Communication method and apparatus
By managing the digital identity attributes of terminal devices on the network side, the complexity problem caused by the storage and management of multiple attributes of terminal devices is solved, and more efficient and secure attribute management is achieved.
Patent Information
- Application Number
- PCT/CN2025/076301
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-09
- Filing Date
- 2025-02-07
- Publication Date
- 2025-08-14
AI Technical Summary
In the new interactive mode, terminal devices need to manage multiple digital identity attributes, and the prior art requires terminal devices to store and manage these attributes, resulting in increased equipment complexity and cost, especially for low-capacity terminal devices.
The digital identity attributes of the terminal device are stored on the network side and provided to the terminal device when necessary, reducing the storage and security calculation burden of the terminal device, and managing and protecting attributes are adopted using management modules.
It reduces the complexity and overhead of terminal devices, improves the efficiency and security of attribute management, and is suitable for various mobile communication systems.
Smart Images

Figure CN2025076301_14082025_PF_FP_ABST
Abstract
Description
Communication method and device
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of the People's Republic of China on February 9, 2024, with application number 202410179195.4 and invention name "A Communication Method and Device", the entire contents of which are incorporated by reference into this application. Technical Field
[0003] The present application relates to the field of communication technology, and in particular to a communication method and device. Background Art
[0004] With the development of mobile communication technology, a new interactive video-based calling mode will become an emerging feature call service. This new calling scenario will see the emergence of a series of new scenarios, such as caller ID enhancement, digital avatar communication, and artificial intelligence (AI) assistants. In addition to traditional calling functions, these scenarios will also feature various new features, such as AI assistants initiating services on behalf of users. These scenarios may involve interaction with external service platforms. Therefore, to enhance communication security, it is necessary to improve the user digital identity system in these scenarios.
[0005] A user's digital identity primarily consists of their identifier, credentials, and / or attributes. Attributes describe the entity's type, frequently used Internet Protocol (IP) addresses, domains, address information, phone numbers, and other information. For example, attributes can include the location information corresponding to the digital identity or service contract information associated with a carrier. Digital identity attributes can be issued by multiple parties. Storing these attributes in a terminal device places high demands on the device, increasing the complexity of its design. Summary of the Invention
[0006] The present application provides a communication method and apparatus for providing a solution for managing attributes of a digital identity.
[0007] In a first aspect, the present application provides a communication method, wherein the execution subject of the method is a first network element or a module or chip in the first network element, and the first network element may be a session management function (SMF) network element or other network elements. The first network element is used as the execution subject for description herein as an example. The method includes: the first network element receiving first information and second information, the first information being used to determine a first attribute type, and the second information being used to indicate a terminal device; obtaining a digital identity of the terminal device after security protection, the digital identity including a first attribute corresponding to the first attribute type; and sending the digital identity after security protection.
[0008] The first network element may receive the first information and the second information from the terminal device and send a securely protected digital identity to the terminal device; or the first network element may receive the first information and the second information from the application server and send a securely protected digital identity to the application server.
[0009] The present application provides a digital identity management process, in which the attributes used to determine the digital identity can be stored on the network side, and the terminal device can obtain the digital identity including the attributes through the network side. Through the method provided by the present application, the attributes of the terminal device are stored by the network side, and when the first information and the second information are received, thereby determining that the terminal device needs to use a digital identity including the first attribute corresponding to the first attribute type, the digital identity including the first attribute is returned. This can reduce the complexity of the terminal device (such as not imposing additional security hardware requirements on the terminal device) and reduce the overhead of the terminal device (such as reducing storage and security computing consumption).
[0010] In a possible implementation, the first information is an application identifier, and the application identifier corresponds to the first attribute type; or the first information is an identifier of the first attribute type.
[0011] In the above technical solution, when the first information is of the first attribute type, the network can directly determine the first attribute corresponding to the first attribute type, thereby improving efficiency. When the first attribute is an application identifier, the device requesting attributes from the network does not need to determine which attributes to request; the network only needs to determine the first attribute type based on the application identifier, thereby improving efficiency.
[0012] In one possible implementation, before the first network element obtains the first attribute based on the first information and the second information, the method also includes: receiving a first identifier and an access credential; the management module corresponding to the first identifier is used to manage one or more attributes of the terminal device, and the one or more attributes include the first attribute; if the access credential is successfully verified, the first attribute is obtained from the management module corresponding to the first identifier.
[0013] In the above technical solution, by verifying the access credentials of the management module and then obtaining the first attribute from the management module, the attributes of the terminal device can be prevented from being obtained by a third-party device, thereby ensuring the security of the attributes of the terminal device.
[0014] In one possible implementation, before the first network element receives the first information and the second information, the method further includes: receiving first indication information and second indication information from the terminal device; the second indication information indicates one or more attributes, the first indication information instructs the network side to manage the one or more attributes indicated by the second indication information, and the one or more attributes include the first attribute; creating the management module, and the management module is used to manage the one or more attributes.
[0015] In the above technical solution, by creating a management module to manage one or more attributes of the terminal device, the terminal device can be assisted in obtaining attributes from the issuer of the attribute, avoiding the need for the terminal device to interact with multiple network elements to obtain multiple attributes. The attributes are obtained and managed by the network side, which can reduce the complexity of the terminal device and reduce the overhead of the terminal device.
[0016] In a possible implementation, after creating the management module, the method further includes: sending the first identifier and the access credential to the terminal device.
[0017] In a possible implementation, after the first network element receives the first information and the second information, the method further includes: acquiring the first attribute from the second network element according to the first information and the second information.
[0018] In one possible implementation, after the first network element receives the first information and the second information, the method further includes: sending the first information and the second information to the second network element; receiving third indication information from the second network element, the third indication information being used to indicate a fourth network element, the fourth network element being the issuer of the first attribute; and obtaining the first attribute from the fourth network element according to the third indication information.
[0019] In the above technical solution, the first attribute is obtained through the issuer of the first attribute, that is, the fourth network element, so that the efficiency of obtaining the attribute can be improved.
[0020] In a second aspect, the present application provides a communication method, wherein the method is performed by a terminal device or a module or chip in the terminal device. The method is described herein using the terminal device as the example. The method comprises: sending first information and second information, wherein the first information is used to determine a first attribute type, and the second information is used to indicate the terminal device; receiving a securely protected digital identity of the terminal device, wherein the digital identity includes a first attribute corresponding to the first attribute type; and sending the securely protected digital identity to an application server, wherein the first attribute is used to access services of the application server.
[0021] In a possible implementation, the first information is an application identifier, and the application identifier corresponds to the first attribute type; or the first information is an identifier of the first attribute type.
[0022] In one possible implementation, before sending the first information and the second information, the method further includes: sending a service request message to the application server, wherein the service request message requests a service; receiving a digital identity query message from the application server, wherein the digital identity query message is used to instruct reporting of the digital identity; and the digital identity query message includes the first information.
[0023] In one possible implementation, before sending the first information and the second information, the method further includes: sending first indication information and second indication information; the second indication information indicates one or more attributes, the first indication information indicates that the network side manages the one or more attributes indicated by the second indication information, and the one or more attributes include the first attribute.
[0024] In a possible implementation, after sending the first indication information and the second indication information, the method further includes: receiving a first identifier and an access credential; and a management module corresponding to the first identifier is used to manage the one or more attributes.
[0025] In a possible implementation, before receiving the securely protected digital identity of the terminal device, the method further includes: sending the first identifier and the access credential.
[0026] In a third aspect, the present application provides a communication method, wherein the execution subject of the method is a second network element or a module or chip in the second network element, and the method is described here by taking the second network element as the execution subject as an example. The method includes: the second network element receiving first information and second information from a first network element, wherein the first information is used to determine a first attribute type, and the second information is used to indicate a terminal device; sending a first attribute corresponding to the first attribute type among the attributes of the terminal device to the first network element; or sending third indication information to the first network element, wherein the third indication information is used to instruct a fourth network element to request the first attribute, and the fourth network element is the issuer of the first attribute.
[0027] In a possible implementation, before receiving the first information and the second information from the first network element, the method further includes: receiving a first correspondence from an application server, where the first correspondence indicates a correspondence between an application identifier and a first attribute type.
[0028] In a possible implementation, the first information is an application identifier; and the method further includes: determining the first attribute type according to the application identifier and the first corresponding relationship.
[0029] In a possible implementation manner, the first information is an identifier of the first attribute type.
[0030] In a fourth aspect, the present application provides a communication method, wherein the execution subject of the method is an application server or a module or chip in the application server. The application server can be an application function (AF) network element or a network element provided by a third party. The description here takes the application server as the execution subject as an example. The method includes: receiving a digital identity of the terminal device after security protection from the terminal device, the digital identity including a first attribute; and verifying whether the terminal device can access the service based on the first attribute.
[0031] In a possible implementation, the securely protected digital identity of the terminal device is located in a service request message, and the service requested by the service request message is associated with the first attribute.
[0032] In a possible implementation, before receiving the securely protected digital identity of the terminal device, the method further includes:
[0033] Receive a service request message from the terminal device, where the service requested by the service request message is associated with the first attribute; send a digital identity query message to the terminal device, where the digital identity query message is used to indicate reporting of the digital identity; the digital identity query message includes first information, where the first information is used to determine a first attribute type, where the first attribute type corresponds to the first attribute.
[0034] In a possible implementation, before receiving the securely protected digital identity of the terminal device, the method further includes: sending a first correspondence to a second network element, where the first correspondence indicates a correspondence between an application identifier and a first attribute type.
[0035] In a fifth aspect, the present application provides a communication method, wherein the execution subject of the method is a first network element or a module or chip in the first network element, and the first network element may be a network element such as a session management function (SMF) network element. The first network element is used as the execution subject for description herein as an example. The method includes: the first network element receiving first information and second information, the first information being used to determine a first attribute type, and the second information being used to indicate a terminal device; determining a first attribute corresponding to the first attribute type among the attributes of the terminal device based on the first information and the second information; and sending the first attribute.
[0036] In a possible implementation, the first information is an application identifier, and the application identifier corresponds to the first attribute type; or the first information is an identifier of the first attribute type.
