optionally, the attribute information corresponding to node #2 can also include the identifier of node #2, which can constitute a triplet of identifier, attribute, and signature.

[0358] That is, when node #2 needs to access node #4's data, node #2 can generate and send request #4 to node #4 to request access to node #4's data. It should be understood that request #4 can also include relevant access data information such as the type of data and data size that node #2 requests access to, to indicate the specific data content that node #2 wants to obtain. In this embodiment of the application, request #4 can also be referred to as the second request, and node #4 can also be referred to as the fifth node. In other words, request #4 corresponds to the second request, and node #4 corresponds to the fifth node.

[0359] In one possible design, node #2 needs to establish security authentication with node #4 before it can interact with node #4. In other words, before node #2 sends request #4, it needs to complete security authentication with node #4 to establish a secure connection for interaction.

[0360] In this design, node #4 can perform security authentication with node #2 by verifying the identity of node #2. In one possible implementation, node #2 sends identification information to node #4, and correspondingly, node #2 receives identification information from node #4. The identification information may include the identity of node #2, the identity of node #1 related to the identity of node #2, and the signature of node #1 related to the identity of node #2. The identity of node #1 related to the identity of node #2 is used to identify the node #1 that assigns the identity to node #2, and the signature of node #1 related to the identity of node #2 refers to the signature of the identity assigned to node #2 by node #1 that assigns the identity to node #2, so as to prove the authenticity and legitimacy of the identity of node #2.

[0361] After node #4 obtains the identification information of node #2, it can use the credential information of node #1 related to the identification of node #2 to verify the identification of node #2. When the identification of node #2 is verified, node #4 determines to establish a security authentication with node #2. At this time, the security authentication between node #2 and node #4 is considered to be completed, so that node #4 can establish a secure connection with node #2.

[0362] Exemplarily, the credential information of node #1 associated with the identity of node #2 may be a certificate of node #1 associated with the identity of node #2. The certificate of node #1 may include a public key, a digital signature of the public key, information indicating the authority that issued the public key, and information indicating the owner of the public key (such as the identity of node #1 associated with the identity of node #2). Thus, node #4 can use the public key in the credential information to verify the signature of node #1 associated with the identity of node #2 in the identification information. If the verification is successful, the identity of node #2 is considered to be legitimate and authentic. In other words, if the verification is successful, node #2 is considered to be the true owner of the identity, and node #4 can establish a secure connection with node #2.

[0363] It should be understood that if the identity of node #2 fails to pass verification, a secure connection cannot be established between node #2 and node #4.

[0364] Node #4 can obtain the credential information of node #1 associated with the identifier of node #2 from the blockchain based on the identifier of node #2 and / or the identifier of node #1 associated with the identifier of node #2. This means that node #1 associated with the identifier of node #2 publishes its credential information on the blockchain, allowing node #4 to obtain the corresponding credential information from the blockchain. Alternatively, node #4 can directly obtain the corresponding credential information from the corresponding node #1 based on the identifier of node #1 associated with the identifier of node #2, without limitation.

[0365] Therefore, only after completing security authentication can node #2 send request #4 to node #4, and correspondingly, node #4 can receive request #4 from node #2.

[0366] Optionally, in a scenario where the attribute information corresponding to node #2 is published on the blockchain, request #4 may also include the address of the attribute information corresponding to node #2 on the blockchain, so that node #4 can query based on the address whether the attribute information corresponding to node #2 stored on the blockchain is consistent with the attribute information corresponding to node #2 carried in request #4, so as to verify the attribute information.

[0367] S602. Node #4 determines whether node #2 meets the requirements for accessing the data of node #4 based on the attribute information and certification information corresponding to node #2.

[0368] Among them, the proof information is used to verify the attributes corresponding to node #2, that is, the proof information is used to verify whether the attributes corresponding to node #2 carried in request #4 are the real and legal attributes of node #2, or whether node #2 is the real owner of the attributes. Exemplarily, the proof information includes the credential information of node #1 related to the attributes corresponding to node #2. Among them, node #1 related to the attributes corresponding to node #2 refers to the node that provides attribute endorsement services for node #2, which can be one or more, such as the device corresponding to a social authority or the device corresponding to a third-party trusted agency. The credential information can be the certificate of node #1 related to the attributes corresponding to node #2, including the public key, the digital signature of the public key, information indicating the issuing authority of the public key, and information indicating the owner of the public key.

[0369] Optionally, the certification information may also include a hash of the attribute corresponding to node #2, or the attribute corresponding to node #2, to verify whether the attribute corresponding to node #2 carried in request #4 is consistent with that in the certification information.

[0370] It should be understood that there may be one or more attributes corresponding to node #2, and different attributes may be associated with different nodes #1, so the corresponding signatures and credential information may also be different.

[0371] That is, for node #4 in S602 to determine whether node #2 meets the requirements for accessing node #4's data, at least the following two verification processes are included:

[0372] Verification process 1: After receiving request #4, node #4 can use the proof information to first verify the attributes corresponding to node #2 in request #4 to determine whether the attributes corresponding to node #2 in request #4 are authentic and legal, that is, to determine whether node #2 is the true owner of the attributes.

[0373] Exemplarily, node #4 verifies the signature in the attribute information corresponding to node #2 in request #4 based on the public key in the proof information. If the signature verification passes, the attribute corresponding to node #2 in request #4 is considered to be authentic and legal, and the following verification process 2 is continued. Otherwise, the attribute corresponding to node #2 in request #4 is considered to be unreliable, and node #4 can reject request #4, not support node #2's access to its data, or not authorize node #2 to access its data.

