Communication method, first entity, second entity, communication system, and storage medium
The first entity processes the request of the second entity according to the perception-related policy of the resource owner and generates a token to implement authorization, thereby solving the problem that the resource owner cannot process the authorization in time and improving the efficiency of perception communication.
Patent Information
- Application Number
- PCT/CN2024/082312
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-18
- Publication Date
- 2025-09-25
AI Technical Summary
In the perception communication scenario, when the resource owner cannot process the authorization in time, the entity used to initiate the perception request cannot obtain authorization in time, resulting in low perception communication efficiency.
The first entity receives information sent by the second entity, performs authorization processing according to the resource owner's perception-related policy, generates a token and sends it to the second entity to achieve authorization.
The efficiency of the sensing communication is improved, so that the second entity can obtain the authorization of the resource owner in a timely manner.
Smart Images

Figure CN2024082312_25092025_PF_FP_ABST
Abstract
Description
Communication method, first entity, second entity, communication system and storage medium Technical Field
[0001] The present disclosure relates to the field of communication technologies, and in particular to a communication method, a first entity, a second entity, a communication system, and a storage medium. Background Art
[0002] Wireless sensing technology can acquire sensing data about a target without actually contacting it. This data can be used to analyze the target and obtain relevant information about it. In sensing communication scenarios, the entity initiating the sensing request must obtain authorization from the resource owner.
[0003] Summary of the Invention
[0004] In the perception communication scenario, when the resource owner cannot process the authorization in time, the entity used to initiate the perception request cannot obtain authorization from the resource owner in time, which is a technical problem that needs to be solved.
[0005] The embodiments of the present disclosure provide a communication method, a first entity, a second entity, a communication system, and a storage medium.
[0006] According to the first aspect of an embodiment of the present disclosure, a communication method is proposed, which is executed by a first entity. The method includes: receiving first information sent by a second entity, where the first information is used to request authorization from a resource owner; and performing authorization processing based on the first information and the perception-related policy corresponding to the resource owner.
[0007] According to the second aspect of an embodiment of the present disclosure, a communication method is proposed, which is executed by a second entity. The method includes: sending first information to a first entity, where the first information is used to request authorization from a resource owner, and the first entity is used to perform authorization processing based on the first information and the perception-related policy corresponding to the resource owner.
[0008] According to the third aspect of an embodiment of the present disclosure, a first entity is proposed, including: a transceiver module, receiving first information sent by a second entity, wherein the first information is used to request authorization from a resource owner; and a processing module, performing authorization processing based on the first information and the perception-related policy corresponding to the resource owner.
[0009] According to the fourth aspect of an embodiment of the present disclosure, a second entity is proposed, including: a transceiver module, used to send first information to a first entity, the first information is used to request authorization from a resource owner, and the first entity is used to perform authorization processing based on the first information and the perception-related policy corresponding to the resource owner.
[0010] According to a fifth aspect of an embodiment of the present disclosure, a first entity is proposed, comprising: one or more processors; wherein the processor is configured to execute the communication method of the first aspect.
[0011] According to a sixth aspect of an embodiment of the present disclosure, a second entity is proposed, comprising: one or more processors; wherein the processor is configured to execute the communication method of the second aspect.
[0012] According to a seventh aspect of an embodiment of the present disclosure, a communication system is proposed, including a first entity and a second entity, wherein the first entity is configured to implement the communication method of the first aspect, and the second entity is configured to implement the communication method of the second aspect.
[0013] According to an eighth aspect of an embodiment of the present disclosure, a storage medium is proposed, which stores instructions, and is characterized in that when the instructions are executed on a communication device, the communication device executes the communication method of the first aspect or the second aspect.
[0014] Through the embodiment of the present disclosure, the second entity requests the first entity to obtain authorization from the resource owner. The first entity can perform authorization processing based on the first information and the perception-related policy corresponding to the resource owner, so that the second entity can obtain the authorization of the resource owner in a timely manner, thereby improving the efficiency of perception communication. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure, the following drawings required for describing the embodiments are introduced. The following drawings are merely some embodiments of the present disclosure and do not impose specific limitations on the protection scope of the present disclosure.
[0016] FIG1 is an exemplary schematic diagram of the architecture of a communication system provided according to an embodiment of the present disclosure.
[0017] FIG2 is an interactive schematic diagram illustrating a communication method according to an embodiment of the present disclosure.
[0018] FIG3A is a flow chart illustrating a communication method according to an embodiment of the present disclosure.
[0019] FIG3B is a flow chart illustrating a communication method according to an embodiment of the present disclosure.
[0020] FIG4 is a flow chart showing a communication method according to an embodiment of the present disclosure.
[0021] FIG5 is an interactive diagram illustrating a communication method according to an embodiment of the present disclosure.
[0022] FIG6 is an interactive diagram illustrating a communication method according to an embodiment of the present disclosure.
[0023] FIG7A is a schematic structural diagram of the first entity proposed in an embodiment of the present disclosure.
[0024] FIG7B is a schematic structural diagram of the second entity proposed in an embodiment of the present disclosure.
[0025] FIG8A is a schematic structural diagram of a communication device proposed in an embodiment of the present disclosure.
[0026] FIG8B is a schematic diagram of the structure of the chip proposed in an embodiment of the present disclosure. DETAILED DESCRIPTION
[0027] The embodiments of the present disclosure provide a communication method, a first entity, a second entity, a communication system, and a storage medium.
[0028] In a first aspect, an embodiment of the present disclosure proposes a communication method, which is executed by a first entity, and the method includes: receiving first information sent by a second entity, where the first information is used to request authorization from a resource owner; and performing authorization processing according to the first information and the perception-related policy corresponding to the resource owner.
[0029] In the above embodiment, the second entity requests the first entity to obtain authorization from the resource owner. The first entity can perform authorization processing based on the first information and the perception-related policy corresponding to the resource owner, so that the second entity can obtain the authorization of the resource owner in a timely manner, thereby improving the efficiency of perception communication.
[0030] In combination with some embodiments of the first aspect, in some embodiments, the first information includes at least one of the following: an identifier of the perception target or the owner of the perception target; first perception role information; the first perception role information includes the first terminal identifier and / or the perception role corresponding to the first terminal identifier; the first perception area; the first perception time; a request to associate the perception result with the first identity identifier; a request to open the perception context information, and the request to open the perception context includes a third terminal identifier.
[0031] In the above embodiment, the first information sent by the second entity to the first entity includes the above content, which can improve the efficiency of the first entity in processing authorization.
[0032] In combination with some embodiments of the first aspect, in some embodiments, the perception-related policy includes at least one of the following: an identifier of the resource owner; an indication of whether perception is allowed; information of a second perception role that is allowed or prohibited; the second perception role information includes a second terminal identifier and / or a perception role corresponding to the second terminal identifier; an allowed or prohibited second perception area; an allowed or prohibited second perception time; an indication of whether association of the perception result with the second identity identifier is allowed; an indication of whether association of the resource owner's identifier with the perception result is allowed; an indication of whether opening of the perception context information is allowed.
[0033] In the above embodiment, the perception-related policy includes the above content, which can improve the efficiency of the first entity in processing authorization.
[0034] In combination with some embodiments of the first aspect, in some embodiments, authorization processing is performed based on the first information and the perception-related policy corresponding to the resource owner, including: performing authorization processing when the first information complies with the perception-related policy; wherein the authorization processing includes at least one of the following: generating a token; sending a token to the second entity; and agreeing to the authorization request of the second entity.
[0035] In the above embodiment, when the first information complies with the perception-related policy, the first entity generates a token or sends a token to the second entity or agrees to the second entity's authorization request, so that the second entity can obtain the authorization of the resource owner when the resource owner cannot process the authorization in time.
[0036] In combination with some embodiments of the first aspect, in some embodiments, the information in the token includes at least one of the following: an identifier of the resource owner; an indication allowing perception; first perception role information; a first perception area; a first perception time; an indication allowing the perception result to be associated with the first identity identifier; an indication allowing the perception context information to be opened, and the indication allowing the perception context information to be opened includes a third terminal identifier.
[0037] In combination with some embodiments of the first aspect, in some embodiments, the first information complies with the perception-related policy, including: the first information includes an identifier of the perception target or the perception target owner, the perception-related policy includes an identifier of the resource owner and an indication of allowing perception, the identifier of the perception target or the perception target owner in the first information and the identifier of the resource owner in the perception-related policy are the same or there is a mapping relationship between them; the token includes the identifier of the perception target or the perception target owner and / or an indication of allowing perception.
[0038] In the above embodiment, when the first information includes the identification of the perception target or the perception target owner, and the perception-related policy includes the identification of the resource owner and an indication of allowing perception, if the identification of the perception target or the perception target owner in the first information and the identification of the resource owner in the perception-related policy are the same or have a mapping relationship, then the generated token includes the identification of the perception target or the perception target owner and / or the indication of allowing perception. This makes it possible to enable the second entity to obtain the authorization of the resource owner when the resource owner cannot process the authorization in a timely manner.
[0039] In combination with some embodiments of the first aspect, in some embodiments, the first information complies with the perception-related policy, including: the first information includes first perception role information, the perception-related policy includes allowed second perception role information, the first terminal identifier in the first information and the second terminal identifier in the perception-related policy are the same or have a mapping relationship, the perception role corresponding to the first terminal identifier and the perception role corresponding to the second terminal identifier are the same or have a mapping relationship; the token includes allowed perception role information.
[0040] In the above embodiment, when the first information includes the first perception role information and the perception-related policy includes the permitted second perception role information, if the first terminal identifier in the first information and the second terminal identifier in the perception-related policy are the same or have a mapping relationship, and the perception role corresponding to the first terminal identifier and the perception role corresponding to the second terminal identifier are the same or have a mapping relationship, then the generated token includes the permitted perception role information. This allows the second entity to obtain the resource owner's authorization when the resource owner cannot process the authorization in a timely manner.
[0041] In combination with some embodiments of the first aspect, in some embodiments, the first information complies with the perception-related policy, including: the first information includes first perception role information, the perception-related policy includes the identifier of the resource owner, the first terminal identifier in the first perception role information and the identifier of the resource owner in the perception-related policy are the same or have a mapping relationship; the token includes allowed perception role information.
[0042] In the above embodiment, when the first information includes the first perception role information and the perception-related policy includes the resource owner's identifier, if the first terminal identifier in the first perception role information and the resource owner's identifier in the perception-related policy are identical or have a mapping relationship, the generated token includes the permitted perception role information. This allows the second entity to obtain authorization from the resource owner even if the resource owner cannot process the authorization in a timely manner.
