Communication methods, network function, communication system and storage medium

The method of verifying NPN information through the network function service provider solves the problem of weak communication security on the NPN client side and realizes effective protection of sensitive information.

WO2025208537A1PCT designated stage Publication Date: 2025-10-09BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/086127
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-04-03
Publication Date
2025-10-09

AI Technical Summary

Technical Problem

The deployment of network functions on the client side of the non-public network (NPN) has weak security, which may lead to the leakage of sensitive information. Existing technologies cannot effectively prevent the illegal acquisition of terminal information.

Method used

The network function service provider receives and verifies the service request sent by the network function service consumer, including NPN information, to ensure communication security.

Benefits of technology

By verifying NPN information, the security of NPN client-side communications is improved, preventing illegal access to sensitive information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024086127_09102025_PF_FP_ABST
    Figure CN2024086127_09102025_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure relates to communication methods, a network function, a communication system and a storage medium. A method comprises: a network function service provider receives a service request sent by a network function service consumer, the service request comprising non-public network (NPN) information; and the network function service provider verifies the service request. In the embodiments of the present disclosure, the network function service provider performs verification on the network function service consumer, thus improving the communication security.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method, network function, communication system and storage medium Technical Field

[0001] The present disclosure relates to the field of communication technology, and in particular to a communication method, a network function, a communication system, and a storage medium. Background Art

[0002] A non-public network (NPN) can be carried by a public land mobile network (PLMN). For performance and privacy reasons, NPN users can request the deployment of one or more dedicated network functions (NFs) on the customer premises. Deploying dedicated NFs on the customer premises can, for example, involve deploying the NFs to the customer's (e.g., Enterprise A) computer room. For example, a dedicated user plane function (UPF) and some control plane (CP) functions can be deployed on the customer premises.

[0003] Compared to PLMN operators, NPN users may have limited resources for network security protection. For example, the physical security of the customer side may be weaker than that of the PLMN operator's core network. If the network function deployed on the NPN customer side is compromised, it may request sensitive terminal (UE) information, which may not be relevant to the services allowed by the NPN.

[0004] Summary of the Invention

[0005] How to improve the security of NPN client-side communications is a technical problem that needs to be solved.

[0006] The embodiments of the present disclosure provide a communication method, a network function, a communication system, and a storage medium.

[0007] According to a first aspect of an embodiment of the present disclosure, a communication method is proposed, which includes: a network function service provider receiving a service request sent by a network function service consumer, wherein the service request includes non-public network NPN information; and the network function service provider verifies the service request.

[0008] According to a second aspect of an embodiment of the present disclosure, a communication method is proposed, including: a network function service provider sends first information to an NRF, where the first information includes NPN information.

[0009] According to a third aspect of an embodiment of the present disclosure, a communication method is proposed, comprising: an NRF receiving a token request sent by a network function service consumer, wherein the token request includes NPN information; and the NRF verifying the token request.

[0010] According to a fourth aspect of an embodiment of the present disclosure, a communication method is proposed, the method including: an NRF receiving first information sent by a network function service provider, the first information including NPN information.

[0011] According to a fifth aspect of an embodiment of the present disclosure, a communication method is proposed, the method including: an NRF receiving second information sent by a network function consumer, the second information including NPN information associated with the network function service consumer.

[0012] According to a sixth aspect of an embodiment of the present disclosure, a communication method is proposed, the method comprising: a network function service consumer sends a service request to a network function service provider, wherein the service request includes NPN information.

[0013] According to a seventh aspect of an embodiment of the present disclosure, a communication method is proposed, the method comprising: a network function service consumer sends a token request to an NRF, wherein the token request includes NPN information.

[0014] According to an eighth aspect of an embodiment of the present disclosure, a communication method is proposed, the method comprising: a network function service consumer sending second information to an NRF, wherein the second information comprises NPN information associated with the network function service consumer.

[0015] According to the ninth aspect of the embodiment of the present disclosure, a network function service provider is proposed, including: a transceiver module for receiving a service request sent by a network function service consumer, wherein the service request includes non-public network NPN information; and a processing module for verifying the service request.