[0374] Regarding the certification information, in one possible design, node #4 can obtain it from the blockchain. That is, the blockchain has the certification information deployed, and node #4 can obtain the corresponding certification information from the blockchain based on the identifier of node #2 and / or the identifier of node #1 related to the attributes corresponding to node #2. Exemplarily, node #4 sends request #5 to the blockchain node, and the blockchain node responds by receiving request #5 from node #4. Request #5 is used to request the certification information corresponding to node #2. Request #5 may include the identifiers of node #1 and node #2 related to the attributes corresponding to node #2. Thus, the blockchain node can obtain the certification information from its local or local blockchain based on request #5 and send it to node #4. Optionally, the certification information corresponding to node #2 can be sent in the response to request #5 or in another message, without limitation. In this embodiment of the present application, request #5 can also be referred to as the third request, or in other words, request #5 corresponds to the third request.

[0375] In addition to the above possible designs, node #4 can also obtain proof information from node #1 related to the attribute corresponding to node #2, and there is no limitation on this.

[0376] After completing the above-mentioned verification process 1 and the verification passes, the following verification process 2 is executed: Node #4 determines whether the requirements for accessing the data of node #4 are met based on the attributes corresponding to the verified node #2. The requirements for accessing the data of node #4 are set based on the attribute requirements corresponding to node #2, which can be called access policy, access condition, etc., and there is no limitation on this.

[0377] For example, the requirements for accessing node #4's data are: (employee of company A, or employee of company B, or employee of company C) and currently located in China. The attributes corresponding to node #2 in request #4 include that node #2 is an employee of company B and is currently located in China. Therefore, node #4 can determine that node #2 meets the requirements for accessing node #4's data based on the attributes corresponding to node #2 in request #4, and thus accept node #2's data access request or authorize node #2 to access the data.

[0378] On the contrary, if node #2 does not meet the requirements for accessing the data of node #4, such as the attributes corresponding to node #2 in request #4 include that node #2 is an employee of company B and node #2 is currently located abroad, then node #4 will not accept the data access request of node #2, or will prohibit node #2 from accessing the data.

[0379] If node #2 meets the requirements for accessing node #4's data, node #4 can send a response to request #4 to indicate that node #2 can access node #4's data. In one possible design 1, the response to request #4 can carry the data that node #2 wants to access. Thus, node #2 can obtain the access data based on the response to request #4.

[0380] In a possible design 2, to reduce the complexity of data access, node #4 can encrypt its data and store it uniformly on the storage node, and publish the information used to access the data on the blockchain, so that node #2 accessing the data can obtain the information used to access the data from the blockchain and complete the data access.

[0381] Under this design 2, in order for node #2 to decrypt the encrypted data obtained from node #4, node #4, upon determining that node #2 meets the requirements for accessing node #4's data, can also generate and send a first key for node #2. That is, node #4 can send the first key to node #2, where the first key is used to decrypt the encrypted data of node #4 and can be determined based on the corresponding attributes of node #2. Optionally, the first key can be sent in the response corresponding to the above request #4 or in other messages, without limitation.

[0382] Node #4 can also record node #2's access history on the blockchain. In one possible implementation, node #4 sends information indicating node #2's access history to the blockchain node. In return, the blockchain node receives information indicating node #2's access history from node #4. This information can indicate when, where, and what data node #2 accessed from node #4. Thus, the blockchain node records node #2's access history.

[0383] In addition, under the above-mentioned design 2, the communication method provided in the embodiment of the present application may further include the following steps:

[0384] S603: Node #4 sends data access information to the blockchain node. Correspondingly, the blockchain node receives the data access information from node #4.

[0385] Among them, the information used for data access is used to indicate how to access the data stored in node #4. The information used for data access can be configured as a profile of node #4. The information used for data access includes information used to indicate the requirements that node #2 must meet to access the data of node #4 and information used to indicate how to obtain the data of node #4.

[0386] The information used to indicate the requirements that node #2 must meet to access the data of node #4 can be called an access policy or access condition, which is the requirement of node #4 for node #2 requesting access to data, and can be set based on the corresponding attribute requirements for node #2.

[0387] The information for instructing to obtain the data of node #4 may include the storage address where the encrypted data of node #4 is located and / or information indicating the encrypted data of node #4. The storage address where the encrypted data of node #4 is located indicates the location of the storage node storing the encrypted data of node #4, and the information indicating the encrypted data of node #4 may be represented by an index or data feature description to facilitate querying data of corresponding type or feature.

[0388] In the embodiment of the present application, the encryption of the data of node #4 can be performed using symmetric key encryption or asymmetric key encryption, without limitation. For example, node #4 uses the second key to encrypt its data.

[0389] Optionally, the information indicating the acquisition of data for node #4 may further include an encrypted second key (i.e., a ciphertext of the second key). For example, the second key is K, and the encryption method for the second key may be ciphertext-policy attribute-based encryption (CPABE). The CPABE-encrypted second key, i.e., the ciphertext, is K1.

[0390] Thus, after the blockchain node obtains the data access information corresponding to node #4, it can publish or trade the information on the blockchain. Optionally, the blockchain node can send the address of the data access information corresponding to node #4 on the blockchain to node #4.

[0391] Furthermore, node #2 can obtain information for data access from the blockchain. When node #2 meets the requirements for accessing node #4's data, that is, node #2 is authorized to access node #4's data, node #2 can obtain the encrypted data of node #4 from the storage node based on the information for indicating the acquisition of node #4's data in the information for data access, as described in S604 below.

[0392] It should be understood that the embodiment of the present application does not limit the execution order of S603 and S601 to S602. S603 can be executed before or after S601 to S602.

[0393] S604: Node #2 sends request #6 to the blockchain node. Accordingly, the blockchain node receives request #6 from node #2.

[0394] Request #6 is used to request information for accessing node #4's data. Request #6 includes node #4's identifier. Upon receiving request #6, the blockchain node can query node #4's identifier to obtain the corresponding data access information and send it to node #2. In this embodiment of the present application, request #6 may also be referred to as the fourth request, or, in other words, may correspond to the fourth request.

[0395] S605: The blockchain node sends data access information to node #2. In response, node #2 receives data access information from the blockchain node.