[0037] In one possible implementation, before the first network element obtains the first attribute based on the first information and the second information, the method also includes: receiving a first identifier and an access credential; the management module corresponding to the first identifier is used to manage one or more attributes of the terminal device, and the one or more attributes include the first attribute; if the access credential is successfully verified, the first attribute is obtained from the management module corresponding to the first identifier.
[0038] In one possible implementation, before the first network element receives the first information and the second information, the method further includes: receiving first indication information and second indication information from the terminal device; the second indication information indicates one or more attributes, the first indication information instructs the network side to manage the one or more attributes indicated by the second indication information, and the one or more attributes include the first attribute; creating the management module, and the management module is used to manage the one or more attributes.
[0039] In one possible implementation, after creating the management module, the method further includes: sending the first identifier and the access credential to the terminal device. For example, the access credential includes but is not limited to a username, password, token, certificate, etc., which is not limited in this application.
[0040] In a possible implementation, after the first network element receives the first information and the second information, the method further includes: acquiring the first attribute from the second network element according to the first information and the second information.
[0041] In one possible implementation, after the first network element receives the first information and the second information, the method further includes: sending the first information and the second information to the second network element; receiving third indication information from the second network element, the third indication information being used to indicate a fourth network element, the fourth network element being the issuer of the first attribute; and obtaining the first attribute from the fourth network element according to the third indication information.
[0042] In a sixth aspect, the present application provides a communication method, wherein the execution subject of the method is a terminal device or a module or chip in the terminal device. The method is described here using the terminal device as the execution subject as an example. The method includes: sending first information and second information, wherein the first information is used to determine a first attribute type, and the second information is used to indicate the terminal device; receiving a first attribute, wherein the first attribute is an attribute among the attributes of the terminal device corresponding to the first attribute type; obtaining a digital identity of the terminal device, wherein the digital identity includes the first attribute; and sending the securely protected digital identity to an application server, wherein the first attribute is used to access the services of the application server.
[0043] In a possible implementation, the first information is an application identifier, and the application identifier corresponds to the first attribute type; or the first information is an identifier of the first attribute type.
[0044] In one possible implementation, before sending the first information and the second information, the method further includes: sending a service request message to the application server, wherein the service request message requests a service; receiving a digital identity query message from the application server, wherein the digital identity query message is used to instruct reporting of the digital identity; and the digital identity query message includes the first information.
[0045] In one possible implementation, before sending the first information and the second information, the method further includes: sending first indication information and second indication information; the second indication information indicates one or more attributes, the first indication information indicates that the network side manages the one or more attributes indicated by the second indication information, and the one or more attributes include the first attribute.
[0046] In a possible implementation, after sending the first indication information and the second indication information, the method further includes: receiving a first identifier and an access credential; and a management module corresponding to the first identifier is used to manage the one or more attributes.
[0047] In a possible implementation, before receiving the first attribute, the method further includes: sending the first identifier and the access credential.
[0048] In a seventh aspect, the present application further provides a communication device capable of implementing any of the methods provided in any of the first to sixth aspects. The communication device can be implemented via hardware or by hardware executing corresponding software implementations. The hardware or software includes one or more units or modules corresponding to the aforementioned functions.
[0049] In one possible implementation, the communication device includes a processor configured to support the communication device in executing the corresponding functions of the first network element or terminal device or the second network element or application server in the above-described method. The communication device may also include a memory, which may be coupled to the processor and stores program instructions and data necessary for the communication device. Optionally, the communication device also includes an interface circuit configured to support communication between the communication device and a device such as a terminal device.
[0050] In one possible implementation, the communication device includes corresponding functional modules for implementing the steps in the above method. The functions can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions.
[0051] In one possible implementation, the structure of the communication device includes a processing unit and a communication unit, which can perform the corresponding functions in the above method examples. For details, please refer to the description of the method provided in any one of the first to sixth aspects, which will not be repeated here.
[0052] In an eighth aspect, a communication device is provided, comprising a processor and an interface circuit, the interface circuit being configured to receive signals from a communication device other than the communication device and transmit them to the processor, or to transmit signals from the processor to a communication device other than the communication device, the processor implementing the functional modules of the method in any possible implementation of any of the first to sixth aspects through logic circuitry or by executing a computer program or instruction. Optionally, the communication device further comprises a memory configured to store the computer program or instruction.
[0053] In the ninth aspect, a computer-readable storage medium is provided, which stores a computer program or instruction. When the computer program or instruction is executed by a processor, the method in any possible implementation of any one of the first to sixth aspects is implemented.
[0054] In a tenth aspect, a computer program product storing instructions is provided, which, when read and executed by a computer, implements the method in any possible implementation of any one of the first to sixth aspects.
[0055] In an eleventh aspect, a circuit is provided for executing the method in any possible implementation of any one of the first to sixth aspects, wherein the circuit may include a chip circuit. Optionally, the circuit may also be coupled to a memory.
[0056] In a twelfth aspect, a chip is provided, comprising a processor. When the processor executes a computer program or instruction, the processor is configured to implement the method of any possible implementation of any of the first to sixth aspects. Optionally, the chip may further include a memory. The chip may be composed of a single chip or may include a chip and other discrete components.
[0057] In the thirteenth aspect, a communication device is provided, comprising a processor, which implements the method in any possible implementation of any one of the first to sixth aspects through a logic circuit or executing a computer program or instruction.
[0058] In a fourteenth aspect, a communication device is provided, comprising a unit or module for executing the method in any possible implementation of any one of the first to sixth aspects above.
[0059] In a fifteenth aspect, embodiments of the present application further provide a communication system. The communication system includes: a first network element for implementing the method in the aforementioned first aspect and any possible implementation thereof; a terminal device for implementing the method in the aforementioned second aspect and any possible implementation thereof; a second network element for implementing the method in the aforementioned third aspect and any possible implementation thereof; and an application server for implementing the method in the aforementioned fourth aspect and any possible implementation thereof. BRIEF DESCRIPTION OF THE DRAWINGS
[0060] FIG1 is a schematic diagram of a network device architecture applicable to an embodiment of the present application;
[0061] FIG2 is a flow chart of a communication method provided in an embodiment of the present application;
[0062] FIG3 is a flow chart of a communication method provided in an embodiment of the present application;
[0063] FIG4 is a flow chart of a communication method provided in an embodiment of the present application;
[0064] FIG5 is a flow chart of a communication method provided in an embodiment of the present application;
[0065] FIG6 is a flow chart of a communication method provided in an embodiment of the present application;
[0066] FIG7 is a flow chart of a communication method provided in an embodiment of the present application;
[0067] FIG8 is a flow chart of a communication method provided in an embodiment of the present application;
[0068] FIG9 is a flow chart of a communication method provided in an embodiment of the present application;
[0069] FIG10 is a schematic diagram of the structure of a communication device provided in an embodiment of the present application;
[0070] FIG11 is a schematic diagram of the structure of a communication device provided in an embodiment of the present application;
[0071] FIG12 is a schematic diagram of the structure of a communication device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0072] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application. Obviously, the embodiments described are only a part of the embodiments of the present application, not all of the embodiments. The terms "first", "second" and corresponding terminology labels in the present application are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the terms used in this way can be interchangeable under appropriate circumstances. This is merely a way of distinguishing objects with the same properties when describing the embodiments of the present application. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, so that a process, method, system, product or device that includes a series of units is not necessarily limited to those units, but may include other units that are not clearly listed or inherent to these processes, methods, products or devices. The methods and devices provided in the embodiments of the present application are based on the same or similar technical concepts. Since the principles of solving problems by the methods and devices are similar, the implementation of the devices and methods can refer to each other, and the repetitions will not be repeated.
[0073] The method provided in the embodiment of the present application can be applied to various mobile communication systems, for example, the Internet of Things (IoT), narrowband Internet of Things (NB-IoT), a fourth generation (4G) communication system (such as long term evolution (LTE)), a fifth generation (5G) communication system (such as 5G new radio (NR)), a hybrid architecture of LTE and NR, 6G or new communication systems emerging in future communication developments, etc. The communication system may also include a machine to machine (M2M) network, a machine type communication (MTC) or other networks.
[0074] Figure 1 is a schematic diagram of a 5G network architecture applicable to the present application. The 5G network architecture shown in Figure 1 may include terminal equipment, access network equipment and core network (CN) equipment. The terminal equipment accesses the data network (DN) through the access network equipment and the core network equipment. Among them, the core network equipment includes a variety of network functions (NF) or network elements, for example, including some or all of the following network elements: unified data management (UDM) network element, unified database (UDR) network element, network exposure function (NEF) network element, application function (AF) network element, policy control function (PCF) network element, access and mobility management function (AMF) network element, session management function (SMF) network element, user plane function (UPF) network element, network repository function (NRF) network element.
[0075] The access network device may be a radio access network (RAN) device. For example: a base station, an evolved NodeB (eNodeB), a transmission reception point (TRP), a next generation NodeB (gNB) in a 5G mobile communication system, a next generation base station in a sixth generation (6G) mobile communication system, a base station in a future mobile communication system, or an access node in a wireless fidelity (WiFi) system, etc.; it may also be a module or unit that performs part of the functions of a base station, for example, a centralized unit (CU) or a distributed unit (DU). The radio access network device may be a macro base station, a micro base station or an indoor station, a relay node or a donor node, etc. The embodiments of the present application do not limit the specific technology and specific device form adopted by the radio access network device.
[0076] Terminal devices can be user equipment (UE), mobile stations, mobile terminals, etc. Terminal devices can be widely used in various scenarios, such as device-to-device (D2D), vehicle-to-everything (V2X) communication, machine-type communication (MTC), Internet of Things (IoT), virtual reality, augmented reality, industrial control, autonomous driving, telemedicine, smart grid, smart furniture, smart office, smart wearables, smart transportation, smart cities, etc. Terminal devices can be mobile phones, tablets, computers with wireless transceiver capabilities, wearable devices, vehicles, urban air vehicles (such as drones, helicopters, etc.), ships, robots, robotic arms, smart home devices, etc. Terminal devices can be devices that carry digital humans or digital images (specifically, they can be public cloud devices, telecommunications cloud devices, user devices, or network devices that store digital humans or digital images).
