Communication method and apparatus
Receiving the target attribute information through the network device, solving the problem of users repeatedly providing attribute information in different applications, and achieving fast and efficient attribute information acquisition and isolation management.
Patent Information
- Application Number
- PCT/CN2025/073708
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-09
- Filing Date
- 2025-01-21
- Publication Date
- 2025-08-14
AI Technical Summary
It is time-consuming and risky for users to repeatedly provide attribute information in different applications, and it is difficult for the prior art to obtain user attribute information quickly and efficiently.
The clone identification is received through the network device, the attribute information of the target attribute identification is determined, and the application is directly sent to the application. The application does not require manual input by the user, so that the isolation management of attribute information is realized.
It realizes the application to quickly and efficiently obtain user attribute information, avoid repeated input, ensure the isolation of attribute information of different clone identifiers, and improve management efficiency.
Smart Images

Figure CN2025073708_14082025_PF_FP_ABST
Abstract
Description
Communication method and device
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of the People's Republic of China on February 9, 2024, with application number 202410179008.2 and application name "A Communication Method and Device", the entire contents of which are incorporated by reference into this application. Technical Field
[0003] The present application relates to the field of wireless communication technology, and in particular to a communication method and device. Background Art
[0004] With the rapid development of network technology, users have access to more and more applications. If users create a different user account and password for each available application, it will bring the burden of managing multiple user accounts and passwords. If users create the same user account and password for all available applications, this will increase the risk of leakage of user accounts and passwords for each application.
[0005] To address these issues, a federated identity architecture can be used to manage user accounts and passwords across different applications. Generally speaking, for any application to be accessed, a user first obtains their ID from a trusted identity provider (IDP) and uses this ID to log in to the application. This unique identifier distinguishes different users and can be a number, a string, or other format.
[0006] However, after logging in to the application to be accessed using the user's ID, in some cases, the application to be accessed also needs to obtain the user's attribute information, including but not limited to the user's name, user address, etc. If the user provides the above attribute information when using different applications to be accessed, it will take a lot of time to repeatedly provide the same attribute information. How to quickly and efficiently obtain the user's attribute information by the application to be accessed is a technical problem that needs to be solved urgently. Summary of the Invention
[0007] The present application provides a communication method and apparatus for quickly and efficiently obtaining user attribute information.
[0008] In a first aspect, an embodiment of the present application provides a communication method, wherein the execution subject of the method is a first network device or a module or chip in the first network device, and the method is described here by taking the first network device as the execution subject as an example. The method includes: the first network device receives a first message from a first application, wherein the first message includes a first avatar identifier, the first avatar identifier is used to identify an entity accessing the first application, and the first message is used to request attribute information of a target attribute identifier corresponding to the entity; the first network device sends attribute information corresponding to the target attribute identifier to the first application, and the attribute information corresponding to the target attribute identifier is determined from at least one attribute information corresponding to the first avatar identifier.
[0009] In this method, the first application can directly obtain the attribute information corresponding to the first avatar identifier from the first network device, eliminating the need for the user to enter the attribute information within the first application. This allows the first application to quickly and efficiently obtain the attribute information. Furthermore, since the first avatar identifier is used to log in to the first application, the first application can only obtain the attribute information corresponding to the first avatar identifier from the first network device, and cannot obtain the attribute information corresponding to other avatar identifiers. This allows the isolation of the attribute information corresponding to different avatar identifiers, effectively managing the attribute information corresponding to different avatar identifiers.
[0010] In one possible design, the first message also includes a first authentication credential; the method may also include: the first network device uses the first authentication credential to confirm that the first avatar identifier verification is successful.
[0011] In one possible design, the first message also includes a first identifier, which is used to identify the first application or the target business in the first application, and the target business is the business accessed by the entity in the first application; before the first network device determines at least one attribute information corresponding to the first avatar identifier, it may also include: the first network device uses the access permission information corresponding to the first avatar identifier to confirm that the first identifier verification is successful.
[0012] In one possible design, the first identifier is used to identify the first application; the first network device uses the access permission information corresponding to the first clone identifier to confirm that the first identifier verification is successful, which may include: if the access permission information corresponding to the first clone identifier includes the first identifier, the first network device confirms that the first identifier verification is successful.
[0013] In one possible design, the first identifier is used to identify the target business; the first network device uses the access permission information corresponding to the first clone identifier to confirm that the first identifier verification is successful, which may include: the first network device first determines the business type of the target business based on the first identifier; if the access permission information corresponding to the first clone identifier includes the business type of the target business, the first network device confirms that the first identifier verification is successful.
[0014] In one possible design, the method may also include: the first network device sends a second message to the terminal device, the second message is used to request verification information corresponding to the first verification identifier; the first verification identifier is determined based on the first mapping relationship and the target attribute identifier, the first mapping relationship includes multiple attribute identifiers and the first verification identifier corresponding to each attribute identifier in the multiple attribute identifiers, the multiple attribute identifiers include the target attribute identifier; the first application is installed on the terminal device; the first network device receives a third message from the terminal device, the third message includes verification information corresponding to the first verification identifier; the first network device verifies the verification information corresponding to the first verification identifier, and the third message is used to request verification of the verification information.
[0015] In one possible design, the method may also include: the first network device sends a fourth message to the terminal device, wherein the fourth message is used to request authorization permission, and the authorization permission includes allowing the first application or target service related to the first identifier to obtain attribute information corresponding to the target attribute identifier; the first network device receives a fifth message from the terminal device, wherein the fifth message is used to indicate authorization permission.
[0016] In one possible design, the method may further include: the first network device receiving a sixth message from the terminal device, the sixth message including the entity's root identifier, the root identifier being used to uniquely identify the entity, and the sixth message being used to request a first avatar identifier corresponding to the root identifier; the first network device generating the first avatar identifier corresponding to the root identifier; and the first network device sending the first avatar identifier to the terminal device. This design allows for convenient determination of the avatar identifier of a digital identity entity.
[0017] In one possible design, the sixth message also includes a second authentication credential; the method may also include: the first network device uses the second authentication credential to confirm that the root identifier verification is successful.
[0018] In one possible design, the sixth message also includes a second identifier, which is used to identify the identity information of the entity; the method may also include: the first network device sends a seventh message to the second network device, and the seventh message is used to request verification of the second identifier; the first network device receives an eighth message from the second network device, and the eighth message is used to indicate that the second identifier verification is successful.
[0019] In one possible design, the second identifier includes the entity's identity identifier, and the second network device is a preset identity providing node; the seventh message is used to request verification of the entity's identity identifier, and the eighth message is used to indicate that the entity's identity identifier verification is successful.
[0020] In one possible design, the second identifier includes an identity identifier of the entity and an identifier of a target identity providing node;
[0021] The first network device sends the seventh message to the second network device, which may include: the first network device sends the seventh message to the target identity providing node based on the identifier of the target identity providing node, and the seventh message is used to request verification of the identity of the entity; the first network device receives the eighth message from the second network device, which may include: the first network device receives the eighth message from the target identity providing node, and the eighth message is used to indicate that the identity verification of the entity is successful.
[0022] In one possible design, the first network device sends a seventh message to the target identity providing node using a verification address corresponding to an identifier of the target identity providing node. The verification address corresponding to the identifier of the target identity providing node is determined based on a second mapping relationship and the identifier of the target identity providing node, the second mapping relationship including identifiers of multiple identity providing nodes and a verification address corresponding to each of the multiple identifiers of the identity providing nodes; and the multiple identifiers of the identity providing nodes including the identifier of the target identity providing node.
[0023] In one possible design, the method may further include: the first network device receives a ninth message from the identity providing node, the ninth message including an identifier of the identity providing node and a verification address corresponding to the identifier of the identity providing node; the first network device adds the identifier of the identity providing node and the verification address corresponding to the identifier of the identity providing node to the second mapping relationship.
[0024] In one possible design, the sixth message also includes an identifier of at least one application, or a type of at least one service; the method may also include: the first network device adds an identifier of at least one application, or a type of at least one service to the access permission information corresponding to the first clone identifier.
[0025] In one possible design, the method may further include: the first network device sends a first authentication credential to the terminal device, where the first authentication credential is generated for the first avatar identifier.
[0026] In one possible design, the method may further include: the first network device receiving a tenth message from the terminal device, the tenth message being used to request the root identifier of the entity; and the first network device sending the root identifier to the terminal device. This design provides a method for conveniently determining the root identifier of the entity.
[0027] In a possible design, the tenth message includes an identifier of a user identity module SIM card; the root identifier is determined according to a subscription permanent identifier SUPI corresponding to the identifier of the SIM card.
[0028] In one possible design, the method may further include: the first network device determines attribute information corresponding to the root identifier based on first information corresponding to the identifier of the SIM card, where the first information is used to identify the attribute information of the entity.
[0029] In one possible design, the tenth message includes the device identifier of the terminal device; the root identifier is determined based on the device identifier.
[0030] In one possible design, the tenth message also includes second information, and the second information is used to identify attribute information of the entity. The method may also include: the first network device determines the second information as attribute information corresponding to the root identifier.
[0031] In one possible design, the method may further include: the first network device sends a second authentication credential to the terminal device, the second authentication credential is generated for the root identifier, and the second authentication credential is used to verify the root identifier.
[0032] In a second aspect, an embodiment of the present application provides a communication method, wherein the execution subject of the method is a first application. The method comprises: the first application sends a first message to a first network device, wherein the first message includes a first avatar identifier, the first avatar identifier is used to identify an entity accessing the first application, and the first message is used to request attribute information of a target attribute identifier corresponding to the entity; the first application receives attribute information corresponding to the target attribute identifier from the first network device, wherein the attribute information corresponding to the target attribute identifier is determined from at least one attribute information corresponding to the first avatar identifier.
