Service processing method and apparatus

By generating different first user identifiers for users and combining digital signatures and validity management, privacy leakage problems when signing user numbers or accessing third-party services are solved, and the security and management efficiency of business access are improved.

WO2025180174A1PCT designated stage Publication Date: 2025-09-04HUAWEI TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/075276
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-27
Filing Date
2025-01-26
Publication Date
2025-09-04

AI Technical Summary

Technical Problem

When users use user numbers as user accounts to sign contracts or access third-party services, it is easy to lead to leakage of privacy information, and the existing technology cannot effectively protect user privacy.

Method used

By generating different first user identifiers for users, used to sign contracts or access different services, avoiding direct exposure of user numbers, combining digital signatures and validity management, ensuring the legality and security of the identifier.

Benefits of technology

It realizes the protection of user privacy when signing contracts or accessing services, prevents illegal access and privacy leakage, and improves the security of business access and the management efficiency of user identification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025075276_04092025_PF_FP_ABST
    Figure CN2025075276_04092025_PF_FP_ABST
Patent Text Reader

Abstract

A service processing method and apparatus, which relate to the technical field of communications. The method comprises: receiving a first request, wherein the first request comprises a service identifier, and the service identifier is used for identifying a service that a user requests for subscription; and determining a first user identifier, wherein the first user identifier is used for identifying the user, the first user identifier is different from another first user identifier created for another service that the user requests for subscription, each first user identifier is used for making a request to subscribe to a service, and the first user identifier is further used for making a request to access the service. In the method, a network generates different first user identifiers for different services that a user requests for subscription, and the user uses the different first user identifiers to subscribe to or access different services, thereby avoiding privacy leakage of the user.
Need to check novelty before this filing date? Find Prior Art

Description

Business processing method and device

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims priority to the Chinese patent application filed with the China Patent Office on February 27, 2024, with application number 202410221822.6 and application name “Business Processing Method and Device”, the entire contents of which are incorporated by reference into this application. Technical Field

[0003] The present application relates to the field of communication technology, and in particular to a service processing method and device. Background Art

[0004] In order to access the services provided by a third-party service provider SP (Service Provider), users need to sign a service agreement with the third-party service provider. Currently, third-party service providers mostly use user numbers (for example, user mobile phone numbers) as user accounts to sign service agreements with users. When a user uses a user number as a user account to sign a contract or access a third-party service, it is easy for the application server to obtain the third-party service contract or access record information corresponding to the user number. For example, when a user uses the same user number as a user account to sign a contract or access multiple different third-party services, the user's contract or access record is easily obtained and leaked by the third-party service provider. Therefore, there is a problem of user privacy information leakage when using a user number as a user account to sign a contract or access a third-party service. Summary of the Invention

[0005] The embodiments of the present application provide a service processing method, device, and system.

[0006] In a first aspect, a method is provided, comprising the following steps: receiving a first request, the first request including a service identifier, the service identifier being used to identify the service for which the user requests to sign up; determining a first user identifier, the first user identifier being used to identify the user, the first user identifier being different from another first user identifier created for another service for which the user requests to sign up, the first user identifier being used to request to sign up for the service, and the first user identifier being further used to request access to the service.

[0007] By adopting the above implementation, the network can generate different first user identifiers for users when signing contracts or accessing different services, thereby preventing leakage of user privacy.

[0008] In a possible implementation, the receiving the first request includes: receiving the first request from a first network element, where the first network element is an access and mobility management network element, or an operator portal.

[0009] In one possible implementation, the method further includes: sending a second request to the first application server, the second request including the first user identifier, the second request being used to request signing up for the service, and the first application server being used to process the service; and receiving a second response from the first application server, the second response being used to indicate whether the service requested by the user to sign up is successfully signed up.

[0010] In a possible implementation, the method further includes: receiving a first verification request from the first application server, the first verification request including the first user identifier; and verifying that the user is a legitimate user based on the first user identifier.

[0011] By verifying the legitimacy of the first user identifier, it is possible to prevent an illegal user from obtaining the first user identifier to access services that the illegal user has not signed up for, thereby ensuring the security of service access.

[0012] In a possible implementation, the first request includes a second user identifier, where the second user identifier is a user number of the user and / or a subscriber permanent identifier (SUPI).

[0013] In a possible implementation, the method further includes: sending a first response to the first network element, where the first response is used to indicate that the service requested by the user is successfully signed up, and the first response includes the first user identifier.

[0014] In a possible implementation, the first response further includes a validity period, where the validity period is used to indicate the validity period of the first user identifier. When the validity period expires, the first user identifier is unavailable.

[0015] By setting the validity period, the identity management network element can manage the validity period of the first user identity, regularly renew the user's contracted services, and verify the legitimacy of the first user identity during the renewal process. Therefore, the security of the first user identity can be improved.

[0016] In one possible implementation, the method further includes: storing the first user identifier and the association relationship between the service identifier and the second user identifier; after receiving a first verification request from the first application server, verifying that the user holding the first user identifier is a legitimate user based on the association relationship between the first user identifier and the service identifier and the second user identifier.

[0017] In a possible implementation, the first request further includes a user identity attribute, where the user identity attribute is used to indicate the identity type used by the user requesting to subscribe to the service.

[0018] In a possible implementation, determining the first user identifier includes: the first user identifier created for the user identity attribute of the user for requesting to subscribe to the service is different from another first user identifier created for another identity attribute of the user for requesting to subscribe to the service.

[0019] In this implementation, a user can subscribe to the same service multiple times using different identity attributes. The network can generate and issue different first user identifiers for different identity attributes of the same user, thereby protecting the user's privacy from being leaked when accessing services with different identities.

[0020] In a possible implementation, the method further includes: determining a validity period corresponding to the first user identifier.

[0021] In a possible implementation, the method further includes: after receiving the first verification request from the first application server, determining, based on the validity period, whether the first application server holds a valid first user identifier for accessing the service.

[0022] In a possible implementation, the first user identifier includes a first digital signature, and the method further includes: after receiving a first verification request from a first application server, verifying whether the first user identifier is legitimate according to the first digital signature.

[0023] The first application server can verify, based on the first digital signature, that the first application identifier is issued by the identity management network element, thereby improving the security of using the first user identifier.

[0024] In one possible implementation, the first verification request also includes a second digital signature corresponding to the first user identifier, and the method further includes: after receiving the verification request including the second digital signature corresponding to the first user identifier, verifying whether the first user identifier is legal based on the second digital signature.

[0025] Through the second digital signature, the network can verify that the service request carrying the second digital signature is issued by a legitimate user, thereby improving the security of service access.

[0026] In one possible implementation, the first verification request also includes replay attack verification information corresponding to the first user identifier, and the method further includes: after receiving the verification request including the replay attack verification information corresponding to the first user identifier, verifying whether the user holding the first user identifier is a legitimate user based on the replay attack verification information.

[0027] In one possible implementation, the first request also includes a first access control attribute, which is used to indicate whether the user authorizes the first application server to hold the first user identifier to access other services on behalf of the user, and / or the scope of authorizing the first application server to access other services on behalf of the user.

[0028] By setting an access control attribute for the first user ID, it is determined whether the first application server is allowed to use the first user ID provided by the user to access other services. The user authorizes the first application server to access other services on the user's behalf through the first access control attribute, which brings convenience to the user in accessing other services.

[0029] In one possible implementation, the second response received from the first application server also includes a second access control attribute, which is used to indicate whether the first application server accepts the first application server holding the first user identifier to access other services, and / or the scope of the first application server accepting the first application server to access other services.

[0030] In a possible implementation manner, the method further includes: the first response sent to the first network element also includes the second access control attribute.

[0031] In a possible implementation, the method further includes: after receiving the verification request including the second access control attribute, determining, based on the second access control attribute, whether the first application server legally holds the first user identifier to access the other service.

[0032] In a possible implementation, the method further includes: receiving a second verification request from a second application server, the second verification request being used to request verification of whether the first application server legally holds the first user identifier, the second verification request including the first user identifier.

[0033] According to a second aspect, a method is provided, which includes the following steps: sending a service contract signing request to a first network element, wherein the service contract signing request is used to request signing the service, and the service contract signing request includes a service identifier, and the service identifier is used to indicate the service that the user requests to sign; receiving a service contract signing response, wherein the service contract signing response is used to indicate that the service contract is successful, and the service contract signing response includes a first user identifier, and the first user identifier is used to access the service, and the first user identifier is different from another first user identifier corresponding to another service requested to be accessed by the user.

[0034] The above method can be executed by a terminal device.

[0035] By adopting the above implementation, the terminal device can use different first user identities to sign contracts or access different services, thereby avoiding privacy leakage.

[0036] In one possible implementation, the service contract signing request includes a first access control attribute, which is used to indicate that the user authorizes the first application server to access other services on behalf of the user, and / or authorizes the first application server to access the scope of other services on behalf of the user, and the first application server is used to process the service.

[0037] In a possible implementation, the service subscription request includes a user identity attribute, where the user identity attribute is used to indicate an identity type used by the user requesting to subscribe to the service.

[0038] In a possible implementation, the method further includes: sending a service access request to the first application server, where the service access request is used to request access to the service, and the service access request includes the first user identifier.

[0039] In one possible implementation, the service access request includes a second access control attribute obtained from the service signing response, and the second access control attribute is used to indicate whether the first application server accepts the first application server holding the first user identifier to access other services, and / or the scope of the first application server accepting the first application server to access other services.

[0040] In a possible implementation, the service access request includes a validity period obtained from the service signing response, and the validity period is used to determine whether the first user identifier is valid.

[0041] In one possible implementation, the method further includes: sending a third request to the first network element, the third request being used to request renewal of the service, the third request including the first user identifier; receiving a third response sent from the first network element, the third response being used to indicate whether the renewal of the third-party service is successful, the third response including the first user identifier whose validity period has been updated.

[0042] In a possible implementation, sending the third request to the first network element includes: judging that the first user identifier is about to expire during the validity period, and sending the third request before the first user identifier expires.

[0043] According to a third aspect, a method is provided, comprising the following steps: receiving a service access request, the service access request including a first user identifier, the first user identifier being used to access the service, the first user identifier being different from another first user identifier corresponding to another service requested to be accessed by the user; and sending a verification request to the first network element, the verification request being used to request the first network element to verify the first user identifier, the first user identifier being generated by the first network element, and the verification request including the first user identifier.

[0044] The above method may be executed by an application server.

[0045] With the above implementation, the application server requests the second network element to verify the first user identifier to ensure that the first user identifier is used legally.

[0046] In a possible implementation, the first user identification includes a first digital signature, and the first digital signature is used to verify whether the first user identification is legal.

[0047] In a possible implementation, the service access request includes a validity period corresponding to the first user identifier, where the validity period is used to indicate a validity period of the first user identifier. When the validity period expires, the first user identifier is unavailable.

[0048] In one possible implementation, the service access request includes an access control attribute, which is used to indicate whether the first application server accepts the first application server holding the first user identifier to access other services, and / or the first application server accepts the scope of the first application server's access to the other services, and the first application server is used to process the service.

[0049] In a possible implementation, the verification request further includes the access control attribute, and the access control attribute is used to determine whether the first application server legally holds the first user identifier to access the other service.

[0050] In a possible implementation, the verification request further includes a second digital signature, where the second digital signature is created by the user and is used to verify whether the first user identification is legitimate.

[0051] In a possible implementation, the verification request further includes replay attack verification information corresponding to the first user identifier, and the replay attack verification information is used to verify whether the user holding the first user identifier is a legitimate user.

[0052] In a possible implementation, the verification request further includes the validity period, and the validity period is used to determine whether the first application server holds a valid first user identifier to access the service.

[0053] In a possible implementation, the method further includes: receiving a verification response from the first network element, where the verification response is used to indicate that the first user identifier has been successfully verified.

[0054] In a possible implementation, the method further includes: sending the service access request to a second application server, where the service access request is used to request access to the other service, and the second application server is used to process the other service.

[0055] In a fourth aspect, a communication device is provided, the communication device including a unit or module for executing the method described in any one of the first aspects. The communication device can provide a data channel signaling control function. Specifically, the communication device can include a processing unit and a transceiver unit.

[0056] The transceiver unit receives a first request, which includes a service identifier, and the service identifier is used to identify the service that the user requests to sign up for; the processing unit determines a first user identifier, and the first user identifier is used to identify the user. The first user identifier is different from another first user identifier created for another service that the user requests to sign up for. The first user identifier is used to request to sign up for the service, and the first user identifier is also used to request access to the service.

[0057] In a possible implementation manner, the processing unit is specifically configured to: receive the first request from a first network element through a transceiver unit, where the first network element is an access and mobility management network element, or an operator portal.

[0058] In one possible implementation, the processing unit is specifically used to: send a second request to the first application server through the transceiver unit, the second request includes the first user identifier, the second request is used to request to sign up for the service, and the first application server is used to process the service; receive a second response from the first application server, the second response is used to indicate whether the service requested by the user to sign up is successfully signed.

[0059] In a possible implementation, the processing unit is specifically configured to: receive a first verification request from the first application server via a transceiver unit, the first verification request including the first user identifier; and verify that the user is a legitimate user based on the first user identifier.