[0396] In a possible implementation, the information used for data access may be carried in the response corresponding to request #6 and sent, or carried in other messages and sent, without limitation.

[0397] Therefore, after node #2 receives the information for data access from the blockchain node, it can obtain the encrypted data of node #4 based on the information for data access.

[0398] It should be understood that the embodiment of the present application does not limit the execution order of S604 to S605 and S601 to S602. S604 to S605 can be executed before or after S601 to S602.

[0399] Optionally, node #2 may also execute the above S601 based on the information indicating the requirements that node #2 must meet to access the data of node #4, and apply for attributes that meet the requirements, so as to obtain permission to access the data of node #4. In this case, S604 may be executed before S601.

[0400] S606: Node #2 sends request #7 to the storage node. Correspondingly, the storage node receives request #7 from node #2.

[0401] After node #2 obtains the information for data access, it can determine the location of the storage node based on the storage address in the information indicating the data to be obtained from node #4, and send request #7 to the corresponding storage node. Request #7 is used to request the data of node #4. Request #7 includes the identifier of node #4 and the index or feature description corresponding to the data of node #4 that node #2 wants to obtain. In this embodiment of the present application, request #7 can also be referred to as the seventh request, or in other words, request #7 corresponds to the seventh request.

[0402] S607: The storage node sends the encrypted data of node #4 to node #2. Correspondingly, node #2 receives the encrypted data of node #4 from the storage node.

[0403] In a possible implementation, the encrypted data of node #4 may be carried in the response corresponding to request #7 and sent, or carried in other messages and sent, without limitation.

[0404] After node #2 obtains the encrypted data of node #4, it can decrypt the encrypted data of node #4 according to the obtained first key to obtain the data of node #4.

[0405] In one possible design, the encrypted data of node #4 is data encrypted using the second key, and the first key can be used to decrypt the encrypted data. In other words, node #2 can decrypt the data using the first key to obtain the second key, and then use the second key to decrypt the data of node #4. Alternatively, node #2 can directly decrypt the data of node #4 using the first key.

[0406] Based on the communication method shown in FIG6 , node #4 performs data access control on node #2 according to the attribute information corresponding to node #2, which can improve the reliability and security of data access.

[0407] In addition to the data access control by node #4 on node #2 shown in Figure 6 above, the blockchain node can also control data access to node #2 by calling a smart contract. For example, Figure 7 is a flow chart of another communication method provided in an embodiment of the present application. As shown in Figure 7, the communication method includes:

[0408] S701: Node #2 sends request #8 to the blockchain node. In response, the blockchain node receives request #8 from node #2.

[0409] Request #8 is used to request the invocation of the first smart contract, which is used to determine whether node #2 can access node #4's data. In other words, request #8 is used to request the blockchain node to invoke the first smart contract to determine whether node #2 can access node #4's data. Request #8 may include information such as the identifier of node #2, the identifier of node #4, the identifier of the first smart contract, and parameter information used as input for the first smart contract. In this embodiment of the present application, request #8 may also be referred to as the eighth request, or in other words, request #8 corresponds to the eighth request.

[0410] In an embodiment of the present application, the first smart contract can be set based on the requirements for the attributes of node #2. Therefore, the parameter information used as input for the first smart contract can be the attribute information corresponding to node #2. The attribute information corresponding to node #2 can include the attributes corresponding to node #2 and the signature of node #1 related to the attributes corresponding to node #2. For a specific description, please refer to the relevant description of the attributes corresponding to node #2 in the above S601, which will not be repeated here.

[0411] In some possible designs, the identifier of node #2 and / or the identifier of node #4 may also serve as input parameters of the first smart contract.

[0412] The first smart contract can be understood as providing data access authorization services for node #2. Node #2, through request #8, instructs the blockchain node to invoke the first smart contract to determine whether it can access node #4's data. In one possible implementation, the first smart contract can be installed on the blockchain at the request of node #4. The installation process for the first smart contract can be described in the smart contract installation process shown in Figure 1, which is not described in detail here. Thus, the blockchain node can obtain usage information corresponding to the first smart contract, such as the service type corresponding to the first smart contract, the input parameter settings of the first smart contract, and the output parameter settings of the first smart contract. For details, see the description of information #3 above, which is not described here.

[0413] S702. The blockchain node determines whether node #2 can access the data of node #4 based on request #8 and the first smart contract.

[0414] After receiving request #8, the blockchain node can call the first smart contract according to request #8, input the input parameters of request #8 into the first smart contract, and determine whether node #2 can access the data of node #4 based on the output of the first smart contract. The first smart contract can be considered as an access policy.

[0415] In one possible design, the input of the first smart contract includes attribute information corresponding to node #2, and the output of the first smart contract is used to indicate whether node #2 can access node #4's data. The output of the first smart contract may include a first output, which can be represented by 0 or 1. A first output of 0 indicates that node #2 cannot access node #4's data, and a first output of 1 indicates that node #2 can access node #4's data.

[0416] After the blockchain node completes its determination, it can send a response to request #8 to node #2. This response indicates whether node #2 can access node #4's data. For example, the response to request #8 carries indication information 1, which can indicate, via a single bit, whether node #2 can access node #4's data. For example, a bit value of 1 indicates that node #2 can access node #4's data, while a bit value of 0 indicates that node #2 cannot access node #4's data. Thus, after receiving the response to request #8, node #2 can determine whether it can access node #4's data.

[0417] In the scenario where node #4's data is encrypted and stored on a storage node outside the blockchain, the output of the first smart contract may further include a second output indicating the first key for decrypting the encrypted data of node #4. If node #2 can access node #4's data, the second output may be the first key, which is not null; if node #2 cannot access node #4's data, the second output may be the first key, which is null.

[0418] In this scenario, when node #2 is able to access the data of node #4, the blockchain node also needs to send the first key to node #2. The first key can be carried in the response corresponding to the above request #8 or sent using other messages.