[0033] In this method, the first application can directly obtain the attribute information corresponding to the first avatar identifier from the first network device, eliminating the need for the user to enter the attribute information within the first application. This allows the first application to quickly and efficiently obtain the attribute information. Furthermore, since the first avatar identifier is used to log in to the first application, the first application can only obtain the attribute information corresponding to the first avatar identifier from the first network device, and cannot obtain the attribute information corresponding to other avatar identifiers. This allows the isolation of the attribute information corresponding to different avatar identifiers, effectively managing the attribute information corresponding to different avatar identifiers.
[0034] In one possible design, the first message also includes a first authentication credential, which is used to verify the first avatar identifier.
[0035] In a third aspect, the present application further provides a communication device capable of implementing any of the methods provided in any of the first to second aspects above. The communication device may be implemented in hardware or by executing corresponding software implementations in hardware. The hardware or software includes one or more units or modules corresponding to the above functions.
[0036] In one possible design, the communication device includes a processor configured to support the communication device in executing the corresponding functions performed by the first network device or the first application in the method described above. The communication device may also include a memory, which may be coupled to the processor and stores program instructions and data necessary for the communication device. Optionally, the communication device also includes an interface circuit for supporting communication between the communication device and a device such as a terminal device.
[0037] In one possible design, the communication device includes corresponding functional modules for implementing the steps in the above method. The functions can be implemented by hardware or by hardware executing corresponding software implementations. The hardware or software includes one or more modules corresponding to the above functions.
[0038] In one possible design, the structure of the communication device includes a processing unit and a communication unit, which can perform the corresponding functions in the above method examples. For details, please refer to the description of the method provided in any one of the first to second aspects, which will not be repeated here.
[0039] In a fourth aspect, an embodiment of the present application further provides a communication device, comprising modules / units for executing any of the methods provided in any of the first to second aspects above. These modules / units may be implemented in hardware, or may be implemented in software by hardware.
[0040] In a fifth aspect, an embodiment of the present application provides a communication device comprising a memory and a processor; wherein the processor is used to execute a computer program or instruction stored in the memory, so that the communication device implements any method provided in any one of the first to second aspects above.
[0041] In the sixth aspect, an embodiment of the present application also provides a computer-readable storage medium, which includes a computer program. When the computer program runs on a communication device, the computer-readable storage medium implements any method provided in any of the first to second aspects above.
[0042] In a seventh aspect, an embodiment of the present application further provides a computer program product, which, when executed on a communication device, enables the communication device to implement any of the methods provided in any of the first to second aspects above.
[0043] In an eighth aspect, a chip is provided, comprising a processor and a memory, for implementing any of the methods provided in any of the first and second aspects. The chip may be composed of a single chip or may include a chip and other discrete devices.
[0044] In the ninth aspect, a communication system is provided, including: a first network device and a first application; the first network device is used to implement the method in the aforementioned first aspect and any possible implementation method of the first aspect, and the first application is used to implement the method in the aforementioned second aspect and any possible implementation method of the second aspect.
[0045] In a tenth aspect, the present application provides a computer program product. When a computer reads and executes the computer program product, the computer implements any method provided in any one of the first to second aspects above.
[0046] These and other aspects of the present application will become more readily apparent from the description of the following embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] FIG1 is a schematic diagram of the structure of a communication system provided in an embodiment of the present application;
[0048] FIG2 is a flow chart of a communication method provided in an embodiment of the present application;
[0049] FIG3 is a schematic diagram of the structure of digital identity information provided in an embodiment of the present application;
[0050] FIG4 is a flow chart of a communication method provided in an embodiment of the present application;
[0051] FIG5 is a schematic diagram of the structure of digital identity information provided in an embodiment of the present application;
[0052] FIG6 is a schematic diagram of the structure of digital identity information provided in an embodiment of the present application;
[0053] FIG7 is a flow chart of a communication method provided in an embodiment of the present application;
[0054] FIG8 is a flow chart of a communication method provided in an embodiment of the present application;
[0055] FIG9 is a flow chart of a communication method provided in an embodiment of the present application;
[0056] FIG10 is a flow chart of a communication method provided in an embodiment of the present application;
[0057] FIG11 is a schematic structural diagram of a communication device provided in an embodiment of the present application;
[0058] FIG12 is a schematic structural diagram of a communication device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0059] In order to make the purpose, technical solutions and advantages of this application more clear, the application will be further described in detail below with reference to the accompanying drawings. The specific operation methods and functional descriptions in the method embodiments can also be applied to the device embodiments or system embodiments.
[0060] Figure 1 is a schematic diagram of a communication system applicable to an embodiment of the present application. As shown in Figure 1, the communication system 10 includes one or more network devices 20 and one or more terminal devices 30. The interface between the network device and the terminal device may be a Uu interface (or air interface), and data can be transmitted between the network device 20 and the terminal device 30 via air interface resources. The terminal device can access a data network (DN) through the network device. The components of the communication system are described below.
[0061] (1) Terminal equipment
[0062] Terminal devices include devices that provide voice and / or data connectivity to users. For example, a terminal device is a device with wireless transceiver capabilities that can be deployed on land, including indoors or outdoors, handheld, wearable, or vehicle-mounted; it can also be deployed on the water (such as ships, etc.); it can also be deployed in the air (such as airplanes, balloons, and satellites, etc.). The terminal device can be a tag, a mobile phone, a tablet computer, a computer with wireless transceiver capabilities, a virtual reality (VR) terminal, an augmented reality (AR) terminal, a wireless terminal in industrial control, a vehicle-mounted terminal, a wireless terminal in self-driving, a wireless terminal in remote medical care, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, a wireless terminal in a smart home, a wearable terminal, etc. The embodiments of the present application do not limit the application scenarios. Terminal equipment may sometimes also be referred to as terminal, user equipment (UE), access terminal, vehicle-mounted terminal, vehicle-mounted equipment, industrial control terminal, UE unit, UE station, mobile station, mobile station, remote station, remote terminal, mobile device, UE terminal, wireless communication equipment, UE agent or UE device, etc. The terminal equipment may be fixed or mobile. It will be understood that all or part of the functions of the terminal equipment in this application may also be implemented by software functions running on hardware, or by virtualization functions instantiated on a platform (such as a cloud platform). The terminal equipment in this application may be a terminal for a fifth generation (5G) network or a terminal for a sixth generation (6G) network, and this application does not limit this.
[0063] (2) Network equipment
[0064] Network equipment may include access network equipment and core network equipment.
[0065] Access network equipment is a device that provides wireless communication capabilities for terminal devices. Access network equipment includes but is not limited to: the next-generation base station (g NodeB, gNB) in 5G, evolved NodeB (eNB), radio network controller (RNC), NodeB (NB), base station controller (BSC), base transceiver station (BTS), home base station (for example, home evolved NodeB, or home nodeB, HNB), baseband unit (BBU), transmitting and receiving point (TRP), transmitting point (TP), mobile switching center, etc.
[0066] Access network equipment and terminal devices can be fixed or mobile. They can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; on water; and in the air on aircraft, balloons, and satellites. The embodiments of this application do not limit the application scenarios of access network equipment and terminal devices.
[0067] In some possible network structures, access network equipment may include one or more centralized units (CUs) and one or more distributed units (DUs). Multiple DUs may be centrally controlled by a single CU. This architecture may be referred to as a CU-DU separation architecture. As an example, the interface between the CU and the DU may be referred to as an F1 interface, where the control plane (CP) interface may be an F1-C interface and the user plane (UP) interface may be an F1-U interface.
[0068] The core network equipment includes some or all of the following network elements: unified data management (UDM) network element, unified data repository (UDR) network element, network exposure function (NEF) network element (not shown in the figure), application function (AF) network element, policy control function (PCF) network element, access and mobility management function (AMF) network element, tag management function (TMF) network element, session management function (SMF) network element, user plane function (UPF) network element, and network repository function (NRF) network element.
[0069] The unified data management network element is a control plane network element provided by the operator, responsible for storing information such as the subscriber permanent identifier (SUPI), credentials, security context, and subscription data of subscribers in the operator's network. The information stored by the unified data management network element can be used for authentication and authorization of terminal devices accessing the operator's network. Among them, the subscribers of the above-mentioned operator network can specifically be users who use services provided by the operator network, such as users who use China Telecom's mobile phone SIM cards or users who use China Mobile's mobile phone SIM cards. The SUPI of the above-mentioned subscriber can be the number of the mobile phone SIM card, etc. The credentials and security context of the above-mentioned subscriber can be small files storing the encryption key of the mobile phone SIM card or information related to the encryption of the mobile phone SIM card, used for authentication and / or authorization. The above-mentioned security context can be data (cookie) or token stored on the user's local terminal (such as a mobile phone). The subscription data of the above-mentioned subscriber can be the supporting services of the mobile phone SIM card, such as the data package or network usage of the mobile phone SIM card. It should be noted that permanent identifiers, credentials, security contexts, authentication data (cookies), and tokens are equivalent to authentication and authorization-related information. In this application document, for the sake of convenience of description, no distinction or restriction is made. Unless otherwise specified, the embodiments of this application will be described using security context as an example, but the embodiments of this application are also applicable to authentication and / or authorization information expressed in other ways. In 5G, the data management network element can be a UDM network element. In future communications such as 6G, the data management network element can still be a UDM network element, or have other names, which are not limited in this application.