[0016] According to a tenth aspect of an embodiment of the present disclosure, a network function service provider is proposed, including: a transceiver module, configured to send first information to an NRF, where the first information includes NPN information.

[0017] According to the eleventh aspect of the embodiment of the present disclosure, an NRF is proposed, including: a transceiver module for receiving a token request sent by a network function service consumer, wherein the token request includes NPN information; and a processing module for verifying the token request.

[0018] According to a twelfth aspect of an embodiment of the present disclosure, an NRF is proposed, including: a transceiver module, configured to receive first information sent by a network function service provider, where the first information includes NPN information.

[0019] According to the thirteenth aspect of the embodiment of the present disclosure, an NRF is proposed, including: a transceiver module, used to receive second information sent by a network function consumer, where the second information includes NPN information associated with the network function service consumer.

[0020] According to the fourteenth aspect of the embodiment of the present disclosure, a network function service consumer is proposed, including: a transceiver module, used to send a service request to a network function service provider, wherein the service request includes NPN information.

[0021] According to a fifteenth aspect of an embodiment of the present disclosure, a network function service consumer is proposed, including: a transceiver module, configured to send a token request to an NRF, wherein the token request includes NPN information.

[0022] According to the sixteenth aspect of the embodiment of the present disclosure, a network function service consumer is proposed, including: a transceiver module, used to send second information to the NRF, where the second information includes NPN information associated with the network function service consumer.

[0023] According to a seventeenth aspect of an embodiment of the present disclosure, a network function service provider is proposed, comprising: one or more processors; wherein the processor is configured to execute the communication method of the first aspect or the second aspect.

[0024] According to an eighteenth aspect of the embodiments of the present disclosure, an NRF is proposed, comprising: one or more processors; wherein the processor is used to execute the communication method of the third aspect, the fourth aspect, or the fifth aspect.

[0025] According to the nineteenth aspect of the embodiment of the present disclosure, a network function service consumer is proposed, including: one or more processors; wherein the processor is used to execute the communication method of the sixth aspect or the seventh aspect or the eighth aspect.

[0026] According to the twentieth aspect of the embodiment of the present disclosure, a communication system is proposed, including a network function service provider, an NRF and a network function service consumer, wherein the network function service provider is configured to implement the communication method of the first aspect or the second aspect, the NRF is configured to implement the communication method of the third aspect or the fourth aspect or the fifth aspect, and the network function service consumer is configured to implement the communication method of the sixth aspect or the seventh aspect or the eighth aspect.

[0027] According to the twenty-first aspect of an embodiment of the present disclosure, a storage medium is proposed, which stores instructions, and is characterized in that when the instructions are executed on a communication device, the communication device executes any one of the methods of the first to eighth aspects.

[0028] Through the embodiments of the present disclosure, the network function service provider receives a service request sent by a network function service consumer, which includes NPN information. The network function service provider verifies the network function service consumer based on the NPN information, which can improve communication security. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure, the following drawings required for describing the embodiments are introduced. The following drawings are merely some embodiments of the present disclosure and do not impose specific limitations on the protection scope of the present disclosure.

[0030] FIG1A is a schematic diagram of the architecture of a PNI-NPN with a dedicated UPF and partial CP functions deployed on the client side.

[0031] FIG1B is a schematic diagram showing a communication system architecture according to an embodiment of the present disclosure.

[0032] FIG2 is an interactive schematic diagram illustrating a communication method according to an embodiment of the present disclosure.

[0033] FIG3A is a flow chart illustrating a communication method according to an embodiment of the present disclosure.

[0034] FIG3B is a flow chart illustrating a communication method according to an embodiment of the present disclosure.

[0035] FIG3C is a flow chart illustrating a communication method according to an embodiment of the present disclosure.

[0036] FIG4A is a flow chart showing a communication method according to an embodiment of the present disclosure.

[0037] FIG4B is a flow chart illustrating a communication method according to an embodiment of the present disclosure.