[0419] In this scenario, in one possible design, the first key can directly decrypt the encrypted data of node #4 to obtain the data of node #4. In another possible design, the first key is used to decrypt the encrypted second key, and the second key is used to encrypt the data of node #4. In other words, the data of node #4 is encrypted by node #4 using the second key and then stored in the storage node. In this case, the data of node #4 needs to be decrypted using the first key to obtain the second key, and then the encrypted data of node #4 needs to be decrypted using the second key to obtain the data of node #4.

[0420] Thus, node #2 can obtain the encrypted data of node #4 from the storage node and decrypt it using the first key to obtain the data of node #4. The specific implementation process of node #2 obtaining the encrypted data from the storage node can be found in the relevant descriptions of S603 to S607 above, and will not be repeated here.

[0421] In addition, the blockchain node can also generate and record the access status of node #2, such as recording the access status on the blockchain to record when and where node #2 accessed what data of node #4.

[0422] Based on the communication method shown in Figure 7, the blockchain node can call the first smart contract to control data access to node #2 according to the attribute information corresponding to node #2, which can improve the reliability and security of data access.

[0423] In each of the above embodiments, the methods and / or steps implemented by the blockchain node may also be implemented by components (e.g., processors, chips, chip systems, circuits, logic modules, or software) that can be used for the blockchain node; the methods and / or steps implemented by node #1 may also be implemented by components (e.g., processors, chips, chip systems, circuits, logic modules, or software) that can be used for node #1; the methods and / or steps implemented by node #2 may also be implemented by components (e.g., processors, chips, chip systems, circuits, logic modules, DUs, or software) that can be used for node #2; the methods and / or steps implemented by node #3 may also be implemented by components (e.g., processors, chips, chip systems, circuits, logic modules, DUs, or software) that can be used for the node The methods and / or steps implemented by the operator node may also be implemented by the components (e.g., processor, chip, chip system, circuit, logic module, or software) of point #3; the methods and / or steps implemented by node #4 may also be implemented by the components (e.g., processor, chip, chip system, circuit, logic module, or software) that can be used for the node #4; the methods and / or steps implemented by the operator node may also be implemented by the components (e.g., processor, chip, chip system, circuit, logic module, or software) that can be used for the operator node; the methods and / or steps implemented by the storage node may also be implemented by the components (e.g., processor, chip, chip system, circuit, logic module, or software) that can be used for the storage node.

[0424] The above primarily introduces the solutions provided by this application. Accordingly, this application also provides a communication device for implementing the various methods described in the aforementioned method embodiments. The communication device may be node #1 in the aforementioned method embodiments, or a device comprising node #1, or a component usable for node #1, such as a chip or chip system. Alternatively, the communication device may be node #2 in the aforementioned method embodiments, or a device comprising node #2, or a component usable for node #2, such as a chip or chip system. Alternatively, the communication device may be node #3 in the aforementioned method embodiments, or a device comprising node #3, or a component usable for node #3, such as a chip or chip system. Alternatively, the communication device may be node #4 in the aforementioned method embodiments, or a device comprising node #4, or a component usable for node #4, such as a chip or chip system. Alternatively, the communication device may be a carrier node in the aforementioned method embodiments, or a device comprising a carrier node, or a component usable for a carrier node, such as a chip or chip system. Alternatively, the communication device may be the storage node in the above method embodiment, or a device including a storage node, or a component that can be used for a storage node, such as a chip or a chip system.

[0425] In some embodiments, in order to implement the above functions, the communication device includes hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art should easily appreciate that, in combination with the units and algorithm steps of the various examples described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0426] The embodiment of the present application can divide the functional modules of the communication device according to the above method embodiment. For example, each functional module can be divided according to each function, or two or more functions can be integrated into one processing module. The above integrated modules can be implemented in the form of hardware or in the form of software functional modules. It should be noted that the division of modules in the embodiment of the present application is schematic and is only a logical functional division. In actual implementation, there may be other division methods.

[0427] Taking the communication device as any node from node #1 to node #4, or an operator node or a storage node in the above method embodiment as an example, Figure 8 is a schematic structural diagram of a communication device provided in an embodiment of the present application. As shown in Figure 8, the communication device 800 includes: a processing module 801 and a transceiver module 802. Among them, the processing module 801 is used to perform the processing function of any node from node #1 to node #4, or an operator node or a storage node in the above method embodiment. The transceiver module 802 is used to perform the transceiver function of any node from node #1 to node #4, or an operator node or a storage node in the above method embodiment.

[0428] Among them, all relevant contents of each step involved in the above method embodiment can be referred to the functional description of the corresponding functional module and will not be repeated here.

[0429] Since the communication device 800 provided in this embodiment can execute the above method, the technical effects that can be obtained can refer to the above method embodiments and will not be repeated here.

[0430] In one possible design solution, in an embodiment of the present application, the transceiver module 802 may include a receiving module and a sending module (not shown in FIG8 ), wherein the sending module and the receiving module are respectively used to implement the sending function and the receiving function of the communication device 800 .

[0431] In one possible design, communication device 800 may further include a storage module (not shown in FIG8 ) storing a program or instruction. When processing module 801 executes the program or instruction, communication device 800 may perform the functions of any node among node #1 to node #4, or an operator node or a storage node in any of the methods shown in FIG2 to FIG7 .

[0432] In some embodiments, the processing module 801 involved in the communication device 800 can be implemented by a processor or a processor-related circuit component, which can be a processor or a processing unit; the transceiver module 802 can be implemented by a transceiver or a transceiver-related circuit component, which can be a transceiver or a transceiver unit.

[0433] For example, FIG9 is a schematic diagram of the structure of another communication device provided in an embodiment of the present application. The communication device can be any node from node #1 to node #4, or an operator node or a storage node in the above-mentioned method embodiment, or a chip (system) or other parts or components that can be set at any node from node #1 to node #4, or an operator node or a storage node. As shown in FIG9 , the communication device 900 may include a processor 901. In one possible design scheme, the communication device 900 may further include a memory 902 and / or a transceiver 903. The processor 901 is coupled to the memory 902 and the transceiver 903, such as by being connected via a communication bus.