[0070] The unified database network element is a control plane network element provided by the operator's network, which includes the access function of executing contract data, policy data, application data, and other types of data. In 5G, the unified database network element can be a UDR network element. In future communications such as 6G, the unified database network element can still be a UDR network element or have other names, which are not limited in this application.
[0071] The access and mobility management function network element is a control plane network element provided by the operator network, which is responsible for access control and mobility management of terminal devices accessing the operator network, such as mobile state management, allocation of user temporary identity, authentication and authorization of users, etc. In 5G, the access and mobility management function network element can be an AMF network element. In future communications such as the 6th generation (6G), the access and mobility management function network element can still be an AMF network element, or have other names, which are not limited in this application.
[0072] The user plane function network element is a gateway provided by the operator and is the gateway for communication between the operator network and the DN. The user plane function network element includes user plane related functions such as data packet routing and transmission, packet detection, service usage reporting, Quality of Service (QoS) processing, lawful interception, uplink packet detection, downlink data packet storage, etc. In 5G, the user plane network element can be a UPF network element. In future communications such as 6G, the user plane network element can still be a UPF network element or have other names, which are not limited in this application.
[0073] The solution provided in this application is described below with reference to the accompanying drawings.
[0074] In current networks, users can log in to an application using their ID, accessing it and using some of its services. However, in real-world scenarios, when users access an application or use some of its services, they often need to associate attributes with it. This means the application also needs to obtain the user's attribute information.
[0075] To prevent users from repeatedly providing the same attribute information to different applications, this application provides an implementation method, whereby a network device obtains and stores the avatar identifiers of different entities accessing different applications. An entity can also be referred to as a digital identity entity, and can be any of a person, a machine, a digital person, or a spirit. The application to be accessed can obtain the relevant attribute information of the entity currently accessing the application to be accessed from the avatar identifiers of different entities stored in the network device, eliminating the need for the entity accessing the application to be accessed to repeatedly fill in the attribute information.
[0076] In an embodiment of the present application, before obtaining the entity's clone identifier, the network device may first determine the entity's root identifier, and then may generate at least one clone identifier for the entity's root identifier. The entity's root identifier is first introduced in detail below.
[0077] 1) Root Identifier: Every entity has a corresponding root identifier. This unique identifier uniquely identifies the entity. The root identifier remains unchanged when the entity accesses different applications. The entity's root identifier can be determined by the terminal device and sent to the network device for storage. Alternatively, the network device can determine the entity's root identifier.
[0078] The root identifier is determined differently for different types of terminal devices. Terminal devices can be divided into two types: those with a subscriber identity module (SIM) card and those without. For example, a SIM card-equipped terminal device might be a mobile phone, while a SIM-unequipped terminal device might be a watch, tablet, or computer.
[0079] If the terminal device includes a SIM card, the root identifier can be determined based on the identifier of the SIM card. If the terminal device does not include a SIM card, the root identifier can be determined based on the device identifier of the terminal device. The device identifier of the terminal device can be a hardware identifier of the terminal device or a software identifier of the terminal device, which is not limited here. For example, the software identifier of the terminal device can be determined based on the software development kit (SDK) installed on the terminal device.
[0080] The following describes how a network device determines a root identifier corresponding to an entity in conjunction with specific embodiments. The method by which a terminal device determines a root identifier corresponding to an entity is similar to the method by which a network device determines a root identifier corresponding to an entity, and is not described in detail.
[0081] In an embodiment of the present application, it is assumed that a first application is installed in the terminal device, and the first application is the application to be accessed. Before the entity accesses the first application, the root identifier corresponding to the entity can be determined first. The embodiment of the present application provides a communication method for determining the root identifier corresponding to the entity, which can be interactively executed by a first network device and a terminal device, wherein the first network device can be a network element located at a network operator, such as an identity management (IdM) network element, or other network elements with identity management functions, which are not limited here. The communication method provided in the embodiment of the present application may include the following steps as shown in Figure 2:
[0082] S201, the terminal device sends a tenth message to the first network device; correspondingly, the first network device receives the tenth message from the terminal device.
[0083] In an embodiment of the present application, the tenth message can be used to request the root identifier of the entity.
[0084] For different types of terminal devices, the content included in the tenth message may include the following two possible implementations:
[0085] In a first possible implementation, when the terminal device includes a SIM card, the tenth message may include an identifier of the SIM card.
[0086] In the case where the terminal device includes a SIM card, the first network device may determine the root identifier of the entity according to the identifier of the SIM card, including the following two possible implementations:
[0087] In implementation mode A, after receiving the tenth message, the first network device may determine the root identifier of the entity according to the SUPI corresponding to the identifier of the SIM card.
[0088] In one possible implementation, the first network device may directly use the SUPI corresponding to the SIM card identifier as the root identifier, or the first network device may encode the SUPI corresponding to the SIM card identifier and use the encoded SUPI as the root identifier. It should be understood that the SUPI or the encoded SUPI is a unique identifier used to distinguish different entities.
[0089] In implementation mode B, after receiving the tenth message, the first network device may determine the root identifier of the entity according to the identifier of the SIM card.
[0090] In one possible implementation, the first network device may generate a root identifier for the entity based on the identifier of the SIM card. The root identifier is a unique identifier that can be used to distinguish different entities. In this embodiment of the present application, the root identifier may be in a network access identifier (NAI) format.
[0091] Optionally, the NAI format may be username@realm, where realm may be a public land mobile network identifier (PLMN ID). The PLMN ID may be determined based on the mobile country code (MCC) and the mobile network code (MNC), such as PLMN ID = MCC + MNC. Different root identifiers correspond to different usernames.
[0092] In an embodiment of the present application, an entity can obtain a SIM card from a network operator by signing a contract. When signing the contract, the entity can send relevant information of the entity to the network operator. The network operator uses the relevant information of the entity as the first information and associates the identifier of the SIM card with the first information. The first information can be used to identify the attribute information of the entity.
[0093] The first information includes at least one of the following: identity information, status information, contract information, service information, etc. After obtaining the first information of the entity, the first network device uses the identity information, status information, contract information and service information in the first information as attribute information of the entity.
[0094] The above four types of attribute information are described in detail as follows:
[0095] 1) Identity Information: This can be the identity information corresponding to a digital identity entity, such as a user's personal identity information or a corporate entity's identity information. If the digital identity entity is an individual user, the user's personal identity information includes information such as the user's ID number, name, and address. If the digital identity entity is a corporate entity, the corporate entity's identity information includes information such as the company's social credit code, company name, registered address, and name of the corporate entity.
[0096] 2) Status information: This may include the location information corresponding to the digital identity entity, the reachability status recorded in the network, the network element identifier currently providing the service, and other information.
[0097] 3) Contract information: may include business information signed at the network operator, including but not limited to account data, contract data, etc. Contract data includes a list of contracted operator services, payment methods and other information.
[0098] 4) Service Information: This may include service authorization information and access control information. Service authorization information records the authorization information received by the digital identity entity and / or the authorization information provided by the digital identity entity to another digital identity entity. Authorization information includes, but is not limited to, authorization permissions, authorization time limit, and authorization content. Access control information records the applications and / or service types that the digital identity entity is allowed to access.
[0099] The attribute identifier may include at least one of the following: "identity attribute," "status attribute," "contract attribute," and "service attribute." The obtained identity information is used as the attribute information corresponding to the identity attribute, the status information is used as the attribute information corresponding to the status attribute, the contract information is used as the attribute information corresponding to the contract attribute, and the service information is used as the attribute information corresponding to the service attribute.
[0100] In a second possible implementation, when the terminal device does not include a SIM card, the tenth message may include a device identifier of the terminal device.
[0101] Optionally, when the terminal device does not include a SIM card, before sending the tenth message to the first network device, the terminal device may establish a transport layer security (TLS) connection with the first network device to ensure the integrity and privacy of the transmitted message.
[0102] In the case that the terminal device does not include a SIM card, the first network device may determine the root identifier of the entity through implementation mode C.
[0103] In implementation C, after receiving the tenth message, the first network device may generate a root identifier of the entity according to the device identifier of the terminal device.
[0104] In a possible implementation, the first network device may directly generate a root identifier for uniquely identifying the entity based on the device identifier of the terminal device, wherein the root identifier may be in NAI format.
[0105] Optionally, the tenth message may further include second information of the entity, where the second information may be used to identify attribute information of the entity. The second information may include identity information. The identity information included in the second information may be identity information corresponding to the entity.
[0106] Optionally, for the tenth message in implementation C, the tenth message may further include third information of the entity, where the third information is used to verify the entity.
[0107] In the case where the entity is an individual user, the third information includes the user's ID card photo or facial photo. The first network device can send the user's ID number, user name, user address and user's ID card photo or facial photo to the first identity issuing / verification agency for verification. The following discussion is based on the example of the first identity issuing / verification agency being the Public Security Bureau No. 1. If the Public Security Bureau No. 1 verifies the above information, the first network device can generate the entity's root identifier based on the device identifier of the terminal device.
[0108] In the case where the entity is a corporate legal person, the third information includes the business license of the enterprise. The first network device can send the enterprise's social credit code, enterprise name, enterprise registration address, corporate legal person name and business license to the second identity issuing / verification agency. The following discussion is based on the example of the second identity issuing / verification agency being the industrial and commercial administrative authority. If the industrial and commercial administrative authority verifies the above information, the first network device can generate the entity's root identifier based on the device identifier of the terminal device.
[0109] In implementation C, after the terminal device accesses the first network device, the first network device may also determine the state information, contract information, service information, etc. corresponding to the entity. The first network device may use identity information, state information, contract information, and service information as attribute information.