[0077] Access network equipment and terminal devices can be fixed or mobile. They can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; on water; or in the air on aircraft, balloons, and satellites. The embodiments of this application do not limit the application scenarios of access network equipment and terminal devices.
[0078] The following describes the core network equipment involved in this application:
[0079] The AMF network element performs functions such as mobility management and access authentication / authorization. It is also responsible for delivering user policies between terminal devices and the PCF. The SMF network element performs functions such as session management, execution of control policies issued by the PCF, selection of the UPF, and allocation of Internet Protocol (IP) addresses for terminal devices. The UPF network element, as an interface with the data network, performs functions such as user plane data forwarding, session / flow-level billing and statistics, and bandwidth limitation. The UDM network element performs functions such as managing subscription data and user access authorization. The UDR network element performs functions for accessing subscription data, policy data, application data, and other types of data. The NEF network element supports the opening of capabilities and events. The AF network element delivers application-side requirements to the network side, such as quality of service (QoS) requirements or user status event subscriptions. The AF can be a third-party functional entity or an application server deployed by the operator. The PCF network element is responsible for policy control functions such as billing at the session and service flow levels, QoS bandwidth assurance, mobility management, and terminal device policy decisions. NRF network elements can be used to provide network element discovery functions, providing network element information corresponding to the network element type based on requests from other network elements. NRF network elements also provide network element management services, such as network element registration, update, deregistration, and network element status subscription and push.
[0080] A DN is a network located outside of a carrier network. A carrier network can connect to multiple DNs, and a variety of services can be deployed on the DN, providing data and / or voice services to terminal devices. For example, a DN is the private network of a smart factory. Sensors installed in the workshop can be terminal devices. The DN houses a sensor control server, which provides services to the sensors. Sensors can communicate with the control server, receive instructions from the control server, and transmit collected sensor data to the control server based on the instructions. Another example is a DN that is a company's internal office network. An employee's mobile phone or computer can be a terminal device, allowing them to access information and data resources on the company's internal office network.
[0081] It can be understood that the above network elements are examples of one implementation method, and this application does not exclude the existence of network elements or devices with the above network element functions in 6G or newer wireless communication systems that have other names or other forms.
[0082] The functions of each interface are described as follows:
[0083] 1. N7: The interface between PCF and SMF, used to deliver PDU session granularity and service data flow granularity control policy.
[0084] 2. N15: Interface between PCF and AMF, used to deliver UE policies and access control related policies.
[0085] 3. N5: The interface between AF and PCF, used for issuing application service requests and reporting network events.
[0086] 4. N4: The interface between SMF and UPF, used to transmit information between the control plane and the user plane, including the control of the forwarding rules, QoS control rules, traffic statistics rules, etc. for the user plane and the reporting of information on the user plane.
[0087] 5. N11: The interface between SMF and AMF, used to transmit PDU session tunnel information between RAN and UPF, transmit control messages sent to UE, transmit radio resource control information sent to RAN, etc.
[0088] 6. N2: The interface between AMF and RAN, used to transmit radio bearer control information from the core network side to the RAN.
[0089] 7. N1: The interface between AMF and UE, access-independent, used to deliver QoS control rules to UE.
[0090] 8. N8: Interface between AMF and UDM, used by AMF to obtain access and mobility management-related subscription data and authentication data from UDM, and AMF to register UE current mobility management-related information with UDM.
[0091] 9. N10: The interface between SMF and UDM, used by SMF to obtain session management-related contract data from UDM, and for SMF to register UE current session-related information with UDM.
[0092] 10. N35: Interface between UDM and UDR, used by UDM to obtain user contract data information from UDR.
[0093] 11. N36: Interface between PCF and UDR, used by PCF to obtain policy-related contract data and application data-related information from UDR.
[0094] 12. N52: The interface between UDM and NEF, used by NEF to open network capabilities to third-party application functions. For example, third-party application functions subscribe to reachability events of all users in a specific group from UDM through NEF.
[0095] In current networks, users log in to application servers using a username and password, thereby accessing service data through the application servers. However, in real-world applications, identity authentication often requires attribute association in some scenarios. For example, during the communication phase, there's a need to verify the true identity of the other party (for government affairs, express delivery services) or the identity of a real person (for banks), but existing mechanisms don't yet support this capability. Future mobile communication technologies will provide users with new service capabilities. For example, in new call scenarios, enhanced caller ID, real-person authentication using a digital person image, and real-person authorization for AI assistants will be available. To improve communication security, the concept of digital identity has been proposed, and new call scenarios will require the use of a user's digital identity. A user's digital identity primarily consists of one or more of the following: user identification, credentials, and attributes.
[0096] The identifier is a permanent user identifier used to uniquely identify a digital identity entity, such as a person, machine, digital person, or intelligent entity. It can be assigned by the network, such as a telephone number or network access identifier (NAI).
[0097] Credential: A digital authentication credential that can be a digital certificate, token, and / or biometric;
[0098] Attributes: Attributes describe the entity's type, commonly used Internet Protocol (IP) addresses, domains, address information, and / or telephone numbers. For example, an attribute may include the location information corresponding to the digital identity, or may include service contract information associated with the operator.
[0099] There are many types of digital identity attributes, for example, they can be divided into the following attributes:
[0100] 1) Identity attributes: These are used to identify the identity information corresponding to the digital identity, such as the user's personal identity information or the identity information of a corporate entity. If the digital identity entity is an individual user, the user's personal identity information includes information such as the user's ID number, name, and address. If the digital identity entity is a corporate entity, the corporate entity's identity information includes information such as the company's social credit code, company name, registered address, and name of the corporate entity; or, it may include information such as contract information associated with the operator.
[0101] 2) Status attributes: Contains information such as the location information corresponding to the digital identity, the reachability status recorded in the network, or the network element identifier currently providing services for it, and supports internal / external entities to query the status of the entity corresponding to the digital identity;
[0102] 3) Contract attributes: business contract information associated with the operator, including account data, contract data, such as the list of contracted operator services, payment methods, etc.;
[0103] 4) Business attributes: These may include business authorization information, which can be used to record the authorization information received by the digital identity and / or the authorization information provided to the outside, such as the specific permissions authorized by the real person (which may include the authorization purpose, authorization content, authorization time limit, etc.), or the authorization information provided to another entity (such as allowing another entity to use the digital identity to perform corresponding business); or they can be used to control access requests to the digital identity, such as limiting the digital identity to only allow access to specific / specific types of business (such as enterprise applications, target third-party service providers (SP)).
[0104] Different types of attributes have different issuers. For example, identity attributes can come from authoritative institutions, and contract attributes can come from operators, etc. In the future, the attributes of digital identities may be further multi-sourced, and the complexity of intercommunication is high. If the attributes of digital identities are stored by terminal devices, the requirements for terminal devices will be high, which will increase the complexity of terminal device design and the cost of terminal devices. Especially in mobile communications, some terminal devices are low-capability terminal devices and cannot maintain attributes with complex sources. To this end, the present application provides a method that can store the attributes of digital identities on the network side. When the terminal device needs to use the attributes, it can obtain the attributes through the network side, which can reduce the complexity of the terminal device.
[0105] It can be understood that the present application does not specifically limit the specific structure of the execution subject of the method provided in the embodiment of the present application, and can be applied to modules in terminal devices or network devices, as long as it can communicate according to the method provided in the embodiment of the present application by running a program that records the code of the method provided in the embodiment of the present application.
[0106] In this application, terms with the same name across various embodiments are given specific meanings only the first time they appear. For other embodiments, please refer to the previous definitions. For example, if the first information is used to determine the first attribute type, then the function and meaning of the first information remain unchanged in the processes of Figures 2 to 9.
[0107] In this application, before communicating with an application server, a terminal device can first request the attributes of its digital identity from the network, and then send a service request message to the application server. The service request message can carry these attributes. If the application server determines that the attributes reported by the terminal device meet the requirements, it can authorize the terminal device to access the corresponding service, as described in detail below.
[0108] As shown in Figure 2, a flow chart of a communication method provided in an embodiment of the present application is provided. In this process, the name of the network device is not limited. For example, the network device can be called an identity management (IDM) network element; the network device can be an existing network element in the 4G or 5G network architecture, such as an SMF network element, or a newly defined network element in a future communication system. In this application, the network device can also be replaced by multiple network elements. For example, the function of the network device can be performed by a first network element (such as an SMF network element), a second network element (such as an UDM network element) and a third network element (such as an NEF network element), that is, the SMF network element, the UDM network element and the NEF network element respectively perform part of the functions of the network device in the following process. The first network element, the second network element and the third network element may also be modules in the network device or independent devices. The following is an example of the interaction between the network device and the terminal device. The application server can provide services for the terminal device, such as voice call services, instant messaging services or network video services, etc.; wherein the application server can be a network element in the mobile network or provide equipment for a third party. In this case, the application server interacts with the network through the NEF.
[0109] Step 201: The terminal device sends first information and second information.
[0110] Correspondingly, the network device receives the first information and the second information.
[0111] This application does not limit how the terminal device sends the first information and the second information. For example, the terminal device may send a digital identity request message, which is used to request the digital identity of the terminal device and may include the first information and the second information.
[0112] Optionally, before sending the first information and the second information, the terminal device may also register with the network device and establish a secure connection. The specific registration process and the process of establishing a secure connection are not limited in this application and will not be described in detail here.
[0113] In the present application, the second information is used to indicate the terminal device. For example, the second information is the identifier of the terminal device. For example, the identifier of the terminal device can be the user permanent identifier (SUPI) of the terminal device or a temporary mobile subscriber identity (s-TMSI) or an international mobile subscriber identity (IMSI), etc. This application does not limit this.
[0114] In this application, the first information is used to determine a first attribute type, and the first attribute type corresponds to a first attribute. The first attribute type may include one or more attribute types, each of which may correspond to one or more attribute information. That is, the first attribute may include one or more attributes. In this application, attribute types may include, but are not limited to, identity attributes, status attributes, contract attributes, and service attributes.