[0434] The following is a detailed introduction to the various components of the communication device 900 in conjunction with FIG9 :

[0435] The processor 901 is the control center of the communication device 900 and can be a single processor or a collective term for multiple processing elements. For example, the processor 901 includes one or more CPUs, or can be an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application, such as one or more microprocessors (digital signal processors, DSPs) or one or more field programmable gate arrays (FPGAs).

[0436] In one possible design, the processor 901 may execute various functions of the communication device 900 by running or executing software programs stored in the memory 902 and calling data stored in the memory 902 .

[0437] In a specific implementation, as an embodiment, the processor 901 may include one or more CPUs, such as CPU0 and CPU1 shown in FIG. 9 .

[0438] In a specific implementation, as an embodiment, the communication device 900 may also include multiple processors, such as the processor 901 and the processor 904 shown in Figure 9. Each of these processors may be a single-core processor or a multi-core processor. The processor here may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).

[0439] The memory 902 is used to store the software program for executing the solution of the present application, and the execution is controlled by the processor 901. The specific implementation method can refer to the above method embodiment and will not be repeated here.

[0440] In one possible design, the memory 902 can be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, an optical disc storage (including a compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 902 can be integrated with the processor 901 or exist independently and be coupled to the processor 901 through the interface circuit of the communication device 900 (not shown in FIG9 ), which is not specifically limited in this embodiment of the present application.

[0441] Transceiver 903 is used for communication with other communication devices. For example, if communication device 900 is a terminal device, transceiver 903 can be used to communicate with an access network device or another terminal device. For another example, if communication device 900 is a network device, transceiver 903 can be used to communicate with a terminal device or another network device.

[0442] In one possible design solution, transceiver 903 may include a receiver and a transmitter (not separately shown in FIG9 ), wherein the receiver is used to implement a receiving function, and the transmitter is used to implement a sending function.

[0443] In one possible design scheme, the transceiver 903 can be integrated with the processor 901, or it can exist independently and be coupled to the processor 901 through the interface circuit of the communication device 900 (not shown in Figure 9). This embodiment of the present application does not specifically limit this.

[0444] It should be noted that the structure of the communication device 900 shown in FIG9 does not constitute a limitation on the communication device. An actual communication device may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.

[0445] In addition, the technical effects of the communication device 900 can refer to the technical effects of the methods described in the above method embodiments, and will not be repeated here.

[0446] An embodiment of the present application further provides a computer-readable storage medium on which a computer program or instruction is stored. When the computer program or instruction is executed by a computer, the functions of the above-mentioned method embodiment are realized.

[0447] The embodiments of the present application also provide a computer program product, which implements the functions of the above method embodiments when executed by a computer.

[0448] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware, or any combination thereof. When implemented using a software program, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions according to the embodiments of the present application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more media integrated therein. The available medium may be a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a DVD), or a semiconductor medium (eg, a solid state disk (SSD)).

[0449] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0450] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0451] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0452] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0453] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0454] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or an access network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a ROM, a random access memory RAM, a magnetic disk, or an optical disk.

[0455] Although the present application is described herein in conjunction with various embodiments, in the process of implementing the claimed application, those skilled in the art may understand and implement other variations of the disclosed embodiments by reviewing the drawings, the disclosure, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude multiple situations. A single processor or other unit may implement several functions listed in the claims. Certain measures are recorded in different dependent claims, but this does not mean that these measures cannot be combined to produce good results.

[0456] Although the present application has been described with reference to specific features and embodiments thereof, it is apparent that various modifications and combinations may be made thereto without departing from the spirit and scope of the present application. Accordingly, this specification and the drawings are merely illustrative of the present application as defined by the appended claims and are deemed to cover any and all modifications, variations, combinations or equivalents within the scope of the present application. Obviously, those skilled in the art may make various modifications and variations to the present application without departing from the spirit and scope of the present application. Thus, the present application is intended to include such modifications and variations as fall within the scope of the claims of the present application and their equivalents.

Claims

1. A communication method, characterized in that, The method includes: The first node obtains attribute information, where the attribute information is used to indicate the attributes corresponding to the second node that has been proven; The first node sends the attribute information to the second node.

2. The method according to claim 1, characterized in that, The method further includes: The first node sends first information to the second node, where the first information is used to indicate the address of the attribute information on the blockchain.

3. The method according to claim 1 or 2, characterized in that The obtaining of the attribute information includes: The first node receives a first request from the second node, where the first request is used to request to obtain attributes; The first node sends the attribute information to the second node according to the first request.

4. The method according to claim 3, wherein The first node sending the attribute information to the second node according to the first request includes: The first node generates the attribute information using a smart contract according to the first request, where the smart contract is associated with an attribute endorsement service; The first node sends the attribute information to the second node.

5. The method according to claim 4, characterized in that, The method further includes: The first node receives a fifth request from the fourth node, where the first request is used to request to install the smart contract, and the fourth node is a node for providing an attribute endorsement or proof service; The first node installs the smart contract according to the fifth request.

6. The method according to claim 5, characterized in that, The installing of the smart contract according to the fifth request includes: The first node sends second information to the fourth node according to the fifth request, where the second information is used to indicate whether it supports installing the smart contract; The first node receives third information from the fourth node, where the third information is used to indicate installing the smart contract, and the third information is determined according to the second information corresponding to at least one blockchain node on the blockchain.

7. The method according to claim 6, wherein In the case where the result of whether it supports installing the smart contract is recorded by the first node on the blockchain, the second information includes the address of the result of whether it supports installing the smart contract on the blockchain.