[0060] In a possible implementation, the first request includes a second user identifier, where the second user identifier is a user number of the user and / or a subscriber permanent identifier (SUPI).

[0061] In a possible implementation, the processing unit is specifically configured to: send a first response to the first network element through the transceiver unit, wherein the first response is used to indicate that the service requested by the user is successfully signed, and the first response includes

[0062] The first user identifier.

[0063] In a possible implementation, the first response further includes a validity period, where the validity period is used to indicate the validity period of the first user identifier. When the validity period expires, the first user identifier is unavailable.

[0064] In one possible implementation, the processing unit is specifically used to: store the first user identifier and the association relationship between the service identifier and the second user identifier; after receiving a first verification request from the first application server, verify that the user holding the first user identifier is a legitimate user based on the association relationship between the first user identifier and the service identifier and the second user identifier.

[0065] In a possible implementation, the first request further includes a user identity attribute, where the user identity attribute is used to indicate the identity type used by the user requesting to subscribe to the service.

[0066] In a possible implementation, the processing unit is specifically configured to: create the first user identifier for the user identity attribute of the user for requesting to subscribe to the service different from another first user identifier for another identity attribute of the user for requesting to subscribe to the service.

[0067] In a possible implementation, the processing unit is specifically configured to determine a validity period corresponding to the first user identifier.

[0068] In a possible implementation, the processing unit is specifically configured to: after receiving the first verification request from the first application server, determine, based on the validity period, whether the first application server holds a valid first user identifier for accessing the service.

[0069] In a possible implementation, the first user identifier includes a first digital signature, and the processing unit is specifically configured to: after receiving a first verification request from a first application server, verify whether the first user identifier is legitimate according to the first digital signature.

[0070] In one possible implementation, the first verification request also includes a second digital signature corresponding to the first user identifier, and the processing unit is specifically used to: after receiving a verification request including the second digital signature corresponding to the first user identifier, verify whether the first user identifier is legal based on the second digital signature.

[0071] In one possible implementation, the first verification request also includes replay attack verification information corresponding to the first user identifier, and the processing unit is specifically used to: after receiving the verification request including the replay attack verification information corresponding to the first user identifier, verify whether the user holding the first user identifier is a legitimate user based on the replay attack verification information.

[0072] In one possible implementation, the first request also includes a first access control attribute, which is used to indicate whether the user authorizes the first application server to hold the first user identifier to access other services on behalf of the user, and / or the scope of authorizing the first application server to access other services on behalf of the user.

[0073] In one possible implementation, the second response received from the first application server also includes a second access control attribute, which is used to indicate whether the first application server accepts the first application server holding the first user identifier to access other services, and / or the scope of the first application server accepting the first application server to access other services.

[0074] In a possible implementation manner, the first response sent to the first network element further includes the second access control attribute.

[0075] In a possible implementation, the processing unit is specifically configured to: after receiving the verification request including the second access control attribute, determine, based on the second access control attribute, whether the first application server legally holds the first user identifier to access the other service.

[0076] In one possible implementation, the processing unit is specifically used to: receive a second verification request from a second application server through a transceiver unit, the second verification request is used to request verification of whether the first application server legally holds the first user identifier, and the second verification request includes the first user identifier.

[0077] In a fifth aspect, a communication device is provided, the communication device including a unit or module for executing any of the methods described in the second aspect. The communication device may include a processing unit and a transceiver unit.

[0078] The processing unit sends a service contract signing request to the first network element through the transceiver unit, where the service contract signing request is used to request signing the service, and the service contract signing request includes a service identifier, and the service identifier is used to indicate the service that the user requests to sign the service; the processing unit receives a service contract signing response through the transceiver unit, where the service contract signing response is used to indicate that the service contract is successful, and the service contract signing response includes a first user identifier, where the first user identifier is used to access the service, and the first user identifier is different from another first user identifier corresponding to another service requested to be accessed by the user.

[0079] In one possible implementation, the service contract signing request includes a first access control attribute, which is used to indicate that the user authorizes the first application server to access other services on behalf of the user, and / or authorizes the first application server to access the scope of other services on behalf of the user, and the first application server is used to process the service.

[0080] In a possible implementation, the service subscription request includes a user identity attribute, where the user identity attribute is used to indicate an identity type used by the user requesting to subscribe to the service.

[0081] In a possible implementation, the processing unit is specifically configured to: send a service access request to the first application server through the transceiver unit, where the service access request is used to request access to the service, and the service access request includes the first user identifier.

[0082] In one possible implementation, the service access request includes a second access control attribute obtained from the service signing response, and the second access control attribute is used to indicate whether the first application server accepts the first application server holding the first user identifier to access other services, and / or the scope of the first application server accepting the first application server to access other services.

[0083] In a possible implementation, the service access request includes a validity period obtained from the service signing response, and the validity period is used to determine whether the first user identifier is valid.

[0084] In one possible implementation, the processing unit is specifically used to: send a third request to the first network element through the transceiver unit, the third request is used to request renewal of the service, and the third request includes the first user identifier; receive a third response sent from the first network element, the third response is used to indicate whether the renewal of the third-party service is successful, and the third response includes the first user identifier whose validity period has been updated.

[0085] In a possible implementation, sending the third request to the first network element includes: judging that the first user identifier is about to expire during the validity period, and sending the third request before the first user identifier expires.

[0086] In a sixth aspect, a communication device is provided, the communication device including a unit or module for executing any of the methods described in the third aspect. The communication device may include a processing unit and a transceiver unit.

[0087] The processing unit receives a service access request through the transceiver unit, where the service access request includes a first user identifier, where the first user identifier is used to access the service, and where the first user identifier is different from another first user identifier corresponding to another service requested to be accessed by the user; the processing unit sends a verification request to the first network element through the transceiver unit, where the verification request is used to request the first network element to verify the first user identifier, where the first user identifier is generated by the first network element, and the verification request includes the first user identifier.

[0088] In a possible implementation, the first user identification includes a first digital signature, and the first digital signature is used to verify whether the first user identification is legal.

[0089] In a possible implementation, the service access request includes a validity period corresponding to the first user identifier, where the validity period is used to indicate a validity period of the first user identifier. When the validity period expires, the first user identifier is unavailable.

[0090] In one possible implementation, the service access request includes an access control attribute, which is used to indicate whether the first application server accepts the first application server holding the first user identifier to access other services, and / or the first application server accepts the scope of the first application server's access to the other services, and the first application server is used to process the service.

[0091] In a possible implementation, the verification request further includes the access control attribute, and the access control attribute is used to determine whether the first application server legally holds the first user identifier to access the other service.

[0092] In a possible implementation, the verification request further includes a second digital signature, where the second digital signature is created by the user and is used to verify whether the first user identification is legitimate.

[0093] In a possible implementation, the verification request further includes replay attack verification information corresponding to the first user identifier, and the replay attack verification information is used to verify whether the user holding the first user identifier is a legitimate user.

[0094] In a possible implementation, the verification request further includes the validity period, and the validity period is used to determine whether the first application server holds a valid first user identifier to access the service.

[0095] In a possible implementation, the processing unit is specifically configured to: receive a verification response from the first network element through a transceiver unit, where the verification response is used to indicate that the first user identifier has been successfully verified.

[0096] In a possible implementation, the processing unit is specifically configured to: send the service access request to the second application server through the transceiver unit, where the service access request is used to request access to the other service, and the second application server is configured to process the other service.

[0097] In the seventh aspect, a communication system is provided, including an identity management network element, a terminal device and an application server, wherein the identity management network element is used to implement the method as described in any one of the first aspects above, the terminal device is used to implement the method as described in any one of the second aspects above, and the application server is used to implement the method as described in any one of the third aspects above.

[0098] In an eighth aspect, a readable storage medium is provided, in which a program is stored. When the program is executed by a communication device, the method as described in any one of the first aspects above is implemented, or the method as described in any one of the second aspects above is implemented, or the method as described in any one of the third aspects above is implemented.

[0099] In the ninth aspect, a chip system is provided, comprising: a memory for storing a computer program; a processor; when the processor calls and runs the computer program from the memory, the communication device equipped with the chip system executes the method as described in any one of the first aspects above, or executes the method as described in any one of the second aspects above, or executes the method as described in any one of the third aspects above.

[0100] In a tenth aspect, a computer program product is provided, comprising instructions, which, when executed on a processor, cause the processor to execute the method described in any one of the first aspects above, or the method described in any one of the second aspects above, or the method described in any one of the third aspects above. BRIEF DESCRIPTION OF THE DRAWINGS

[0101] FIG1 is a schematic diagram of the architecture of a communication system used in an embodiment of the present application;

[0102] FIG2 is a flow chart of a service contract signing method provided in an embodiment of the present application;

[0103] FIG3 is a flow chart of a service contract signing method provided in an embodiment of the present application;

[0104] FIG4 is a flow chart of a service contract signing method provided in an embodiment of the present application;

[0105] FIG5 is a flow chart of a service access method provided in an embodiment of the present application;

[0106] FIG6 is a flow chart of a service access method provided in an embodiment of the present application;

[0107] FIG7 is a flow chart of a service renewal method provided in an embodiment of the present application;

[0108] FIG8 is a possible exemplary block diagram of a device involved in an embodiment of the present application;

[0109] FIG9 is a schematic diagram of a possible structure of the device involved in the embodiments of the present application. DETAILED DESCRIPTION

[0110] To make the objectives, technical solutions, and advantages of this application more clear, the present application will be further described in detail below with reference to the accompanying drawings. The specific operating methods in the method embodiments can also be applied to the device embodiments or system embodiments. In the description of this application, unless otherwise specified, the meaning of "multiple" is two or more.

[0111] In the various embodiments of the present application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.

[0112] It is understood that the various numbers used in this application are merely for ease of description and are not intended to limit the scope of this application. The order of execution of the above-mentioned processes does not necessarily imply a specific order of execution. The order of execution of each process should be determined by its function and inherent logic.

[0113] The terms "first," "second," "third," "fourth," and various other terminology designations, if any, in the specification and claims of this application and in the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a particular order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate so that the embodiments described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "including" and "having," and any variations thereof, are intended to cover non-exclusive inclusions, e.g., a process, method, system, product, or apparatus comprising a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0114] The technical solutions provided in this application can be applied to various communication systems, such as the fifth generation (5G) communication system (also known as the new radio (NR) system), the fourth generation (4G) communication system (also known as the long term evolution (LTE) system), the LTE frequency division duplex (FDD) system, the LTE time division duplex (TDD) system, etc. The technical solutions provided in this application can also be applied to future communication systems, such as the sixth generation (6G) mobile communication system.

[0115] In order to prevent user privacy from being leaked when a user signs a contract or accesses a third-party service, the present application proposes a service processing method, which can be applied to the communication system 100 introduced in FIG1 .

[0116] The communication system shown in Figure 1 includes the following network elements: identity management network element (Identifier Management, IdM), access and mobility management function network element (access and mobility management function, AMF), session management function (session management function, SMF), unified data function (Unified data function, UDM), user plane function (User plane function, UPF), wireless network equipment (for example, (Radio) Access Network, (R) AN), terminal equipment and application server (or Application Function, AF). The communication system may also include an operator's portal website.

[0117] The above devices or network elements are introduced below.

[0118] (1) Identity management network element: The identity management network element is a newly defined network element in the present invention, and its main function is to verify the real identity of the user and issue a digital identity certificate to the user, or a digital identity identifier (in this application, both are referred to as the first user identifier). The digital identity certificate or digital identity identifier is used to identify the digital identity of the user. The digital identity certificate or digital identity identifier is a unique identifier with a security mode, which enables the user to be uniquely identified. The digital identity certificate or digital identity identifier can be used to verify the digital identity of the user. The identity management network element can be an independent network function NF (Network Function) or it can be part of the UDM network function. This application does not limit the name of the identity management network element, and during the implementation process, the function of the identity management network element can also be performed by network elements or network functions with other names.

[0119] (2) User data management network element: stores and manages user terminal network and service subscription data. In the 5G communication system, the user data management network element can be a unified data management (UDM).

[0120] (3) Access and mobility management network element: It is mainly used for the registration, mobility management, and tracking area update processes of terminals in the mobile network. The access and mobility management network element terminates non-access stratum (NAS) messages, completes registration management, connection management, and reachability management, allocates tracking area lists (TA lists) and mobility management, and transparently routes session management (SM) messages to the session management network element. In the 5th generation (5G) communication system, the access and mobility management network element can be the access and mobility management function (AMF).

[0121] (4) Session management network element: It is mainly used for session management in mobile networks, such as session establishment, modification, and release. Specific functions include allocating Internet Protocol (IP) addresses to terminals and selecting user plane network elements that provide message forwarding functions. In 5G communication systems, the session management network element can be a session management function (SMF).

[0122] (5) User plane function network element: Mainly responsible for processing user messages, such as forwarding and billing. User plane network elements can also include protocol data unit (PDU) session anchors (PSA). In 5G communication systems, user plane network elements can be user plane functions (UPF).