[0043] In combination with some embodiments of the first aspect, in some embodiments, the perception role includes at least one of a perception sender and a perception receiver.
[0044] In combination with some embodiments of the first aspect, in some embodiments, the first information complies with the perception-related policy, including: the first information includes a first perception area, the perception-related policy includes an allowed second perception area, the first perception area is included in the second perception area, or the first perception area and the second perception area are the same; the token includes the first perception area.
[0045] In the above embodiment, when the first information includes a first perception zone and the perception-related policy includes an allowed second perception zone, if the first perception zone is included in the second perception zone, or if the first perception zone and the second perception zone are the same, the generated token includes the first perception zone. This allows the second entity to obtain authorization from the resource owner even if the resource owner cannot process the authorization in a timely manner.
[0046] In combination with some embodiments of the first aspect, in some embodiments, the first information complies with the perception-related policy, including: the first information includes a first perception time, the perception-related policy includes an allowed second perception time, the first perception time and the second perception time are the same or the first perception time is covered by the second perception time; the token includes the first perception time.
[0047] In the above embodiment, when the first information includes a first perception time and the perception-related policy includes an allowed second perception time, if the first perception time and the second perception time are the same or the first perception time is overlapped by the second perception time, the generated token includes the first perception time. This allows the second entity to obtain authorization from the resource owner even if the resource owner cannot process the authorization in a timely manner.
[0048] In combination with some embodiments of the first aspect, in some embodiments, the first information complies with the perception-related policy, including: the first information includes a request to associate the perception result with a first identity identifier, the perception-related policy includes an indication allowing the perception result to be associated with a second identity identifier, the first identity identifier and the second identity identifier are the same or there is a mapping relationship; the token includes an indication allowing the perception result to be associated with the first identity identifier.
[0049] In the above embodiment, when the first information includes a request to associate the perception result with the first identity, and the perception-related policy includes an indication allowing the perception result to be associated with the second identity, if the first identity and the second identity are identical or have a mapping relationship, the generated token includes an indication allowing the perception result to be associated with the first identity. This allows the second entity to obtain authorization from the resource owner even if the resource owner cannot process the authorization in a timely manner.
[0050] In combination with some embodiments of the first aspect, in some embodiments, the first information complies with the perception-related policy, including: the first information includes a request to associate the perception result with a first identity identifier, the perception-related policy includes the identifier of the resource owner, and the first identity identifier and the identifier of the resource owner are the same or there is a mapping relationship; the token includes an indication allowing the perception result to be associated with the first identity identifier.
[0051] In the above embodiment, when the first information includes a request to associate the perception result with the first identity, and the perception-related policy includes the resource owner's identity, if the first identity and the second identity are identical or have a mapping relationship, the generated token includes an indication allowing the perception result to be associated with the first identity. This allows the second entity to obtain authorization from the resource owner even if the resource owner cannot process the authorization in a timely manner.
[0052] In combination with some embodiments of the first aspect, in some embodiments, the first identity includes at least one of a user permanent identifier SUPI, a hidden user identifier SUCI, an application layer ID, a general public user identifier GPSI, an international mobile subscriber identity IMSI, and an international mobile subscriber number MSISDN, and the second identity includes at least one of SUPI, SUCI, application layer ID, GPSI, IMSI, and MSISDN.
[0053] In combination with some embodiments of the first aspect, in some embodiments, the first information complies with the perception-related policy, including: the first information includes a request to open perception context information, the third terminal identifier in the request to open perception context information and the identifier of the resource owner in the perception-related policy are the same or there is a mapping relationship, the perception-related policy includes an indication to allow the perception context information to be open; the token includes an indication to allow the perception context information to be open.
[0054] In the above embodiment, if the first information includes a request to release the awareness context information and the awareness-related policy includes an indication to allow the release of the awareness context information, if the third terminal identifier in the request to release the awareness context information and the resource owner identifier in the awareness-related policy are the same as or have a mapping relationship, then the generated token includes the indication to allow the release of the awareness context information. This allows the second entity to obtain authorization from the resource owner even if the resource owner cannot process the authorization in a timely manner.
[0055] In combination with some embodiments of the first aspect, in some embodiments, the resource owner identifier includes at least one of a SUPI, a SUCI, an application layer ID, a GPSI, an IMSI, and an MSISDN; the first terminal identifier includes at least one of a SUPI, a SUCI, an application layer ID, a GPSI, an IMSI, and an MSISDN; the second terminal identifier includes at least one of a SUPI, a SUCI, an application layer ID, a GPSI, an IMSI, and an MSISDN; and the third terminal identifier includes at least one of a SUPI, a SUCI, an application layer ID, a GPSI, an IMSI, and an MSISDN.
[0056] In combination with some embodiments of the first aspect, in some embodiments, the first entity stores identifiers of multiple resource owners and perception-related policies corresponding to the identifiers of the respective resource owners.
[0057] In the above embodiment, the first entity pre-stores the identifiers of multiple resource owners and the perception-related policies corresponding to the identifiers of the respective resource owners, which can improve the efficiency of the first entity in processing authorization.
[0058] In combination with some embodiments of the first aspect, in some embodiments, the method further includes: receiving identity authentication information of the second entity sent by the second entity; and authenticating the second entity based on the identity authentication information.
[0059] In the above embodiment, the first entity authenticates the second entity, which can improve the reliability of authorization.
[0060] In combination with some embodiments of the first aspect, in some embodiments, the resource owner is one of a perception target, a perception target owner, a terminal, a user using the terminal, and a subscribed user related to the terminal.
[0061] In combination with some embodiments of the first aspect, in some embodiments, the second entity is one of a terminal, a client, an application function or a network function.
[0062] In the second aspect, an embodiment of the present disclosure proposes a communication method, which is executed by a second entity. The method includes: sending first information to a first entity, where the first information is used to request authorization from a resource owner, and the first entity is used to perform authorization processing based on the first information and the perception-related policy corresponding to the resource owner.
[0063] In the above embodiment, the second entity requests the first entity to obtain authorization from the resource owner. The first entity can perform authorization processing based on the first information and the perception-related policy corresponding to the resource owner, so that the second entity can obtain the authorization of the resource owner in a timely manner, thereby improving the efficiency of perception communication.
[0064] In combination with some embodiments of the second aspect, in some embodiments, the first information includes at least one of the following: an identifier of the perception target or the owner of the perception target; first perception role information; the first perception role information includes the first terminal identifier and / or the perception role corresponding to the first terminal identifier; the first perception area; the first perception time; a request to associate the perception result with the first identity identifier; a request to open the perception context information, and the request to open the perception context includes a third terminal identifier.
[0065] In combination with some embodiments of the second aspect, in some embodiments, the perception-related policy includes at least one of the following: an identifier of the resource owner; an indication of whether perception is allowed; allowed or prohibited second perception role information; the second perception role information includes a second terminal identifier and / or a perception role corresponding to the second terminal identifier; an allowed or prohibited second perception area; an allowed or prohibited second perception time; an indication of whether association of the perception result with the second identity identifier is allowed; an indication of whether association of the resource owner's identifier with the perception result is allowed; an indication of whether opening of the perception context information is allowed.
[0066] In combination with some embodiments of the second aspect, in some embodiments, the method further includes: receiving a token sent by the first entity, where the token is generated when the first information complies with the perception-related policy.
[0067] In combination with some embodiments of the second aspect, in some embodiments, the information in the token includes at least one of the following: an identifier of the resource owner; an indication allowing perception; first perception role information; a first perception area; a first perception time; an indication allowing the perception result to be associated with the first identity identifier; an indication allowing the perception context information to be opened, and the indication allowing the perception context information to be opened includes a third terminal identifier.
[0068] In combination with some embodiments of the second aspect, in some embodiments, the first information complies with the perception-related policy, including: the first information includes an identifier of the perception target or the perception target owner, the perception-related policy includes an identifier of the resource owner and an indication of allowing perception, the identifier of the perception target or the perception target owner in the first information and the identifier of the resource owner in the perception-related policy are the same or there is a mapping relationship between them; the token includes the identifier of the perception target or the perception target owner and / or an indication of allowing perception.
[0069] In combination with some embodiments of the second aspect, in some embodiments, the first information complies with the perception-related policy, including: the first information includes first perception role information, the perception-related policy includes allowed second perception role information, the first terminal identifier in the first information and the second terminal identifier in the perception-related policy are the same or have a mapping relationship, the perception role corresponding to the first terminal identifier and the perception role corresponding to the second terminal identifier are the same or have a mapping relationship; the token includes allowed perception role information.
[0070] In combination with some embodiments of the second aspect, in some embodiments, the first information complies with the perception-related policy, including: the first information includes first perception role information, the perception-related policy includes the identifier of the resource owner, the first terminal identifier in the first perception role information and the identifier of the resource owner in the perception-related policy are the same or have a mapping relationship; the token includes allowed perception role information.
[0071] In combination with some embodiments of the second aspect, in some embodiments, the perception role includes at least one of a perception sender and a perception receiver.
[0072] In combination with some embodiments of the second aspect, in some embodiments, the first information complies with the perception-related policy, including: the first information includes a first perception area, the perception-related policy includes an allowed second perception area, the first perception area is included in the second perception area, or the first perception area and the second perception area are the same; the token includes the first perception area.
[0073] In combination with some embodiments of the second aspect, in some embodiments, the first information complies with the perception-related policy, including: the first information includes a first perception time, the perception-related policy includes an allowed second perception time, the first perception time and the second perception time are the same or the first perception time is covered by the second perception time; the token includes the first perception time.
[0074] In combination with some embodiments of the second aspect, in some embodiments, the first information complies with the perception-related policy, including: the first information includes a request to associate the perception result with a first identity identifier, the perception-related policy includes an indication allowing the perception result to be associated with a second identity identifier, the first identity identifier and the second identity identifier are the same or there is a mapping relationship; the token includes an indication allowing the perception result to be associated with the first identity identifier.
[0075] In combination with some embodiments of the second aspect, in some embodiments, the first information complies with the perception-related policy, including: the first information includes a request to associate the perception result with a first identity identifier, the perception-related policy includes the identifier of the resource owner, and the first identity identifier and the identifier of the resource owner are the same or there is a mapping relationship; the token includes an indication allowing the perception result to be associated with the first identity identifier.