[0110] In an embodiment of the present application, the first network device may store the root identifier of the entity and at least one attribute information in an associated manner.
[0111] S202, the first network device sends a root identifier to the terminal device; correspondingly, the terminal device receives the root identifier from the first network device.
[0112] In an embodiment of the present application, after the terminal device obtains the root identifier of the entity, it can be stored in the terminal device.
[0113] The above method provides a convenient way to determine the root identity of an entity.
[0114] In one possible implementation, after determining the entity's root identifier, the first network device may also determine a digital authentication credential corresponding to the root identifier. The digital authentication credential corresponding to the root identifier is referred to herein as a second authentication credential. The second authentication credential is a digital authentication credential used to verify the root identifier. The second authentication credential can be used to verify the legitimacy of the root identifier.
[0115] In a possible implementation, after receiving the root identifier of the entity, the terminal device may also determine the second authentication credential corresponding to the root identifier and send the second authentication credential to the first network device.
[0116] The following describes in detail how the first network device generates the second authentication credential for the root identifier of the entity in conjunction with the step of generating the root identifier by the first network device in FIG. 2 .
[0117] After generating the entity's root identifier through any of Embodiments A to C above, the first network device may generate a second authentication credential based on the root identifier, where the second authentication credential may be used to verify the root identifier. It should be understood that the second authentication credential may be an authentication vector, a pre-set certificate, a pre-set private key, or the like, without limitation herein.
[0118] In an embodiment of the present application, the first network device may store the entity's root identifier, the second authentication credential, and at least one attribute information in association with each other, as shown in FIG3 .
[0119] After the first network device generates the second authentication credential, the first network device may send the second authentication credential to the terminal device. Accordingly, after obtaining the second authentication credential, the terminal device may associate the root identifier with the second authentication credential and store the association in the terminal device.
[0120] 2) Clone identification: One entity corresponds to at least one clone identification. When an entity accesses different applications, it can use different clone identifications. The clone identification can be determined by the terminal device, and the terminal device sends the clone identification to the network device for storage, or the network device can determine at least one clone identification of the entity. For example, for the same entity, the entity can use clone identification 1 when accessing application A, and can use clone identification 2 when accessing application B. Different clone identifications of the same entity can be determined based on the root identification of the entity using different algorithms. Of course, the entity can also freely determine the clone identification for accessing different applications.
[0121] The following describes how a network device determines the avatar identifier corresponding to an entity with reference to specific embodiments. The method by which a terminal device determines the avatar identifier corresponding to an entity is similar to the method by which a network device determines the avatar identifier corresponding to an entity, and will not be described in detail.
[0122] In an embodiment of the present application, it is assumed that a first application is installed in the terminal device, and the first application is the application to be accessed. Before the entity accesses the first application, the root identifier of the entity can be determined by the communication method shown in Figure 2. After determining the root identifier of the entity, at least one clone identifier corresponding to the entity can also be determined. An embodiment of the present application provides a communication method for determining the first clone identifier in at least one clone identifier corresponding to an entity, as shown in Figure 4, which can be interactively executed by a first network device, a terminal device, and a second network device, wherein the second network device can be an identity providing network element, or other network element with identity providing function, which is not limited here. The order of the steps in Figure 4 is only an example. In actual applications, the execution order of the steps in Figure 4 can be adjusted. The communication method may include the following steps as shown in Figure 4:
[0123] Optionally, the above method may include S401.
[0124] S401: A terminal device accesses a first network device through an access side.
[0125] For different types of terminal devices, the terminal device accessing the first network device may include the following two possible implementations:
[0126] In a first possible implementation, when the terminal device includes a SIM card, the terminal device can access the first network device through the third generation partnership project (3GPP) / non-third generation partnership project (Non-3GPP) and establish a trusted connection with the first network device.
[0127] A second possible implementation method is that when the terminal device does not include a SIM card, since the terminal device does not have non-access stratum (NAS) capability, the terminal device can access the first network device through a mobile hotspot (wifi) / wired method, and establish a trusted connection with the first network device through nodes such as the trusted wlan interworking function (TWIF) / network exposure function (NEF) / non-3GPP interworking function (N3IWF).
[0128] S402, the terminal device sends a sixth message to the first network device; correspondingly, the first network device receives the sixth message from the terminal device.
[0129] In an embodiment of the present application, the sixth message may include the entity's root identifier, which is used to uniquely identify the entity, and the sixth message is used to request the first avatar identifier corresponding to the root identifier. Optionally, the sixth message may also include a second authentication credential, wherein the second authentication credential can be used to verify the root identifier.
[0130] Optionally, the sixth message may further include a second identifier, which is used to identify the identity information of the entity. In the embodiment of the present application, the second identifier includes the following three possible situations:
[0131] In scenario 1, when the entity is a user, the second identifier may include the entity's identity identifier, for example, the user's ID number.
[0132] In scenario 2, where the entity is a personal user, the second identifier may include the entity's identity identifier and the identifier of the target identity providing node. For example, the identity identifier may be the user's ID number, and the target identity providing node may be the First Public Security Bureau. Alternatively, the identity identifier may be an employee ID number, and the target identity providing node may be an enterprise. Alternatively, the identity identifier may be the user's ID number, and the target identity providing node may be an enterprise.
[0133] In addition, the second identifier in scenario 2 can also be an email account, based on which the entity's identity identifier and the target identity providing node's identifier can be determined. For example, the email account is zhangsan@idip.com, where zhangsan is the identity identifier and idip is the target identity providing node's identifier.
[0134] In the third scenario, when the entity is a corporate legal person, the second identifier may include the entity's identity identifier. For example, the identity identifier may be the corporate social credit code.
[0135] In the fourth scenario, when the entity is a corporate legal person, the second identifier may include the entity's identity identifier and the identifier of the target identity provider node. For example, the identity identifier may be the enterprise's social credit code, and the target identity provider node may be the industrial and commercial administration authority.
[0136] Optionally, the sixth message may further include an identifier of at least one application, or a type of at least one service. For example, the at least one application may be application A or application B. The at least one service type may be shopping, video, or the like.
[0137] Optionally, the sixth message may also include other attribute information of the entity, such as social attribute information. If the entity is an individual user, the social attribute information may include the user's occupation, the industry type to which the user's occupation belongs, etc., without limitation here. If the entity is a corporate legal person, the social attribute information may include the industry type to which the enterprise belongs, the enterprise's revenue, etc., without limitation here.
[0138] Optionally, the above method may further include S403 to S404.
[0139] S403, the first network device uses the second authentication credential to verify the root identifier. If the verification fails, execute S404; otherwise, execute S405.
[0140] S404: The first network device sends an eleventh message to the terminal device; accordingly, the terminal device receives the eleventh message from the first network device. The process ends, that is, S405 to S409 are no longer executed.
[0141] In the embodiment of the present application, the eleventh message is used to indicate that the first avatar identifier is not allocated. Optionally, the eleventh message may also include the reason for not allocating the first avatar identifier, that is, "root identifier verification failed."
[0142] Optionally, the above method may further include S405 to S407.
[0143] S405 , the first network device sends a seventh message to the second network device; correspondingly, the second network device receives the seventh message from the first network device.
[0144] In this embodiment of the present application, the seventh message is used to request verification of the second identifier, and the seventh message may include the second identifier.
[0145] S406: The second network device verifies the second identifier. If the verification is successful, execute S407.
[0146] S407 , the second network device sends an eighth message to the first network device; correspondingly, the first network device receives the eighth message from the second network device.
[0147] In one possible implementation, when the second network device passes or fails to verify the second identifier, the second network device can send an eighth message to the first network device, wherein, when the second identifier verification passes, the eighth message can be used to indicate that the second identifier verification passes; when the second identifier verification fails, the eighth message can be used to indicate that the second identifier verification fails.
[0148] In one possible implementation, the eighth message includes a first identification identifier. When the first identification identifier is true, the eighth message is used to indicate that the second identification verification is successful; when the first identification identifier is false, the eighth message is used to indicate that the second identification verification is unsuccessful.
[0149] It should be understood that the execution order of S403-S404 and S405-S407 is not particular. The communication method shown in FIG4 may include any one of S403-S404 and S405-S407, or may include all of them.
[0150] S408: When the eighth message indicates that the second identifier is verified successfully, the first network device generates a first clone identifier corresponding to the root identifier.
[0151] S409: The first network device sends a first avatar identifier to the terminal device; correspondingly, the terminal device receives the first avatar identifier from the first network device.
[0152] Optionally, after determining the entity's first avatar identifier, the first network device may also determine a digital authentication credential corresponding to the first avatar identifier. The digital authentication credential corresponding to the first avatar identifier is referred to herein as the first authentication credential, wherein the first authentication credential is a digital authentication credential used to verify the first avatar identifier. The first authentication credential can be used to verify the legitimacy of the first avatar identifier. The first network device may generate the first authentication credential at S410 and send the first authentication credential to the terminal device at S411.
[0153] S410: The first network device generates a first authentication credential corresponding to the first avatar identifier. The first authentication credential is used to verify the first avatar identifier. It should be understood that the first authentication credential can be an authentication vector, a pre-set certificate, a pre-set private key, etc., which is not limited here.
[0154] Optionally, when the sixth message includes other attribute information, the first network device may use the identity information, status information, contract information, service information and other attribute information in the sixth message as attribute information of the entity corresponding to the first avatar identifier.
[0155] Optionally, when the sixth message can also include the identifier of at least one application, or the type of at least one service, the identifier of at least one application, or the type of at least one service can be added to the access control information in the service information corresponding to the first avatar identifier.