[0123] (6) Terminal device: A terminal device can be any device that can access a network and may also be referred to as user equipment (UE), terminal device, access terminal, user unit, user station, mobile station, mobile station (MS), mobile terminal (MT), remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent, or user device. UE can be a device that provides voice / data connectivity to a user, such as a handheld device or vehicle-mounted device with wireless connection capabilities. At present, some examples of terminals include: mobile phones, tablet computers, computers with wireless transceiver functions (such as laptops, PDAs, etc.), mobile internet devices (MIDs), virtual reality (VR) devices, augmented reality (AR) devices, wireless terminals in industrial control, wireless terminals in self-driving, wireless terminals in remote medical, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, wireless terminals in smart homes, cellular phones, cordless phones, session initiation protocol (SIP) phones, wireless local loop (WLL) stations, personal digital assistants (PDAs), and so on. assistant, PDA), handheld devices with wireless communication capabilities, computing devices or other processing devices connected to a wireless modem, vehicle-mounted devices, wearable devices, terminal devices in 4G / 5G networks, or terminal devices in future evolved public land mobile networks (PLMNs), etc. The embodiments of this application do not limit the specific technology, device form, and name adopted by the terminal device.

[0124] (7) Access Network Equipment (R)AN: It is responsible for the wireless access of terminal devices. Possible deployment forms include: separation scenarios of centralized units (CU) and distributed units (DU) and single-site scenarios. Among them, in the separation scenario, CU supports radio resource control (RRC), packet data convergence protocol (PDCP), service data adaptation protocol (SDAP) and other protocols; DU mainly supports radio link control layer (RLC), media access control layer (MAC) and physical layer protocols. In the single-site scenario, a single site may include (new radio Node, gNB), evolved Node B (eNB), radio network controller (RNC), Node B (NB), base station controller (BSC), base transceiver station (BTS), home base station, base band unit (BBU), etc.

[0125] (8) Application function (AF) or application server: A network element or server that provides services to a third-party service provider (SP). Application functions can communicate with the control plane of the operator's network through the Network Exposure Function (NEF). Application servers are typically located on the Internet or other data networks (DNs). User terminals connect to application servers through the user plane to provide third-party services to users.

[0126] (9) Network Exposure Function: Located between the core network and the AF, it manages open network data. The AF accesses core network internal data through the NEF. For example, the IdM can communicate with the AF or application server through the NEF. The NEF provides security to ensure the security of external applications accessing the 3GPP network, and offers features such as QoS customization capabilities for external applications, subscription to mobility status events, and AF request distribution.

[0127] (10) Operator Portal: A website or server established by an operator for service management. Users can access the operator portal, also known as the operator portal, through a mobile network or the Internet to subscribe to or unsubscribe from the operator's services and view service packages, billing information, account information, etc. Third-party service providers (SPs) that have a cooperative relationship with the operator also display their services on the operator portal for users to subscribe to. In the present invention, users can also connect to the operator portal via the Internet and request the IdM to issue a digital identity for them.

[0128] (11) Data network: a network that provides services such as Internet access, operator services or third-party services.

[0129] FIG2 is a flow chart of a service subscription and access method provided by an embodiment of the present application.

[0130] S201: A first network element sends a first request to a second network element.

[0131] For example, the first network element may be an access and mobility management network element, such as the AMF in FIG1 , and the second network element may be an identity management network element, such as the IdM in FIG1 .

[0132] Among them, the first request is used to request to sign a service. For example, the service may be a third-party service, and the third-party service may be provided by a network function or application server outside the operator network, such as AF in Figure 1. In this embodiment, the network function or application server that provides the service is referred to as the first network function or the first application server. For the convenience of expression, the two are collectively referred to as the first application server. Optionally, the first request is used to request the creation of a first user identifier. The first user identifier may also be referred to as a digital identity credential, or a digital identity identifier. The first user identifier is used to identify the user. In the present invention, the user uses the first user identifier to sign a contract and access the service.

[0133] The first request includes a service identifier, which can be used to determine the service, or to determine the application server corresponding to the service. For example, the first network element or the second network element can determine the first application server corresponding to the service based on the service identifier. Exemplarily, the service identifier can be an application identifier (Application Identifier, APP ID), or it can also be the domain name or IP address of the first application server, or it can also be the uniform resource locator (Uniform Resource Locator, URL) of the first application server. The present invention does not limit the specific form of the service identifier.

[0134] Optionally, the first request also includes a second user identifier, which may be a user number, such as a mobile phone number, or a subscriber permanent identifier (SUPI). The subscriber permanent identifier SUPI can be used to identify a user. The subscriber identity module (SIM) or user identity module (UIM) is the physical carrier of the SUPI. When a user inserts the SIM / UIM into a terminal device, the user can use the SUPI to pass network authentication and access the network normally.

[0135] It should be noted that the first request may carry a mobile phone number, or a subscriber permanent identifier (SUPI), or both.

[0136] Optionally, before step S201, in step S200, the terminal device may send a service subscription request to the first network element. The service subscription request includes a service identifier.

[0137] It should be noted that the first network element may also be an operator portal, such as the portal in Figure 1. If the first network element is an operator portal, the service subscription request may optionally include a user number, such as a telephone number. The first request carries the user number.

[0138] S202: The second network element determines a first user identifier.

[0139] Exemplarily, when the second network element determines the first user identifier, it may randomly generate a string. For example, the string may be composed of one or more of numbers, letters, or other special characters. The string can uniquely identify the user. In order to prevent the first application server from leaking user privacy, when the user requests to sign up for different services, the second network element creates different first user identifiers for the user. For example, when the user requests to sign up for service #1 (or the first request carries service identifier #1), the second network element creates a first user identifier #1 for the user, or creates string #1; when the user requests to sign up for service #2 (or the first request carries service identifier #2), the second network element creates a first user identifier #2 for the user, or creates string #2. The first user identifier #1 is different from the first user identifier #2, or in other words, string #1 is different from string #2.

[0140] In this implementation, a user uses different first user identifiers when signing up for different services, thereby preventing leakage of user privacy.

[0141] Optionally, the first user identifier may further include a first digital signature, where the first digital signature is generated by the second network element and is used to verify that the first user identifier is allocated or issued by the second network element. Exemplarily, the digital signature may be generated by the second network element using a private key, or may be generated by the second network element using a shared key with the first application server.

[0142] Optionally, the first user identifier may also have one or more attributes, for example, the attribute may include a service identifier. The service identifier may be used to determine which service the first user identifier corresponds to.

[0143] Alternatively, the attribute may include a validity period for the first user identifier. The validity period is used to define the time range in which the first user identifier is available. Exemplarily, the validity period may be a time period, for example, based on the time when the first user identifier is generated or received, after which the first user identifier becomes invalid; or the validity period may be a time point after which the first user identifier becomes invalid.

[0144] Optionally, the first user identifier can also be guaranteed to correspond to a unique citizen. For example, if national regulations require citizens to sign up for services using their real names, the second network element can ensure that each first user identifier corresponds to a unique citizen. For example, when a carrier issues a SIM or UIM card to a user, they verify the user's citizen ID card to ensure that the SUPI or phone number corresponds to a real citizen.

[0145] S203: The second network element sends a second request to the first application server.

[0146] The second request includes the first user identifier and is used to request a subscription service from the first application server.

[0147] Optionally, if the first user identifier includes a first digital signature, and the first digital signature is generated by the second network element using a private key, the second request may further include a public key corresponding to the first digital signature of the first user identifier, where the public key corresponds to the private key used by the second network element to generate the first digital signature for the first user identifier in S202. The public key may be used to verify the first digital signature of the first user identifier.

[0148] Optionally, the second request may further include a service identifier.

[0149] S204: The first application server creates a user account for the user to access the service.

[0150] Exemplarily, the first application server verifies the first digital signature included in the first user identifier. For example, if the second network element uses a shared secret key to generate the first digital signature of the first user identifier in S202, the first application server uses the secret key pre-shared with the first digital second network element for verification; if the second network element uses a private key to generate the first digital signature of the first user identifier in S202, the first application server uses the public key corresponding to the private key to verify the first digital signature. Exemplarily, the public key can be obtained by the first application server from the public key certificate of the second network element, or can be carried in the second request in S203.

[0151] If the first digital signature is verified successfully, an account is created for the user. For example, a character string in the first user identifier that can uniquely identify the user is used as the account for the user to access services.

[0152] S205: The first application server sends a second response to the second network element.

[0153] The second response is used to indicate whether the contract signing is successful. For example, the second response includes indication information indicating whether the contract signing is successful. Exemplarily, the indication information may be a bit. If the second response carries a bit 1 or true, it indicates that the service contract signing is successful. Conversely, if it carries a bit 0 or false, or does not carry any value, it indicates that the service contract signing failed.

[0154] Optionally, the second response also includes the first user identifier.

[0155] Optionally, if the second request in S203 includes a service identifier, the second response may also include the service identifier.

[0156] S206: The second network element stores the association relationship between the first user identifier, the second user identifier, and the service identifier.

[0157] In the first implementation, the first user identifier can be used as a query method when storing the association relationship. For example, the association relationship between the stored first user identifier, the second user identifier, and the service identifier can be found by querying the first user identifier. Because the first user identifier is unique, the association relationship can be found in this way. Exemplarily, when using the association relationship to verify the legitimacy of the first user identifier, the second network element is queried based on the first user identifier to see whether a storage record corresponding to the association relationship is stored, and it is verified whether the service identifier in the storage record corresponds to the first application server. If the service identifier corresponds to the first application server, it is considered that the legitimacy verification of the first user identifier has passed.

[0158] In the second implementation, the first user identifier and the service identifier can be used as a query method when storing the association relationship. For example, the association relationship between the stored first user identifier, the second user identifier and the service identifier can be found by querying the first user identifier and the service identifier. Exemplarily, when using the association relationship to verify the legitimacy of the first user identifier, it is possible to first verify whether the service identifier corresponds to the first application server. If the service identifier corresponds to the first application server, the first user identifier or the first user identifier and the service identifier are used to query whether the second network element stores a storage record of the corresponding association relationship. If the association relationship is stored, it is considered that the legitimacy verification of the first user identifier has passed. Optionally, when storing the association relationship, the attribute information corresponding to the first identifier can also be saved. For example, the attribute information can include a validity period attribute.

[0159] It should be noted that this step is optional.

[0160] In addition, if step S206 is executed, S206 can be combined with S202. That is, the second network element can store the association relationship between the first user identifier, the service identifier, and the second user identifier when creating the first user identifier.

[0161] S207: The second network element sends a first response to the first network element.

[0162] The first response is used to indicate whether the contract signing is successful. For example, the indication information may be used to indicate whether the service the user requested to sign is successfully signed. The first response also includes a first user identifier.

[0163] Optionally, the first response also includes a service identifier.

[0164] Optionally, the first response also includes a second user identifier.

[0165] If the first network element is an AMF, the first request in S201 may carry a SUPI, a user number, or both. For example, if S201 carries a SUPI, the first response also carries a SUPI. The AMF can find the corresponding user's terminal device based on the SUPI and send the service subscription response to the corresponding terminal device. If S201 carries a user number, the first response carries the user number. The AMF can search for the SUPI based on the user number and find the corresponding user's terminal device. If S201 carries both a SUPI and a user number, the first response may carry either a SUPI or a user number. If it carries the user number, the AMF can search for the SUPI based on the user number.

[0166] If the first network element is an operator portal, the first request in S201 may carry the user number. In this case, the first response also carries the user number.

[0167] Optionally, the first network element may send a service signing response to the terminal device, as shown in S208 in Figure 2. The service signing response is used to indicate whether the service signing is successful, and the service signing response also includes the first user identifier.

[0168] The above steps describe the service signing process. The second network element generates different first user identifiers, which uniquely identify the user, for each service the user is requesting access to. Because the user uses different first user identifiers when signing up for different services, the first application server cannot access the user's subscription records for other services, thus preventing privacy leaks.

[0169] The following describes a process in which a user accesses a service based on the first user ID.

[0170] S209: The first application server receives the service access request 1.

[0171] Exemplarily, the service access request 1 is sent by the terminal device, and the service access request 1 includes the first user identifier.

[0172] Optionally, the first user identifier may include the first digital signature generated by the second network element in S202.

[0173] Optionally, the service access request 1 may include a public key certificate corresponding to the first digital signature of the first user identifier. The public key is used by the network to subsequently verify the legitimacy of the first user identifier.

[0174] Optionally, the service access request 1 may also include a second digital signature generated by the terminal device for the first user identifier. The terminal device can use the private key issued by the second network element to the user (that is, the private key corresponding to the first user identifier) ​​to digitally sign the service access request 1 including the first user identifier, that is, generate a second digital signature. Exemplarily, the second network element generates the private key and the public key corresponding to the private key for the user. The second network element issues the private key to the user, for example, and can transmit it encrypted through an Internet protocol security (IPsec) tunnel. The public key can be retained by the second network element for verifying the second digital signature generated using the private key.

[0175] Optionally, the service access request 1 may also include replay attack verification information. For example, the replay attack verification information may be a timestamp, which may correspond to the time when the user or terminal device initiates the access request or performs a digital signature. Alternatively, the replay attack verification information may also be a random number, which is generated when the user or terminal device initiates service access. The private key corresponding to the first user identifier and the second digital signature of the service access request 1 containing the replay attack verification information are used to ensure that the service access request 1 is valid for one time, that is, if an illegal user obtains the first user identifier of the user in the access request message after the legitimate user has made an access request, they will not be able to access the service provided by the first application server.