[0076] In combination with some embodiments of the second aspect, in some embodiments, the first identity includes at least one of a user permanent identifier SUPI, a hidden user identifier SUCI, an application layer ID, a general public user identifier GPSI, an international mobile subscriber identity IMSI, and an international mobile subscriber number MSISDN, and the second identity includes at least one of SUPI, SUCI, application layer ID, GPSI, IMSI, and MSISDN.
[0077] In combination with some embodiments of the second aspect, in some embodiments, the first information complies with the perception-related policy, including: the first information includes a request to open perception context information, the third terminal identifier in the request to open perception context information and the identifier of the resource owner in the perception-related policy are the same or there is a mapping relationship, the perception-related policy includes an indication to allow the perception context information to be open; the token includes an indication to allow the perception context information to be open.
[0078] In combination with some embodiments of the second aspect, in some embodiments, the resource owner identifier includes at least one of SUPI, SUCI, application layer ID, GPSI, IMSI, and MSISDN; the first terminal identifier includes at least one of SUPI, SUCI, application layer ID, GPSI, IMSI, and MSISDN; the second terminal identifier includes at least one of SUPI, SUCI, application layer ID, GPSI, IMSI, and MSISDN; and the third terminal identifier includes at least one of SUPI, SUCI, application layer ID, GPSI, IMSI, and MSISDN.
[0079] In combination with some embodiments of the second aspect, in some embodiments, the first entity stores identifiers of multiple resource owners and perception-related policies corresponding to the identifiers of the respective resource owners.
[0080] In combination with some embodiments of the second aspect, in some embodiments, the method further includes: sending identity authentication information of the second entity to the first entity.
[0081] In combination with some embodiments of the second aspect, in some embodiments, the resource owner is one of a perception target, a perception target owner, a terminal, a user using the terminal, and a subscribed user related to the terminal.
[0082] In combination with some embodiments of the second aspect, in some embodiments, the second entity is one of a terminal, a client, an application function or a network function.
[0083] In the third aspect, an embodiment of the present disclosure proposes a first entity, including: a transceiver module for receiving first information sent by a second entity, wherein the first information is used to request authorization from a resource owner; and a processing module for performing authorization processing based on the first information and the perception-related policy corresponding to the resource owner.
[0084] In the fourth aspect, an embodiment of the present disclosure proposes a second entity, including: a transceiver module, used to send first information to a first entity, the first information is used to request authorization from a resource owner, and the first entity is used to perform authorization processing based on the first information and the perception-related policy corresponding to the resource owner.
[0085] In a fifth aspect, an embodiment of the present disclosure proposes a first entity, comprising: one or more processors; wherein the processor is used to execute the communication method of the first aspect.
[0086] In a sixth aspect, an embodiment of the present disclosure proposes a second entity, comprising: one or more processors; wherein the processor is used to execute the communication method of the second aspect.
[0087] In a seventh aspect, an embodiment of the present disclosure proposes a communication system, comprising a first entity and a second entity, wherein the first entity is configured to implement the communication method of the first aspect, and the second entity is configured to implement the communication method of the second aspect.
[0088] In an eighth aspect, an embodiment of the present disclosure proposes a storage medium storing instructions, wherein the storage medium is characterized in that when the instructions are executed on a communication device, the communication device executes the communication method of the first aspect or the second aspect.
[0089] In a ninth aspect, an embodiment of the present disclosure proposes a program product. When the program product is executed by a communication device, the communication device executes the method described in the optional implementation manner of the first aspect or the second aspect.
[0090] In a tenth aspect, an embodiment of the present disclosure proposes a computer program, which, when executed on a computer, enables the computer to execute the method described in the optional implementation of the first aspect or the second aspect.
[0091] In an eleventh aspect, an embodiment of the present disclosure provides a chip or a chip system, wherein the chip or chip system includes a processing circuit configured to execute the method described in the optional implementation of the first aspect or the second aspect.
[0092] It is understandable that the aforementioned network functions, terminals, communication systems, storage media, program products, computer programs, chips, or chip systems are all used to execute the methods proposed in the embodiments of the present disclosure. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects of the corresponding methods and will not be repeated here.
[0093] The embodiments of the present disclosure provide a communication method, a first entity, a second entity, a communication system, and a storage medium. In some embodiments, the terms "communication method" and "information processing method," "communication perception method," "perception communication method," and "perception authorization method" are interchangeable, and the terms "information processing system," "communication system," "communication perception information," "perception communication system," and "perception authorization system" are interchangeable.
[0094] The embodiments of the present disclosure are not exhaustive and are merely illustrative of some embodiments, and are not intended to be a specific limitation on the scope of protection of the present disclosure. In the absence of contradiction, each step in a certain embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a certain embodiment can also be implemented as an independent embodiment, and the order of the steps in a certain embodiment can be arbitrarily exchanged. In addition, the optional implementation methods in a certain embodiment can be arbitrarily combined; in addition, the embodiments can be arbitrarily combined. For example, some or all steps of different embodiments can be arbitrarily combined, and a certain embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.
[0095] In each embodiment of the present disclosure, unless otherwise specified or provided for by logic, the terms and / or descriptions between the embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form a new embodiment based on their inherent logical relationships.
[0096] The terms used in the embodiments of the present disclosure are only for the purpose of describing specific embodiments and are not intended to limit the present disclosure.
[0097] In the embodiments of the present disclosure, unless otherwise specified, elements expressed in the singular, such as "a", "an", "the", "above", "said", "the", "the", etc., may mean "one and only one", or "one or more", "at least one", etc. For example, when using articles such as "a", "an", "the" in English in translation, the noun following the article may be understood as a singular expression or a plural expression.
[0098] In the embodiments of the present disclosure, “plurality” refers to two or more.
[0099] In some embodiments, the terms "at least one," "one or more," "a plurality of," "multiple," etc. may be used interchangeably.
[0100] In some embodiments, descriptions such as "at least one of A and B," "A and / or B," "A in one case, B in another case," or "in response to one case A, in response to another case B" may include the following technical solutions depending on the situation: in some embodiments, A (A is executed independently of B); in some embodiments, B (B is executed independently of A); in some embodiments, execution is selected from A and B (A and B are selectively executed); and in some embodiments, A and B (both A and B are executed). The above is also applicable when there are more branches such as A, B, and C.
[0101] In some embodiments, "A or B" and other descriptions may include the following technical solutions depending on the situation: in some embodiments, A (A is executed independently of B); in some embodiments, B (B is executed independently of A); in some embodiments, execution is selected from A and B (A and B are selectively executed). The above is also applicable when there are more branches such as A, B, C, etc.
[0102] The prefixes such as "first" and "second" in the embodiments of the present disclosure are only used to distinguish different description objects and do not constitute any restriction on the position, order, priority, quantity or content of the description objects. For the statement of the description object, please refer to the description in the context of the claims or embodiments, and no unnecessary restriction should be constituted due to the use of prefixes. For example, if the description object is a "field", the ordinal number before the "field" in the "first field" and the "second field" does not limit the position or order between the "fields". "First" and "second" do not limit whether the "fields" they modify are in the same message, nor do they limit the order of the "first field" and the "second field". For another example, if the description object is a "level", the ordinal number before the "level" in the "first level" and the "second level" does not limit the priority between the "levels". For another example, the number of description objects is not limited by the ordinal number and can be one or more. Taking "first device" as an example, the number of "devices" can be one or more. In addition, the objects modified by different prefixes can be the same or different. For example, if the description object is "device", then the "first device" and the "second device" can be the same device or different devices, and their types can be the same or different; for another example, if the description object is "information", then the "first information" and the "second information" can be the same information or different information, and their contents can be the same or different.
[0103] In some embodiments, “including A,” “comprising A,” “used to indicate A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.
[0104] In some embodiments, terms such as "in response to...", "in response to determining...", "in the case of...", "at the time of...", "when...", "if...", "if...", etc. can be used interchangeably.
[0105] In some embodiments, terms such as "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not less than", and "above" can be replaced with each other, and terms such as "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", and "below" can be replaced with each other.
[0106] In some embodiments, devices, etc. can be interpreted as physical or virtual, and their names are not limited to the names recorded in the embodiments. Terms such as "device", "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", and "subject" can be used interchangeably.
[0107] In some embodiments, "network" can be interpreted as devices included in the network (eg, access network equipment, core network equipment, etc.).
[0108] In some embodiments, the terms "access network device (AN device)", "radio access network device (RAN device)", "base station (BS)", "radio base station" "fixed station", "node", "access point", "transmission point (TP)", "reception point (RP)", "transmission / reception point (TRP)" "panel", "antenna panel", "antenna array", "cell", "macro cell", "small cell", "femto cell", "pico cell", "sector", "cell group", "serving cell", "carrier", "component carrier", "bandwidth part (BWP)" and the like may be used interchangeably.
[0109] In some embodiments, the terms "terminal", "terminal device", "user equipment (UE)", "user terminal", "mobile station (MS)", "mobile terminal (MT)", subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, client, etc. can be used interchangeably.
[0110] In some embodiments, the access network device, the core network device, or the network device can be replaced by a terminal. For example, the various embodiments of the present disclosure can also be applied to a structure in which the communication between the access network device, the core network device, or the network device and the terminal is replaced by communication between multiple terminals (for example, device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, it is also possible to set the structure in which the terminal has all or part of the functions of the access network device. In addition, terms such as "uplink" and "downlink" can also be replaced by terms corresponding to communication between terminals (for example, "side"). For example, uplink channels, downlink channels, etc. can be replaced by side channels, and uplinks, downlinks, etc. can be replaced by side links.
[0111] In some embodiments, the terminal may be replaced by an access network device, a core network device, or a network device. In this case, the access network device, the core network device, or the network device may have a structure that has all or part of the functions of the terminal.
[0112] In some embodiments, obtaining data, information, etc. may comply with the laws and regulations of the country where the data is obtained.
[0113] In some embodiments, data, information, etc. may be obtained with the user's consent.
[0114] In addition, each element, each row, or each column in the table of the embodiment of the present disclosure can be implemented as an independent embodiment, and the combination of any elements, any rows, and any columns can also be implemented as an independent embodiment.
[0115] FIG1 is a schematic diagram showing the architecture of a communication system according to an embodiment of the present disclosure.
[0116] As shown in FIG1 , a communication system 100 includes a first entity 101 and a second entity 102 .
[0117] In some embodiments, the first entity 101 may be an authorization server.