8. The method according to claim 6 or 7, characterized in that, The third information includes the result of whether at least one blockchain node on the blockchain supports installing the smart contract, and / or, the address of the result of whether the at least one blockchain node supports installing the smart contract on the blockchain.

9. The method according to any one of claims 5 - 8, characterized in that, The method further includes: Receiving fourth information from the fourth node, where the fourth information is used to indicate the usage information of the smart contract.

10. The method according to claim 9, wherein The fourth information includes at least one of the following: the attribute endorsement service corresponding to the smart contract, the address of the smart contract, the input parameters of the smart contract, the output parameters of the smart contract, or the application template of the attribute information.

11. The method according to claim 1 or 2, characterized in that, The method further includes: The first node sends the attribute information to a blockchain node; The first node receives first information from the blockchain node, where the first information is used to indicate the address of the attribute information on the blockchain.

12. A communication method, characterized in that, The method includes: The second node receives attribute information from the first node, where the attribute information is used to indicate the attributes corresponding to the second node that has been proven; The second node determines the attributes corresponding to the second node according to the attribute information.

13. The method according to claim 12, wherein The method further includes: The second node receives first information from the first node, and the first information is used to indicate the address of the attribute information on the blockchain.

14. The method according to claim 12 or 13, characterized in that The method further includes: The second node sends a first request to the first node, and the first request is used to request to obtain an attribute.

15. The method according to any one of claims 3-9 or 14, characterized in that, The first request includes at least one of the following: the identifier of the second node, information indicating the type of the attribute to be requested, the identity authentication information corresponding to the second node, or the signature of the third node on the identity authentication information corresponding to the second node.

16. The method according to any one of claims 1-15, characterized in that, The attribute information includes the attribute corresponding to the second node and the signature of the fourth node related to the attribute corresponding to the second node.

17. The method according to claim 16, characterized in that The attribute information further includes at least one of the following: the issuance time of the attribute information, the validity period of the attribute information, the identifier of the second node, or the signature of the blockchain node on the attribute corresponding to the second node.

18. A communication method, characterized in that, The method includes: The fifth node receives a second request from the second node, and the second request is used to request to access the data of the fifth node, and the second request includes the attribute information corresponding to the second node; The fifth node determines whether the second node meets the requirement for accessing the data of the fifth node according to the attribute information corresponding to the second node and the proof information, and the proof information is used to verify the attribute corresponding to the second node.

19. The method according to claim 18, wherein The second request further includes the address of the attribute information corresponding to the second node on the blockchain.

20. The method according to claim 18 or 19, characterized in that, The method further includes: The fifth node sends a third request to the blockchain node, and the third request is used to request to obtain the proof information; The fifth node receives the proof information from the blockchain node.

21. The method according to claim 20, wherein The proof information includes the voucher information of the fourth node related to the attribute corresponding to the second node.

22. The method according to claim 21, wherein The proof information further includes: the hash of the attribute corresponding to the second node, and / or the attribute corresponding to the second node.

23. The method according to any one of claims 18-22, characterized in that, The fifth node receives a second request from the second node, including: The fifth node receives the identity information from the second node, and the identity information includes the identifier of the second node and the signature of the fourth node related to the identifier of the second node; When the identifier of the second node is verified, it is determined to establish a security authentication with the second node; When the security authentication is completed, the fifth node receives the second request from the second node.

24. The method according to any one of claims 18-23, characterized in that, The method further includes: The fifth node sends information for data access to the blockchain node, and the information for data access includes information indicating the requirements that the second node needs to meet for accessing the data of the fifth node and information indicating to obtain the data of the fifth node.

25. The method according to any one of claims 18 - 24, characterized in that, The method further includes: When the second node meets the requirement for accessing the data of the fifth node, the fifth node sends a first key to the second node, where the first key is determined according to the attribute corresponding to the second node, and the first key is used to decrypt the encrypted data of the fifth node.

26. The method according to claim 25, wherein The method further includes: The fifth node sends information for data access to the blockchain node. The information for data access includes information for indicating requirements that the data accessed by the second node from the fifth node needs to meet and information for indicating obtaining the data of the fifth node.

27. The method according to claim 26, characterized in that, The information for indicating obtaining the data of the fifth node includes the encrypted storage address where the data of the fifth node is located, and / or information for indicating the encrypted data of the fifth node.

28. The method according to claim 27, characterized in that, The data of the fifth node is encrypted with a second key. The information for indicating obtaining the data of the fifth node further includes: the encrypted second key, and the first key is specifically used for decrypting the encrypted second key.

29. The method according to claim 27 or 28, characterized in that, The method further includes: The fifth node sends the encrypted data of the fifth node to the storage node corresponding to the storage address.

30. The method according to any one of claims 18-29, characterized in that, The method further includes: The fifth node sends information for indicating the access record of the second node to the blockchain node.

31. The method according to any one of claims 18 - 30, characterized in that, The attribute information corresponding to the second node includes the attribute corresponding to the second node and the signature of the fourth node related to the attribute corresponding to the second node.

32. A communication method, characterized in that, The method includes: The second node generates a second request for requesting access to the data of the fifth node. The second request includes the attribute information corresponding to the second node. The second node sends the second request to the fifth node.

33. The method according to claim 32, wherein The second request further includes the address of the attribute information corresponding to the second node on the blockchain.

34. The method according to claim 32 or 33, characterized in that, The second node sending the second request to the fifth node includes: The second node establishes a security authentication with the fifth node according to the identifier of the second node. When the security authentication is completed, the second node sends the second request to the fifth node.

35. The method according to any one of claims 32 - 34, characterized in that, The method further includes: The second node receives a first key from the fifth node. The first key is determined according to the attribute corresponding to the second node, and the first key is used for decrypting the encrypted data of the fifth node.