[0115] The specific implementation method of the first information is not limited. For example, the first information can be an identifier of the first attribute type. The identifier of the first attribute type is used to indicate or identify the first attribute type. Specifically, it can be the name, code, category or indicator of the first attribute type. The network device can directly determine the first attribute type based on the first information. For another example, the first information is an application identifier, and the application identifier can correspond to the first attribute type. The correspondence between the application identifier and the first attribute type is preset, or the correspondence between the application identifier and the first attribute type is indicated in advance by the network device to the terminal device. Among them, an application identifier is used to identify a service. The service can be an application service deployed by an operator, such as a voice call service; the service can also be an application service provided by a third party, such as an instant messaging service or an online video service.
[0116] In one implementation, the first information is determined by the terminal device. In another implementation, the first information comes from an application server. For example, before step 201, the terminal device may send a service request message to the application server. The service request message may include an application identifier, and the service request message is used to request the service corresponding to the application identifier. The application server determines, based on the service request message, that the service requested in the service request message is associated with the first attribute. The application server may then send a digital identity query message to the terminal device. The digital identity query message is used to indicate the digital identity of the terminal device being reported, and the digital identity query message may include the first information.
[0117] Optionally, if the first information is an application identifier, the network device may determine the first attribute type corresponding to the application identifier based on the application identifier and the first correspondence. The first correspondence indicates the attribute type corresponding to each application identifier in at least one application identifier. For example, the first correspondence indicates the correspondence between the application identifier and the first attribute type. The first correspondence may be stored in the network device, obtained through an application server, or obtained through other means, and this application is not limited thereto.
[0118] For example, as shown in FIG3 , the network device may obtain the first corresponding relationship through implementation method one or implementation method two.
[0119] Implementation method 1 includes the following process:
[0120] Step 301A: The network device sends a query request message or a subscription message to the application server. The query request message is used to request the correspondence between services and attribute types, and the subscription message is used to subscribe to the correspondence between services and attribute types.
[0121] Among them, a business corresponds to an application identifier, so the correspondence between the business and the attribute type can also be replaced by the correspondence between the application identifier and the attribute type.
[0122] The network device may send the query request message periodically or aperiodically, or upon receiving the first information from the terminal device, and this application does not limit this. The application server may also provide a standardized open interface, and the subscription message sent by the network device may include the standardized open interface, thereby obtaining the correspondence between the service and attribute type through the standardized open interface.
[0123] Optionally, the query request message or subscription message may include an application identifier, so that the application server can provide an attribute type corresponding to the application identifier.
[0124] Step 302A: The application server sends a query response message or a subscription notification message, where the query response message or the subscription notification message includes the first corresponding relationship.
[0125] The application server indicates the attribute type corresponding to each application identifier in at least one application identifier to the network device through the first corresponding relationship, so that the network device can determine the attribute type indicated by the first information according to the first corresponding relationship.
[0126] Implementation method 2 includes the following process:
[0127] Step 300: The application server sends a first correspondence relationship to a public network element.
[0128] A public network element can be a network element in a mobile communication network or a network element provided by a third party. A public network element can also be called a blockchain network element or a public warehouse network element.
[0129] Step 301B: The network device sends a query request message to the public network element. The query request message is used to request the correspondence between services and attribute types.
[0130] The network device may send the query request message periodically or non-periodically, or may send the query request message when receiving the first information from the terminal device. This application does not limit this.
[0131] Optionally, the query request message may include an application identifier, so that the application server can provide an attribute type corresponding to the application identifier.
[0132] Step 302B: The public network element sends a query response message, where the query response message includes the first corresponding relationship.
[0133] In the second implementation method, the public network element can obtain the correspondence between the application identifiers and attribute types of multiple application servers. The network equipment no longer needs to connect to multiple application servers. It only needs to obtain the correspondence between the application identifiers and attribute types of the services included in each application server from the public network element, reducing the complexity of the network equipment and improving efficiency.
[0134] In the process shown in FIG3 , the method executed by the network device may also be replaced by a network element such as an NEF network element, and this application does not limit this.
[0135] In this application, a management module is a module or unit used to manage and protect the digital identity and attributes of a terminal device. The network can manage the digital identity and attributes of a terminal device through the management module. The management module may also be referred to as a digital wallet, electronic wallet, or online wallet. The network can assign a dedicated management module to each terminal device. The management module can be understood as a module or unit used to manage and protect the digital identity and attributes of a terminal device. The management module can be implemented through software and / or hardware, and the information in the management module cannot be accessed by devices other than the terminal device.
[0136] In a first implementation manner, before sending the first information and the second information, the terminal device may first request the network device to allocate a management module to the terminal device.
[0137] For example, a terminal device sends first and second indication information to a network device; the second indication information indicates one or more attributes, and the first indication information instructs the network to manage the one or more attributes indicated by the second indication information. For example, an attribute may correspond to an attribute type, and the second indication information may be an attribute type identifier list including one or more attribute type identifiers. The network device may determine the one or more attributes to be managed based on the attribute type identifier list.
[0138] The network device may create a management module for the terminal device, which is used to manage one or more attributes of the terminal device. In this implementation, the management module is only used to manage the one or more attributes indicated by the second indication information. Unless instructed by the terminal device, the network device does not use the management module to manage other attributes of the terminal device. This ensures the information security of the terminal device and prevents privacy leaks.
[0139] The network device may also send the first identification and access credentials of the management module to the terminal device. The access credentials are used to determine whether the terminal device has permission to access the management module and can be understood as a key or password for accessing the management module.
[0140] In this implementation, the terminal device may also send the first identifier and access credentials of the management module when sending the first information and the second information. For example, the digital identity request message may also include the first identifier and access credentials. If the network device successfully verifies the access credentials, it obtains the first attribute corresponding to the first attribute type.
[0141] In a second implementation, the terminal device does not request the network device to allocate a management module to the terminal device before sending the first and second information. In this implementation, after the terminal device sends the first and second information, if the network device determines that the corresponding management module has not been allocated to the terminal device, it instructs the terminal device to first request the network device to allocate a management module. The terminal device may send the first and second indication information, and the network device may create a management module for the terminal device based on the first and second indication information. The specific process can be referred to above.
[0142] In this implementation, the network device may reject the first attribute corresponding to the first attribute type of the current request, and the terminal device may resend the first information and the second information, and send the first identifier and access credentials of the management module.
[0143] Or the network device does not reject the first attribute corresponding to the first attribute type of this request. After the network device creates a management module for the terminal device, it can obtain one or more attributes indicated by the second indication information and manage one or more attributes indicated by the second indication information in the management module.
[0144] Step 202: The network device obtains the digital identity of the terminal device that has undergone security protection.
[0145] In this application, the network device can determine that the attribute requested by the terminal device is the first attribute corresponding to the first attribute type based on the first information and the second information. The network device can obtain the first attribute in various ways, and several possible implementations are given below.
[0146] Implementation method one, the network device can receive the first identifier and access credentials of the management module; the management module is used to manage one or more attributes of the terminal device, and the one or more attributes include the first attribute; if the network device successfully verifies the access credentials, the first attribute corresponding to the first attribute type is obtained from the management module.
[0147] In a second implementation method, the network device requests the first attribute from a fourth network element based on the first information and the second information, and receives the first attribute from the fourth network element, where the fourth network element is the issuer of the first attribute. For example, based on the first information and the second information, the network device determines that the attribute requested by the terminal device is the first attribute corresponding to the first attribute type, and the network device sends an identifier of the first attribute type and an identifier of the terminal device to the fourth network element. Alternatively, the network device sends an application identifier and an identifier of the terminal device to the fourth network element, so that the fourth network element can return the first attribute corresponding to the first attribute type among the attributes of the terminal device.
[0148] Among them, after the network device determines that the attribute requested by the terminal device is the first attribute, it can directly obtain the first attribute through the fourth network element; the network device can also first search for the first attribute in the management module, and when it determines that the first attribute is not included in the management module, obtain the first attribute through the fourth network element. This application does not limit this.
[0149] If the first attribute corresponding to the first attribute type includes multiple attributes, for example, the first attribute includes attribute A and attribute B, the network device may obtain a part of the attributes corresponding to the first attribute type in the management module, for example, only obtain attribute A; for the other part of the attributes corresponding to the first attribute type, for example, attribute B, the network device may obtain them through the fourth network element, for example, obtain attribute B through the fourth network element.
[0150] After obtaining the first attribute, the network device can determine the digital identity of the terminal device based on the first attribute. The digital identity of the terminal device may include the first attribute and other information, such as the terminal device identifier, application identifier, validity period of the digital identity, and / or number of validity times of the digital identity.
[0151] The network device can securely protect the digital identity of the terminal device and obtain the securely protected digital identity of the terminal device. This application does not limit how the network device specifically secures the digital identity.
[0152] For example, in the first implementation method, the network device encrypts the digital identity of the terminal device, and the encrypted digital identity is the digital identity of the terminal device that has been securely protected.
[0153] In a second implementation, the network device performs a cryptographic operation on the terminal device's identifier and the first attribute to obtain a certificate, and uses the certificate as part of the terminal device's digital identity, including ensuring that the digital identity of the certificate is the securely protected digital identity of the terminal device. Cryptographic operations include, but are not limited to, calculating digital signatures, message authentication codes (MACs), and / or zero-knowledge proofs.
[0154] In a third implementation, the network device performs a cryptographic operation on the terminal device's identifier and first attribute to obtain a certificate, which it then uses as part of the terminal device's digital identity. The network device then encrypts the digital identity including the certificate. After encryption, the digital identity including the certificate becomes the securely protected digital identity of the terminal device.
[0155] The above are just examples. Network devices can also use other methods to protect the security of digital identities. I will not illustrate them one by one here.
[0156] Step 203: The network device sends the digital identity of the terminal device that has undergone security protection. The digital identity is used to access services of the application server.
[0157] Accordingly, the terminal device receives the digital identity of the terminal device that has been securely protected.
[0158] The terminal device may store the securely protected digital identity locally, for example, in a Subscriber Identity Module (SIM) card or a Software Development Kit (SDK) of the terminal device.
[0159] Step 204: The terminal device sends the securely protected digital identity to the application server.