[0118] In some embodiments, the first entity 101 may be one of a Network Exposure Function (NEF), a Common API Framework (CAPIF) core function, and a Network Repository Function (NRF).
[0119] In some embodiments, the second entity 102 may be a perception requesting end for initiating a perception request.
[0120] In some embodiments, the second entity 102 may be a third party or a network function (NF). The third party may be one of a terminal (UE), a client, and an application function (AF).
[0121] In some embodiments, the terminal includes, for example, a mobile phone, a wearable device, an Internet of Things device, a car with communication capabilities, a smart car, a tablet computer, a computer with wireless transceiver capabilities, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in a smart grid, a wireless terminal device in transportation safety, a wireless terminal device in a smart city, and at least one of a wireless terminal device in a smart home, but is not limited thereto.
[0122] In some embodiments, the network function may be a functional network element in a core network device. The core network device may be a device including a first network element, a second network element, etc., or may be multiple devices or a device group, each including all or part of the first network element, the second network element, etc. The network element may be virtual or physical. The core network may include, for example, at least one of an evolved packet core (EPC), a 5G core network (5GCN), and a next generation core (NGC).
[0123] In some embodiments, the network function may be a Gateway Mobile Location Centre (GMLC), a Location Management Function (LMF), or a network function specifically developed for the awareness service.
[0124] It can be understood that the communication system described in the embodiment of the present disclosure is for the purpose of more clearly illustrating the technical solution of the embodiment of the present disclosure, and does not constitute a limitation on the technical solution proposed in the embodiment of the present disclosure. Ordinary technicians in this field can know that with the evolution of the system architecture and the emergence of new business scenarios, the technical solution proposed in the embodiment of the present disclosure is also applicable to similar technical problems.
[0125] The following embodiments of the present disclosure may be applied to the communication system 100 shown in FIG1 , or a portion thereof, but are not limited thereto. The entities shown in FIG1 are illustrative only. The communication system may include all or part of the entities shown in FIG1 , or may include other entities outside of FIG1 . The number and form of the entities are arbitrary, and the entities may be physical or virtual. The connection relationships between the entities are illustrative only. The entities may be connected or disconnected, and the connection may be in any manner, including direct or indirect, wired or wireless.
[0126] The embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), future radio access (FRA), new radio access technology (RAT), new radio (NR), new radio access (NX), future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (registered trademark), Public Land Mobile Network (PLMN) networks, Device-to-Device (D2D) systems, Machine-to-Machine (M2M) systems, Internet of Things (IoT) systems, Vehicle-to-Everything (V2X), systems utilizing other communication methods, and next-generation systems based on and extending these methods. Furthermore, multiple systems may be combined (for example, a combination of LTE or LTE-A with 5G).
[0127] The disclosed embodiments relate to wireless sensing technology, which can obtain information about a remote sensing target and its characteristics without actually contacting the remote object. By analyzing the sensing data of the sensing target and its surroundings, meaningful information about the sensing target and its characteristics can be obtained. Among them, radar (radio detection and ranging) is a widely used wireless sensing technology that uses radio waves to determine the distance (range), angle or instantaneous linear velocity of the sensing target. Sensing technology can also include non-radio frequency sensors that have been used in other fields, such as time-of-flight (ToF) cameras, accelerometers, gyroscopes and lidars.
[0128] The disclosed embodiments can be applied to 3GPP-supported perception systems. Integrated perception and communication in 3GPP systems means that perception capabilities are provided by the same wireless communication system and infrastructure used for communication. Furthermore, in 3GPP-supported perception systems, both UEs and NR RAN nodes can act as perception senders and / or perception receivers.
[0129] The communication method provided by the embodiments of the present disclosure can be applied to real-time environmental monitoring, autonomous vehicles / unmanned aerial vehicles (UAVs), air pollution monitoring, indoor healthcare, and intrusion detection. Real-time environmental monitoring can use wireless signals to reconstruct environmental maps, further improving positioning accuracy and enabling environmentally-related applications. For example, a range of real-time monitoring applications can be implemented, including dynamic three-dimensional maps for assisted driving, pedestrian flow statistics, intrusion detection, and traffic detection. Autonomous vehicle / UAV applications share some common functional requirements. For example, autonomous vehicles / UAVs should support detect and avoid (DAA) to avoid obstacles. At the same time, autonomous vehicles / UAVs should have the ability to monitor path information, such as route selection and traffic compliance. Air pollution monitoring can use the received wireless information for weather or air quality monitoring, based on the varying attenuation characteristics of the received wireless signal quality as a function of air humidity, particulate matter (PM) concentration, and carrier frequency. Indoor healthcare and intrusion detection can implement respiratory rate estimation, respiratory depth estimation, apnea detection, elderly vital sign monitoring, and indoor intrusion detection.
[0130] The communication method provided by the embodiments of the present disclosure can be applied to perception-assisted communication scenarios. In perception-assisted communication scenarios, the terminal's location and channel environment can be perceived to narrow the beam scanning range and shorten the beam training time. The UE's location, speed, motion trajectory, and channel environment can be perceived to perform beam prediction, reducing the overhead of beam measurement and the delay of beam tracking. The UE's attributes and channel environment can be perceived to improve the performance of channel estimation.
[0131] In perception scenarios, it is important to obtain authorization from the perception target (e.g., person, user, building) or the perception target owner (e.g., owner of a building) or the terminal.
[0132] Specifically, before sensing a target, a third party (e.g., a terminal, a client on the terminal, AF) or a network function needs to obtain authorization from the sensing target or the sensing target owner.
[0133] In addition, it is also important to authorize a request for a specific terminal to act as a sensing sender or sensing receiver.
[0134] However, in the case that the sensing target or the sensing target owner or the terminal cannot process the authorization in time, the entity for sensing initiation cannot obtain the authorization of the sensing target or the sensing target owner or the terminal in time.
[0135] The present disclosure provides a communication method in which a first entity receives first information sent by a second entity for requesting authorization from a resource owner, and the first entity performs authorization processing based on the first information and a perception-related policy corresponding to the resource owner. Based on the communication method provided by the present disclosure, the first entity can perform authorization processing based on the first information and a perception-related policy corresponding to the resource owner, allowing the second entity to obtain authorization from the resource owner in a timely manner, thereby improving the efficiency of perception communication.
[0136] FIG2 is an interactive diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG2 , the embodiment of the present disclosure relates to a communication method, and the method includes:
[0137] Step S2101: The second entity sends its identity authentication information to the first entity.
[0138] In some embodiments, the first entity receives identity authentication information of the second entity sent by the second entity.
[0139] In some embodiments, the first entity may be an authorization server.
[0140] In some embodiments, the first entity may be one of a NEF, a CAPIF core function, and a NRF.
[0141] In some embodiments, the second entity may be a perception requesting end for initiating a perception request.
[0142] In some embodiments, the second entity may be one of a terminal, a client, an AF, an access network device, and a NF.
[0143] In some embodiments, the authentication information may be, for example, client credentials, keys, passwords, certificates, and the like.
[0144] In some embodiments, when the second entity requests access to the resource owner's information, the second entity may request an authorization token from the first entity using the second entity's authentication information.
[0145] In some embodiments, the resource owner may be one of a perception target, a perception target owner, a terminal, a user using the terminal, and a subscriber associated with the terminal.
[0146] In some embodiments, the resource owner may store the resource owner's identifier and the corresponding perception-related policy in the first entity, so that the first entity can perform authorization processing according to the corresponding perception-related policy of the resource owner.
[0147] In some embodiments, the first entity stores identifiers of multiple resource owners and perception-related policies corresponding to the identifiers of each resource owner, so that the first entity can determine the identifier of the corresponding resource owner based on the first information, and determine the corresponding perception-related policy based on the identifier of the resource owner.
[0148] Step S2102: The first entity authenticates the second entity based on the authentication information of the second entity.
[0149] In some embodiments, the first entity authenticates the second entity based on the second entity's authentication information. After the second entity's authentication is passed, authorization processing is performed based on the first information and the perception-related policies corresponding to the resource owner, which can improve the reliability of authorization.
[0150] Step S2103: The second entity sends first information to the first entity.
[0151] In some embodiments, the first entity receives first information sent by the second entity.
[0152] In some embodiments, the identity authentication information and the first information may be carried in different requests or in the same request, which is not limited in this disclosure.
[0153] In some embodiments, the first information is used to request authorization from a resource owner.
[0154] In some embodiments, the first information may include at least one of the following:
[0155] identification of the perceived target or the perceived target's owner;
[0156] First perception role information; the first perception role information includes the first terminal identifier and / or the perception role corresponding to the first terminal identifier;
[0157] First perception area;
[0158] First perception time;
[0159] A request to associate the perception result with the first identity;
[0160] A request for opening the context awareness information is provided, where the request for opening the context awareness includes a third terminal identifier.
[0161] In some embodiments, the first terminal identifier includes at least one of a user permanent identifier (SUPI), a user concealed identifier (SUCI), an application layer ID, a generic public subscriber identifier (GPSI), an international mobile subscriber identity (IMSI), and an international mobile subscriber number (MSISDN).
[0162] In some embodiments, the third terminal identity includes at least one of SUPI, SUCI, application layer ID, GPSI, IMSI and MSISDN.
[0163] In some embodiments, the first terminal identifier and the third terminal identifier may be the same or different.
[0164] In some embodiments, the first identity includes at least one of SUPI, SUCI, application layer ID, GPSI, IMSI, and MSISDN.
[0165] In some embodiments, the perception role includes at least one of a perception sender and a perception receiver.
[0166] For example, the first information may include an identifier of a perception target that the second entity wants to perceive, or the second information may include an identifier of a perception target owner corresponding to the perception target that the second entity wants to perceive.
[0167] For another example, the first information may include the first terminal identifier and the perception role played by the first terminal in the perception process.
[0168] For another example, the first information may include a first perception area and / or a first perception time that the second entity wants to perceive.
[0169] For another example, the first information may include a request to associate the perception result with a first identity identifier, where the first identity identifier may be a 3GPP user identity.
[0170] For another example, the first information may include a request to open the perception context information.
[0171] Step S2104: The first entity performs authorization processing according to the first information and the perception-related policy corresponding to the resource owner.
[0172] In some embodiments, the resource owner stores its corresponding perception-related policy in the first entity, that is, the first entity stores the perception-related policy corresponding to the resource owner.