[0176] Optionally, service access request 1 may include validity period information of the first user identifier, which may be used to indicate the validity period of the first user identifier. Alternatively, the validity period information may be used to indicate that the first user identifier has a corresponding validity period, and the terminal device may instruct the network to verify the validity period of the first user identifier through the validity period information.

[0177] Optionally, the service access request 1 may include indication information, where the indication information instructs the network to verify the validity period of the first user identifier.

[0178] When the service access request 1 includes the validity period of the first user identifier, or includes instruction information instructing the network to verify the validity period of the first user identifier, the network needs to verify the validity period of the first user identifier in subsequent service access processes.

[0179] S210: The first application server verifies the legitimacy of the first user identifier.

[0180] Exemplarily, the first application server verifies the user's contract record. For example, the first application server uses the first user ID to search for the user's service contract record. For example, the first application server uses a character string in the first user ID that uniquely identifies the user as the user account to search for the contract record. If the user's contract record is found, it is assumed that the user has signed a contract using the first user ID, and subsequent verification procedures are performed, i.e., verification of the user's first user ID is continued. If no contract record is found, the service access request is rejected, and verification of the first user ID is not further performed.

[0181] Exemplarily, the first application server verifies the first user identifier of the user. The first application server verifies using different methods depending on the content included in the first user identifier.

[0182] If the first user identifier includes a character string for identifying the user, for example, only includes this character string, the first application server only needs to perform the above-mentioned user contract record verification, and no additional verification of the first user identifier is required.

[0183] If the service access request 1 includes an attribute corresponding to the first user identifier (e.g., a validity period). For example, the validity period indicates the period during which the first user identifier is valid, the first application server verifies the validity period of the first identifier. For example, the first application server determines whether the current time, or the time when the service access request was received, is within the time range indicated by the validity period corresponding to the first user identifier. If the time is within the time range indicated by the validity period corresponding to the first user identifier, the validity period verification is considered to have passed. Otherwise, the verification fails, and the first user identifier is determined to be invalid.

[0184] If the first user identifier includes a first digital signature, wherein the first digital signature is generated by the second network element, further, if the second network element and the first application server have pre-configured a shared key, or the first application server has obtained the public key certificate of the second network element, the first application server can use the public key or shared key to verify the first user identifier to determine whether the first user identifier is generated by a legitimate second network element. Exemplarily, in the process of the second network element generating the first user identifier, the second network element uses the shared key to generate the first digital signature corresponding to the first user identifier. At this time, the second network element can pre-configure the shared key to the first application server. Exemplarily, for the above-mentioned public key certificate, the first application server can obtain it in the service access request 1, for example, the service access request 1 carries the public key certificate of the first digital signature corresponding to the first user identifier.

[0185] In the above case, the first application server may verify the first user identifier. In other cases, the first application server requests the second network element to verify the first user identifier (for example, through subsequent step S211 ).

[0186] For example, if the service requested by the user is for operator billing, a verification request may be sent to the second network element, requesting the second network element to verify the first user identifier. For example, in the above scenario, the first user identifier includes a string used to identify the user, or the first user identifier includes a first digital signature. If the service is for operator billing, the first application server requests the second network element to verify the first user identifier.

[0187] If service access request 1 includes validity period information, the first application server may also request verification of the first user identifier from the second network element. For example, the validity period included in service access request 1 may have been tampered with or may be unreliable. To ensure the accuracy of the verification, the first application server may request verification of the validity period of the first identifier from the second network element. Alternatively, if the validity period information included in service access request 1 is merely an indication requesting verification of the validity period, the first application server cannot obtain the specific validity period and therefore cannot perform verification. In this case, the first application server requests verification of the validity period of the first identifier from the second network element.

[0188] If service access request 1 includes a second digital signature, the first application server requests the second network element to verify the legitimacy of the user holding the first user identifier (see step S212 for details). This second digital signature is generated by the terminal device using a private key issued by the second network element. The second network element holds the public key for verifying the second digital signature, while the first application server does not. Therefore, in this case, the first application server requests the second network element to verify the legitimacy of the user holding the first user identifier.

[0189] S211: The first application server sends a first verification request to the second network element.

[0190] The first verification request is used to request the second network element to verify the first user identifier, and the first verification request includes the first user identifier.

[0191] Optionally, the first user identification may include a first digital signature.

[0192] Optionally, the first verification request may include a second digital signature generated by the terminal device corresponding to the first user identifier. Optionally, the first verification request may also include replay attack verification information.

[0193] Optionally, the first verification request may include a service identifier.

[0194] S212. The second network element verifies whether the user holding the first user identifier is legitimate.

[0195] The verification method of the second network element is different according to the different contents included in the first user identifier.

[0196] In the first case, the first user identifier includes a character string used to identify the user, for example, only includes this character string. Exemplarily, after receiving the first verification request, the second network element determines the first user identifier and then verifies that the user holding the first user identifier is a legitimate user by searching for the association between the first user identifier, the service identifier, and the second user identifier stored in S202 or S206. For example, if the second network element finds the association between the first user identifier, the service identifier, and the second user identifier using the first user identifier, or using the second user identifier and the service identifier, the first user identifier is deemed to have been verified successfully.

[0197] In the second case, the service access request 1 includes an attribute corresponding to the first user identifier (e.g., validity period information). Exemplarily, the validity period information indicates the validity period of the first user identifier. Alternatively, the validity period information can be used to indicate that the first user identifier has a corresponding validity period, and the terminal device instructs the network to verify the validity period of the first user identifier through the validity period information. Alternatively, the validity period information carried by the service access request 1 is simply information indicating a request for validity period verification. In this case, the second network element searches for the stored validity period corresponding to the first user identifier and verifies whether the first user identifier is valid based on the validity period stored by the second network element. For example, if the second network element receives the verification request within the validity period of the first user identifier, the validity period verification of the first user identifier is considered to have passed. If the validity period attribute carried by the service access request 1 is simply information indicating a request for validity period verification, the second network element searches for the first user identifier with a corresponding validity period. If the validity period information carried by the service access request 1 indicates the validity period of the first user identifier, the second network element can directly use this validity period, or it can also search for the first user identifier with a corresponding validity period. Because the validity period carried in the verification request may be tampered with, in order to ensure the accuracy of the validity period verification, the second network element may search for the validity period cached in itself and perform verification based on the found validity period.

[0198] In a third case, the first user identifier includes a first digital signature. The second network element verifies the first user identifier based on the public key or shared secret key corresponding to the digital signature. If the verification succeeds, it is determined that the first user identifier is issued or created by the second network element.

[0199] In the fourth case, the first verification request also includes a second digital signature of the first user identifier. The second network element verifies the second digital signature using the public key in the user's public key certificate. If the second network element verifies the second digital signature using the public key, it can be determined that the user holding the first user identifier is a legitimate user. Furthermore, if the first verification request also carries replay attack verification information, the second network element verifies the replay attack verification information. For example, the replay attack information can be a timestamp, and the second network element verifies the timestamp. Exemplarily, if the second network element determines that the service request message 1 carrying the timestamp is the first verification, the verification is considered to be successful. Optionally, in addition to the first verification, the following condition needs to be met: the verification can only be considered successful if the time interval between the time corresponding to the timestamp and the verification time is less than a first threshold. Exemplarily, the first threshold can be a preset value. For example, the timestamp field of the user identity indicates the time of 00:00:00 on December 28, 2023, and the second network element performs verification at 01:00:00 on December 28, 2023. The preset threshold is 10 minutes, and the interval is greater than the preset threshold, so the verification fails. Alternatively, the second network element has previously verified a service request message 1 with the same timestamp. In this case, the service request message 1 being verified is considered to be initiated by an illegal user, or the user has been subjected to a replay attack. Therefore, it can be determined that the legitimacy verification of the first user has failed. It should be noted that the initial verification means that the service request message 1 carrying the first user identity has not been previously verified by the second network element, or in other words, the service request message 1 carrying the first user identity and the corresponding timestamp have not been previously verified by the second network element. After each verification, the second network element stores the service request message 1 carrying the first user identity and the corresponding timestamp for the current verification. If the timestamp corresponding to the service request message 1 carrying the first user identity in the current verification is the same as the timestamp of the service request message 1 carrying the first user identity previously stored by the second network element, the verification is considered to have failed.

[0200] The second network element sends the verification result to the first application server. For example, S212 may also include the step of the second network element sending a verification request response to the first application server. Exemplarily, the verification request response may include indication information of whether the user legitimacy verification has passed, for example, a 1-bit indication information.

[0201] Optionally, if the verification fails, the reason for the verification failure can also be indicated, for example, the second network element fails to find the association between the first user identifier and the service identifier and the second user identifier, or the validity period verification fails, or the first user identifier is not issued by the second network element, or the second digital signature is not generated by the terminal device (or the second digital signature verification fails), or the replay attack verification fails.

[0202] Optionally, before the second network element performs the verification in the third case and / or the fourth case, it may first verify the association between the first user identifier, the second user identifier, and the service identifier. For example, if the association verification passes, the digital signature verification in the third and fourth cases is further performed. Otherwise, the digital signature verification in the third and fourth cases is not performed, and the verification is determined to have failed. For an exemplary method for verifying the association between the first user identifier, the second user identifier, and the service identifier, see S206.

[0203] It should be noted that the above cases 2 to 4 are not mutually exclusive, and the second network element may perform one, several, or all of the verification processes.

[0204] Optionally, the first application server may send a service access response 1 to the terminal device, for example, step S213 in Figure 2. The service access response 1 is used to indicate whether the first application server accepts the service access request of the terminal device.

[0205] For example, if the user holding the first user identifier is verified to be legitimate, the first application server may determine to accept the service access request 1 of the user, otherwise, reject the service access request 1 of the user. It should be noted that if the first application server fails to verify the user's contract record, the service access request 1 of the user is rejected.

[0206] In this embodiment, the first application server only obtains the first user identifier generated for the user by the second network element. Depending on the service accessed by the user, the first user identifier generated by the second network element also varies. Furthermore, the first application server does not obtain the user's number or the association between the first user identifier and the user number. Therefore, the first application server cannot obtain personal privacy information such as the user's phone number, thereby preventing privacy leaks.

[0207] In another scenario, the same user signs up for or accesses services using different identity attributes. To prevent privacy leakage between different user identity attributes, the second network element creates different first user identifiers for the user based on the different user identity attributes. The following describes the steps of this implementation.

[0208] Correspondingly, in another implementation, the first request in step S201 further includes user identity attributes.

[0209] Among them, the user identity attribute is used to indicate the identity type with which the user requests to sign a contract for the service. For example, the identity attribute includes a personal identity attribute, or an organizational identity attribute. Among them, the personal identity attribute indicates that the user signs a contract or accesses a service in his personal identity, such as for personal entertainment or learning purposes; the organizational identity attribute indicates that the user signs a contract or accesses a service in his organizational identity attribute, such as for work purposes. When users sign contracts or access services with different identity attributes, the first application server can treat them as different users, that is, the signing or access behaviors between different identity attributes of the user are independent of each other. It should be noted that personal identity attributes and work unit identity attributes are only examples of user identity attributes, and are not limited to these two categories. Users can also have other user identity attributes.

[0210] Accordingly, based on the above steps S202-S212, the following actions may be added:

[0211] In step S202, the second network element creates a first user identifier. Exemplarily, when creating the first user identifier for a user, the second network element creates different first user identifiers based on the user's different identity attributes. For example, when a user requests to sign up for a service using their personal identity attributes, the second network element creates first user identifier #1 for the user. When the user requests to sign up for the same service using their corporate identity attributes, the second network element creates first user identifier #2 for the user. First user identifier #1 and first user identifier #2 are different. Optionally, the attribute information corresponding to the first user identifier may include user identity attributes.

[0212] In step S203, optionally, the second request may further include user identity attributes.

[0213] In step S205, optionally, the second response may further include user identity attributes.

[0214] In step S206, the second network element may optionally further store an association relationship between the user identity attribute and the first user identifier, the second user identifier, and the service identifier. Accordingly, the association relationship may also use the first user identifier, the service identifier, and the user identity attribute as a query method. For example, the stored association relationship may be searched using the first user identifier, the service identifier, and the user identity attribute.

[0215] In step S207, optionally, the first response may further include user identity attributes.

[0216] In step S209, optionally, the service access request 1 may further include user identity attributes.

[0217] In step S211, optionally, the first verification request may further include user identity attributes.

[0218] In this implementation, a user can subscribe to the same service multiple times using different identity attributes. The second network element can generate and issue different first user identifiers for different identity attributes of the same user, thereby protecting the privacy of the user from being leaked when accessing services with different identities.

[0219] In another scenario, the user can authorize the first application server to access other services by holding the first user identifier through access control attributes. The steps of this embodiment are described below.

[0220] Correspondingly, in one implementation, the first request in step S201 further includes a first access control attribute.