[0038] FIG4C is a flow chart illustrating a communication method according to an embodiment of the present disclosure.

[0039] FIG4D is a flow chart illustrating a communication method according to an embodiment of the present disclosure.

[0040] FIG5A is a flow chart illustrating a communication method according to an embodiment of the present disclosure.

[0041] FIG5B is a flow chart illustrating a communication method according to an embodiment of the present disclosure.

[0042] FIG5C is a flow chart illustrating a communication method according to an embodiment of the present disclosure.

[0043] FIG6 is an interactive diagram illustrating a communication method according to an embodiment of the present disclosure.

[0044] FIG7A is an interactive diagram illustrating a communication method according to an embodiment of the present disclosure.

[0045] FIG7B is an interactive diagram illustrating a communication method according to an embodiment of the present disclosure.

[0046] FIG7C is an interactive diagram illustrating a communication method according to an embodiment of the present disclosure.

[0047] FIG7D is a schematic diagram showing the relationship among a UE, an NF service consumer, and an NPN according to an embodiment of the present disclosure.

[0048] FIG8A is a schematic diagram of the structure of the network function service provider proposed in an embodiment of the present disclosure.

[0049] FIG8B is a schematic diagram of the structure of the NRF proposed in an embodiment of the present disclosure.

[0050] FIG8C is a schematic diagram of the structure of the network function service consumer proposed in an embodiment of the present disclosure.

[0051] FIG9A is a schematic structural diagram of a communication device proposed in an embodiment of the present disclosure.

[0052] FIG9B is a schematic diagram of the structure of the chip proposed in an embodiment of the present disclosure. DETAILED DESCRIPTION

[0053] The embodiments of the present disclosure provide a communication method, a network function, a communication system, and a storage medium.

[0054] In a first aspect, an embodiment of the present disclosure proposes a communication method, which includes: a network function service provider receives a service request sent by a network function service consumer, wherein the service request includes non-public network NPN information; and the network function service provider verifies the service request.

[0055] In the above embodiment, the network function service provider receives a service request sent by the network function service consumer, which includes NPN information. The network function service provider verifies the network function service consumer based on the NPN information, which can improve communication security.

[0056] In combination with some embodiments of the first aspect, in some embodiments, the service request includes a token, and the token includes NPN information; the network function service provider verifies the service request, including: verifying whether the NPN information in the token is consistent with the NPN information actually associated with the network function service consumer.

[0057] In combination with some embodiments of the first aspect, in some embodiments, the NPN information actually associated with the network function service consumer is the NPN associated with the network function service consumer recorded in the certificate of the network function service consumer.

[0058] In combination with some embodiments of the first aspect, in some embodiments, the service request includes a terminal identifier; the network function service provider verifies the service request, including: verifying that the NPN associated with the network function service consumer has an association relationship with the terminal corresponding to the terminal identifier.

[0059] In combination with some embodiments of the first aspect, in some embodiments, the NPN associated with the network function service consumer is the NPN associated with the network function service consumer recorded in the certificate of the network function service consumer.

[0060] In combination with some embodiments of the first aspect, in some embodiments, the verification that the NPN associated with the network function service consumer has an association relationship with the terminal corresponding to the terminal identifier includes at least one of the following: the network function service provider determines, based on a unified data management (UDM) or a unified data repository (UDR), that the terminal has subscribed to the NPN associated with the network function service consumer; the network function service provider determines, based on the UDM or UDR, that there is an association relationship between the terminal and the NPN associated with the network function service consumer; the network function service provider determines, based on the UDM or UDR, that the NPN associated with the network function service consumer serves the terminal; the terminal identifier is included in a list of terminals associated with the NPN stored locally by the network function service provider.

[0061] In combination with some embodiments of the first aspect, in some embodiments, the method further includes: the network function service provider sends first information to the network storage function NRF; wherein, the first information includes at least one of the following: service and NPN information allowing requesting the service; resource and NPN information allowing requesting the resource; association relationship between NPN information and terminal identification.