[0160] In one implementation, the terminal device may send a securely protected digital identity via a service request message. The service request message may further include an application identifier, and the service request message applies the service corresponding to the application identifier.
[0161] In another implementation, the terminal device may first send a service request message to the application server. Upon receiving the digital identity query message from the application server, the terminal device sends a digital identity query response message including the securely protected digital identity to the application server. The details of this implementation are described in the flow shown in Figure 7 below and are not further elaborated here.
[0162] In this application, the application server can provide the terminal device with services corresponding to the application identifier. For example, the service can be an application service deployed by the operator, such as a voice call service; the service can also be an application service provided by a third party, such as an instant messaging service or an online video service.
[0163] The application server obtains the securely protected digital identity and can verify it. For example, if the securely protected digital identity of a terminal device is encrypted, the application server can use the corresponding key to decrypt the securely protected digital identity of the terminal device. If the decryption is successful, the terminal device's digital identity is confirmed to be valid.
[0164] For another example, if the digital identity of a securely protected terminal device includes a certificate, the application server can verify the legitimacy of the certificate. If the verification is successful, the digital identity of the terminal device is determined to be valid. This application does not specify how the application server verifies the legitimacy of the certificate and will not be further described here.
[0165] Furthermore, the first attribute in the digital identity can be used to verify whether the service of the application server can be accessed. For example, after the application server determines that the digital identity of the terminal device is valid, it can also determine whether the first attribute included in the digital identity meets the attribute requirements of the service corresponding to the application identifier. The attributes required for different services may be different, so when the terminal device requests a service, it needs to carry the attributes required for the service in the digital identity. The application server determines that the first attribute included in the digital identity meets the attribute requirements of the service corresponding to the application identifier, that is, based on the first attribute included in the digital identity, it determines that the terminal device can access the service corresponding to the service identifier in the application server. Conversely, if the application server determines that the first attribute included in the digital identity does not meet the attribute requirements of the service corresponding to the application identifier, then it determines that the terminal device cannot access the service corresponding to the service identifier in the application server.
[0166] Optionally, the digital identity also includes a validity period or a validity count. The application server may further determine whether the validity period of the digital identity is valid, or whether the validity count of the digital identity is greater than 0. If the validity period of the digital identity has expired, or the validity count of the digital identity is equal to 0, then even if the first attribute included in the digital identity meets the attribute requirements of the service corresponding to the application identifier, the terminal device cannot access the service in the application server.
[0167] Through the method provided in this application, the network side manages the attributes of the terminal device. When the terminal device needs to use a digital identity, it can request the network side to return a digital identity including corresponding attributes. This can reduce the complexity of the terminal device and reduce the overhead of the terminal device.
[0168] In the above process, the first network element (such as the SMF network element), the second network element (such as the UDM network element), and the third network element (such as the NEF network element) respectively perform part of the functions of the network device in the process of Figure 2. Specifically, Figure 4 is a flow chart of a communication method provided in an embodiment of the present application. In this process, the terminal device can first request a digital identity from the first network element. After the terminal device obtains the digital identity, it uses the digital identity to request services from the application server. In the following process, the first information is an application identifier and the second information is an identifier of the terminal device.
[0169] Step 401: The terminal device sends an application identifier and a terminal device identifier to a first network element.
[0170] For example, the terminal device may send a digital identity request message, where the digital identity request message is used to request the digital identity of the terminal device. The digital identity request message includes an application identifier and an identifier of the terminal device.
[0171] After obtaining the application identifier and the terminal device identifier, the first network element obtains the corresponding first attribute. Specifically, if the first network element does not store the first attribute corresponding to the first attribute type corresponding to the application identifier among the terminal device attributes, step 402 may be executed. If the first network element does store the first attribute, step 404 may be executed directly.
[0172] Optionally, step 402: the first network element sends the application identifier and the identifier of the terminal device to the second network element.
[0173] Optionally, step 403: the second network element sends the first attribute of the terminal device to the first network element.
[0174] There are multiple possible implementations for how the second network element can obtain the first attribute of the terminal device based on the application identifier and the terminal device identifier. For example, in implementation method one, if the first attribute is already stored in the second network element, the first attribute can be directly obtained. For example, if the first attribute includes attribute A and attribute B, and if the second network element stores attribute A and attribute B of the terminal device, attribute A and attribute B are directly sent to the first network element.
[0175] Implementation method 2: If the second network element can communicate directly with the fourth network element (i.e., the issuer of the first attribute), the second network element obtains the first attribute directly through the fourth network element. If the second network element cannot communicate directly with the fourth network element (i.e., the issuer of the first attribute), the second network element can request the first attribute from the fourth network element through the third network element.
[0176] For example, the first attribute includes attribute A and attribute B. The second network element determines that the issuer of attribute A and attribute B is the fourth network element, and then obtains attribute A and attribute B from the fourth network element.
[0177] Optionally, in another implementation, the second network element may also send third indication information to the first network element, where the third indication information is used to indicate the fourth network element, so that the first network element may obtain the first attribute from the fourth network element according to the third indication information.
[0178] The third indication information may be the address information or identifier of the fourth network element. This application does not limit how the second network element or the third network element determines the address information or identifier of the fourth network element. For example, the second network element or the third network element may determine the fourth network element based on a correspondence between the first attribute type and the address information or identifier of the fourth network element, where the correspondence is preset or preconfigured. Alternatively, the first attribute type may include the address information or identifier of the fourth network element, and the second network element or the third network element may determine the fourth network element based on the address information or identifier of the fourth network element in the first attribute type.
[0179] Step 404: The first network element obtains the digital identity of the terminal device and sends the digital identity of the terminal device that has undergone security protection to the terminal device.
[0180] The digital identity of the terminal device after security protection includes the terminal device's identification, the first attribute, and may also include information such as certification credentials. For details, please refer to the description of step 203, which will not be repeated here.
[0181] Step 405: The terminal device sends a service request message to the application server.
[0182] The service request message includes information such as the digital identity of the terminal device after security protection, the identifier of the terminal device, and the application identifier. The service request message applies the service corresponding to the application identifier.
[0183] The application server can verify the securely protected digital identity. If the application server determines that the digital identity of the terminal device is valid and, based on the first attribute of the digital identity, determines that the terminal device can access the application server's services, the application server can provide the terminal device with the services corresponding to the application identifier. The specific process is described in step 204 and is not repeated here.
[0184] Optionally, step 406: the application server sends a service request response message to the terminal device, where the service request response message may indicate that the service corresponding to the application identifier is agreed to be provided to the terminal device.
[0185] In this application, the network side can manage the attributes and digital identity of the terminal device through the management module. There may be multiple implementations of the network side creating a management module for managing the attributes of the terminal device under what circumstances.
[0186] In one implementation, before step 401 in the above process, the terminal device may request the network to create a management module for managing the terminal device's attributes. In this implementation, the terminal device may also send the management module's first identifier and access credentials. The first network element successfully verifies the access credentials and then obtains the first attribute corresponding to the first attribute type based on the application identifier and the terminal device identifier.
[0187] For example, as shown in FIG5 , the process of the terminal device requesting the network side to create a management module may include the following steps:
[0188] Step 501: The terminal device sends a first request message to the second network element.
[0189] The first request message may be a message sent by the terminal device during the user's contract signing process, or may be a message sent at any time after the terminal device accesses the network. The first request message may include the terminal device identifier, first indication information, and second indication information. The second indication information indicates one or more attributes, and the first indication information indicates that the network side manages the one or more attributes indicated by the second indication information.
[0190] Optionally, the second network element may first determine that a management module can be created for the terminal device, and then create the management module for the terminal device. For example, based on the terminal device's subscription information, it may be determined that the terminal device's attributes support network-side management. It should be understood that the subscription information may be stored in the second network element or obtained by the second network element from another network element.
[0191] In this application, the second network element can create a management module for the terminal device itself, or can instruct the first network element to create a management module for the terminal device. The following description takes instructing the first network element to create a management module for the terminal device as an example.
[0192] Step 502: The second network element sends a second request message to the first network element. The second request message may be used to instruct the creation of a management module.
[0193] The second request message includes the terminal device identifier and the second indication information. The second request message including the second indication information is described herein as an example. The second request message may also generate new indication information based on the second indication information, such as fourth indication information, where the fourth indication information has the same function as the second indication information.
[0194] Step 503: The first network element creates a management module for the terminal device and sends a second response message to the second network element.
[0195] The second response message includes information such as the identifier of the terminal device, the first identifier of the management module, and the access credential.
[0196] Step 504: The second network element sends a first response message to the terminal device.
[0197] The first response message includes information such as the first identification and access credentials of the management module.
[0198] In another implementation, the terminal device does not request the network to allocate a management module to the terminal device before sending the application identifier and the terminal device identifier. In this implementation, after the terminal device sends the application identifier and the terminal device identifier, that is, after step 401, the first network element instructs the terminal device to trigger the creation of the management module. The first network element may send a message to the terminal device to trigger the creation of the management module, and the specific name of the message is not limited. The specific process for the terminal device to trigger the creation of the management module can be referred to the process shown in Figure 6.
[0199] Step 601: The terminal device sends a management module request message to the first network element.
[0200] The management module request message, which may also be referred to by other names, such as an access message or a registration message, is used to request the network to create a management module for managing the attributes of the terminal device. The management module request message may include an identifier of the terminal device, first indication information, and second indication information.
[0201] There are two scenarios for creating a management module: In scenario 1, the first network element can directly create a management module for the terminal device; in scenario 2, the first network element can determine through the second network element whether it can create a management module for the terminal device and then create a management module for the terminal device. In scenario 2, the second network element can determine whether network-side management of terminal device attributes is supported based on the terminal device's contract information.
[0202] The following describes the second case as an example.
[0203] Step 602: The first network element sends a third request message to the second network element.
[0204] The third request message includes the identifier of the terminal device, the first indication information, and the second indication information. The third request message may request to determine whether a management module can be created for the terminal device.
[0205] The second network element determines that the subscription information of the terminal device supports the attribute of network-side management of the terminal device, then determines that a management module can be created for the terminal device, and instructs the first network element to create the management module for the terminal device. The subscription information can be stored in the second network element or obtained by the second network element from another network element.