36. The method according to claim 35, characterized in that, The method further includes: The second node sends a fourth request to the blockchain node for requesting information for accessing the data of the fifth node. The second node receives the information for data access from the blockchain node. The information for data access includes information for indicating requirements that the second node needs to meet for accessing the data of the fifth node and information for indicating obtaining the data of the fifth node. The second node obtains the encrypted data of the fifth node according to the information for data access. The second node decrypts the encrypted data of the fifth node according to the first key.

37. The method according to claim 36, characterized in that, The information for indicating obtaining the data of the fifth node includes the encrypted storage address where the data of the fifth node is located, and / or information for indicating the encrypted data of the fifth node.

38. The method according to claim 37, wherein The data of the fifth node is encrypted with a second key, and the information for indicating to obtain the data of the fifth node further includes: the encrypted second key, and the first key is specifically used to decrypt the encrypted second key.

39. The method according to claim 37 or 38, characterized in that, The second node obtains the encrypted data of the fifth node according to the information for data access, including: The second node sends a seventh request to the storage node corresponding to the storage address, and the seventh request is used to request to obtain the data of the fifth node; The second node receives the encrypted data of the fifth node from the storage node.

40. The method according to any one of claims 36 - 39, characterized in that, The second node decrypts the encrypted data of the fifth node according to the first key, including: The second node decrypts the encrypted second key according to the first key; The second node decrypts the data of the fifth node encrypted with the second key according to the second key.

41. The method according to any one of claims 32 - 40, characterized in that, The attribute information corresponding to the second node includes the attribute corresponding to the second node and the signature of the fourth node related to the attribute corresponding to the second node.

42. A communication method, characterized in that, The method includes: A blockchain node receives a fifth request from a fourth node, and the fifth request is used to request to install a smart contract corresponding to an attribute endorsement service supported by the fourth node; The blockchain node installs the smart contract according to the fifth request.

43. The method according to claim 42, wherein The blockchain node installs the smart contract according to the fifth request, including: The blockchain node sends second information to the fourth node according to the fifth request, and the second information is used to indicate whether it supports installing the smart contract; The blockchain node receives third information from the fourth node, and the third information is used to indicate installing the smart contract, and the third information is determined according to the second information corresponding to at least one blockchain node on the blockchain.

44. The method according to claim 43, wherein In the case where the result of whether it supports installing the smart contract is recorded on the blockchain by the blockchain node, the second information includes the address on the blockchain of the result of whether it supports installing the smart contract.

45. The method according to claim 43 or 44, characterized in that, The third information includes the result of whether at least one blockchain node on the blockchain supports installing the smart contract, and / or, the address on the blockchain of the result of whether the at least one blockchain node supports installing the smart contract.

46. The method according to any one of claims 42-45, characterized in that, The method further includes: The blockchain node receives fourth information from the fourth node, and the fourth information is used to indicate the usage information of the smart contract.

47. The method according to claim 46, characterized in that, The fourth information includes at least one of the following: the attribute endorsement service corresponding to the smart contract, the address of the smart contract, the input parameters of the smart contract, the output parameters of the smart contract, or the application template of the attribute information.

48. A communication method, characterized in that, The method includes: The fourth node generates a fifth request, and the fifth request is used to request to install a smart contract corresponding to an attribute endorsement service supported by the fourth node; The fourth node sends the fifth request to the blockchain node.

49. The method according to claim 48, wherein The method further includes: The fourth node receives second information from the blockchain node, and the second information is used to indicate whether to support the installation of the smart contract; The fourth node sends third information to the blockchain node, and the third information is used to indicate the installation of the smart contract, and the third information is determined according to the second information corresponding to at least one blockchain node on the blockchain.

50. The method according to claim 49, characterized in that, In the case where the result of whether to support the installation of the smart contract is recorded on the blockchain by the blockchain node, the second information includes the address of the result of whether to support the installation of the smart contract on the blockchain.

51. The method according to claim 49 or 50, characterized in that, The third information includes the result of whether at least one blockchain node on the blockchain supports the installation of the smart contract, and / or the address of the result of whether the at least one blockchain node supports the installation of the smart contract on the blockchain.

52. The method according to any one of claims 48 - 51, characterized in that, The method further includes: The fourth node sends fourth information to the blockchain node, and the fourth information is used to indicate the usage information of the smart contract.

53. The method according to claim 52, wherein, The fourth information includes at least one of the following: the attribute endorsement service corresponding to the smart contract, the address of the smart contract, the input parameters of the smart contract, the output parameters of the smart contract, or the application template of the attribute information.

54. The method according to claim 48, characterized in that, The method further includes: The fourth node receives a first request from the second node, and the first request is used to request to obtain an attribute; The fourth node sends attribute information to the second node according to the first request.

55. The method according to claim 54, characterized in that, The attribute information includes the attribute corresponding to the second node and the signature of the fourth node related to the attribute corresponding to the second node.

56. The method according to claim 55, wherein The attribute information further includes at least one of the following: the issuance time of the attribute information, the validity period of the attribute information, the identifier of the second node, or the signature of the blockchain node on the attribute corresponding to the second node.

57. The method according to any one of claims 54 - 56, characterized in that, The method further includes: The fourth node receives first information from the blockchain node, and the first information is used to indicate the address of the attribute information on the blockchain.

58. A communication method, characterized in that, The method includes: The operator node determines that the first terminal device and the second terminal device access the network corresponding to the operator node; In the case where it is determined that the first terminal device receives a call request from the second terminal device, the operator node sends the attribute corresponding to the second terminal device to the first terminal device.

59. The method according to claim 58, wherein The method further includes: The operator node sends a sixth request to the blockchain node, and the sixth request is used to request to obtain the attribute corresponding to the second terminal device; The operator node receives the attribute information corresponding to the second terminal device from the blockchain node, and the attribute information corresponding to the second terminal device includes the attribute corresponding to the second terminal device and the signature of the fourth node related to the attribute corresponding to the second terminal device.

60. The method according to claim 59, characterized in that, The attribute information corresponding to the second terminal device further includes the identifier of the second terminal device and / or the signature of the blockchain node on the attribute corresponding to the second terminal device.