[0221] Among them, the first access control attribute is used to indicate whether the first application server is allowed to access other services on behalf of the user, for example, whether the first application server is allowed to access other services on behalf of the user in addition to the service requested to be signed. These other services may be services provided by the operator, or services provided by networks or application servers other than the operator. Optionally, the first access control attribute may also include the scope of other services that the first application server is allowed to access on behalf of the user. Exemplarily, the first access control attribute may be a service list, for example, an APP list, or a domain name or IP address list of the first application server, which lists the services that the user authorizes the first application server to access with the first user identity. Alternatively, further, the first access control attribute also includes tasks that can be performed when accessing each service.

[0222] For example, the service requested for contracting may be an intelligent assistant, which may be one of the services in the above service list. The intelligent assistant may help the user handle telephone services (e.g., answering or making calls), wherein answering or making calls is a task that the intelligent assistant can perform. For example, the first control attribute may further indicate the range of calls that the intelligent assistant is allowed to automatically dial or automatically answer. The range may be a time range, such as the time period during which the intelligent assistant is allowed to answer or make calls, or a number range, such as which phone numbers the intelligent assistant is allowed to answer or dial.

[0223] Accordingly, based on the above steps S202-S207, the following actions may be added:

[0224] In step S202, the attributes of the first user identifier may further include the first access control attribute in step S201.

[0225] In step S203, the second request may further include the first access control attribute in step S201. The first access control attribute is used to inform the first application server which services the user authorizes the first user identifier to represent and which users can access.

[0226] In step S205, the second response may also include a second access control attribute. Exemplarily, upon receiving the first access control attribute carried in the second request, the first application server may further determine whether to accept, or partially accept, the scope of services accessible on behalf of the user as indicated by the first access control attribute. For example, the first application server may accept all of the first access control attributes, in which case the second access control attribute is the same as the first access control attribute. Alternatively, the first application server may only accept some of the services indicated by the first access control attribute, for example, the first application server may only accept some of the services in the service list indicated by the first access control attribute, and these services constitute the second access control attribute.

[0227] In step S206, the second network element may further store the second access control attribute corresponding to the first user identifier when storing the association relationship between the first user identifier, the second user identifier, and the service identifier.

[0228] In step S207, the first response may further include a second access control attribute.

[0229] It should be noted that if a user requests the first application server to use the first user ID to access other services, the service access request 1 in step S209 may include access control attributes. For example, if the second application server provides or processes the other service, the first application server may use the user's first user ID to initiate a communication request to the second application server. The following describes the process of a user requesting the first application server to use the first user ID to access other services.

[0230] Accordingly, the following actions are added to steps S209-S213 during the service access process:

[0231] In step S209, the service access request 1 may further include a second access control attribute.

[0232] In step S211 , the first verification request may further include a second access control attribute.

[0233] In step S212, in addition to verifying whether the first user identifier is held by a legitimate user, the second network element also needs to verify whether the second access control attribute carried by the terminal device in the service access request 1 is correct. For example, the user may carry an illegal second access control attribute in the service access request 1, that is, the second access control attribute carried in the service access request 1 is different from the second access control attribute sent to the user by the network (for example, the second access control attribute carried in S208). For example, the user attempts to expand the scope of authorizing the first application server to hold the first user identifier to access other services on behalf of the user. At this time, in order to ensure that the other services that the user requests the first application server to access on behalf of the user are accepted by the first application server during the contract signing process, the second network element verifies the second access control attribute included in the first verification request.

[0234] Exemplarily, the second network element stores the association relationship between the first user identifier and the second user identifier and the service identifier in S206 (or S202), and the association relationship also includes the second access control attribute corresponding to the first identifier. The second network element finds the second access control attribute it stores, and if the content indicated by the second access control attribute includes the content indicated by the second access control attribute in the first verification request, it is considered that the second access control attribute verification has passed. For example, the content indicated by the second access control attribute is the same as the content indicated by the second access control attribute in the first verification request, or the content indicated by the second access control attribute includes the content indicated by the second access control attribute in the first verification request,

[0235] Exemplarily, the corresponding verification request response sent by the second network element to the first application server includes indication information that the second access control attribute verification has passed. After receiving the indication information, the first application server can determine whether the other services requested by the terminal device are accepted by the first application server during the contract signing process.

[0236] In another implementation, the second network element does not verify the second access control attribute carried in the first verification request. When the terminal device instructs the first application server to access a specific service on behalf of the user, the legitimacy of the accessed service is verified. This implementation is described in subsequent steps.

[0237] It should be noted that if a user requests that the first application server use the first user ID to access other services, the first application server must initiate a communication request to the application server providing the other services. For example, in this embodiment, the application server providing the other services is referred to as the second application server. After receiving the communication request from the first application server, the second application server verifies the legitimacy of the first application server, specifically verifying whether the first application server legally holds the first user ID. Therefore, the following steps must be performed after S213.

[0238] Optionally, after S213, the terminal device sends an indication message to the first application server, where the indication message is used to instruct the terminal device to instruct the first application server to access a service. For example, the indication message instructs the first application server to provide an intelligent assistant service. In the indication message, the terminal device instructs the intelligent assistant to register with the operator network with the first user identifier to answer or make calls, or instructs the intelligent assistant to log in to a website to perform a ticket booking operation. In this case, the telecommunications application server of the operator network, or the application server providing the ticket booking service, can be referred to as the second application server.

[0239] S214: The first application server sends a service access request 2 to the second application server.

[0240] Service access request 2 includes the first user identifier and, optionally, second access control attribute information. Exemplarily, the second access control attribute indicates that the first application server can initiate a communication request to the second application server. Exemplarily, the user authorizes the first application server to access service #1 using the first user identifier. Service #1 is processed by the second application server and is included in the service list indicated by the second access control attribute.

[0241] Optionally, the service access request 2 may further include a validity period attribute.

[0242] In this implementation, the first application server sets the business logic of the first application server according to the second access control attribute in the first user identifier of the user. For example, the second application server provides an intelligent assistant service, and the second access control attribute is used to indicate that the user allows the first application server to use the first user identifier to access the operator network to perform automatic dialing or automatic answering of calls. For example, the first application server sends a service request 2 to the telecommunications application server of the operator network (i.e., the second application server), and the service access request 2 carries the first user identifier of the user. The first application server uses the first user identifier to register with the operator network and wait for the call to be automatically answered. The second access control attribute can also indicate the time period for the first application server to answer or make a call, or the phone number for answering or making a call.

[0243] S215: The second application server sends a second verification request to the second network element. The content included in the second verification request refers to the content in the first verification request in step S211.

[0244] Optionally, the second verification request may carry the indication information in the service access request 2 in S214, where the indication information indicates the service that the terminal device instructs the first application server to access.

[0245] S216: The second network element verifies whether the first application server legally holds the first user identifier. For the verification method, see step S212.

[0246] Optionally, as another verification method, the second network element does not verify the legitimacy of the second access control attribute carried in the first verification request in S212, but instead verifies in this step whether the service that the terminal device instructs the first application server to access is within the service scope indicated by the second access control attribute, or in other words, whether it is in the list indicated by the second access control attribute. For example, the second network element finds the second access control attribute stored in it. If the service that the terminal device instructs the first application server to access is within the service scope indicated by the second access control attribute, then it is considered that the service that the terminal device instructs the first application server to access is accepted by the first application server during the contract signing process, and therefore the verification passes; otherwise, the verification fails.

[0247] Similarly, the second network element sends the verification result to the second application server. Exemplarily, the second network element sends a first user identity verification response message to the second application server. The authentication response message carries the authentication result, for example, a 1-bit indication where a 1 or true indicates successful authentication, and otherwise indicates a failed authentication.

[0248] S217: After receiving the verification result, the second application server sends a communication response to the first application server. Exemplarily, the communication response may be an acceptance of the communication response initiated by the first application server, or a rejection of the communication response initiated by the first application server.

[0249] In this embodiment, by setting an access control attribute for the first user identifier, determining whether the first application server is allowed to use the first user identifier provided by the user to access other services, the scope of use of the first user identifier is expanded. In addition, the user authorizes the first application server to access other services on the user's behalf through the first access control attribute, thereby improving the user experience.

[0250] FIG3 is a flow chart of a service subscription method provided by an embodiment of the present application, in which a terminal device initiates a service subscription request to an access and mobility management network element. The method includes the following steps:

[0251] S301: The terminal device sends a service subscription request 1 to the access and mobility management network element.

[0252] Service Sign-Up Request 1 is used to request a service subscription, or in other words, a terminal device requests access to a mobility management network element to initiate a service subscription request. For example, the service may be provided by a network or application server other than the operator, also known as a third-party service. Service Sign-Up Request 1 includes a service identifier, which can be used to identify the third-party service. For a description of the service identifier, see step S201 in Figure 2.

[0253] In one implementation, the terminal device sends a service subscription request 1 to an access and mobility management network element (eg, AMF) through a radio access network (eg, Radio Access Network, RAN).

[0254] Optionally, the terminal device has successfully registered with the operator's mobile communication network before sending the service contract request 1 to the access and mobility management network element. For example, the terminal device completes the authentication of the terminal device by the mobile network through the service request (Service Request) process. The access and mobility management network element saves the registration information of the terminal device, wherein the registration information includes the context information of the terminal device, and the context information of the terminal device includes the user permanent identification (SUPI) of the terminal device, and the SUPI is used to obtain the user number corresponding to the terminal device. The terminal device sends the service contract request 1 after accessing the user network. For example, the terminal device receives promotion information for a certain service, and the user presses a specified set of buttons in sequence to trigger a contract request for the service.

[0255] Optionally, the service subscription request 1 may be included in a non-access stratum signaling container (NAS Container).

[0256] S302: The access and mobility management network element sends a service subscription request 2 to the identity management network element.

[0257] Service subscription request 2 is used to request a service subscription. Alternatively, the access and mobility management network element requests the identity management network element to initiate a service subscription request. Alternatively, the access and mobility management network element requests the identity management network element to create a first user identifier, which is a user digital identity identifier or digital identity credential. Service subscription request 2 includes a service identifier. For a description of the first user identifier, refer to step S202 in Figure 2 . For a description of service subscription request 2, refer to the first request in step S202 in Figure 2 .

[0258] It should be noted that the identity management network element can be part of the unified data management network element. In other words, the identity management network element is not a separate network element, and its network functions are carried by the unified data management network element (UDM). Alternatively, the identity management network element can be an independent network element or network function (NF). In other words, the identity management network element or identity management network function is independent of the unified data management network element.

[0259] In one implementation, the service subscription request 2 includes a SUPI, which is used to identify the terminal device or user initiating the third-party service subscription request. In this implementation, the identity management network element uses the SUPI to identify the terminal device or user.

[0260] In another implementation, the identity management network element uses a user number to identify the terminal device or user. In this implementation, the service subscription request 2 may include a SUPI, or may include a user number.

[0261] (1) Service subscription request 2 includes a SUPI. In this implementation, the identity management network element can obtain the user number by the following method: the access and mobility management network element sends the user's SUPI to the identity management network element, and the identity management network element obtains the user number from the unified data management network element based on the SUPI. The unified data management network element maintains the corresponding relationship between the SUPI and the user number. For example, if the identity management network element and the unified data management network element are co-located, the identity management network element can obtain the user number from the unified data management network element based on the SUPI. This process is implemented internally in the unified data management network element.

[0262] (2) Service subscription request 2 includes a user number. In this implementation, before the access and mobility management network element sends service subscription request 2, the access and mobility management network element obtains user number information from the unified data management network element based on the SUPI. Exemplarily, the access and mobility management network element sends a user information request message to the unified data management network element, where the request message carries the SUPI. In response, the unified data management network element returns a user information response, where the user information response carries the user number information. The process of the access and mobility management network element obtaining the user number corresponds to S302a and S302b in FIG3 . After obtaining the user number, the user number is carried in service subscription request 2.

[0263] Optionally, the service subscription request 2 may carry both the user number and the SUPI.

[0264] S303: The identity management network element determines the first user identifier. The implementation method of this step is shown in S202 in FIG2 , and the identity management network element is the second network element in FIG2 .

[0265] S304: The identity management network element sends a service subscription request 3 to the application server (APP Server). The implementation method of this step is shown in S203 in Figure 2. The service subscription request 3 corresponds to the second request in Figure 2, and the application server corresponds to the first application server in Figure 2.

[0266] Exemplarily, the identity management network element may send a service subscription request 3 to the application server through the NEF.

[0267] S305: The application server sends a service signing request 4 to the service management function.

[0268] The service signing request 4 is used to request a service signing request, or to request the service management function to create an account for the user to access the service. The content of the service signing request 4 is as described in the service signing request 3.

[0269] S306: The service management function creates an account corresponding to the service for the user according to the first user identifier. For the implementation method of the service management function creating a user account according to the first user identifier, refer to S204 in FIG2 .

[0270] S307: The service management function sends a service signing response 4 to the application server.

[0271] In one implementation, the service signing response 4 includes indication information of whether the signing is successful. Exemplarily, the indication information may be a bit. Optionally, the service signing response 4 includes the first user identifier.

[0272] Optionally, if the user account creation fails in S306, the service management function sends a service signing response 4 to the application server, carrying a signing failure indication. For example, the reason for the creation failure is that the first digital signature of the first user identifier fails to be verified. Optionally, a failure cause value (Cause Value) may also be carried, indicating that the failure reason is that the first user identifier fails to be verified.