[0206] The second network element may directly create a management module for the terminal device, or may instruct the first network element to create a management module for the terminal device. The following description takes instructing the first network element to create a management module for the terminal device as an example.
[0207] Step 603: The second network element sends a second request message to the first network element. The second request message can be used to instruct the first network element to create a management module.
[0208] The second request message includes an identifier of the terminal device and second indication information, and the second request message indicates creation of a management module for the terminal device.
[0209] Step 604: The first network element creates a management module for the terminal device and sends a management module response message to the terminal device.
[0210] The management module response message includes information such as the identifier of the terminal device, the first identifier of the management module, and the access credential.
[0211] After the above process, the network side creates a management module for the terminal device and implements the management attributes of the terminal device.
[0212] In the process of Figure 4, the terminal device first requests a digital identity from the network side, and then carries the digital identity to request services from the application server. In this application, the terminal device can also first request services from the application server, and then report the digital identity according to the instructions of the application server. For details, please refer to the process shown below.
[0213] As shown in Figure 7, a flow chart of a communication method provided in an embodiment of the present application is provided. In this flow, a first network element (e.g., an SMF network element), a second network element (e.g., a UDM network element), and a third network element (e.g., an NEF network element) respectively perform some of the functions of the network device in the flow of Figure 2. In this flow, the first information is described as a first attribute type and the second information is an identifier of a terminal device.
[0214] Step 701: The terminal device sends a service request message to the application server.
[0215] The service request message includes information such as the terminal device identifier and the application identifier.
[0216] Step 702: The application server sends a digital identity query message to the terminal device. The digital identity query message is used to instruct to report the digital identity of the terminal device.
[0217] The application server may carry the first attribute type corresponding to the application identifier in the digital identity query message.
[0218] Step 703: The terminal device sends the first attribute type and the identifier of the terminal device to the first network element.
[0219] For example, the terminal device may send a digital identity request message, where the digital identity request message is used to request the digital identity of the terminal device. The digital identity request message includes the first attribute type and an identifier of the terminal device.
[0220] Optionally, if the first network element determines that the first attribute corresponding to the first attribute type is not included, step 704 may be executed. If the first network element determines that the first attribute corresponding to the first attribute type is included, step 706A may be directly executed.
[0221] Optionally, step 704: the first network element sends the first attribute type and the identifier of the terminal device to the second network element.
[0222] Optionally, step 705: the second network element sends the first attribute of the terminal device to the first network element.
[0223] There may be multiple implementations of how the second network element obtains the first attribute of the terminal device according to the first attribute type and the identifier of the terminal device. For details, please refer to the description of step 403, which will not be repeated here.
[0224] Step 706A: The first network element obtains the digital identity of the terminal device and sends the securely protected digital identity of the terminal device to the terminal device.
[0225] The digital identity of the securely protected terminal device includes the terminal device's identification, the first attribute, and may also include information such as certification credentials. For details, please refer to the description of step 203, which will not be repeated here.
[0226] Step 707A: The terminal device sends the securely protected digital identity of the terminal device to the application server.
[0227] In the above process, step 706A and step 707A can also be replaced by step 706B and step 707B:
[0228] Step 706B: The first network element sends the first attribute of the terminal device to the terminal device.
[0229] Step 707B: The terminal device obtains the digital identity of the terminal device and sends the securely protected digital identity of the terminal device to the application server.
[0230] Optionally, the digital identity determined by the terminal device may include a first attribute and a second attribute, and the second attribute is an attribute in the terminal device.
[0231] The application server can verify the securely protected digital identity. If the application server determines that the digital identity of the terminal device is valid and, based on the first attribute of the digital identity, determines that the terminal device can access the application server's services, the application server can provide the terminal device with the services corresponding to the application identifier. The specific process is described in step 204 and is not repeated here.
[0232] Optionally, step 708: the application server sends a service request response message to the terminal device. The service request response message may indicate that the application server agrees to provide the terminal device with the service corresponding to the application identifier.
[0233] In the previous process, the terminal device requests a digital identity including the terminal device's attributes from the network side, and then sends the securely protected digital identity of the terminal device to the application server. In this application, the network side can also directly send the securely protected digital identity of the terminal device to the application server, which will be described in detail below.
[0234] As shown in FIG8 , it is a flow chart of a communication method provided in an embodiment of the present application.
[0235] Step 801: The terminal device sends third information and second information.
[0236] Correspondingly, the application server receives the third information and the second information.
[0237] The third information is used to indicate the service requested by the terminal device, for example, the third information is an application identifier corresponding to the service requested by the terminal device.
[0238] In the present application, the second information is used to indicate the terminal device, for example, the second information is the identification of the terminal device.
[0239] This application does not limit how the terminal device sends the third information and the second information. For example, the terminal device may send the third information and the second information via a service request message.
[0240] Step 802: The application server sends the first information and the second information to the network device.
[0241] Correspondingly, the network device receives the first information and the second information.
[0242] The first information is determined based on the third information. In one implementation, the first information is the third information, that is, the first information is the application identifier.
[0243] In another implementation, the first information is a first attribute type corresponding to the application identifier, and the correspondence between the application identifier and the first attribute type is preset or may be determined by the application server.
[0244] Step 803: The network device obtains the digital identity of the terminal device that has undergone security protection.
[0245] The network device can determine the first attribute of the terminal device according to the first information and the second information, and determine the digital identity of the terminal device according to the first attribute. The specific content of step 803 can be referred to the description of step 203 and will not be repeated here.
[0246] Step 804: The network device sends the securely protected digital identity of the terminal device to the application server. The digital identity is used to access services of the application server.
[0247] Correspondingly, the application server receives the digital identity of the terminal device after security protection.
[0248] The application server can verify the securely protected digital identity. If the application server determines that the digital identity of the terminal device is valid and, based on the first attribute of the digital identity, determines that the terminal device can access the application server's services, the application server can provide the terminal device with the services corresponding to the application identifier. The specific process is described in step 204 and is not repeated here.
[0249] The specific content of step 804 can be referred to the description in step 204 and will not be repeated here.
[0250] In the above process, when a terminal device requests a service from the application server, the application server obtains the terminal device's digital identity through the network device. Based on the terminal device's digital identity, the application server determines whether the terminal device can access the service on the application server. Throughout this process, the terminal device does not need to participate in the digital identity acquisition process, which reduces complexity and overhead for the terminal device.
[0251] The first network element (e.g., an SMF network element), the second network element (e.g., an UDM network element), and the third network element (e.g., an NEF network element) respectively perform part of the functions of the network device in the process of Figure 8. Specifically, Figure 9 is a flow chart of a communication method provided in an embodiment of the present application. In this process, the first information is a first attribute type, the second information is an identifier of the terminal device, and the third information is an application identifier.
[0252] Step 901: The terminal device sends a service request message to the application server. The service request message includes an application identifier and an identifier of the terminal device.
[0253] The service request message is used to request the service corresponding to the application identifier.
[0254] Step 902: The application server sends a digital identity query message to the first network element. The digital identity query message is used to indicate the digital identity of the terminal device to be reported.
[0255] The digital identity query message includes the first attribute type corresponding to the application identifier and the identifier of the terminal device.
[0256] If the first network element determines that the first attribute corresponding to the first attribute type is not included, step 903 may be executed. If the first network element determines that the first attribute corresponding to the first attribute type is included, step 905 may be executed directly.
[0257] Optionally, step 903: the first network element sends an attribute query request message to the second network element, where the attribute query request message includes the first attribute type and an identifier of the terminal device.
[0258] The attribute query request message may be used to request a first attribute corresponding to a first attribute type among the attributes of the terminal device.
[0259] Optionally, step 904: the second network element sends the first attribute of the terminal device to the first network element.
[0260] There may be multiple implementations of how the second network element obtains the first attribute of the terminal device according to the first attribute type and the identifier of the terminal device. For details, please refer to the description of step 403, which will not be repeated here.
[0261] Step 905: The first network element determines the digital identity of the terminal device according to the first attribute, and sends the digital identity of the terminal device after security protection to the application server.
[0262] The digital identity of the terminal device after security protection includes the terminal device's identification, the first attribute, and may also include information such as certification credentials. For details, please refer to the description of step 203, which will not be repeated here.
[0263] The application server can verify the securely protected digital identity. If the application server determines that the digital identity of the terminal device is valid and, based on the first attribute of the digital identity, determines that the terminal device can access the application server's services, the application server can provide the terminal device with the services corresponding to the application identifier. The specific process is described in step 204 and is not repeated here.
[0264] Optionally, step 906: the application server sends a service request response message to the terminal device. The service request response message may indicate that the application server agrees to provide the terminal device with the service corresponding to the application identifier.
[0265] It is understandable that, in order to implement the functions in the above embodiments, the first network element or terminal device or the second network element or application server includes hardware structures and / or software modules corresponding to executing each function. Those skilled in the art should readily appreciate that, in combination with the units and method steps of each example described in the embodiments disclosed in this application, this application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in hardware or in a manner driven by computer software depends on the specific application scenario and design constraints of the technical solution.
[0266] The following is a schematic diagram of the structure of possible communication devices provided in the embodiments of the present application. These communication devices can be used to implement the functions of the first network element or terminal device or the second network element or application server in the above method embodiments, thereby also achieving the beneficial effects of the above method embodiments.
[0267] As shown in Figure 10, the communication device 1000 includes a processing unit 1010 and a communication unit 1020. The communication device 1000 is used to implement the functions of the first network element or terminal device or the second network element or application server in the above-mentioned method embodiments.
[0268] When the communication device 1000 is used to implement the function of the first network element:
[0269] A communication unit, configured to receive first information and second information, wherein the first information is used to determine a first attribute type, and the second information is used to indicate a terminal device;
[0270] a processing unit, configured to obtain a digital identity of the terminal device after security protection, wherein the digital identity includes a first attribute corresponding to the first attribute type;
[0271] A communication unit is used to send the securely protected digital identity.