[0173] In some embodiments, the perception-related strategy includes at least one of the following:
[0174] The identifier of the resource owner;
[0175] whether to allow perceived instructions;
[0176] The second perception role information that is allowed or prohibited; the second perception role information includes the second terminal identifier and / or the perception role corresponding to the second terminal identifier;
[0177] a second perceptual area that is permitted or prohibited;
[0178] the second perceived time that is permitted or prohibited;
[0179] an indication of whether to allow associating the perception result with the second identity identifier;
[0180] An indication of whether to allow associating the resource owner's identity with the perception result;
[0181] Indicates whether to allow open sensing context information.
[0182] In some embodiments, authorization processing is performed according to the first information and the perception-related policy corresponding to the resource owner, including: performing authorization processing when the first information complies with the perception-related policy.
[0183] In some embodiments, the authorization process includes at least one of the following:
[0184] Generate token;
[0185] sending a token to a second entity;
[0186] Approve the second entity's authorization request.
[0187] Specifically, the first entity can determine the identifier of the resource owner based on the first information, determine the pre-stored perception-related policy corresponding to the resource owner based on the identifier of the resource owner, and then determine whether the first information complies with the perception-related policy. When the first information complies with the perception-related policy, a token is generated or a token is sent to the second entity or the authorization request of the second entity is agreed to.
[0188] In some embodiments, the information in the token includes at least one of the following:
[0189] The identifier of the resource owner;
[0190] Allowing for the instructions to be perceived;
[0191] First perception role information;
[0192] First perception area;
[0193] First perception time;
[0194] an indication allowing the perception result to be associated with the first identity identifier;
[0195] The indication of allowing the opening of the perception context information includes a third terminal identifier.
[0196] For example, the first information may include an identifier of a sensing target or a sensing target owner, and the sensing-related policy may include an identifier of a resource owner and an indication of allowing sensing. The identifier of the resource owner includes at least one of a SUPI, a SUCI, an application layer ID, a GPSI, an IMSI, and an MSISDN.
[0197] If the identifier of the perception target or the perception target owner in the first information is the same as or has a mapping relationship with the identifier of the resource owner in the perception-related policy, it means that the perception target or the perception target owner in the first information is allowed to be perceived, and the generated token includes the identifier of the perception target or the perception target owner and / or an indication of allowing perception, that is, the generated token may only include the identifier of the perception target or the perception target owner (including that the identifier of the perception target or the perception target owner can represent that it is allowed to be perceived), or only include an indication of allowing perception, or include the identifier of the perception target or the perception target owner and an indication of allowing perception.
[0198] If the identifier of the perception target or the perception target owner in the first information is different from the identifier of the resource owner in the perception-related policy and there is no mapping relationship, it means that the perception target or the perception target owner in the first information is not allowed to be perceived, and the perception behavior is not authorized, that is, the generated token does not include the identifier of the perception target or the perception target owner or an indication that perception is allowed.
[0199] For another example, the first information may include first perception role information, which includes the first terminal identifier and / or the perception role corresponding to the first terminal identifier; the perception-related policy may include allowed second perception role information, which includes the second perception role information including the second terminal identifier and / or the perception role corresponding to the second terminal identifier, wherein the second terminal identifier includes at least one of SUPI, SUCI, application layer ID, GPSI, IMSI and MSISDN.
[0200] If the first terminal identifier in the first information is the same as or has a mapping relationship with the second terminal identifier in the perception-related policy, and the perception role corresponding to the first terminal identifier is the same as or has a mapping relationship with the perception role corresponding to the second terminal, then the generated token includes permitted perception role information. The permitted perception role information included in the token may be the first terminal identifier and its corresponding perception role, or the second terminal identifier and its corresponding perception role.
[0201] If the first terminal identifier and the second terminal identifier are different and no mapping relationship exists, the sensing behavior is not authorized, that is, the generated token does not include the role information in the first information.
[0202] If the perception role corresponding to the first terminal identifier is not allowed in the perception-related policy, for example, although the first terminal identifier and the second terminal identifier are the same or there is a mapping relationship, the perception role corresponding to the first terminal identifier and the perception role corresponding to the second terminal are different and there is no mapping relationship, the perception behavior is not authorized, that is, the generated token does not include the role information in the first information.
[0203] For another example, the first information may include first perception role information, and the first perception role information includes a first terminal identifier; the perception-related policy may include an identifier of a resource owner.
[0204] If the first terminal identifier in the first information is the same as or has a mapping relationship with the resource owner identifier in the perception-related policy, the generated token includes allowed perception role information, wherein the allowed perception role information included in the token may be the first terminal identifier and its corresponding perception role.
[0205] If the first terminal identifier is different from the identifier of the resource owner in the perception-related policy and no mapping relationship exists, the perception behavior is not authorized, that is, the generated token does not include the role information in the first information.
[0206] For another example, the first information may include a first perception area, and the perception-related policy may include an allowed second perception area.
[0207] If the first perception area is included in the second perception area, or the first perception area and the second perception area are the same, the generated token includes the first perception area, which means that perception is allowed within the first perception area.
[0208] If there is an area in the first perception area that is not included in the second perception area, the generated token does not include the first perception area, or only includes a portion of the area that is common to the first perception area and the second perception area.
[0209] If the first perception area and the second perception area are completely different, the perception behavior is not authorized, that is, the generated token does not include the first perception area.
[0210] For another example, the first information may include a first sensing time, and the sensing-related policy may include an allowed second sensing time. The first sensing time and the second sensing time may both be a continuous period of time or several periods of time.
[0211] If the first perception time is the same as the second perception time, or the first perception time is covered by the second perception time, the generated token includes the first perception time, which means that perception is allowed within the first perception time.
[0212] If there is time in the first perception time that is not included in the second perception time, the generated token does not include the first perception time, or only includes the same part of the first perception time and the second perception time.
[0213] If the first perception time and the second perception time are completely different, the perception behavior is not authorized, that is, the generated token does not include the first perception time.
[0214] For another example, the first information may include a request to associate the perception result with a first identity, and the perception-related policy may include an indication allowing association of the perception result with a second identity. The first identity includes at least one of a SUPI, a SUCI, an application layer ID, a GPSI, an IMSI, and an MSISDN, and the second identity includes at least one of a SUPI, a SUCI, an application layer ID, a GPSI, an IMSI, and an MSISDN.
[0215] If the first identity identifier and the second identity identifier are identical or have a mapping relationship with each other, the generated token includes an indication allowing the perception result to be associated with the first identity identifier.
[0216] If the first identity identifier and the second identity identifier are different and no mapping relationship exists, the sensing behavior is not authorized, that is, the token does not include an indication of associating the sensing result with the first identity identifier.
[0217] For another example, the first information may include a request to associate the perception result with the first identity identifier, and the perception-related policy may include the identifier of the resource owner.
[0218] If the first identity identifier and the resource owner's identifier are identical or have a mapping relationship, the generated token includes an indication allowing the perception result to be associated with the first identity identifier.
[0219] If the first identity identifier and the resource owner's identifier are different and no mapping relationship exists, the sensing behavior is not authorized, that is, the token does not include an indication of associating the sensing result with the first identity identifier.
[0220] For another example, the first information may include a request to open the perception context information, and the request to open the perception context information includes the third terminal identifier; the perception-related policy may include the identifier of the resource owner and an indication of allowing the perception context information to be opened.
[0221] If the third terminal identifier is identical to the resource owner identifier or there is a mapping relationship between them, the generated token includes an indication of allowing the open perception context information.
[0222] If the third terminal identifier is different from the resource owner identifier and no mapping relationship exists, the sensing behavior is not authorized, that is, the generated token does not include an indication of allowing the disclosure of the sensing context information.
[0223] The communication method provided by the embodiment of the present disclosure can enable the first entity to perform authorization processing based on the first information and the perception-related policy corresponding to the resource owner, so that the second entity can obtain the authorization of the resource owner in a timely manner, thereby improving the efficiency of perception communication.
[0224] In some embodiments, the names of information, etc. are not limited to the names described in the embodiments, and terms such as "information", "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "domain", "field", "symbol", "symbol", "codeword", "codebook", "codeword", "codepoint", "bit", "data", "program", and "chip" can be used interchangeably.
[0225] In some embodiments, terms such as "moment", "time point", "time", and "time position" can be replaced with each other, and terms such as "duration", "period", "time window", "window", and "time" can be replaced with each other.
[0226] In some embodiments, "obtain", "get", "get", "receive", "transmit", "bidirectional transmission", "send and / or receive" can be interchangeable, and can be interpreted as receiving from other entities, obtaining from protocols, obtaining from higher layers, obtaining by self-processing, autonomous implementation, etc.
[0227] In some embodiments, terms such as "send", "transmit", "report", "download", "transmit", "bidirectional transmission", "send and / or receive" can be used interchangeably.
[0228] In some embodiments, terms such as "certain", "preset", "preset", "setting", "indicated", "a certain", "any", and "first" can be interchangeable. "Specific A", "preset A", "preset A", "setting A", "indicated A", "a certain A", "any A", and "first A" can be interpreted as A pre-specified in a protocol, etc., or as A obtained through setting, configuration, or indication, etc., or as specific A, a certain A, any A, or first A, etc., but not limited to this.
[0229] In some embodiments, the determination or judgment can be performed by a value represented by 1 bit (0 or 1), or by a true or false value (Boolean value) represented by true or false, or by comparison of numerical values (for example, comparison with a predetermined value), but is not limited thereto.
[0230] In some embodiments, "not expecting to receive" can be interpreted as not receiving on time domain resources and / or frequency domain resources, or as not performing subsequent processing on the data after receiving it; "not expecting to send" can be interpreted as not sending, or as sending but not expecting the recipient to respond to the content sent.
[0231] The communication method involved in the embodiments of the present disclosure may include at least one of steps S2101 to S2104. For example, step S2101 may be implemented as an independent embodiment, step S2102 may be implemented as an independent embodiment, step S2103 may be implemented as an independent embodiment, step S2104 may be implemented as an independent embodiment, steps S2101+S2102 may be implemented as an independent embodiment, and steps S2103+S2104 may be implemented as independent embodiments, but the present invention is not limited thereto.
[0232] In some embodiments, steps S2101 to S2104 can be performed in an interchangeable order or simultaneously. Under no conflicting conditions, each step can be combined arbitrarily and the order of each step can be interchanged arbitrarily, which is not limited in this disclosure.
[0233] In some embodiments, steps S2101 and S2102 are optional, and one or more of these steps may be omitted or replaced in different embodiments.