[0273] S308: The application server sends a service subscription response 3 to the identity management network element. For implementation, see S205 in Figure 2. The service subscription response 3 corresponds to the second response in Figure 2, and the application server corresponds to the first application server in Figure 2.

[0274] Exemplarily, the application server may send a service subscription response 3 to the identity management network element through the NEF.

[0275] S309: The identity management network element stores the association between the first user identifier and the service identifier and the second user identifier. For implementation methods, see S206 in Figure 2. The identity management network element corresponds to the second network element in Figure 2.

[0276] S310: The identity management network element sends a service subscription response 2 to the access and mobility management network element. For implementation, see S207 in Figure 2. Service subscription response 3 corresponds to the first response in Figure 2, and access and mobility management corresponds to the first network element in Figure 2.

[0277] S311: The access and mobility management network element sends a service subscription response 1 to the terminal device.

[0278] Among them, the service signing response 1 includes indication information on whether the signing is successful.

[0279] Optionally, the service subscription response 1 further includes a first user identifier. The terminal stores the obtained first user identifier for use in subsequent access to the service.

[0280] In another scenario, the same user subscribes to or accesses services with different identity attributes, and the second network element creates different first user identifiers for the user based on the different identity attributes of the user. The following describes the implementation steps of this solution.

[0281] In one implementation, the service subscription request 1 in step S301 further includes user identity attributes. For a description of the user identity attributes, refer to step S201 in FIG2 .

[0282] Accordingly, based on the above steps S302-S311, the following actions may be added:

[0283] In step S302, the service signing request 2 may further include user identity attributes.

[0284] In step S303, the identity management network element creates different first user identifiers for the same user when accessing the same service with different identity attributes.

[0285] In step S304, the service subscription request 3 may further include user identity attributes.

[0286] In step S305, the service signing request 4 may further include user identity attributes.

[0287] In step S307, the service signing response 4 may further include user identity attributes.

[0288] In step S308, the service signing response 3 may further include user identity attributes.

[0289] In step S309, the identity management network element may also store an association between the user identity attribute and the first user identifier, the second user identifier, and the service identifier. Accordingly, this association may also use the second user identifier, the service identifier, and the user identity attribute as a query method. For example, the stored association may be retrieved using the second user identifier, the service identifier, and the user identity attribute. For implementation, refer to step S206 in Figure 2.

[0290] In step S310, the service signing response 2 may further include user identity attributes.

[0291] In step S311, the service signing response 1 may further include user identity attributes.

[0292] In this implementation, a user can subscribe to the same service multiple times using different identity attributes. The second network element can generate and issue different first user identifiers for different identity attributes of the same user, thereby protecting the privacy of the user from being leaked when accessing services with different identities.

[0293] In another scenario, the user can authorize the first application server to access other services by holding the first user identifier through access control attributes. The steps of this embodiment are described below.

[0294] In one implementation, the service subscription request 1 in step S301 further includes a first access control attribute. For a description of the first access control attribute, refer to step S202 in FIG2 .

[0295] Accordingly, based on the above steps S302-S311, the following actions may be added:

[0296] In step S302, the service subscription request 2 may further include a first access control attribute.

[0297] In step S304, the service subscription request 3 may further include a first access control attribute.

[0298] In step S305, the service subscription request 4 may further include a first access control attribute.

[0299] In step S307, the service signing response 4 may further include a second access control attribute.

[0300] In step S308, the service signing response 3 may further include a second access control attribute.

[0301] In step S309, the identity management network element may store the second access control attribute corresponding to the first user identifier when storing the association relationship between the first user identifier, the second user identifier, and the service identifier.

[0302] In step S310, the service signing response 2 may further include a second access control attribute.

[0303] In step S311, the service signing response 1 may further include a second access control attribute.

[0304] In another implementation, the service management function in S305-S307 above can be part of the application server, or the network functions of the service management function can be hosted in the application server. In other words, the service management function and the application server are the same network element. In this implementation, the service management function can be merged with the application server, and the merged network element becomes the application server. After the merger, S305 and S307 in Figure 3 are implemented internally by the application server. The function of creating a user account in step S306 is implemented by the application server.

[0305] In method 300, a user initiates a service subscription request to the first application server via the access and mobility management network element. Alternatively, the user can initiate the service subscription request through the operator's portal. In this embodiment, the user's terminal device connects to the portal via the internet, the user selects the service to be subscribed, and initiates the subscription request. The following describes the implementation steps of this method with reference to Figure 4.

[0306] S401: The terminal device sends a service subscription request 1 to the operator portal.

[0307] For example, the terminal device is already connected to the Internet via a mobile communication network or other network and can access the operator's server. Optionally, the terminal device logs in to the operator's portal using a user number. The terminal device accesses the operator's portal interface, selects the service to be subscribed, and sends a service subscription request to the portal via the Internet.

[0308] The service contract signing request 1 carries a service identifier. For a description of the service identifier, see step S201 in FIG. 2 .

[0309] Optionally, the service contract request 1 also carries a user number, which is used to uniquely identify the user. The service contract request 1 may also not carry a user number. When the service contract request 1 does not carry a user number, the operator portal can obtain the user number based on the user's login information.

[0310] S402: The operator portal sends a request to create a first user identity to the identity management network element.

[0311] The request to create a first user identity carries a service identifier. The request to create a first user identity may also carry a user number. The user number may be obtained by the operator portal through the user's account information when logging into the portal, or may be carried in the service contract request 1 in S401.

[0312] S403: The identity management network element determines the first user identifier. The implementation method refers to step S202 in FIG2 , wherein the identity management network element corresponds to the second network element in FIG2 .

[0313] It should be noted that in steps S401-S403, the identity management network element completes the creation of the first user identity. The following process will use the created first user identity to sign up for a service. When a user initiates a service signing request through the operator portal, there are two implementation methods:

[0314] In the first implementation, the identity management network element initiates a service contract request to the application server. In this implementation, the subsequent contract signing process is the same as the process described in S304-S311 in Figure 3, except that the access and mobility management network element in Figure 3 is replaced with the operator portal. This document will not further describe the implementation steps corresponding to this implementation. It should be noted that in this implementation, the request to create a first user identity in step S402 can also be called a service contract signing request.

[0315] In the second implementation mode, the operator portal initiates a service subscription request to the application server. The implementation steps of the second implementation mode are described below with reference to FIG4 .

[0316] S404: The identity management network element stores the association relationship between the first user identifier and the service identifier and the user number. The implementation method can refer to step S309 in Figure 3. Optionally, the identity management network element can store the association relationship between the first user identifier and the service identifier and the user number in the unified user management network element. In this embodiment, after the identity management network element generates the first user identifier, it sends the first user identifier to the operator portal, and the operator portal uses the first user identifier to initiate a service contract request to the application server. The identity management network element will not receive an indication of whether the contract is successful. Therefore, in this embodiment, after the identity management network element generates the first user identifier, it stores the association relationship between the first user identifier and the service identifier and the user number.

[0317] S405: The identity management network element sends a create first user identity response to the operator portal.

[0318] The create first user identity response message includes the first user identity, which is created by the identity management network element in S403. Optionally, the create first user identity response message may also include a service identity.

[0319] S406: The operator portal sends a service subscription request 2 to the application server.

[0320] The service contract signing request 2 includes the first user identifier. Optionally, the service contract signing request 2 may also include a service identifier.

[0321] Exemplarily, after receiving a response message indicating the successful creation of the first user identifier, the operator portal determines the application server corresponding to the service for which contract is requested. For example, this can be determined based on the service identifier carried in service contract request 2, or based on an interface operation on the operator portal. The operator portal then sends service contract request 2 to the application server, where service contract request 2 carries the first user identifier and may also carry the service identifier.

[0322] S407: The application server sends a service signing request 3 to the service management function.

[0323] The service signing request 3 is used to request a service signing request, or to request the service management function to create an account for the user to access the service. The content of the service signing request 3 is as described in the service signing request 2.

[0324] S408: The service management function creates an account corresponding to the service for the user according to the first user identifier. The implementation method is shown in S204 in Figure 2. The service management function corresponds to the first application server in Figure 2.

[0325] S409: The service management function sends a service signing response 3 to the application server.

[0326] In one implementation, the service signing response 3 includes indication information of whether the signing is successful. Exemplarily, the indication information may be a bit. Optionally, the service signing response 4 includes the first user identifier.

[0327] Optionally, if the first digital signature of the first user identifier fails to be verified in S408, the service management function sends a service signing response to the application server carrying a signing failure indication. Optionally, a failure cause value (Cause Value) may also be carried, indicating that the failure cause is the failure of the first user identifier to be verified.

[0328] S410: The application server sends a service signing response 2 to the operator portal.

[0329] The service signing response 2 includes information indicating whether the signing was successful. Exemplarily, the indication information may be a single bit. For example, if the service signing response 2 carries a bit of 1 or true, it indicates that the service signing was successful. Conversely, if it carries a bit of 0 or false, or does not carry any value, it indicates that the service signing failed. The service signing response 2 also includes the first user identifier.

[0330] Optionally, the service signing response 2 also includes a service identifier.

[0331] S411: The operator portal sends a service signing response 1 to the terminal device.

[0332] The service signing response 1 includes information indicating whether the signing is successful. The content of the information is described in S410. The service signing response 1 also includes a first user identifier. The terminal stores the obtained first user identifier for subsequent use in accessing the service.

[0333] Optionally, the service signing response 1 may also include a user number.

[0334] In this embodiment, a user initiates a service subscription request through the operator's portal. During the subscription request, the first application server only obtains the first user identifier generated for the user by the identity management network element. It does not directly obtain the user's number or the association between the first user identifier and the user number. Therefore, the first application server is prevented from obtaining personal privacy information such as the user's phone number, thereby preventing privacy leaks.

[0335] Similar to the second implementation method in Figure 3, the identity management network element can also generate different first user identifiers for users who sign contracts or access the same service with different identities, avoiding privacy leakage when users sign contracts or access services with different identity attributes.

[0336] In one implementation, the service subscription request 1 in step S401 further includes user identity attributes. For a description of the user identity attributes, refer to step S201 in the second implementation in FIG2 .

[0337] Accordingly, based on the above steps S402-S411, the following actions may be added:

[0338] In step S402, the request to create a first user identification may further include user identity attributes.

[0339] In step S403, the identity management network element creates different first user identifiers for the same user when accessing the same service with different identity attributes.

[0340] In step S404, the identity management network element may further store the association between the user identity attribute and the first user identifier, the second user identifier, and the service identifier. For implementation, reference may be made to step S309 in the second implementation in FIG3 . Optionally, the identity management network element may store the association between the user identity attribute and the first user identifier, the second user identifier, and the service identifier in the unified user management network element.

[0341] In step S405, the create first user identification response may further include user identity attributes.

[0342] In step S406, the service subscription request 2 may further include user identity attributes.

[0343] In step S407, the service subscription request 3 may further include user identity attributes.

[0344] In step S409, the service signing response 3 may further include user identity attributes.

[0345] In step S410, the service signing response 2 may further include user identity attributes.

[0346] In step S411, the service signing response 1 may further include user identity attributes.

[0347] In this implementation, a user can subscribe to the same service multiple times using different identity attributes. The second network element can generate and issue different first user identifiers for different identity attributes of the same user, thereby protecting the privacy of the user from being leaked when accessing services with different identities.

[0348] Similar to the third implementation method in FIG3 , the user may also authorize the first application server to hold the first user identifier to access other services through access control attributes.

[0349] In one implementation, the service subscription request 1 in step S401 further includes access control attributes. For a description of the access control attributes, refer to step S202 in FIG2 .

[0350] Accordingly, based on the above steps S402-S411, the following actions may be added:

[0351] In step S402, the request to create a first user identification may further include an access control attribute.

[0352] In step S403, the attribute information of the first user identifier may further include access control attributes.

[0353] In step S404, when the identity management network element stores the association between the first user identifier, the second user identifier, and the service identifier, it may also store the access control attributes corresponding to the first user identifier. For implementation, refer to step S309 in Figure 3 . Alternatively, the identity management network element may store the access control attributes of the first user identifier in the unified user management network element. Service subscription request 2 may also include access control attributes.

[0354] In step S405, the create first user identification response may further include access control attributes.

[0355] In step S406, the service subscription request 2 may further include access control attributes.

[0356] In step S407, the service contract signing request 3 may further include access control attributes.

[0357] In step S409, the service signing response 3 may further include access control attributes.

[0358] In step S410, the service signing response 2 may further include access control attributes.

[0359] In step S411, the service signing response 1 may further include access control attributes.

[0360] In another implementation, the service management function in steps S407-S409 can be part of an application server, or the network functions of the service management function can be hosted in the application server. In other words, the service management function and the application server are the same network element. In this implementation, the service management function can be merged with the application server, and the merged network element becomes the application server. After the merger, steps S407 and S409 in Figure 4 are implemented internally by the application server. The function of creating a user account in step S408 is implemented by the application server.

[0361] The following describes the process of a user accessing a service using the first user ID with reference to FIG. 5 .