[0156] In an embodiment of the present application, the first network device can associate the root identifier and the second authentication credential of the entity, and associate the first clone identifier and the first authentication credential of the entity, associate the first clone identifier and the attribute information corresponding to the first clone identifier, and store the attribute information corresponding to the root identifier, the second authentication credential, the first clone identifier, the first authentication credential and the first clone identifier, as shown in Figure 5.
[0157] S411, the first network device sends a first authentication credential to the terminal device; correspondingly, the terminal device receives the first authentication credential from the first network device.
[0158] In an embodiment of the present application, after obtaining the first clone identifier and the first authentication credential, the terminal device may associate the first clone identifier with the first authentication credential and store the association in the terminal device. Simultaneously, the root identifier and the first clone identifier are associated. In this case, the root identifier, the second authentication credential, the first clone identifier, and the first authentication credential are stored in the terminal device.
[0159] It should be understood that S408 and S410 in the above method can be executed in combination, that is, the first network device can simultaneously determine the first avatar identifier and the first authentication credential, and S409 and S411 in the above method can also be executed in combination, that is, the first network device sends the first avatar identifier and the first authentication credential to the terminal device at the same time.
[0160] In the above method, the entity's avatar identifier can be determined conveniently, and the attribute information corresponding to the entity's avatar identifier can also be determined.
[0161] Optionally, through the communication method shown in FIG4 , after the terminal device obtains the first avatar identifier of the entity, the terminal device may further send a revocation request to the first network device, where the revocation request is used to request the revocation of the first avatar identifier, and the revocation request includes the first avatar identifier of the entity. After the first network device obtains the first avatar identifier of the entity, it deletes the first avatar identifier and the attribute information corresponding to the first avatar identifier, and sends a revocation response to the terminal device, where the revocation response is used to indicate that the revocation of the first avatar identifier is complete.
[0162] The following describes in detail the relationship between an entity's root identifier and its two avatar identifiers, using specific embodiments. As shown in Figure 6, the root identifier corresponds to two avatar identifiers: a first avatar identifier and a second avatar identifier. The second authentication credential is used to verify the root identifier, the first authentication credential is used to verify the first avatar identifier, and the third authentication credential is a digital authentication credential used to verify the second avatar identifier. The first avatar identifier and the second avatar identifier can correspond to different attribute information.
[0163] Optionally, S405 to S407 are described in detail for the four possible situations included in the second identifier.
[0164] Scenario 1: When the entity is a personal user, the second identifier includes the identity identifier of the entity, the second network device is a preset identity providing node, and the interaction between the first network device and the second network device is shown in FIG7 .
[0165] S701: A first network device sends a seventh message to a preset identity providing node; correspondingly, the preset identity providing node receives the seventh message from the first network device.
[0166] In this embodiment of the present application, the seventh message may be used to request verification of the entity's identity. The seventh message includes the entity's identity. The identity may be, for example, a user's ID number. The preset identity providing node may be a first identity issuing / verifying agency, such as the First Public Security Bureau.
[0167] In a possible implementation, the first network device sends the user ID number to the Public Security Bureau No. 1, which verifies the user ID number.
[0168] S702: If the preset identity providing node has the identity identifier of the entity, the verification is successful, and S703 is executed.
[0169] S703: The preset identity providing node sends an eighth message to the first network device; correspondingly, the first network device receives the eighth message from the preset identity providing node.
[0170] In an embodiment of the present application, the eighth message may be used to indicate that the entity's identity verification has passed.
[0171] In the above method, when the entity is a user, a method for conveniently verifying the identity of the entity is provided.
[0172] In scenario 2, when the entity is a personal user, the second identifier includes the entity's identity identifier and the identifier of the target identity providing node. The second network device is the target identity providing node. The interaction between the first network device and the second network device is shown in FIG8 .
[0173] S801: The first network device sends a seventh message to the target identity providing node according to the identifier of the target identity providing node; accordingly, the target identity providing node receives the seventh message from the first network device.
[0174] In an embodiment of the present application, the seventh message may be used to request verification of the entity's identity. The seventh message includes the entity's identity. The identity may be a user's ID number, and the target identity provider node may be the First Public Security Bureau. Alternatively, the identity may be an employee ID number, and the target identity provider node may be an enterprise. Alternatively, the identity may be a user's ID number, and the target identity provider node may be an enterprise.
[0175] In a possible implementation, the first network device sends the user ID number to the Public Security Bureau No. 1, which verifies the user ID number.
[0176] In a possible implementation, the first network device sends the employee number to the enterprise, and the enterprise verifies the employee number.
[0177] In one possible implementation, the first network device sends the user ID number to the enterprise, and the enterprise verifies the user ID number.
[0178] Before executing S801, the first network device may generate and store a second mapping relationship, wherein the second mapping relationship may be generated in the following three ways:
[0179] In a first method, a first network device receives a ninth message from an identity providing node, wherein the ninth message includes an identifier of the identity providing node and a verification address corresponding to the identifier of the identity providing node. The first network device adds the identifier of the identity providing node and the verification address corresponding to the identifier of the identity providing node to a second mapping relationship. The generated second mapping relationship includes identifiers of multiple identity providing nodes and a verification address corresponding to each of the multiple identifiers of the identity providing nodes. The multiple identifiers of the identity providing nodes in the second mapping relationship include the identifier of the target identity providing node.
[0180] In the second manner, other devices generate a second mapping relationship using the first manner, and send the second mapping relationship to the first network device.
[0181] In a third manner, the identifier of the identity providing node and the verification address corresponding to the identifier of the identity providing node are manually added to the second mapping relationship.
[0182] In one possible implementation, the first network device may determine the verification address corresponding to the identifier of the target identity providing node based on the second mapping relationship, and the first network device may send the seventh message to the target identity providing node through the verification address corresponding to the identifier of the target identity providing node.
[0183] S802: If the target identity providing node has the identity identifier of the entity, the verification is successful, and S803 is executed.
[0184] S803 , the target identity providing node sends an eighth message to the first network device; correspondingly, the first network device receives the eighth message from the target identity providing node.
[0185] In an embodiment of the present application, the eighth message may be used to indicate that the entity's identity verification has passed.
[0186] In the above method, when the entity is a user, a method for conveniently verifying the identity of the entity is provided.
[0187] In scenario three, when the entity is a corporate legal person, the second identifier includes the entity's identity identifier, and the second network device is a pre-set identity provisioning node. The interaction between the first and second network devices can be seen in Figure 7 . In this scenario three, the identity identifier can be, for example, the enterprise's social credit code, and the pre-set identity provisioning node can be a second identity issuing / verifying organization, such as the Administration for Industry and Commerce.
[0188] In one possible implementation, the first network device sends the social credit code of the enterprise to the industrial and commercial administration authority, which verifies the social credit code of the enterprise.
[0189] In scenario 4, where the entity is a corporate legal person, the second identifier includes the entity's identity identifier and the identifier of the target identity providing node, and the second network device is the target identity providing node. The interaction between the first and second network devices can be seen in Figure 8 . In this scenario 4, the identity identifier can be the enterprise's social credit code, and the target identity providing node can be the industrial and commercial administration authority.
[0190] In the above method, when the entity is a corporate legal person, a method for conveniently verifying the identity of the entity is provided.
[0191] In an embodiment of the present application, assuming that a first application is installed in a terminal device, the first application is the application to be accessed. Before an entity accesses the first application, the entity's root identifier can be determined using the communication method shown in FIG2 , and the entity's first avatar identifier can be determined using the communication method shown in FIG4 . After determining the entity's root identifier and first avatar identifier, the embodiment of the present application further provides a communication method in which, after the entity logs into the first application, the first network device can provide the entity's attribute information to the first application. This communication method can be implemented by the first application in the terminal device and the first network device interacting, and can include the following steps as shown in FIG9 :
[0192] S901: A first application sends a first message to a first network device; correspondingly, the first network device receives the first message from the first application.
[0193] In an embodiment of the present application, the first message includes a first avatar identifier, and the first avatar identifier is used to identify the entity currently accessing the first application.
[0194] The first message may further include a target attribute identifier, which is used to request attribute information corresponding to the target attribute identifier of the entity. The target attribute identifier may be at least one of "identity attributes," "status attributes," "contract attributes," and "service attributes." Of course, if the first application and the first network device have pre-agreed on the attribute information of the entity to be requested, the first message may not include the target attribute identifier.
[0195] S902: The first network device determines at least one piece of attribute information corresponding to the first avatar identifier, and determines attribute information corresponding to the target attribute identifier from the at least one piece of attribute information corresponding to the first avatar identifier.
[0196] As described above, the first network device can pre-store the first avatar identifier of the entity, the association relationship between the first avatar identifier and at least one attribute identifier, and the attribute information corresponding to each attribute identifier in at least one attribute identifier. Then, the first network device can use the first avatar identifier of the entity to query at least one attribute identifier and the attribute information corresponding to each attribute identifier, thereby finding the corresponding target attribute information based on the attribute information corresponding to each attribute identifier and further based on the target attribute identifier.
[0197] S903 , the first network device sends attribute information corresponding to the target attribute identifier to the first application; correspondingly, the first application receives the attribute information corresponding to the target attribute identifier from the first network device.
[0198] In the above method, the first application can directly obtain the relevant attribute information of the entity corresponding to the first avatar identifier from the first network device without the user filling in the attribute information in the first application, thereby enabling the first application to quickly and efficiently obtain the attribute information of the entity accessing the first application.