[0272] When the communication device 1000 is used to implement the functions of a terminal device:
[0273] A processing unit, configured to send first information and second information through a communication unit, wherein the first information is used to determine a first attribute type, and the second information is used to indicate a terminal device;
[0274] a processing unit, configured to receive, through a communication unit, a digital identity of the terminal device that has undergone security protection, wherein the digital identity includes a first attribute corresponding to the first attribute type;
[0275] The processing unit is configured to send the securely protected digital identity to the application server via the communication unit, wherein the first attribute is used to verify whether the service of the application server can be accessed.
[0276] When the communication device 1000 is used to implement the function of the second network element:
[0277] a processing unit, configured to receive first information and second information from a first network element through a communication unit, wherein the first information is used to determine a first attribute type, and the second information is used to indicate a terminal device;
[0278] A processing unit, used to send the first attribute corresponding to the first attribute type among the attributes of the terminal device to the first network element through the communication unit; or, to send third indication information to the first network element, wherein the third indication information is used to indicate a fourth network element, and the fourth network element is the issuer of the first attribute.
[0279] A more detailed description of the processing unit 1010 and the communication unit 1020 can be directly obtained by referring to the relevant descriptions in the above-mentioned method embodiments, and will not be repeated here.
[0280] It should be understood that the division of units in the above device is merely a division of logical functions. In actual implementation, they can be fully or partially integrated into one physical entity, or physically separated. Moreover, the units in the device can all be implemented in the form of software called through processing elements; or all be implemented in the form of hardware; or some units can be implemented in the form of software called through processing elements, and some units can be implemented in the form of hardware. For example, each unit can be a separately established processing element, or it can be integrated into a certain chip of the device. In addition, it can also be stored in the form of a program in a memory, called by a certain processing element of the device and execute the function of the unit. In addition, all or part of these units can be integrated together, or they can be implemented independently. The processing element here can also be a processor, which can be an integrated circuit with signal processing capabilities. In the implementation process, each operation of the above method or each unit above can be implemented by the integrated logic circuit of the hardware in the processor element or by software called through the processing element.
[0281] In one example, the unit in any of the above devices may be one or more integrated circuits configured to implement the above method, such as one or more application specific integrated circuits (ASICs), one or more digital singnal processors (DSPs), one or more field programmable gate arrays (FPGAs), or a combination of at least two of these integrated circuit forms. For another example, when the unit in the device can be implemented in the form of a processing element scheduler, the processing element can be a processor, such as a general-purpose central processing unit (CPU), or other processor that can call a program. For another example, these units can be integrated together and implemented in the form of a system-on-a-chip (SOC).
[0282] The above-mentioned receiving unit is an interface circuit of the device, which is used to receive signals from other devices. For example, when the device is implemented as a chip, the receiving unit is the interface circuit of the chip used to receive signals from other chips or devices. The above-mentioned sending unit is an interface circuit of the device, which is used to send signals to other devices. For example, when the device is implemented as a chip, the sending unit is the interface circuit of the chip used to send signals to other chips or devices.
[0283] As another possible product form, the first network element or terminal device or the second network element or application server of the embodiment of the present application can be implemented by a general bus architecture. For ease of explanation, refer to Figure 11, which is a structural diagram of a communication device 1100 provided in an embodiment of the present application, and the communication device 1100 includes a processor 1101 and a transceiver 1102. The communication device 1100 can be a terminal device, or a chip or chip system therein; or, the communication device 1100 can be a network device, or a chip or module therein. Figure 11 only shows the main components of the communication device 1100. In addition to the processor 1101 and the transceiver 1102, the communication device 1100 can further include a memory 1103, and an input and output device (not shown in the figure).
[0284] Optionally, the processor 1101 is primarily used to process communication protocols and communication data, as well as control the entire communication device, execute software programs, and process software program data. The memory 1103 is primarily used to store software programs and data. The transceiver 1102 may include a radio frequency circuit and an antenna. The radio frequency circuit is primarily used to convert baseband signals into radio frequency signals and process radio frequency signals. The antenna is primarily used to transmit and receive radio frequency signals in the form of electromagnetic waves. Input and output devices, such as a touch screen, display, and keyboard, are primarily used to receive user input and output data to the user.
[0285] Optionally, the processor 1101 , the transceiver 1102 , and the memory 1103 may be connected via a communication bus.
[0286] When the communication device is powered on, the processor 1101 can read the software program in the memory 1103, interpret and execute the instructions of the software program, and process the data of the software program. When data needs to be sent wirelessly, the processor 1101 performs baseband processing on the data to be sent and outputs the baseband signal to the radio frequency circuit. The radio frequency circuit performs radio frequency processing on the baseband signal and then transmits the radio frequency signal to the outside in the form of electromagnetic waves through the antenna. When data is sent to the communication device, the radio frequency circuit receives the radio frequency signal through the antenna, converts the radio frequency signal into a baseband signal, and outputs the baseband signal to the processor 1101. The processor 1101 converts the baseband signal into data and processes the data.
[0287] In another implementation, the RF circuit and antenna can be set independently of the processor performing baseband processing. For example, in a distributed scenario, the RF circuit and antenna can be arranged remotely from the communication device.
[0288] In some embodiments, in terms of hardware implementation, those skilled in the art may conceive that the above-mentioned communication device 1000 may take the form of the communication device 1100 shown in FIG. 11 .
[0289] As an example, the functions / implementation process of the processing unit 1010 in FIG10 may be implemented by the processor 1101 in the communication device 1100 shown in FIG11 calling computer-executable instructions stored in the memory 1103. The functions / implementation process of the communication unit 1020 in FIG10 may be implemented by the transceiver 1102 in the communication device 1100 shown in FIG11.
[0290] As another possible product form, the first network element or terminal device or the second network element or application server in this application may adopt the structure shown in Figure 12, or include the components shown in Figure 12. Figure 12 is a schematic diagram of the structure of a communication device 1200 provided in this application.
[0291] As shown in FIG12 , the communication device 1200 includes at least one processor 1201. Optionally, the communication device further includes a communication interface 1202.
[0292] When the program instructions are executed in the at least one processor 1201, the apparatus 1200 may implement the method provided in any of the aforementioned embodiments and any possible designs thereof. Alternatively, the processor 1201 may implement the method provided in any of the aforementioned embodiments and any possible designs thereof through logic circuits or by executing code instructions.
[0293] The communication interface 1202 can be used to receive program instructions and transmit them to the processor. Alternatively, the communication interface 1202 can be used for the communication device 1200 to communicate with other communication devices, such as exchanging control signaling and / or service data. Exemplarily, the communication interface 1202 can be used to receive signals from devices other than the communication device 1200 and transmit them to the processor 1201, or to send signals from the processor 1201 to other communication devices other than the communication device 1200.
[0294] Optionally, the communication interface 1202 may be a code and / or data read and write interface circuit, or the communication interface 1202 may be a signal transmission interface circuit between a communication processor and a transceiver, or a pin of a chip.
[0295] Optionally, the communication device 1200 may further include at least one memory 1203, which may be used to store required program instructions and / or data. It should be noted that the memory 1203 may exist independently of the processor 1201 or may be integrated with the processor 1201. The memory 1203 may be located within or outside the communication device 1200, without limitation.
[0296] Optionally, the communication device 1200 may further include a power supply circuit 1204, which may be used to supply power to the processor 1201. The power supply circuit 1204 may be located in the same chip as the processor 1201, or in another chip other than the chip where the processor 1201 is located.
[0297] Optionally, the communication device 1200 may further include a bus, and various parts of the communication device 1200 may be interconnected via the bus.
[0298] In some embodiments, in terms of hardware implementation, those skilled in the art may conceive that the communication device 1000 shown in FIG. 10 may take the form of the communication device 1200 shown in FIG. 12 .
[0299] As an example, the functions / implementation process of the processing unit 1010 in FIG10 may be implemented by the processor 1201 in the communication device 1200 shown in FIG12 calling computer-executable instructions stored in the memory 1203. The functions / implementation process of the communication unit 1020 in FIG10 may be implemented by the communication interface 1202 in the communication device 1200 shown in FIG12.
[0300] It should be noted that the structure shown in FIG12 does not constitute a specific limitation on the terminal device or network device. For example, in other embodiments of the present application, the terminal device or network device may include more or fewer components than shown in the figure, or combine or split some components, or arrange the components differently. The components shown in the figure may be implemented in hardware, software, or a combination of software and hardware.
[0301] When the communication device is a chip used in a terminal, the terminal chip implements the functions of the terminal in the above method embodiments. The terminal chip receives information from other modules in the terminal (such as a radio frequency module or antenna), and the information is sent by the base station to the terminal; or the terminal chip sends information to other modules in the terminal (such as a radio frequency module or antenna), and the information is sent by the terminal to the base station.
[0302] When the above-mentioned communication device is a module applied to a base station, the base station module implements the functions of the base station in the above-mentioned method embodiment. The base station module receives information from other modules in the base station (such as a radio frequency module or an antenna), and the information is sent by the terminal to the base station; or the base station module sends information to other modules in the base station (such as a radio frequency module or an antenna), and the information is sent by the base station to the terminal. The base station module here can be the baseband chip of the base station, or it can be a DU or other module. The DU here can be a DU under the open radio access network (O-RAN) architecture.
[0303] It is understood that the processor in the embodiments of the present application may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.
[0304] The method steps in the embodiments of the present application can be implemented by hardware or by a processor executing software instructions. The software instructions can be composed of corresponding software modules, and the software modules can be stored in a random access memory, a flash memory, a read-only memory, a programmable read-only memory, an erasable programmable read-only memory, an electrically erasable programmable read-only memory, a register, a hard disk, a mobile hard disk, a CD-ROM or any other form of storage medium well known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be an integral part of the processor. The processor and the storage medium can be located in an ASIC. In addition, the ASIC can be located in a base station or a terminal. Of course, the processor and the storage medium can also exist in a base station or a terminal as discrete components.
[0305] In the above embodiments, all or part of the embodiments may be implemented using software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments may be implemented in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are performed in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, or other programmable device. The computer program or instructions may be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program or instructions may be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium, such as a floppy disk, hard disk, or magnetic tape; an optical medium, such as a digital video disk; or a semiconductor medium, such as a solid-state drive. The computer-readable storage medium may be a volatile or nonvolatile storage medium, or may include both volatile and nonvolatile types of storage media.