[0362] S501: The terminal device establishes a session connection with the application server. After the session connection is established, the terminal device can communicate with the application server.

[0363] S502: The terminal device sends a service access request message to the application server.

[0364] In one implementation, when a user wants to access a service, the application client or browser on the terminal device sends a service access request message to the application server, wherein the service access request message includes the user's first user identifier. For the content of the first user identifier, see step S202 in FIG. 2 .

[0365] S503: After receiving the service access request message, the application server sends a service access control request message to the service management function.

[0366] The access control request message carries the user's first user identifier, and the content of the first user identifier is the same as that in S502. The access control request message is used to request the service management function to verify the user's contract record.

[0367] S504: The business management function verifies the user's contract record.

[0368] In one implementation, the service management function verifies the user's contract record by using the first user identifier to search for the user's service contract record. For example, the service management function uses a character string in the first user identifier that uniquely identifies the user as the user account number to search for the user's service contract record. For details on the verification method, see the process of verifying the user's contract record in step S210 of FIG. 2 .

[0369] It should be noted that if the contract verification passes, S505 is executed; if the verification fails, S509 is executed directly after S504.

[0370] S505: The service management function verifies the first user identifier of the user, verifies whether the first user identifier is issued by a legal identity management network element, and / or verifies the validity period attribute of the first identifier. For the verification method, refer to the part of verifying the first user identifier in step S210 in Figure 2.

[0371] It should be noted that if the service management function needs to request the identity management network element to verify the first user identifier (for specific scenarios, refer to the description of step S210 in Figure 2), then S506-S508 are executed after S505. Otherwise, the service management function can verify the first user identifier on its own. The verification method can refer to the description of step S210 in Figure 2. It should be noted that if the service management function verifies the first user identifier on its own, S506-S508 are not executed, and S509 is executed directly after S505.

[0372] S506: The service management function sends a first user identification verification request to the identity management network element.

[0373] The first user identification verification request includes the first user identification.

[0374] The content of the first user identification verification request refers to the first verification request in step S211 in FIG. 2 , or in other words, the first user identification verification request corresponds to the first verification request in FIG. 2 .

[0375] S507: The identity management network element verifies the first user identifier and the legitimacy of the user holding the first user identifier. For the verification method, see step S212 in FIG2 .

[0376] S508: The identity management network element sends a first user identification verification response to the service management function.

[0377] The first user identification verification response includes indication information of whether the verification is passed.

[0378] Optionally, the first user identification verification response may further include the first user identification.

[0379] Optionally, the first user identity verification response may further include a service identity.

[0380] S509: The service management function sends an access control response to the application server.

[0381] In one implementation, the service management function sends an access control response message to the application server, indicating whether the user identity authentication is passed.

[0382] Optionally, the access control response may further include the first user identifier.

[0383] Optionally, the access control response may also include a service identifier.

[0384] S510: The application server sends a service access response to the terminal device.

[0385] Exemplarily, the application server determines whether to grant the user service access based on the service access control response. If both the user's subscription record verification and the first user identity verification pass, the application server may determine to accept the user's service access request; otherwise, it may deny the user's service access request. The application server sends a service access response message to the terminal, which carries information indicating whether to grant or deny access.

[0386] In this embodiment, the user accesses the service using a first user identifier generated by the operator's identity management network element. The first application server does not directly obtain the user number, nor does it obtain the association between the first user identifier and the user number. Therefore, the first application server is prevented from obtaining the association between the user number and service access information, thereby preventing privacy leakage.

[0387] In another implementation, the service management function can be part of the application server, or the network functions of the service management function can be hosted in the application server. In other words, the service management function and the application server are the same network element. In this implementation, the service management function can be merged with the application server, and the merged network element becomes the application server. After the merger, S503 and S509 in Figure 5 are implemented internally by the application server. The functions in steps S504 and S505 are implemented by the application server. The interaction between S506 and S508 is also completed by the identity management network element and the application server.

[0388] In another implementation, the user authorizes the first application server to access other services on behalf of the user through access control attributes. The implementation steps of this embodiment are described below with reference to FIG6 .

[0389] S601: The terminal device establishes a session connection with the first application server. After the session connection is established, the terminal device can communicate with the first application server. For details, see S501. For example, the first application server can be an intelligent assistant server.

[0390] S602: The terminal device sends a service access request 1 to the first application server. For implementation, refer to step S502 in FIG5 . The service access request 1 corresponds to the service access request in FIG5 .

[0391] S603: The first application server verifies the user's subscription record. For implementation methods, see step S504 in FIG5 .

[0392] S604: The first application server verifies the first user identifier of the user. For the method of verifying the first user identifier, refer to step S505 of FIG. 5 .

[0393] S605: The first application server sends a first user identification verification request 1 to the identity management network element. For implementation, see step S506 in Figure 5. The first user identification verification request 1 corresponds to the first user identification verification request in Figure 5.

[0394] S606: The identity management network element verifies the first user identifier of the user. For the verification method, see step S507 in FIG5 .

[0395] S607: The identity management network element sends a first user identity verification response 1 to the first application server. For the content of the first user identity verification response 1, refer to the first user identity verification response in step S508 in FIG.

[0396] S608: The first application server sends a service access response 1 to the terminal device. For the content of the service access response 1, refer to the service access response in step S510 in FIG. 5 .

[0397] S609: The first application server sends a service access request 2 to the second application server. For implementation, see step S214 in Figure 2. The service access request 2 corresponds to the service access request 2 in step S214 in Figure 2.

[0398] Optionally, before S609, the terminal device sends an indication message to the first application server. The indication message is used to instruct the terminal device to instruct the first application server to access a service. For example, the terminal device instructs the first application server to provide an intelligent assistant service. In the indication message, the terminal device instructs the intelligent assistant to access the second application server to perform a ticket booking service. The second application server provides the ticket booking service.

[0399] S610: The second application server sends a first user identification verification request 2 to the identity management network element. For implementation, see step S215 in Figure 2. The first user identification verification request 2 corresponds to the second verification request in step S215 in Figure 2.

[0400] S611: The identity management network element verifies the first user identifier of the user. For the implementation method, see step S216 in FIG2 .

[0401] S612: The identity management network element sends a first user identity verification response 2 to the second application server, where the first user identity verification response 2 includes indication information of whether the verification is successful.

[0402] Optionally, the first user identification verification response may further include the first user identification.

[0403] Optionally, the first user identity verification response may further include a service identity.

[0404] S613: After receiving the first user identity verification response 2, the second application server sends a service access request response 2 to the first application server. Exemplarily, the service access request response 2 may accept the service access request initiated by the first application server, or may reject the service access request initiated by the first application server. After accepting the service access request from the first application server, the second application server may communicate with the first application server.

[0405] After a user successfully signs up for a service, they can use the operator's identity management network element to generate and issue a first user ID for them to access the signed service within the validity period. If the user wishes to renew their contract before the expiration date, they can use the first user ID to initiate service renewal. The service renewal process is explained below with reference to Figure 7.

[0406] S701: The terminal device sends a service renewal request to the first network element.

[0407] Illustratively, the first network element may be an operator portal or an access and mobility management network element.

[0408] In one implementation, the service renewal request carries the service identifier and the first user identifier issued by the second network element when the contract was signed. The terminal device determines that the first user identifier is about to expire based on the validity period corresponding to the first user identifier. Exemplarily, the terminal device can determine that the first user identifier is about to expire by determining the time interval between the moment when the first user identifier indicated by the validity period attribute expires and the current moment and the size of a specified threshold. For example, assuming the threshold is 24 hours, if the terminal device determines that the difference between the current moment and the moment indicated by the validity period is less than 24 hours, it sends a service renewal request to the first network element.

[0409] S702: The first network element sends a first user identifier verification request to the identity management network element, requesting the identity management network element to verify the first user identifier in the service renewal request.

[0410] In one implementation, the first user identity verification request message includes the first user identity. For the verification method, see S212.

[0411] S703: The identity management network element sends a first user identity verification response to the first network element.

[0412] In one implementation, the first user identity verification response carries an indication of whether the first user identity verification is successful. Exemplarily, the indication information can be a bit. If the first user identity verification response message carries bit 1 or true, it indicates that the first user identity verification is successful. Otherwise, if it carries 0 or false, or does not carry any value, it indicates that the verification failed.

[0413] S704: The first network element sends a first user identifier validity period update request to the identity management network element.

[0414] In one implementation, the first user identity update request is used to request the identity management network element to update the validity period attribute information in the first user identity, wherein the first user identity update request carries the first user identity and the new validity period attribute information.

[0415] Optionally, S704 and S702 may be implemented in combination. For example, the service renewal request sent by the terminal device to the first network element carries the new validity period attribute information of the first user identifier.

[0416] S705: The identity management network element updates the validity period attribute in the first user identifier and digitally signs the first user identifier again.

[0417] Exemplarily, the identity management network element replaces the validity period attribute information corresponding to the original first user identifier with the new validity period attribute information carried in S704, and then digitally signs the first user identifier.

[0418] S706: The identity management network element sends a first user identifier validity period update response message to the first network element.

[0419] In one implementation, the first user identifier validity period update response message carries the first user identifier whose validity period has been updated in S705, that is, the first digital signature of the updated first user identifier.

[0420] Optionally, the first user identifier validity period update response message further carries a new validity period corresponding to the first user identifier.

[0421] S707: After receiving the response message indicating that the validity period of the first user identifier has been successfully updated, the first network element sends a response message indicating that the service subscription has been successfully completed to the terminal device. The response message carries a successful subscription indication and the first user identifier with an updated validity period.

[0422] S708: If the user does not renew the service before the validity period of the first user identifier expires, the first network element checks the first user identifier and filters out expired first user identifiers.

[0423] S709: The first network element determines the corresponding application server based on the service identifier corresponding to the expired first user identifier, and sends a service termination request message to the application server, wherein the service termination request message carries the service identifier and the expired first user identifier. After receiving the service termination request message, the application server deletes the user account information corresponding to the first user identifier.

[0424] S710: If the user does not renew the service before the first user ID expires, the identity management network element will filter out the expired first user ID and clear the association between the first user ID, the second user ID and the service ID. For the content of the second user ID, refer to the description of S201 in Figure 2.

[0425] S711: The terminal device periodically clears expired first user identifiers. For example, the terminal device uses T as a first user identifier validity check period, checks whether the first user identifier is within its corresponding validity period, and clears expired first user identifiers.

[0426] In this embodiment, the terminal device can extend the validity period of the first user identifier by renewing the third-party service before the validity period of the first user identifier expires, and the character string that uniquely identifies the user in the original first user identifier is not changed when the validity period attribute is updated.

[0427] Figures 8 and 9 are schematic diagrams of possible communication devices provided in embodiments of the present application. These communication devices can be used to implement the functions of the terminal device, identity management network element, or application server in the above method embodiments, thereby also achieving the beneficial effects of the above method embodiments. In embodiments of the present application, the communication device can be the above device or a module (such as a chip) in the above device.

[0428] As shown in Figure 8, a communication device 800 includes a processing unit 810 and a transceiver unit 820. The communication device 800 is used to implement the functions of a terminal device, an identity management network element, or an application server in the method embodiments shown in any of Figures 2, 3, 4, 5, 6, or 7.

[0429] When the communication device 800 is used to implement the function of the identity management network element in the method embodiment shown in the above figure:

[0430] The transceiver unit 820 is used to receive a first request, where the first request includes a service identifier, which is used to identify the service that the user requests to sign up for; the processing unit 810 is used to determine a first user identifier, where the first user identifier is used to identify the user, and the first user identifier is different from another first user identifier created for another service that the user requests to sign up for, and the first user identifier is used to request to sign up for the service, and the first user identifier is also used to request access to the service.

[0431] When the communication device 800 is used to implement the functions of the terminal device in the method embodiment shown in the above figures:

[0432] The processing unit 810 is used to send a service contract signing request to the first network element through the transceiver unit 820, where the service contract signing request is used to request signing the service, and the service contract signing request includes a service identifier, which is used to indicate the service that the user requests to sign; the processing unit 810 is used to receive a service contract signing response through the transceiver unit 820, where the service contract signing response is used to indicate that the service signing is successful, and the service contract signing response includes a first user identifier, which is used to access the service, and the first user identifier is different from another first user identifier corresponding to another service requested to be accessed by the user.

[0433] When the communication device 800 is used to implement the function of the application server in the method embodiment shown in the above figures:

[0434] The processing unit 810 is used to receive a service access request through the transceiver unit 820, where the service access request includes a first user identifier, where the first user identifier is used to access the service, and where the first user identifier is different from another first user identifier corresponding to another service that the user requests to access; the processing unit 810 is used to send a verification request to the first network element through the transceiver unit 820, where the verification request is used to request the first network element to verify the first user identifier, where the first user identifier is generated by the first network element, and where the verification request includes the first user identifier.

[0435] A more detailed description of the processing unit 810 and the transceiver unit 820 can be directly obtained by referring to the relevant description in the method embodiment shown in the above figures, and is not repeated here.

[0436] As shown in Figure 9, communication device 900 includes a processor 910 and an interface circuit 920. Processor 910 and interface circuit 920 are coupled to each other. It is understood that interface circuit 920 can be a transceiver or an input / output interface. Optionally, communication device 900 may also include a memory 930 for storing instructions executed by processor 910, input data required by processor 910 to execute instructions, or data generated after processor 910 executes instructions.