[0234] In some embodiments, steps S2103 and S2104 are optional, and one or more of these steps may be omitted or replaced in different embodiments.
[0235] In some embodiments, reference may be made to other optional implementations described before or after the description corresponding to FIG. 2 .
[0236] FIG3A is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in FIG3A , the embodiment of the present disclosure relates to a communication method, which includes:
[0237] Step S3101: Obtain identity authentication information of the second entity.
[0238] The optional implementation of step S3101 can refer to the optional implementation of step S2101 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.
[0239] In some embodiments, the first entity receives identity authentication information of the second entity sent by the second entity.
[0240] Step S3102: Authenticate the second entity based on the authentication information of the second entity.
[0241] The optional implementation of step S3102 can refer to the optional implementation of step S2102 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.
[0242] In some embodiments, the first entity authenticates the second entity based on the authentication information of the second entity.
[0243] Step S3103, obtain first information.
[0244] The optional implementation of step S3103 can refer to the optional implementation of step S2103 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.
[0245] In some embodiments, the first entity receives first information sent by the second entity.
[0246] Step S3104: Perform authorization processing according to the first information and the perception-related policy corresponding to the resource owner.
[0247] The optional implementation of step S3104 can refer to the optional implementation of step S2104 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.
[0248] In some embodiments, the first entity performs authorization processing according to the first information and a perception-related policy corresponding to the resource owner.
[0249] The communication method involved in the embodiments of the present disclosure may include at least one of steps S3101 to S3104. For example, step S3101 may be implemented as an independent embodiment, step S3102 may be implemented as an independent embodiment, step S3103 may be implemented as an independent embodiment, step S3104 may be implemented as an independent embodiment, steps S3101+S3102 may be implemented as an independent embodiment, and steps S3103+S3104 may be implemented as independent embodiments, but the present invention is not limited thereto.
[0250] In some embodiments, steps S3101 to S3104 can be performed in an interchangeable order or simultaneously. Under no conflicting conditions, each step can be combined arbitrarily and the order of each step can be interchanged arbitrarily, which is not limited in this disclosure.
[0251] In some embodiments, steps S3101 and S3102 are optional, and one or more of these steps may be omitted or replaced in different embodiments.
[0252] In some embodiments, steps S3103 and S3104 are optional, and one or more of these steps may be omitted or replaced in different embodiments.
[0253] FIG3B is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in FIG3B , the embodiment of the present disclosure relates to a communication method, and the method includes:
[0254] Step S3201, obtain first information.
[0255] The optional implementation of step S3201 can refer to the optional implementation of step S2103 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.
[0256] In some embodiments, the first entity receives first information sent by the second entity.
[0257] Step S3202: Perform authorization processing according to the first information and the perception-related policy corresponding to the resource owner.
[0258] The optional implementation of step S3202 can refer to the optional implementation of step S2104 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.
[0259] In some embodiments, the first entity performs authorization processing according to the first information and a perception-related policy corresponding to the resource owner.
[0260] The communication method involved in the embodiment of the present disclosure may include at least one of steps S3201 and S3202. For example, step S3201 may be implemented as an independent embodiment, and step S3202 may be implemented as an independent embodiment, but the present invention is not limited thereto.
[0261] In some embodiments, steps S3201 to S3202 can be performed in an interchangeable order or simultaneously. Under no conflicting conditions, each step can be combined arbitrarily and the order of each step can be interchanged arbitrarily, which is not limited in this disclosure.
[0262] In some embodiments, step S3201 is optional, and one or more of these steps may be omitted or replaced in different embodiments.
[0263] FIG4 is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in FIG4 , the embodiment of the present disclosure relates to a communication method, which includes:
[0264] Step S4101: Send identity authentication information of the second entity.
[0265] The optional implementation of step S4101 can refer to the optional implementation of step S2101 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.
[0266] In some embodiments, the second entity sends identity authentication information of the second entity to the first entity.
[0267] Step S4102, sending the first information.
[0268] The optional implementation of step S4102 can refer to the optional implementation of step S2103 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.
[0269] In some embodiments, the second entity sends the first information to the first entity.
[0270] The communication method involved in the embodiment of the present disclosure may include at least one of steps S4101 to S4102. For example, step S4101 may be implemented as an independent embodiment, and step S4102 may be implemented as an independent embodiment, but the present invention is not limited thereto.
[0271] In some embodiments, steps S4101 and S4102 can be performed in different orders or simultaneously. Under no conflicting conditions, each step can be combined arbitrarily and the order of each step can be changed arbitrarily, which is not limited in this disclosure.
[0272] In some embodiments, step S4101 is optional, and one or more of these steps may be omitted or replaced in different embodiments.
[0273] In some embodiments, step S4102 is optional, and one or more of these steps may be omitted or replaced in different embodiments.
[0274] Figure 5 is an interactive diagram of a communication method according to an embodiment of the present disclosure. As shown in Figure 5, the embodiment of the present disclosure relates to a communication method, which includes:
[0275] Step S5101: The second entity sends first information to the first entity.
[0276] The optional implementation of step S5101 can refer to the optional implementation of step S2103 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.
[0277] Step S5102: The first entity performs authorization processing according to the first information and the perception-related policy corresponding to the resource owner.
[0278] The optional implementation of step S5102 can refer to the optional implementation of step S2104 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.
[0279] In some embodiments, steps S5101 to S5102 can be performed in an interchangeable order or simultaneously. Under no conflicting conditions, each step can be combined arbitrarily and the order of each step can be interchanged arbitrarily, which is not limited in this disclosure.
[0280] In some embodiments, the above method may include the methods of the above embodiments of the communication system side, terminal side, network function side, etc., which will not be repeated here.
[0281] Figure 6 is an interactive diagram of a communication method according to an embodiment of the present disclosure. As shown in Figure 6, the embodiment of the present disclosure relates to a communication method, which includes:
[0282] In step S6101, the client sends a verification request to the authorization server.
[0283] In some embodiments, the client may be a third party (eg, a client terminal, a client on a terminal, an AF) or a network function or an access network device, etc.
[0284] In some embodiments, the authorization server may be a NEF, a CAPIF core function, or an NRF, among others.
[0285] In some embodiments, the awareness target or awareness target owner provides awareness-related policies to the authorization server.
[0286] In some embodiments, when a client requests access to information of a resource owner (e.g., an awareness target, an awareness target owner, a UE), the client may request an authorization token using only its client credentials (or other supported authentication means).
[0287] In some embodiments, the client authenticates with the authorization server and requests an authorization token from the server's token endpoint.
[0288] In some embodiments, when requesting to sense a specific target or requesting a UE to act as a specific sensing role, the requested scope may include at least one of the following:
[0289] Identification of the sensing target or sensing target owner (e.g., 3GPP subscriber identity);
[0290] Role information (e.g., a UE ID and corresponding role, such as sensing transmitter or sensing receiver);
[0291] target sensing area;
[0292] Sensing time;
[0293] A request to associate a perception result with an identity (eg, a 3GPP user identity); a request to open perception context information, which may include an identity (eg, a 3GPP user identity).
[0294] In some embodiments, the authorization server authenticates and authorizes the client according to the local policy set by the perception target or the perception target owner or the terminal; if the request is authorized or part of the content in the request is authorized, an authorization token is generated and issued.
[0295] In some embodiments, the authorization server (eg, NEF / CAPIF Core Function / NRF) can generate awareness-related tokens based on local policy.
[0296] The policy is determined by the authorization server according to the identification of the sensing target in the request, the identification of the owner of the sensing target, or the identification in the role information.
[0297] In some embodiments, the policy may include at least one of the following:
[0298] Identification of the sensing target or the sensing target owner (e.g., 3GPP user identity);
[0299] instructions that allow or prohibit perception;
[0300] Allowed role information (e.g., a UE ID and corresponding role, such as sensing sender or sensing receiver);
[0301] Permitted or prohibited areas of perception;
[0302] the perceived time allowed or prohibited;
[0303] An indication of allowing or prohibiting association of an identity (e.g., a 3GPP user identity) with the perception result;
[0304] An indication of allowing or prohibiting opening of the perception context information, where the indication may include an identity (eg, a 3GPP user identity).
[0305] In some embodiments, the 3GPP user identity includes at least one of SUPI, SUCI, application layer ID, GPSI, IMSI, and MSISDN.
[0306] Step S6102: The authorization server sends an authorization token to the client.
[0307] In some embodiments, the token may include at least one of the following:
[0308] Identification of the sensing target or the sensing target owner (e.g., 3GPP user identity);
[0309] Allowing for the instructions to be perceived;
[0310] Allowed role information (e.g., a UE ID and corresponding role, such as sensing sender or sensing receiver);
[0311] target perception area;
[0312] Perception of time;
[0313] An indication allowing an identity (e.g., a 3GPP user identity) to be associated with the sensing result;
[0314] An indication of allowing the open perception context information may include an identity (eg, a 3GPP user identity).
[0315] The communication method involved in the embodiments of the present disclosure may include at least one of steps S6101 and S6102. In the embodiments of the present disclosure, any one of steps S6101 and S6102 can be implemented independently. For example, step S6101 can be implemented as an independent embodiment, and step S6102 can be implemented as an independent embodiment, but the present disclosure is not limited thereto.
[0316] In some embodiments, steps S6101 to S6102 can be performed in an interchangeable order or simultaneously. Under no conflicting conditions, each step can be combined arbitrarily and the order of each step can be interchanged arbitrarily, which is not limited in this disclosure.
[0317] In the embodiments of the present disclosure, some or all of the steps and their optional implementations may be arbitrarily combined with some or all of the steps in other embodiments, or may be arbitrarily combined with the optional implementations of other embodiments.
[0318] The embodiments of the present disclosure further provide an apparatus for implementing any of the above methods. For example, an apparatus is provided, comprising units or modules for implementing each step performed by a terminal in any of the above methods. For another example, another apparatus is provided, comprising units or modules for implementing each step performed by a network device (e.g., an access network device, a core network function node, a core network device, etc.) in any of the above methods.