[0199] To describe the communication method shown in FIG9 in detail, an embodiment of the present application further provides a communication method, as shown in FIG10 , in which a first application in a terminal device and a first network device can interact. The order of the steps in FIG10 is only an example. In actual applications, the execution order of the steps in FIG10 can be adjusted. The communication method may include the following steps as shown in FIG10 :
[0200] Optionally, the above method may include S1001 to S1003.
[0201] S1001, the terminal device sends a login request to the first application; correspondingly, the first application receives the login request from the terminal device.
[0202] In an embodiment of the present application, an entity sends a login request to a first application through a terminal, and the login request may include a first avatar identifier of the entity. The first avatar identifier is used to identify the entity accessing the first application.
[0203] Optionally, the login request may further include a first authentication credential, wherein the first authentication credential is used to verify the first avatar identifier.
[0204] S1002: The first application completes the login of the first avatar identifier.
[0205] In an embodiment of the present application, after the first application agrees that the entity can log in based on the first avatar identifier, when a certain service of the first application is accessed by the entity, the first application may need to obtain one or more attribute information of the entity.
[0206] For example, after a user logs in to application X using a first avatar, the user accesses service Y in application X. At this time, application X may need to obtain one or more attribute information of the user, such as the user name, user phone number, and user address.
[0207] When different services in the first application are accessed by the entity, the attribute information of the entity that the first application needs to obtain may be the same or different, and the specific information may be determined based on the different services. For example, the attribute information that needs to be obtained for service Y in application X may include user name, user phone number, and user address, while the attribute information that needs to be obtained for service Z in application X may include user name, user phone number, user address, user ID number, user bank card number, etc.
[0208] S1003: The first application determines a target attribute identifier and a first identifier.
[0209] In an embodiment of the present application, when a first application is accessed by an entity or a service in the first application is accessed by an entity, the first application may determine a target attribute identifier required by the first application or the accessed service in the first application.
[0210] The first application may also determine a first identifier. The first identifier may include an identifier of the first application or an identifier of a service being accessed in the first application. The first identifier may be used to identify the first application or a target service in the first application, where the target service is a service being accessed by an entity in the first application.
[0211] S1004, the first application sends a first message to the first network device; accordingly, the first network device receives the first message from the first application.
[0212] In an embodiment of the present application, the first message includes a first avatar identifier, and the first avatar identifier is used to identify the entity currently accessing the first application.
[0213] The first message also includes a target attribute identifier, and the first message is used to request attribute information of the target attribute identifier corresponding to the entity.
[0214] Optionally, the first message may further include a first identifier, where the first identifier may be used to identify the first application or a target service in the first application.
[0215] The first message may further include a first authentication credential, wherein the first authentication credential is used to verify the first avatar identifier.
[0216] Optionally, the above method may further include S1005, S1006 to S1009, and S1010 to S1012.
[0217] S1005: The first network device verifies the first avatar identifier using the first authentication credential. If the verification is successful, execute S1006; otherwise, execute S1016.
[0218] S1006: The first network device determines a first verification identifier corresponding to the target attribute identifier according to the first mapping relationship.
[0219] In an embodiment of the present application, the first network device stores a first mapping relationship, and the first mapping relationship may be pre-set.
[0220] The first mapping relationship includes multiple attribute identifiers and a first verification identifier corresponding to each of the multiple attribute identifiers. The multiple attribute identifiers may include at least one of "identity attribute", "status attribute", "contract attribute" and "service attribute". The multiple attribute identifiers include a target attribute identifier, which can be understood as the target attribute identifier can be at least one of "identity attribute", "status attribute", "contract attribute" and "service attribute".
[0221] The first verification identifier may include at least one of the following: a biometric verification identifier and an identity verification identifier, wherein the biometric verification identifier is used to obtain the entity's biometric information, and the identity verification identifier is used to obtain the entity's identity identifier.
[0222] It should be understood that the biometric verification identifier can be a face identifier, a fingerprint identifier, an iris identifier, etc., which is not limited here.
[0223] For example, the first mapping relationship may be as follows:
[0224] <“Identity Attributes”: Biometric Verification Identifier and Identity Verification Identifier>
[0225] <"State Attribute": Authentication ID>
[0226] Based on the above first mapping relationship, it can be seen that the first verification identifier corresponding to the "identity attribute" includes the biometric verification identifier and the identity verification identifier, and the first verification identifier corresponding to the "state attribute" includes the identity verification identifier.
[0227] S1007, the first network device sends a second message to the terminal device; accordingly, the terminal device receives the second message from the first network device.
[0228] In the embodiment of the present application, the second message includes the first verification identifier, and the second message is used to request verification information corresponding to the first verification identifier.
[0229] After receiving the second message, the terminal device determines the verification information corresponding to the first verification identifier. Depending on the entity, the verification information determined includes the following two possible situations:
[0230] In scenario 1, if the entity is a user, the terminal device can obtain the user's facial photo / fingerprint information / iris information based on the biometric verification identifier in the second message. The terminal device can also obtain the user's identity identifier, i.e., the user's ID number or employee number, based on the identity verification identifier in the second message.
[0231] In the second scenario, if the entity is a corporate entity, the terminal device can obtain the corporate entity's facial photo, fingerprint information, or iris information based on the biometric verification identifier in the second message. The terminal device can also obtain the corporate identity identifier, namely the corporate social credit code, based on the identity verification identifier in the second message.
[0232] It should be understood that the terminal device can obtain the facial photo of the user or corporate legal person through the camera device on the terminal device, obtain the fingerprint information of the user or corporate legal person through the fingerprint collection device on the terminal device, and obtain the iris information of the user or corporate legal person through the iris collection device on the terminal device.
[0233] Optionally, after the terminal device detects the face of the user or corporate legal person through the camera device, it can also perform liveness detection, which is not described in detail here.
[0234] S1008, the terminal device sends a third message to the first network device; correspondingly, the first network device receives the third message from the terminal device.
[0235] In the embodiment of the present application, the third message includes verification information corresponding to the first verification identifier. The third message is used to request verification of the verification information.
[0236] S1009: The first network device verifies the verification information corresponding to the first verification identifier. If the verification passes, execute S1010; otherwise, execute S1016.
[0237] In an embodiment of the present application, the first network device sends verification information corresponding to the first verification identifier to the second network device for verification.
[0238] When the entity is an individual user, if the verification information includes the user's ID number, the first network device will send the verification information to the Public Security Bureau for verification; if the verification information includes the employee number or the user's ID number, the first network device will send the verification information to the enterprise for verification.
[0239] In the case where the entity is a corporate legal person, if the verification information includes the social credit code of the enterprise, the first network device sends the verification information to the industrial and commercial administration authority for verification.
[0240] S1010, the first network device sends a fourth message to the terminal device; accordingly, the terminal device receives the fourth message from the first network device.
[0241] In an embodiment of the present application, the fourth message is used to request authorization, wherein the authorization includes allowing the first application or target service associated with the first identifier to obtain attribute information corresponding to the target attribute identifier.
[0242] S1011: The terminal device obtains authorization permission. The terminal device may obtain authorization permission from an entity.
[0243] In an embodiment of the present application, after the terminal device receives the fourth message, an authorization permission interface is displayed on the display end of the terminal device. The authorization permission interface includes two options, namely "Allow" and "Do not allow". If the user using the terminal device selects the "Allow" option, the terminal device can obtain the authorization permission; otherwise, the terminal device cannot obtain the authorization permission.
[0244] S1012, the terminal device sends a fifth message to the first network device; correspondingly, the first network device receives the fifth message from the terminal device.
[0245] In this embodiment of the present application, the fifth message is used to indicate the authorization permission.
[0246] It should be understood that the execution order of S1005, S1006-S1009 and S1010-S1012 is not specific. The communication method shown in FIG10 may include any one of S1005, S1006-S1009 and S1010-S1012, or may include all of them.
[0247] Optionally, the above method may further include S1013.
[0248] S1013: The first network device verifies the first identifier using the access permission information corresponding to the first avatar identifier. If the verification passes, execute S1014; otherwise, execute S1016.
[0249] In the embodiment of the present application, the first identifier includes the following two possible forms:
[0250] In scenario 1, when the first identifier is used to identify the first application, if the access permission information corresponding to the first clone identifier includes the first identifier, the first identifier is verified successfully; otherwise, the verification fails.
[0251] In the second scenario, when the first identifier is used to identify the target service, the first network device determines the service type of the target service based on the first identifier. If the access permission information corresponding to the first clone identifier includes the service type of the target service, the first identifier is verified successfully; otherwise, the verification fails.
[0252] S1014: The first network device determines at least one piece of attribute information corresponding to the first avatar identifier, and determines attribute information corresponding to the target attribute identifier from the at least one piece of attribute information corresponding to the first avatar identifier.
[0253] S1015: The first network device sends attribute information corresponding to the target attribute identifier to the first application. Then, the process ends, that is, S1016 is not executed again.
[0254] Optionally, the above method may further include S1016.
[0255] S1016. The first network device sends a twelfth message to the first application; correspondingly, the first application receives the twelfth message from the first network device.
[0256] In the embodiment of the present application, the twelfth message is used to indicate that the attribute information corresponding to the target attribute identifier cannot be obtained.
[0257] In the above method, the first application can directly obtain the relevant attribute information of the entity corresponding to the first avatar identifier from the first network device, without requiring the user to enter the attribute information in the first application. This allows the first application to quickly and efficiently obtain the attribute information of the entity accessing the first application. In addition, because the first avatar identifier is used to log in to the first application, the first application can only obtain the attribute information corresponding to the first avatar identifier from the first network device, and cannot obtain the attribute information corresponding to other avatar identifiers. This can achieve the isolation of the attribute information corresponding to different avatar identifiers and effectively manage the attribute information corresponding to different avatar identifiers.