[0437] When the communication device 900 is used to implement the method shown in the above figures, the processor 910 is used to implement the functions of the above processing unit 910, and the interface circuit 920 is used to implement the functions of the above transceiver unit 920.

[0438] When the communication device is a chip implemented in the device, the chip implements the functions of the corresponding device in the method embodiment. The chip receives information from other modules in the device (such as a radio frequency module or antenna), where the information is sent to the device by other modules; or the chip sends information to other modules in the device (such as a radio frequency module or antenna).

[0439] When the above-mentioned communication device is a module applied to a mobile node, the module implements the functions of the mobile node in the above-mentioned method embodiment. The module receives information from other modules (such as a radio frequency module or antenna), and the information is sent by the terminal to the device; or the module sends information to other modules in the device (such as a radio frequency module or antenna), and the information is sent by the device to the terminal. The module here can be the baseband chip of the device, or it can be a DU or other module. The DU here can be a DU under the open radio access network (O-RAN) architecture.

[0440] It is understood that the processor in the embodiments of the present application may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.

[0441] This application provides another example of a communication device, which includes at least one processor and at least one memory, the at least one processor and the at least one memory being coupled together, the at least one memory being used to store instructions. When the instructions are executed by the at least one processor, the communication device performs the method in the above-described embodiment. For example, as shown in FIG9 , a communication device 900 includes a processor 910 and a memory 930. The processor 910 and the memory 930 are coupled together, and the memory 930 stores instructions. When the instructions stored in the memory 930 are executed by the processor 910, the communication device 900 performs the method performed by the terminal device or network device in the above-described embodiment.

[0442] It should be understood that the processor 910 and the memory 930 may also be integrated together, such as in one chip.

[0443] The method steps in the embodiments of the present application can be implemented in hardware or in software instructions that can be executed by a processor. The software instructions can be composed of corresponding software modules, and the software modules can be stored in random access memory, flash memory, read-only memory, programmable read-only memory, erasable programmable read-only memory, electrically erasable programmable read-only memory, registers, hard disk, mobile hard disk, CD-ROM or any other form of storage medium well known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. The storage medium can also be an integral part of the processor. The processor and storage medium can be located in an ASIC. In addition, the ASIC can be located in a network device or a terminal. The processor and storage medium can also exist in a network device or a terminal as discrete components.

[0444] In the above embodiments, all or part of the embodiments may be implemented using software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments may be implemented in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are performed in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, or other programmable device. The computer program or instructions may be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program or instructions may be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium, such as a floppy disk, hard disk, or magnetic tape; an optical medium, such as a digital video disk; or a semiconductor medium, such as a solid-state drive. The computer-readable storage medium may be a volatile or nonvolatile storage medium, or may include both volatile and nonvolatile types of storage media.

[0445] In the various embodiments of the present application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.

[0446] In this application, "at least one" means one or more, and "more" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. In the text description of this application, the character " / " generally indicates that the previous and next associated objects are in an "or" relationship; in the formula of this application, the character " / " indicates that the previous and next associated objects are in a "division" relationship. "Including at least one of A, B and C" can mean: including A; including B; including C; including A and B; including A and C; including B and C; including A, B and C.

[0447] It is understood that the various numbers used in the embodiments of this application are merely for ease of description and are not intended to limit the scope of the embodiments of this application. The order of the sequence numbers of the above-mentioned processes does not necessarily imply a specific order of execution; the order of execution of the processes should be determined by their functions and inherent logic.

Claims

1. A business processing method, characterized in that: The method comprises: receiving a first request, where the first request includes a service identifier, where the service identifier is used to identify the service that the user requests to sign up for; Determine a first user identifier, where the first user identifier is used to identify the user. The first user identifier is different from another first user identifier created for another service that the user requests to sign up for. The first user identifier is used to request to sign up for the service. The first user identifier is also used to request access to the service.

2. The method according to claim 1, characterized in that The receiving the first request includes: The first request is received from a first network element, where the first network element is an access and mobility management network element, or an operator portal.

3. The method according to claim 1 or 2, characterized in that The method further comprises: Sending a second request to the first application server, where the second request includes the first user identifier and is used to request a subscription for the service, and the first application server is configured to process the service; A second response is received from the first application server, where the second response is used to indicate whether the service requested by the user to sign up is successfully signed up.

4. The method according to claim 3, characterized in that The method further comprises: receiving a first authentication request from the first application server, where the first authentication request includes the first user identifier; The user is verified as a legitimate user based on the first user identifier.

5. The method according to any one of claims 1 to 4, characterized in that: The first request includes a second user identifier, where the second user identifier is a user number of the user and / or a subscriber permanent identifier (SUPI).

6. The method according to claims 1-5, characterized in that The method further comprises: A first response is sent to the first network element, where the first response is used to indicate that the service requested by the user is successfully signed up, and the first response includes the first user identifier.

7. The method according to claim 6, characterized in that The first response further includes a validity period, where the validity period is used to indicate the validity period of the first user identifier. When the validity period expires, the first user identifier is unusable.

8. The method according to any one of claims 1 to 7, characterized in that: The method further comprises: Determine the validity period corresponding to the first user identifier.

9. The method according to claim 7 or 8, characterized in that The method further comprises: After receiving the first verification request from the first application server, it is determined whether the first application server holds a valid first user identifier for accessing the service according to the validity period.

10. The method according to claim 5, characterized in that The method further comprises: Storing the association between the first user identifier and the service identifier and the second user identifier; After receiving the first verification request from the first application server, the server verifies that the user holding the first user identifier is a legitimate user based on the association relationship between the first user identifier and the service identifier and the second user identifier.

11. The method according to any one of claims 1 to 10, characterized in that: The first request further includes a user identity attribute, where the user identity attribute is used to indicate the identity type used by the user requesting to subscribe to the service.

12. The method according to claim 11, characterized in that The determining of the first user identifier includes: The first user identifier created for the user identity attribute of the user and used for requesting to subscribe to the service is different from another first user identifier created for another identity attribute of the user and used for requesting to subscribe to the service.

13. The method according to any one of claims 1 to 12, characterized in that: The first user identification includes a first digital signature, and the method further includes: After receiving the first verification request from the first application server, whether the first user identification is legal is verified according to the first digital signature.

14. The method according to claim 4, characterized in that The first verification request further includes a second digital signature corresponding to the first user identifier, and the method further includes: After receiving the verification request including the second digital signature corresponding to the first user identifier, verify whether the first user identifier is legal based on the second digital signature.

15. The method according to claim 14, characterized in that The first verification request further includes replay attack verification information corresponding to the first user identifier, and the method further includes: After receiving the verification request including the replay attack verification information corresponding to the first user identifier, it is verified whether the user holding the first user identifier is a legitimate user according to the replay attack verification information.

16. The method according to any one of claims 1 to 15, characterized in that: The first request also includes a first access control attribute, which is used to indicate whether the user authorizes the first application server to hold the first user identifier to access other services on behalf of the user, and / or the scope of authorizing the first application server to access other services on behalf of the user.

17. The method according to claim 16, characterized in that The second response received from the first application server also includes a second access control attribute, which is used to indicate whether the first application server accepts the first application server holding the first user identifier to access other services, and / or the scope of the first application server accepting the first application server to access other services.

18. The method according to claim 17, characterized in that The first response sent to the first network element also includes the second access control attribute.

19. The method according to claim 17 or 18, characterized in that The method further comprises: After receiving the verification request including the second access control attribute, it is determined based on the second access control attribute whether the first application server legally holds the first user identifier to access the other service.

20. The method according to any one of claims 17 to 19, characterized in that: The method further comprises: A second verification request is received from a second application server, where the second verification request is used to verify whether the first application server legally holds the first user identifier, and the second verification request includes the first user identifier.

21. A business processing method, characterized in that: The method comprises: Sending a service subscription request to the first network element, where the service subscription request is used to request subscription for the service, and the service subscription request includes a service identifier, where the service identifier is used to indicate the service that the user requests subscription for; A service signing response is received, where the service signing response is used to indicate that the service signing is successful. The service signing response includes a first user identifier, where the first user identifier is used to access the service, and the first user identifier is different from another first user identifier corresponding to another service requested to be accessed by the user.

22. The method according to claim 21, characterized in that The service signing request includes a first access control attribute, which is used to indicate that the user authorizes the first application server to access other services on behalf of the user, and / or authorizes the first application server to access the scope of other services on behalf of the user, and the first application server is used to process the service.

23. The method according to claim 21 or 22, characterized in that The service subscription request includes a user identity attribute, and the user identity attribute is used to indicate the identity type used by the user requesting to subscribe to the service.

24. The method according to any one of claims 21 to 23, characterized in that: The method further comprises: A service access request is sent to the first application server, where the service access request is used to request access to the service, and the service access request includes the first user identifier.

25. The method according to any one of claims 21 to 24, characterized in that: The service access request includes a second access control attribute obtained from the service signing response, where the second access control attribute is used to indicate whether the first application server accepts the first application server holding the first user identifier to access other services, and / or the scope of the first application server's access to other services.

26. The method according to any one of claims 21 to 25, characterized in that: The service access request includes the validity period obtained from the service signing response, and the validity period is used to determine whether the first user identifier is valid.

27. The method according to any one of claims 21 to 26, characterized in that: The method comprises: Sending a third request to the first network element, where the third request is used to request renewal of the service, and the third request includes the first user identifier; A third response sent from the first network element is received, where the third response is used to indicate whether the renewal of the third-party service is successful, and the third response includes the first user identifier whose validity period has been updated.

28. The method according to claim 27, characterized in that The sending the third request to the first network element includes: According to the determination that the first user identifier is about to expire during the validity period, the third request is sent before the validity period of the first user identifier expires.

29. A business processing method, characterized in that: The method comprises: receiving a service access request, the service access request including a first user identifier, the first user identifier being used to access the service, the first user identifier being different from another first user identifier corresponding to another service requested by the user to access; A verification request is sent to the first network element, where the verification request is used to request the first network element to verify the first user identifier, where the first user identifier is generated by the first network element, and the verification request includes the first user identifier.

30. The method according to claim 29, wherein The first user identification includes a first digital signature, and the first digital signature is used to verify whether the first user identification is legal.

31. The method according to claim 29 or 30, characterized in that The service access request includes a validity period corresponding to the first user identifier, where the validity period is used to indicate a validity period of the first user identifier. When the validity period expires, the first user identifier is unavailable.

32. The method according to any one of claims 29 to 31, characterized in that: The service access request includes an access control attribute, where the access control attribute is used to indicate whether the first application server accepts the first application server holding the first user identifier to access other services, and / or the first application server accepts the scope of the first application server's access to the other services, and the first application server is used to process the service.

33. The method according to any one of claims 29 to 32, characterized in that: The verification request further includes the access control attribute, which is used to determine whether the first application server legally holds the first user identifier to access the other services.

34. The method according to any one of claims 29 to 33, characterized in that: The verification request also includes a second digital signature, which is created by the user and is used to verify whether the first user identification is legal.

35. The method according to any one of claims 29 to 34, characterized in that: The verification request further includes replay attack verification information corresponding to the first user identifier, and the replay attack verification information is used to verify whether the user holding the first user identifier is a legitimate user.

36. The method according to any one of claims 29 to 35, characterized in that: The verification request further includes the validity period, which is used to determine whether the first application server holds a valid first user identifier for accessing the service.

37. The method according to any one of claims 29 to 36, characterized in that: The method further comprises: A verification response is received from the first network element, where the verification response is used to indicate that the first user identifier has been successfully verified.

38. The method according to any one of claims 29 to 37, characterized in that: The method further comprises: The service access request is sent to a second application server, where the service access request is used to request access to the other service, and the second application server is used to process the other service.

39. A communication system, characterized in that: It includes an identity management network element and a terminal device, the identity management network element is used to implement the method according to any one of claims 1-20 or the method according to any one of claims 29-38, and the terminal device is used to implement the method according to any one of claims 21-28.

40. A communication device, characterized in that: The method comprises a unit or module for executing the method according to any one of claims 1 to 20, or comprises a unit or module for executing the method according to any one of claims 21 to 28, or implements a unit or module for implementing the method according to any one of claims 29 to 38.

41. A readable storage medium, characterized in that The readable storage medium stores a program, and when the program is executed by the communication device, it implements the method according to any one of claims 1 to 20, or implements the method according to any one of claims 21 to 28, or is used to implement the method according to any one of claims 29 to 38.

42. A computer program product, characterized in that The computer program product includes instructions, which, when executed on a processor, cause the processor to execute the method according to any one of claims 1 to 20, or execute the method according to any one of claims 21 to 28, or implement the method according to any one of claims 29 to 38.

Citation Information

Patent Citations

  • System, device and method for identity security authentication

    CN101291220A

  • Interaction method and system based on pseudo code and pseudo code service platform

    CN110535823A

  • Registration method, privacy server, service information server and registration system

    CN113536367A

  • Information management system, method and device

    CN115720137A

  • System and method for tracking and auditing data access in a network environment

    US9462014B1