[0319] It should be understood that the division of the various units or modules in the above device is merely a division of logical functions. In actual implementation, they may be fully or partially integrated into a physical entity, or they may be physically separated. In addition, the units or modules in the device may be implemented in the form of a processor calling software: for example, the device includes a processor, the processor is connected to a memory, and the memory stores instructions. The processor calls the instructions stored in the memory to implement any of the above methods or implement the functions of the various units or modules of the above device, wherein the processor is, for example, a general-purpose processor, such as a central processing unit (CPU) or a microprocessor, and the memory is a memory within the device or a memory outside the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits, and the functions of some or all of the units or modules can be realized by designing the hardware circuits. The above-mentioned hardware circuits can be understood as one or more processors; for example, in one implementation, the above-mentioned hardware circuit is an application-specific integrated circuit (ASIC), which realizes the functions of some or all of the above units or modules by designing the logical relationship of the components in the circuit; for example, in another implementation, the above-mentioned hardware circuit can be realized by a programmable logic device (PLD). Taking a field programmable gate array (FPGA) as an example, it can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by configuring the configuration file, thereby realizing the functions of some or all of the above units or modules. All units or modules of the above devices can be realized in the form of software called by the processor, or in the form of hardware circuits, or in part by the form of software called by the processor, and the rest by hardware circuits.
[0320] In the embodiments of the present disclosure, the processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction reading and execution capabilities, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationship of the hardware circuit. The logical relationship of the above-mentioned hardware circuit is fixed or reconfigurable. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document and implementing the hardware circuit configuration can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. In addition, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), etc.
[0321] Figure 7A is a schematic diagram of the structure of the first entity proposed in an embodiment of the present disclosure. As shown in Figure 7A, the first entity 7100 may include: a transceiver module 7101 and a processing module 7102. In some embodiments, the transceiver module 7101 is used to receive the first information sent by the second entity; the processing module 7102 is used to perform authorization processing according to the first information and the perception-related policy corresponding to the resource owner. Optionally, the transceiver module is used to execute at least one of the steps (such as steps S2101, S2103, but not limited to) of the processing performed by the first entity in any of the above methods, and the processing module is used to execute at least one of the steps (such as steps S2102, S2104, but not limited to) of the processing performed by the first entity in any of the above methods, which will not be repeated here.
[0322] Figure 7B is a schematic diagram of the structure of the second entity proposed in an embodiment of the present disclosure. As shown in Figure 7B, the second entity 7200 may include a transceiver module 7201. In some embodiments, the transceiver module 7201 is configured to send the first information to the first entity. Optionally, the transceiver module is configured to perform at least one of the steps (e.g., step S2101 and step S2103, but not limited thereto) performed by the second entity in any of the above methods, and will not be further described here.
[0323] In some embodiments, the processing module can be a single module or can include multiple submodules. Optionally, the multiple submodules respectively execute all or part of the steps required to be executed by the processing module. Optionally, the processing module can be interchangeable with the processor.
[0324] Figure 8A is a schematic diagram of the structure of a communication device 8100 proposed in an embodiment of the present disclosure. Communication device 8100 can be a network device (e.g., an access network device, a core network device, etc.), a terminal (e.g., a user equipment, etc.), a chip, a chip system, or a processor that supports a network device to implement any of the above methods, or a chip, a chip system, or a processor that supports a terminal to implement any of the above methods. Communication device 8100 can be used to implement the methods described in the above method embodiments. For details, please refer to the description of the above method embodiments.
[0325] As shown in Figure 8A, the communication device 8100 includes one or more processors 8101. The processor 8101 can be a general-purpose processor or a dedicated processor, for example, a baseband processor or a central processing unit. The baseband processor can be used to process the communication protocol and communication data, and the central processing unit can be used to control the communication device (such as a base station, a baseband chip, a terminal device, a terminal device chip, a DU or a CU, etc.), execute programs, and process program data. Optionally, the communication device 8100 is used to perform any of the above methods. Optionally, one or more processors 8101 are used to call instructions to enable the communication device 8100 to perform any of the above methods.
[0326] In some embodiments, the communication device 8100 further includes one or more transceivers 8102. When the communication device 8100 includes one or more transceivers 8102, the transceiver 8102 performs at least one of the communication steps such as sending and / or receiving in the above method (for example, step S2101 and step S2103, but not limited thereto), and the processor 8101 performs at least one of the other steps (for example, step S2102 and step S2104, but not limited thereto). In an optional embodiment, the transceiver may include a receiver and / or a transmitter, and the receiver and transmitter may be separate or integrated. Optionally, the terms transceiver, transceiver unit, transceiver, transceiver circuit, interface circuit, and interface may be interchangeable, the terms transmitter, transmitting unit, transmitter, and transmitting circuit may be interchangeable, and the terms receiver, receiving unit, receiver, and receiving circuit may be interchangeable.
[0327] In some embodiments, the communication device 8100 further includes one or more memories 8103 for storing data. Alternatively, all or part of the memories 8103 may be located outside the communication device 8100. In alternative embodiments, the communication device 8100 may include one or more interface circuits 8104. Optionally, the interface circuits 8104 are connected to the memories 8103 and may be configured to receive data from the memories 8103 or other devices, or to send data to the memories 8103 or other devices. For example, the interface circuits 8104 may read data stored in the memories 8103 and send the data to the processor 8101.
[0328] The communication device 8100 described in the above embodiment may be a network device or a terminal, but the scope of the communication device 8100 described in the present disclosure is not limited thereto, and the structure of the communication device 8100 may not be limited by FIG. 8A. The communication device may be an independent device or may be part of a larger device. For example, the communication device may be: 1) an independent integrated circuit IC, or a chip, or a chip system or subsystem; (2) a collection of one or more ICs, optionally, the above IC collection may also include a storage component for storing data or programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, a terminal device, an intelligent terminal device, a cellular phone, a wireless device, a handheld device, a mobile unit, an in-vehicle device, a network device, a cloud device, an artificial intelligence device, etc.; (6) others, etc.
[0329] FIG8B is a schematic diagram of the structure of a chip 8200 according to an embodiment of the present disclosure. If the communication device 8100 can be a chip or a chip system, please refer to the schematic diagram of the structure of the chip 8200 shown in FIG8B , but the present disclosure is not limited thereto.
[0330] The chip 8200 includes one or more processors 8201. The chip 8200 is configured to execute any of the above methods.
[0331] In some embodiments, chip 8200 further includes one or more interface circuits 8202. Terms such as interface circuit, interface, and transceiver pins may be used interchangeably. In some embodiments, chip 8200 further includes one or more memories 8203 for storing data. Alternatively, all or part of memory 8203 may be located external to chip 8200. Optionally, interface circuit 8202 is connected to memory 8203 and may be used to receive data from memory 8203 or other devices, or may be used to send data to memory 8203 or other devices. For example, interface circuit 8202 may read data stored in memory 8203 and send the data to processor 8201.
[0332] In some embodiments, the interface circuit 8202 performs at least one of the communication steps (e.g., step S2101 and step S2103, but not limited thereto) of the aforementioned method. The interface circuit 8202 performing the communication steps (e.g., step S2101 and step S2103, but not limited thereto) of the aforementioned method means, for example, that the interface circuit 8202 performs data exchange between the processor 8201, chip 8200, memory 8203, or transceiver device. In some embodiments, the processor 8201 performs at least one of the other steps (e.g., step S2102 and step S2104, but not limited thereto).
[0333] The modules and / or devices described in various embodiments, such as virtual devices, physical devices, and chips, can be arbitrarily combined or separated according to circumstances. Optionally, some or all steps can also be performed collaboratively by multiple modules and / or devices, which is not limited here.
[0334] The present disclosure also proposes a storage medium having instructions stored thereon, which, when executed on the communication device 8100, causes the communication device 8100 to execute any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but is not limited thereto, and may also be a storage medium readable by other devices. Optionally, the storage medium may be a non-transitory storage medium, but is not limited thereto, and may also be a temporary storage medium.
[0335] The present disclosure also provides a program product, which, when executed by the communication device 8100, enables the communication device 8100 to perform any of the above methods. Optionally, the program product is a computer program product.
[0336] The present disclosure also proposes a computer program, which, when executed on a computer, causes the computer to perform any one of the above methods.
Claims
1. A communication method, characterized in that: Executed by a first entity, the method includes: receiving first information sent by a second entity, where the first information is used to request authorization from a resource owner; Authorization processing is performed according to the first information and the perception-related policy corresponding to the resource owner.
2. The method according to claim 1, characterized in that The first information includes at least one of the following: identification of the perceived target or the perceived target's owner; First perception role information; the first perception role information includes the first terminal identifier and / or the perception role corresponding to the first terminal identifier; First perception area; First perception time; A request to associate the perception result with the first identity; A request for opening the context awareness information includes a third terminal identifier.
3. The method according to claim 2, characterized in that The perception-related strategy includes at least one of the following: the identifier of the resource owner; whether to allow perceived instructions; The second perception role information that is allowed or prohibited; the second perception role information includes the second terminal identifier and / or the perception role corresponding to the second terminal identifier; a second perceptual area that is permitted or prohibited; the second perceived time that is permitted or prohibited; an indication of whether to allow associating the perception result with the second identity identifier; An indication of whether to allow associating the resource owner's identity with the perception result; Indicates whether to allow open sensing context information.
4. The method according to claim 3, characterized in that Performing authorization processing according to the first information and a perception-related policy corresponding to the resource owner, including: When the first information complies with the perception-related policy, performing authorization processing; The authorization process includes at least one of the following: Generate token; sending a token to the second entity; Agree to the authorization request of the second entity.
5. The method according to claim 4, characterized in that The information in the token includes at least one of the following: the identifier of the resource owner; Allowing for the indication to be perceived; First perception role information; First perception area; First perception time; an indication allowing the perception result to be associated with the first identity identifier; The indication of allowing the opening of the perception context information includes a third terminal identifier.
6. The method according to claim 4, characterized in that The first information complies with the perception-related policy, including: the first information includes an identifier of a perception target or a perception target owner, the perception-related policy includes an identifier of a resource owner and an indication of permission to be perceived, and the identifier of the perception target or the perception target owner in the first information and the identifier of the resource owner in the perception-related policy are the same as or have a mapping relationship with each other; The token includes an identification of the sensing target or the sensing target owner and / or an indication of permission to be sensed.
7. The method according to claim 4, characterized in that The first information complies with the perception-related policy, including: the first information includes first perception role information, the perception-related policy includes allowed second perception role information, the first terminal identifier in the first information and the second terminal identifier in the perception-related policy are the same as or have a mapping relationship, and the perception role corresponding to the first terminal identifier and the perception role corresponding to the second terminal identifier are the same as or have a mapping relationship; The token includes allowed perception role information.
8. The method according to claim 4, characterized in that The first information complies with the perception-related policy, including: the first information includes first perception role information, the perception-related policy includes an identifier of a resource owner, and the first terminal identifier in the first perception role information and the identifier of the resource owner in the perception-related policy are the same as or have a mapping relationship with each other; The token includes allowed perception role information.