[0258] In the embodiments provided above, the methods provided in the embodiments of the present application are introduced from the perspective of interaction between various devices. In order to implement the various functions in the methods provided in the embodiments of the present application, the first network device may include a hardware structure and / or a software module, and implement the above functions in the form of a hardware structure, a software module, or a hardware structure plus a software module. Whether a function of the above functions is executed in the form of a hardware structure, a software module, or a hardware structure plus a software module depends on the specific application and design constraints of the technical solution.
[0259] The division of modules in the embodiments of the present application is illustrative and is merely a logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional modules in the various embodiments of the present application may be integrated into a single processor, or may exist physically separately, or two or more modules may be integrated into a single module. The aforementioned integrated modules may be implemented in the form of hardware or software functional modules.
[0260] Similar to the above concept, as shown in FIG11 , an embodiment of the present application further provides a communication device 1100 for implementing the functions of the first network device or the first application in the above method. For example, the communication device may be a software module or a chip system. In the embodiment of the present application, the chip system may be composed of a chip, or may include a chip and other discrete components. The communication device 1100 may include: a communication unit 1101 and a processing unit 1102.
[0261] In the embodiment of the present application, the communication unit and processing unit included in the communication device 1100 are respectively used to perform the sending and receiving steps of the first network device or the first application in the above method embodiment. The communication unit and the processing unit can be an integrated unit or two independent units.
[0262] The communication device provided in the embodiment of the present application is described in detail below with reference to Figures 11 and 12. It should be understood that the description of the device embodiment corresponds to the description of the method embodiment. Therefore, for matters not described in detail, reference can be made to the method embodiment above. For the sake of brevity, they will not be repeated here.
[0263] In one implementation, the communication device 1100 may perform the following functions:
[0264] The communication unit 1101 is used to receive a first message from a first application, wherein the first message includes a first avatar identifier, the first avatar identifier is used to identify an entity accessing the first application, and the first message is used to request attribute information of a target attribute identifier corresponding to the entity.
[0265] The communication unit 1101 is further configured to send attribute information corresponding to the target attribute identifier to the first application, where the attribute information corresponding to the target attribute identifier is determined from at least one attribute information corresponding to the first avatar identifier.
[0266] In one possible design, the first message also includes a first authentication credential; before determining at least one attribute information corresponding to the first avatar identifier, the processing unit 1102 is used to: use the first authentication credential to confirm that the first avatar identifier is verified.
[0267] In one possible design, the first message also includes a first identifier, which is used to identify the first application or the target business in the first application, and the target business is the business accessed by the entity in the first application; the processing unit 1102 is also used to: use the access permission information corresponding to the first avatar identifier to confirm that the first identifier verification is successful.
[0268] In one possible design, the first identifier is used to identify the first application; the processing unit 1102 is specifically configured to: if the access permission information corresponding to the first clone identifier includes the first identifier, confirm that the first identifier has been verified successfully.
[0269] In one possible design, the first identifier is used to identify the target business; the processing unit 1102 is specifically used to: determine the business type of the target business based on the first identifier; if the access permission information corresponding to the first clone identifier includes the business type of the target business, confirm that the first identifier verification is successful.
[0270] In one possible design, the processing unit 1102 is also used to: the communication unit 1101 is also used to: send a second message to the terminal device, the second message is used to request verification information corresponding to the first verification identifier; the first verification identifier is determined based on the first mapping relationship and the target attribute identifier, the first mapping relationship includes multiple attribute identifiers and a first verification identifier corresponding to each attribute identifier in the multiple attribute identifiers, the multiple attribute identifiers include a target attribute identifier; the first application is installed on the terminal device; the communication unit 1101 is also used to: receive a third message from the terminal device, the third message includes verification information corresponding to the first verification identifier; the third message is used to request verification of the verification information.
[0271] In one possible design, the communication unit 1101 is also used to: send a fourth message to the terminal device, wherein the fourth message is used to request authorization permission, and the authorization permission includes allowing the first application or target service related to the first identifier to obtain attribute information corresponding to the target attribute identifier; the communication unit 1101 is also used to: receive a fifth message from the terminal device, wherein the fifth message is used to indicate authorization permission.
[0272] In one possible design, the communication unit 1101 is also used to: receive a sixth message from the terminal device, wherein the sixth message includes the root identifier of the entity, the root identifier is used to uniquely identify the entity, and the sixth message is used to request the first avatar identifier corresponding to the root identifier; the processing unit 1102 is also used to: generate the first avatar identifier corresponding to the root identifier; the communication unit 1101 is also used to: send the first avatar identifier to the terminal device.
[0273] In one possible design, the sixth message also includes a second authentication credential; the processing unit 1102 is further used to: use the second authentication credential to confirm that the root identifier verification is successful.
[0274] In one possible design, the sixth message also includes a second identifier, which is used to identify the identity information of the entity; the communication unit 1101 is also used to: send a seventh message to the second network device, and the seventh message is used to request verification of the second identifier; receive an eighth message from the second network device, and the eighth message is used to indicate that the second identifier verification is successful.
[0275] In one possible design, the second identifier includes the entity's identity identifier, and the second network device is a preset identity providing node; the seventh message is used to request verification of the entity's identity identifier, and the eighth message is used to indicate that the entity's identity identifier verification is successful.
[0276] In one possible design, the second identifier includes an identity identifier of the entity and an identifier of a target identity providing node;
[0277] The communication unit 1101 is specifically configured to: send a seventh message to the target identity providing node according to the identifier of the target identity providing node, where the seventh message is used to request the identity identifier of the verification entity;
[0278] The communication unit 1101 is specifically configured to receive an eighth message from the target identity providing node, where the eighth message is used to indicate that the entity's identity verification has passed.
[0279] In one possible design, the communication unit 1101 is specifically configured to send a seventh message to the target identity providing node using a verification address corresponding to an identifier of the target identity providing node. The verification address corresponding to the identifier of the target identity providing node is determined based on a second mapping relationship and the identifier of the target identity providing node, the second mapping relationship including identifiers of multiple identity providing nodes and a verification address corresponding to the identifier of each of the multiple identity providing nodes; the identifiers of the multiple identity providing nodes including the identifier of the target identity providing node.
[0280] In one possible design, the communication unit 1101 is specifically used to: receive a ninth message from the identity providing node, the ninth message including the identifier of the identity providing node and the verification address corresponding to the identifier of the identity providing node; and add the identifier of the identity providing node and the verification address corresponding to the identifier of the identity providing node to the second mapping relationship.
[0281] In one possible design, the sixth message also includes an identifier of at least one application, or a type of at least one service; the processing unit 1102 is also used to: add an identifier of at least one application, or a type of at least one service to the access permission information corresponding to the first avatar identifier.
[0282] In a possible design, the communication unit 1101 is further used to: send a first authentication credential to the terminal device, where the first authentication credential is generated for the first avatar identifier.
[0283] In one possible design, the communication unit 1101 is further used to: receive a tenth message from the terminal device, where the tenth message is used to request the root identifier of the entity; and send the root identifier to the terminal device.
[0284] In a possible design, the tenth message includes the identifier of the SIM card; the root identifier is determined according to the subscription permanent identifier SUPI corresponding to the identifier of the SIM card.
[0285] In a possible design, the processing unit 1102 is further used to: determine attribute information corresponding to the root identifier based on first information corresponding to the identifier of the SIM card, where the first information is used to identify attribute information of the entity.
[0286] In one possible design, the tenth message includes the device identifier of the terminal device; the root identifier is determined based on the device identifier.
[0287] In one possible design, the tenth message also includes second information, where the second information is used to identify attribute information of the entity. The processing unit 1102 is further used to: determine the second information as attribute information corresponding to the root identifier.
[0288] In one possible design, the communication unit 1101 is further used to: send a second authentication credential to the terminal device, where the second authentication credential is generated for the root identifier.
[0289] In one implementation, the communication device 1100 may perform the following functions:
[0290] Communication unit 1101 is configured to send a first message to a first network device, where the first message includes a first avatar identifier, the first avatar identifier is used to identify an entity accessing a first application, and the first message is used to request attribute information of a target attribute identifier corresponding to the entity;
[0291] The communication unit 1101 is further configured to receive attribute information corresponding to a target attribute identifier from the first network device, where the attribute information corresponding to the target attribute identifier is determined from at least one attribute information corresponding to the first avatar identifier.
[0292] In one possible design, the first message also includes a first authentication credential, which is used to verify the first avatar identifier.
[0293] The above are just examples. The communication unit and processing unit in the communication device 1100 can also perform other functions. For more detailed descriptions, please refer to the relevant descriptions in the method embodiment shown above, which will not be repeated here.
[0294] In the embodiments provided above, the methods provided in the embodiments of the present application are described from the perspective of a communication device as an execution subject. In order to implement the various functions in the methods provided in the embodiments of the present application, the communication device may include a hardware structure and / or a software module, and implement the above functions in the form of a hardware structure, a software module, or a hardware structure plus a software module. Whether a function of the above functions is executed in the form of a hardware structure, a software module, or a hardware structure plus a software module depends on the specific application and design constraints of the technical solution.
[0295] Exemplarily, when hardware implementation is adopted, the hardware implementation of the communication device may refer to FIG. 12 and its related description.