[0306] In the various embodiments of the present application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.
[0307] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, optical storage, etc.) that contain computer-usable program code.
[0308] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the present application. It should be understood that each flow and / or box in the flow chart and / or block diagram, as well as the combination of the flow chart and / or box in the flow chart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device for implementing the functions specified in one or more flow charts and / or one or more boxes in the block diagram.
[0309] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0310] Obviously, those skilled in the art may make various changes and modifications to the present application without departing from the scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is intended to include these modifications and variations.
Claims
1. A communication method, characterized in that: include: receiving first information and second information, wherein the first information is used to determine a first attribute type, and the second information is used to indicate a terminal device; Obtaining a securely protected digital identity of the terminal device, where the digital identity includes a first attribute corresponding to the first attribute type; The securely protected digital identity is sent.
2. The method according to claim 1, characterized in that The first information is an application identifier, and the application identifier corresponds to the first attribute type; Alternatively, the first information is an identifier of the first attribute type.
3. The method according to claim 1 or 2, characterized in that The method further comprises: receiving a first identifier and an access credential; wherein a management module corresponding to the first identifier is used to manage one or more attributes of the terminal device, the one or more attributes including the first attribute; If the access credential is successfully verified, the first attribute is obtained from the management module corresponding to the first identifier.
4. The method according to claim 3, characterized in that The method further comprises: Receiving first indication information and second indication information from a terminal device; the second indication information indicates the one or more attributes, the first indication information instructs the network side to manage the one or more attributes indicated by the second indication information, the one or more attributes including the first attribute; The management module is created, where the management module is used to manage the one or more attributes.
5. The method according to claim 4, characterized in that The method further comprises: Send the first identifier and the access credential to the terminal device.
6. The method according to claim 1 or 2, characterized in that The method further comprises: The first attribute is acquired from a second network element according to the first information and the second information.
7. The method according to claim 1 or 2, characterized in that The method further comprises: sending the first information and the second information to a second network element; receiving third indication information from the second network element, where the third indication information is used to indicate a fourth network element, where the fourth network element is the issuer of the first attribute; Acquire the first attribute from the fourth network element according to the third indication information.
8. A communication method, characterized in that: include: Sending first information and second information, where the first information is used to determine the first attribute type, and the second information is used to indicate the terminal device; receiving a securely protected digital identity of the terminal device, the digital identity including a first attribute corresponding to the first attribute type; The securely protected digital identity is sent to an application server, where the first attribute is used to access services of the application server.
9. The method according to claim 8, characterized in that The first information is an application identifier, and the application identifier corresponds to the first attribute type; Alternatively, the first information is an identifier of the first attribute type.
10. The method according to claim 8 or 9, characterized in that The method further comprises: Sending a service request message to the application server, wherein the service request message requests the service; A digital identity query message is received from the application server, where the digital identity query message is used to instruct reporting of the digital identity; the digital identity query message includes the first information.
11. The method according to any one of claims 8 to 10, characterized in that: The method further comprises: Sending first indication information and second indication information; the second indication information indicates one or more attributes, the first indication information instructs the network side to manage the one or more attributes indicated by the second indication information, and the one or more attributes include the first attribute.
12. The method according to claim 11, characterized in that The method further comprises: A first identifier and an access credential are received; and a management module corresponding to the first identifier is used to manage the one or more attributes.
13. The method according to claim 12, characterized in that Before receiving the securely protected digital identity of the terminal device, the method further includes: The first identifier and the access credential are sent.
14. A communication method, characterized in that: include: receiving first information and second information from a first network element, wherein the first information is used to determine a first attribute type, and the second information is used to indicate a terminal device; Sending a first attribute corresponding to the first attribute type among the attributes of the terminal device to the first network element; Alternatively, third indication information is sent to the first network element, where the third indication information is used to indicate a fourth network element, and the fourth network element is the issuer of the first attribute.
15. The method according to claim 14, characterized in that The method further comprises: A first correspondence is received from an application server, where the first correspondence indicates a correspondence between an application identifier and a first attribute type.
16. The method according to claim 15, characterized in that The first information is an application identifier; the method further includes: The first attribute type is determined according to the application identifier and the first corresponding relationship.
17. The method according to claim 14, characterized in that The first information is an identifier of the first attribute type.
18. A communication method, characterized in that: include: Receiving a securely protected digital identity of a terminal device from a terminal device, wherein the digital identity includes a first attribute; Verify whether the terminal device can access the service based on the first attribute.
19. The method according to claim 18, characterized in that The digital identity of the terminal device that has undergone security protection is located in a service request message, and the service requested by the service request message is associated with the first attribute.
20. The method according to claim 18 or 19, characterized in that Before receiving the securely protected digital identity of the terminal device, the method further includes: Receive a service request message from the terminal device, where the service requested by the service request message is associated with the first attribute; send a digital identity query message to the terminal device, where the digital identity query message is used to indicate reporting of the digital identity; the digital identity query message includes first information, where the first information is used to determine a first attribute type, where the first attribute type corresponds to the first attribute.
21. The method according to any one of claims 18 to 20, characterized in that Before receiving the securely protected digital identity of the terminal device from the terminal device, the method further includes: A first correspondence is sent to the second network element, where the first correspondence indicates a correspondence between the application identifier and the first attribute type.
22. A communication method, characterized in that: include: receiving first information and second information, wherein the first information is used to determine a first attribute type, and the second information is used to indicate a terminal device; Determine, according to the first information and the second information, a first attribute among the attributes of the terminal device corresponding to the first attribute type; The first attribute is sent.
23. The method according to claim 22, characterized in that The first information is an application identifier, and the application identifier corresponds to the first attribute type; or the first information is an identifier of the first attribute type.
24. The method according to claim 22 or 23, characterized in that Before determining, according to the first information and the second information, a first attribute corresponding to the first attribute type among the attributes of the terminal device, the method further includes: receiving a first identifier and an access credential; wherein a management module corresponding to the first identifier is used to manage one or more attributes of the terminal device, the one or more attributes including the first attribute; If the access credential is successfully verified, the first attribute is obtained from the management module corresponding to the first identifier.
25. The method according to any one of claims 22 to 24, characterized in that Before receiving the first information and the second information, the method further includes: receiving first indication information and second indication information from the terminal device, wherein the second indication information indicates one or more attributes, and the first indication information instructs the network side to manage the one or more attributes indicated by the second indication information, wherein the one or more attributes include the first attribute; The management module is created, where the management module is used to manage the one or more attributes.
26. The method according to claim 25, characterized in that After creating the management module, the method further includes: Send the first identifier and the access credential to the terminal device.
27. The method according to any one of claims 22 to 26, characterized in that After receiving the first information and the second information, the method further includes: The first attribute is acquired from a second network element according to the first information and the second information.
28. The method according to any one of claims 22 to 27, characterized in that After receiving the first information and the second information, the method further includes: sending the first information and the second information to a second network element; receiving third indication information from the second network element, where the third indication information is used to indicate a fourth network element, where the fourth network element is the issuer of the first attribute; Acquire the first attribute from the fourth network element according to the third indication information.
29. A communication method, characterized in that: include: receiving a first attribute, where the first attribute is an attribute of a terminal device corresponding to the first attribute type; Obtaining a digital identity of the terminal device, where the digital identity includes the first attribute; The securely protected digital identity is sent to an application server, where the first attribute is used to access services of the application server.
30. The method according to claim 29, wherein The first information is an application identifier, and the application identifier corresponds to the first attribute type; or the first information is an identifier of the first attribute type.
31. A communication device, characterized in that: Comprising a module for performing the method of any one of claims 1 to 7, or a module for performing the method of any one of claims 8 to 13, or a module for performing the method of any one of claims 14 to 17, or a module for performing the method of any one of claims 18 to 21, or a module for performing the method of any one of claims 22 to 28, or a module for performing the method of any one of claims 29 to 30.
32. A communication device, characterized in that: The method comprises a processor and an interface circuit, wherein the interface circuit is used to receive signals from other communication devices outside the communication device and transmit them to the processor or send signals from the processor to other communication devices outside the communication device, and the processor implements the method according to any one of claims 1 to 7, or the method according to any one of claims 8 to 13, or the method according to any one of claims 14 to 17, or the method according to any one of claims 18 to 21, or the method according to any one of claims 22 to 28, or the method according to any one of claims 29 to 30 through a logic circuit or executing code instructions.
33. A computer-readable storage medium, characterized in that The storage medium stores a computer program or instructions. When the computer program or instructions are executed by the communication device, the method according to any one of claims 1 to 7, or the method according to any one of claims 8 to 13, or the method according to any one of claims 14 to 17, or the method according to any one of claims 18 to 21, or the method according to any one of claims 22 to 28, or the method according to any one of claims 29 to 30 is implemented.
34. A computer program product, characterized in that When the computer program product is executed by a computer, the computer executes the method according to any one of claims 1 to 7, or the method according to any one of claims 8 to 13, or the method according to any one of claims 14 to 17, or the method according to any one of claims 18 to 21, or the method according to any one of claims 22 to 28, or the method according to any one of claims 29 to 30.
35. A communication system, characterized in that: Includes one or more of the following devices: A first network element, a terminal device, and a second network element; The first network element is used to execute the method according to any one of claims 1 to 7, the terminal device is used to execute the method according to any one of claims 8 to 13, and the second network element is used to execute the method according to any one of claims 14 to 17.
36. A communication system, characterized in that: Includes one or more of the following devices: application server, first network element and terminal device; The application server is used to execute the method described in any one of claims 18 to 21, the first network element is used to execute the method described in any one of claims 22 to 28, and the terminal device is used to execute the method described in any one of claims 29 to 30.
Citation Information
Patent Citations
Authentication method, system, terminal and digital identity authentication function entity
CN114007218A
User identity management for accessing services
US20080307500A1
Cyberspace Identification Trust Authority (CITA) System and Method
US20130226813A1
Identity Vault Service
US20200351266A1
Authentication using a digital identifier for UE access
US20240022908A1