61. A communication method, characterized in that, The method includes: The blockchain node receives a fourth request from the second node, and the fourth request is used to request information for accessing data of the fifth node; The blockchain node sends information for data access to the second node, and the information for data access includes information for indicating requirements that need to be met for the second node to access the data of the fifth node and information for indicating obtaining the data of the fifth node.

62. The method according to claim 61, characterized in that, The method further includes: The blockchain node receives the information for data access from the fifth node.

63. The method according to claim 61 or 62, characterized in that, The information for indicating obtaining the data of the fifth node includes the encrypted storage address where the data of the fifth node is located, and / or information for indicating the encrypted data of the fifth node.

64. The method according to claim 63, characterized in that, The data of the fifth node is encrypted with a second key, and the information for indicating obtaining the data of the fifth node further includes: the encrypted second key.

65. The method according to any one of claims 61 - 64, characterized in that, The method further includes: The blockchain node receives information for indicating the access record of the second node from the fifth node.

66. A communication method, characterized in that, The method includes: The blockchain node receives an eighth request from the second node, and the eighth request is used to request to invoke a first smart contract, and the first smart contract is used to determine whether the second node can access the data of the fifth node; The blockchain node determines whether the second node can access the data of the fifth node according to the eighth request and the first smart contract.

67. The method according to claim 66, wherein The eighth request includes the attribute information corresponding to the second node.

68. The method according to claim 67, characterized in that, The attribute information corresponding to the second node includes the attribute corresponding to the second node and the signature of the fourth node related to the attribute corresponding to the second node.

69. The method according to any one of claims 66-68, characterized in that, The method further includes: When the second node can access the data of the fifth node, the blockchain node sends a first key to the second node, and the first key is used to decrypt the encrypted data of the fifth node.

70. The method according to any one of claims 66 - 69, characterized in that, The method further includes: The blockchain node receives the information for data access from the fifth node, and the information for data access includes information for indicating requirements that need to be met for the second node to access the data of the fifth node and information for indicating obtaining the data of the fifth node.

71. The method according to claim 70, characterized in that, The method further includes: The blockchain node receives a fourth request from the second node, and the fourth request is used to request information for accessing the data of the fifth node; The blockchain node sends the information for data access to the second node.

72. The method according to claim 70 or 71, characterized in that, The information for indicating obtaining the data of the fifth node includes the encrypted storage address where the data of the fifth node is located, and / or information for indicating the encrypted data of the fifth node.

73. The method according to claim 72, wherein The data of the fifth node is encrypted with a second key, and the information for indicating obtaining the data of the fifth node further includes: the encrypted second key.

74. The method according to any one of claims 66 - 73, characterized in that, The method further includes: When the second node can access the data of the fifth node, the blockchain node generates and records the access situation of the fifth node.

75. A communication method, characterized in that, The method includes: The second node generates an eighth request for requesting to invoke a first smart contract, and the first smart contract is used to determine whether the second node can access the data of the fifth node; The second node sends the eighth request to a blockchain node.

76. The method according to claim 75, characterized in that, The eighth request includes the attribute information corresponding to the second node.

77. The method according to claim 76, characterized in that, The attribute information corresponding to the second node includes the attribute corresponding to the second node and the signature of the fourth node related to the attribute corresponding to the second node.

78. The method according to any one of claims 75 - 77, characterized in that, The method further includes: The second node receives a first key from the blockchain node, and the first key is used to decrypt the encrypted data of the fifth node.

79. The method according to claim 78, wherein The method further includes: The second node sends a fourth request to the blockchain node, and the fourth request is used to request to obtain information for accessing the data of the fifth node; The second node receives the information for data access from the blockchain node, and the information for data access includes information for indicating the requirements that the second node needs to meet for accessing the data of the fifth node and information for indicating obtaining the data of the fifth node; The second node obtains the encrypted data of the fifth node according to the information for data access; The second node decrypts the encrypted data of the fifth node according to the first key.

80. The method according to claim 79, characterized in that, The information for indicating obtaining the data of the fifth node includes the storage address where the encrypted data of the fifth node is located, and / or information for indicating the encrypted data of the fifth node.

81. The method according to claim 80, characterized in that, The data of the fifth node is encrypted by a second key, and the information for indicating obtaining the data of the fifth node further includes: the encrypted second key.

82. The method according to claim 81, characterized in that, The second node obtains the encrypted data of the fifth node according to the information for data access, including: The second node sends a seventh request to the storage node corresponding to the storage address, and the seventh request is used to request to obtain the data of the fifth node; The second node receives the encrypted data of the fifth node from the storage node.

83. The method according to claim 81 or 82, characterized in that, The second node decrypts the encrypted data of the fifth node according to the first key, including: The second node decrypts the encrypted second key according to the first key; The second node decrypts the data of the fifth node encrypted by the second key according to the second key.

84. A communication device, characterized in that, Includes a module for executing the method according to any one of claims 1-83.

85. A communication device, characterized in that, Includes: A processor; The processor is used to run a computer program or instruction so that the method according to any one of claims 1-83 is implemented.

86. A communication chip, characterized in that, Wherein there are instructions, and when the chip runs on a communication device, the method according to any one of claims 1-83 is implemented.

87. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program or instruction, and when the computer program or instruction is executed by a communication device, the method according to any one of claims 1-83 is implemented.

88. A computer program product, characterized in that, Comprising computer program code which, when run on a communication device, causes the communication device to implement the method according to any one of claims 1 - 83.

Citation Information

Patent Citations

  • Communication method and device

    CN120342644A

  • Blockchain-based telephone number identification method and apparatus, and storage medium

    CN109327627A

  • An identity authentication method based on a block chain and terminal equipment

    CN109740320A

  • Video storage system, video processing method and device, equipment and storage medium

    CN110602455A

  • Training management method and device and electronic equipment

    CN111754658A