[0296] Referring to Figure 12 , the communication device may include: one or more processors 1202; a memory 1203; one or more application programs (not shown); and one or more computer programs 1204. The aforementioned components may be connected via one or more communication buses 1201. The one or more computer programs 1204 are stored in the aforementioned memory 1203 and configured to be executed by the one or more processors 1202. The one or more computer programs 1204 include instructions that can be used to execute the method of any of the aforementioned embodiments. The one or more processors 1202 may perform the functions of the communication unit 1101 and the processing unit 1102.
[0297] An embodiment of the present application further provides a computer-readable storage medium, in which computer instructions are stored. When the computer instructions are executed on a communication device, the communication device implements the communication method in the above embodiment.
[0298] An embodiment of the present application further provides a computer program product, which, when executed on a computer, enables the computer to execute the communication method in the above embodiment.
[0299] Among them, the communication device, computer-readable storage medium, computer program product or chip provided in the embodiments of the present application are all used to execute the corresponding methods provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding methods provided above, and will not be repeated here.
[0300] Through the description of the above implementation methods, technical personnel in the relevant field can understand that for the convenience and simplicity of description, only the division of the above-mentioned functional modules is used as an example. In actual applications, the above-mentioned functions can be distributed and completed by different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.
[0301] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of modules or units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0302] Units described as separate components may or may not be physically separate, and components shown as units may be one physical unit or multiple physical units, that is, they may be located in one place or distributed in multiple places. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0303] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0304] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for enabling a device (which can be a single-chip microcomputer, chip, etc.) or a processor (processor) to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0305] The above content is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.
Claims
1. A communication method, characterized in that: The method is applied to a first network device, comprising: receiving a first message from a first application, the first message including a first avatar identifier, the first avatar identifier being used to identify an entity accessing the first application, and the first message being used to request attribute information of a target attribute identifier corresponding to the entity; Attribute information corresponding to the target attribute identifier is sent to the first application, where the attribute information corresponding to the target attribute identifier is determined from at least one attribute information corresponding to the first avatar identifier.
2. The method according to claim 1, wherein The first message also includes a first authentication credential, and the method further includes: The first authentication credential is used to confirm that the first avatar identifier has been verified.
3. The method according to claim 1 or 2, wherein: The first message further includes a first identifier, where the first identifier is used to identify the first application or a target service in the first application, where the target service is a service accessed by the entity in the first application. The method further includes: The access permission information corresponding to the first avatar identifier is used to confirm that the first identifier verification is successful.
4. The method according to claim 3, wherein The first identifier is used to identify the first application; The confirming that the first identity verification is successful using the access permission information corresponding to the first avatar identity includes: If the access permission information corresponding to the first avatar identifier includes the first identifier, it is confirmed that the first identifier verification has passed.
5. The method according to claim 3, wherein The first identifier is used to identify the target service; The confirming that the first identity verification is successful using the access permission information corresponding to the first avatar identity includes: determining a service type of the target service according to the first identifier; If the access permission information corresponding to the first avatar identifier includes the service type of the target service, it is confirmed that the first identifier verification has passed.
6. The method according to any one of claims 1 to 5, characterized in that: The method further comprises: sending a second message to the terminal device, the second message being used to request verification information corresponding to a first verification identifier; the first verification identifier being determined based on the first mapping relationship and the target attribute identifier, the first mapping relationship including a plurality of attribute identifiers and a first verification identifier corresponding to each of the plurality of attribute identifiers, the plurality of attribute identifiers including the target attribute identifier; and the first application being installed on the terminal device; A third message is received from the terminal device, where the third message includes verification information corresponding to the first verification identifier; and the third message is used to request verification of the verification information.
7. The method according to any one of claims 3 to 5, characterized in that: The method further comprises: Sending a fourth message to the terminal device, where the fourth message is used to request authorization, where the authorization includes allowing a first application or target service associated with the first identifier to obtain attribute information corresponding to the target attribute identifier; A fifth message is received from the terminal device, where the fifth message is used to indicate the authorization permission.
8. The method according to any one of claims 1 to 7, wherein: The method further comprises: receiving a sixth message from a terminal device, the sixth message including a root identifier of the entity, the root identifier being used to uniquely identify the entity, and the sixth message being used to request the first avatar identifier corresponding to the root identifier; Generate the first avatar identifier corresponding to the root identifier; Send the first avatar identifier to the terminal device.
9. The method according to claim 8, wherein The sixth message also includes a second authentication credential; and the method further includes: The second authentication credential is used to confirm that the root identifier verification is successful.
10. The method according to claim 8 or 9, characterized in that The sixth message further includes a second identifier, where the second identifier is used to identify the identity information of the entity; and the method further includes: Sending a seventh message to the second network device, where the seventh message is used to request verification of the second identifier; An eighth message is received from the second network device, where the eighth message is used to indicate that the second identifier verification is successful.
11. The method according to claim 10, wherein The second identifier includes the identity identifier of the entity, and the second network device is a preset identity providing node; the seventh message is used to request verification of the identity identifier of the entity, and the eighth message is used to indicate that the identity identifier of the entity has been verified successfully.
12. The method according to claim 10, wherein The second identifier includes the identity identifier of the entity and the identifier of the target identity providing node; The sending the seventh message to the second network device includes: sending a seventh message to the target identity providing node according to the identifier of the target identity providing node, wherein the seventh message is used to request verification of the identity identifier of the entity; The receiving an eighth message from the second network device includes: An eighth message is received from the target identity providing node, where the eighth message is used to indicate that the identity verification of the entity is successful.
13. The method according to claim 12, wherein: The sending a seventh message to the target identity providing node according to the identifier of the target identity providing node includes: The seventh message is sent to the target identity providing node through the verification address corresponding to the identifier of the target identity providing node; the verification address corresponding to the identifier of the target identity providing node is determined according to the second mapping relationship and the identifier of the target identity providing node, the second mapping relationship including the identifiers of multiple identity providing nodes and the verification address corresponding to the identifier of each identity providing node in the multiple identity providing nodes; the identifiers of the multiple identity providing nodes include the identifier of the target identity providing node.
14. The method according to claim 13, wherein The method further comprises: receiving a ninth message from the identity providing node, the ninth message including an identifier of the identity providing node and a verification address corresponding to the identifier of the identity providing node; The identifier of the identity providing node and the verification address corresponding to the identifier of the identity providing node are added to the second mapping relationship.
15. The method according to any one of claims 8 to 14, wherein: The sixth message further includes an identifier of at least one application, or a type of at least one service; and the method further includes: The identifier of the at least one application, or the type of the at least one service, is added to the access permission information corresponding to the first avatar identifier.
16. The method according to any one of claims 8 to 15, wherein: The method further comprises: The first authentication credential is sent to the terminal device, where the first authentication credential is generated for the first avatar identifier and is used to verify the first avatar identifier.
17. The method according to any one of claims 8 to 16, wherein: The method further comprises: receiving a tenth message from the terminal device, wherein the tenth message is used to request a root identifier of the entity; Send the root identifier to the terminal device.
18. The method according to claim 17, wherein The tenth message includes the identifier of a subscriber identity module SIM card; the root identifier is determined according to a subscription permanent identifier SUPI corresponding to the identifier of the SIM card.
19. The method according to claim 18, wherein The method further comprises: Attribute information corresponding to the root identifier is determined according to first information corresponding to the identifier of the SIM card, where the first information is used to identify attribute information of the entity.
20. The method of claim 17, wherein: The tenth message includes the device identifier of the terminal device; the root identifier is determined based on the device identifier.
21. The method according to claim 20, wherein The tenth message further includes second information, where the second information is used to identify attribute information of the entity. The method further includes: The second information is determined as attribute information corresponding to the root identifier.
22. The method according to any one of claims 17 to 21, wherein: The method further comprises: A second authentication credential is sent to the terminal device, where the second authentication credential is generated for the root identifier and is used to verify the root identifier.
23. A communication method, characterized in that: The method is applied to a first application and includes: Sending a first message to a first network device, where the first message includes a first avatar identifier, the first avatar identifier is used to identify an entity accessing the first application, and the first message is used to request attribute information of a target attribute identifier corresponding to the entity; Attribute information corresponding to the target attribute identifier is received from the first network device, where the attribute information corresponding to the target attribute identifier is determined from at least one attribute information corresponding to the first avatar identifier.
24. The method according to claim 23, wherein The first message also includes a first authentication credential, which is used to verify the first avatar identifier.
25. A communication device, characterized in that: including processor and memory; The processor is configured to execute the computer program or instructions stored in the memory, so that the communication device implements the method according to any one of claims 1 to 22, or implements the method according to any one of claims 23 to 24.
26. A computer-readable storage medium, characterized in that A computer program or instruction is stored, and when the computer program or instruction is executed on a computer, the computer-readable storage medium implements the method according to any one of claims 1 to 22, or implements the method according to any one of claims 23 to 24.
27. A chip, characterized in that: The chip comprises a processor coupled to a memory and configured to execute a computer program or instruction stored in the memory, so that the chip implements the method according to any one of claims 1 to 22, or implements the method according to any one of claims 23 to 24.
28. A communication system, characterized in that: include: A first network device and a first application, wherein the first network device is used to implement the method according to any one of claims 1 to 22; and the first application is used to implement the method according to any one of claims 23 to 24.
29. A computer program product, characterized in that When a computer reads and executes the computer program product, the computer is enabled to implement the method according to any one of claims 1 to 22, or the method according to any one of claims 23 to 24.
Citation Information
Patent Citations
Data processing method and device
CN106056444A
Authentication system and authentication method
JP2012164191A
Information processing method and system, server, terminal and computer storage medium
WO2019084922A1
Information query method and apparatus, device, and computer readable storage medium
WO2023124107A1