9. The method according to claim 7 or 8, characterized in that The perception role includes at least one of a perception sender and a perception receiver.
10. The method according to claim 4, characterized in that The first information complies with the perception-related policy, including: the first information includes a first perception area, the perception-related policy includes an allowed second perception area, the first perception area is included in the second perception area, or the first perception area and the second perception area are the same; The token includes the first perception area.
11. The method according to claim 4, characterized in that The first information complies with the perception-related policy, including: the first information includes a first perception time, the perception-related policy includes an allowed second perception time, the first perception time and the second perception time are the same or the first perception time is covered by the second perception time; The token includes the first perceived time.
12. The method according to claim 4, characterized in that The first information complies with the perception-related policy, including: the first information includes a request to associate the perception result with a first identity identifier, the perception-related policy includes an indication allowing the perception result to be associated with a second identity identifier, and the first identity identifier and the second identity identifier are the same or have a mapping relationship; The token includes an indication allowing the perception result to be associated with the first identity.
13. The method according to claim 4, characterized in that The first information complies with the perception-related policy, including: the first information includes a request to associate the perception result with a first identity identifier, the perception-related policy includes an identifier of a resource owner, and the first identity identifier and the identifier of the resource owner are the same or have a mapping relationship; The token includes an indication allowing the perception result to be associated with the first identity.
14. The method according to claim 12 or 13, characterized in that The first identity includes at least one of a user permanent identifier SUPI, a hidden user identifier SUCI, an application layer ID, a general public user identifier GPSI, an international mobile subscriber identity IMSI, and an international mobile subscriber number MSISDN; the second identity includes at least one of SUPI, SUCI, an application layer ID, GPSI, IMSI, and MSISDN.
15. The method according to claim 4, characterized in that The first information complies with the perception-related policy, including: the first information includes a request to open perception context information, the third terminal identifier in the request to open the perception context information and the identifier of the resource owner in the perception-related policy are the same as or have a mapping relationship, and the perception-related policy includes an indication of allowing the opening of perception context information; The token includes an indication allowing open-aware context information.
16. The method according to claim 3, characterized in that The resource owner's identifier includes at least one of SUPI, SUCI, application layer ID, GPSI, IMSI, and MSISDN; The first terminal identifier includes at least one of SUPI, SUCI, application layer ID, GPSI, IMSI and MSISDN; The second terminal identifier includes at least one of SUPI, SUCI, application layer ID, GPSI, IMSI and MSISDN; The third terminal identifier includes at least one of SUPI, SUCI, application layer ID, GPSI, IMSI and MSISDN.
17. The method according to claim 1, wherein The first entity stores identifiers of multiple resource owners and perception-related policies corresponding to the identifiers of the respective resource owners.
18. The method according to any one of claims 1 to 16, characterized in that The method further comprises: receiving identity authentication information of the second entity sent by the second entity; Authenticate the second entity based on the authentication information.
19. The method according to any one of claims 1 to 16, characterized in that The resource owner is one of a perception target, a perception target owner, a terminal, a user using the terminal, and a subscriber related to the terminal.
20. The method according to any one of claims 1 to 16, characterized in that The second entity is one of a terminal, a client, an application function or a network function.
21. A communication method, characterized in that: Executed by a second entity, the method includes: A first message is sent to a first entity, where the first message is used to request authorization from a resource owner, and the first entity is used to perform authorization processing according to a perception-related policy corresponding to the first message and the resource owner.
22. The method according to claim 21, characterized in that The first information includes at least one of the following: identification of the perceived target or the perceived target's owner; First perception role information; the first perception role information includes the first terminal identifier and / or the perception role corresponding to the first terminal identifier; First perception area; First perception time; A request to associate the perception result with the first identity; A request for opening the context awareness information includes a third terminal identifier.
23. The method according to claim 22, characterized in that The perception-related strategy includes at least one of the following: the identifier of the resource owner; whether to allow perceived instructions; The second perception role information that is allowed or prohibited; the second perception role information includes the second terminal identifier and / or the perception role corresponding to the second terminal identifier; a second perceptual area that is permitted or prohibited; the second perceived time that is permitted or prohibited; an indication of whether to allow associating the perception result with the second identity identifier; An indication of whether to allow associating the resource owner's identity with the perception result; Indicates whether to allow open sensing context information.
24. The method according to claim 23, wherein The method further comprises: A token is received from the first entity, where the token is generated when the first information complies with the perception-related policy.
25. The method according to claim 24, characterized in that The information in the token includes at least one of the following: the identifier of the resource owner; Allowing for the indication to be perceived; First perception role information; First perception area; First perception time; an indication allowing the perception result to be associated with the first identity identifier; The indication of allowing the opening of the perception context information includes a third terminal identifier.
26. The method according to claim 24, characterized in that The first information complies with the perception-related policy, including: the first information includes an identifier of a perception target or a perception target owner, the perception-related policy includes an identifier of a resource owner and an indication of permission to be perceived, and the identifier of the perception target or the perception target owner in the first information and the identifier of the resource owner in the perception-related policy are the same as or have a mapping relationship with each other; The token includes an identification of the sensing target or the sensing target owner and / or an indication of permission to be sensed.
27. The method according to claim 24, characterized in that The first information complies with the perception-related policy, including: the first information includes first perception role information, the perception-related policy includes allowed second perception role information, the first terminal identifier in the first information and the second terminal identifier in the perception-related policy are the same as or have a mapping relationship, and the perception role corresponding to the first terminal identifier and the perception role corresponding to the second terminal identifier are the same as or have a mapping relationship; The token includes allowed perception role information.
28. The method according to claim 24, characterized in that The first information complies with the perception-related policy, including: the first information includes first perception role information, the perception-related policy includes an identifier of a resource owner, and the first terminal identifier in the first perception role information and the identifier of the resource owner in the perception-related policy are the same as or have a mapping relationship with each other; The token includes allowed perception role information.
29. The method according to claim 27 or 28, characterized in that The perception role includes at least one of a perception sender and a perception receiver.
30. The method according to claim 24, wherein The first information complies with the perception-related policy, including: the first information includes a first perception area, the perception-related policy includes an allowed second perception area, the first perception area is included in the second perception area, or the first perception area and the second perception area are the same; The token includes the first perception area.
31. The method according to claim 24, wherein The first information complies with the perception-related policy, including: the first information includes a first perception time, the perception-related policy includes an allowed second perception time, the first perception time and the second perception time are the same or the first perception time is covered by the second perception time; The token includes the first perceived time.
32. The method according to claim 24, wherein The first information complies with the perception-related policy, including: the first information includes a request to associate the perception result with a first identity identifier, the perception-related policy includes an indication allowing the perception result to be associated with a second identity identifier, and the first identity identifier and the second identity identifier are the same or have a mapping relationship; The token includes an indication allowing the perception result to be associated with the first identity.
33. The method according to claim 24, wherein The first information complies with the perception-related policy, including: the first information includes a request to associate the perception result with a first identity identifier, the perception-related policy includes an identifier of a resource owner, and the first identity identifier and the identifier of the resource owner are the same or have a mapping relationship; The token includes an indication allowing the perception result to be associated with the first identity.
34. The method according to claim 32 or 33, characterized in that The first identity includes at least one of a user permanent identifier SUPI, a hidden user identifier SUCI, an application layer ID, a general public user identifier GPSI, an international mobile subscriber identity IMSI, and an international mobile subscriber number MSISDN; the second identity includes at least one of SUPI, SUCI, an application layer ID, GPSI, IMSI, and MSISDN.
35. The method according to claim 24, wherein The first information complies with the perception-related policy, including: the first information includes a request to open perception context information, the third terminal identifier in the request to open the perception context information and the identifier of the resource owner in the perception-related policy are the same as or have a mapping relationship, and the perception-related policy includes an indication of allowing the opening of perception context information; The token includes an indication allowing open-aware context information.
36. The method according to claim 23, wherein The resource owner's identifier includes at least one of SUPI, SUCI, application layer ID, GPSI, IMSI, and MSISDN; The first terminal identifier includes at least one of SUPI, SUCI, application layer ID, GPSI, IMSI and MSISDN; The second terminal identifier includes at least one of SUPI, SUCI, application layer ID, GPSI, IMSI and MSISDN; The third terminal identifier includes at least one of SUPI, SUCI, application layer ID, GPSI, IMSI and MSISDN.
37. The method according to claim 21, wherein The first entity stores identifiers of multiple resource owners and perception-related policies corresponding to the identifiers of the respective resource owners.
38. The method according to any one of claims 21 to 37, characterized in that The method further comprises: Sending the identity authentication information of the second entity to the first entity.
39. The method according to any one of claims 21 to 37, characterized in that The resource owner is one of a perception target, a perception target owner, a terminal, a user using the terminal, and a subscriber related to the terminal.
40. The method according to any one of claims 21 to 37, characterized in that The second entity is one of a terminal, a client, an application function or a network function.
41. A first entity, characterized in that include: a transceiver module, configured to receive first information sent by a second entity, where the first information is used to request authorization from a resource owner; A processing module is used to perform authorization processing according to the first information and the perception-related policy corresponding to the resource owner.
42. A second entity, characterized in that include: The transceiver module is used to send first information to a first entity, where the first information is used to request authorization from a resource owner, and the first entity is used to perform authorization processing based on the first information and the perception-related policy corresponding to the resource owner.
43. A first entity, characterized in that include: one or more processors; The first entity is configured to execute the communication method according to any one of claims 1 to 20.
44. A second entity, characterized in that include: one or more processors; The second entity is configured to execute the communication method according to any one of claims 21 to 40.
45. A communication system, characterized in that The method comprises a first entity and a second entity, wherein the first entity is configured to implement the communication method according to any one of claims 1 to 20, and the second entity is configured to implement the communication method according to any one of claims 21 to 40.
46. A storage medium storing instructions, characterized in that: When the instruction is executed on a communication device, the communication device is caused to execute the communication method according to any one of claims 1 to 20 or the communication method according to any one of claims 21 to 40.
Citation Information
Patent Citations
Information processing method and device, communication equipment and storage medium
CN117280765A
Method and device for provisioning collective perception in communication networks
US20190386896A1
Method and apparatus for providing sensing service, and communication device and storage medium
WO2023141771A1
Perception service obtaining method and apparatus
WO2024000331A1