[0062] In combination with some embodiments of the first aspect, in some embodiments, the verification of the service request includes at least one of the following: verifying whether the NPN information in the service request is consistent with the NPN information actually associated with the network function service consumer; verifying whether the NPN information in the service request is consistent with the NPN information in the first information.

[0063] In combination with some embodiments of the first aspect, in some embodiments, the NPN information actually associated with the network function service consumer is the NPN associated with the network function service consumer recorded in the certificate of the network function service consumer.

[0064] In combination with some embodiments of the first aspect, in some embodiments, the NRF verifies the token request based on at least one of the first information, the second information of the network function service consumer, and the certificate of the network function service consumer.

[0065] In combination with some embodiments of the first aspect, in some embodiments, the second information includes NPN information associated with the network function service consumer, and the NPN information includes at least one of the following: a closed access group CAG identifier associated with the NPN; location information; and an NPN identifier.

[0066] In a second aspect, an embodiment of the present disclosure proposes a communication method, which includes: a network function service provider sends first information to an NRF, where the first information includes NPN information.

[0067] In combination with some embodiments of the second aspect, in some embodiments, the NPN information in the first information includes at least one of the following: service and NPN information allowing requesting the service; resource and NPN information allowing requesting the resource; association between NPN information and terminal identification.

[0068] In a third aspect, an embodiment of the present disclosure proposes a communication method, which includes: an NRF receiving a token request sent by a network function service consumer, wherein the token request includes NPN information; and the NRF verifying the token request.

[0069] In combination with some embodiments of the third aspect, in some embodiments, the method also includes: the NRF receives first information sent by the network function provider and second information sent by the network function service consumer; the NRF verifies the token request, including: verifying the token request based on at least one of the first information, the second information and the network function service consumer certificate.

[0070] In combination with some embodiments of the third aspect, in some embodiments, the token request is verified based on at least one of the first information, the second information and the network function service consumer certificate, including: verifying whether the NPN information in the token request is consistent with the NPN in the second information; verifying whether the NPN information in the token request is consistent with the NPN associated with the network function service consumer recorded in the network function service consumer certificate; verifying whether the NPN information in the token request is consistent with the NPN information in the first information.

[0071] In combination with some embodiments of the third aspect, in some embodiments, the second information includes NPN information associated with the network function service consumer, and the NPN information includes at least one of the following: a closed access group CAG identifier associated with the NPN; location information; and an NPN identifier.

[0072] In combination with some embodiments of the third aspect, in some embodiments, the first information includes at least one of the following: service and NPN information allowing requesting the service; resource and NPN information allowing requesting the resource; association between NPN information and terminal identification.

[0073] In combination with some embodiments of the third aspect, in some embodiments, the method further includes: the NRF sending a token to the network function service consumer, where the token includes NPN information.

[0074] In a fourth aspect, an embodiment of the present disclosure proposes a communication method, which includes: an NRF receiving first information sent by a network function service provider, where the first information includes NPN information.

[0075] In combination with some embodiments of the fourth aspect, in some embodiments, the NPN information in the first information includes at least one of the following: service and NPN information allowing requesting the service; resource and NPN information allowing requesting the resource; association relationship between NPN information and terminal identification.

[0076] In a fifth aspect, an embodiment of the present disclosure proposes a communication method, which includes: an NRF receives second information sent by a network function consumer, where the second information includes NPN information associated with the network function service consumer.

[0077] In combination with some embodiments of the fifth aspect, in some embodiments, the NPN information in the second information includes at least one of the following: a closed access group CAG identifier associated with the NPN; location information; and an NPN identifier.

[0078] In a sixth aspect, an embodiment of the present disclosure proposes a communication method, which includes: a network function service consumer sends a service request to a network function service provider, wherein the service request includes NPN information.

[0079] In combination with some embodiments of the sixth aspect, in some embodiments, the service request includes a token and the token NPN information.

[0080] In combination with some embodiments of the sixth aspect, in some embodiments, the service request includes a terminal identifier.

[0081] In combination with some embodiments of the sixth aspect, in some embodiments, the method further includes: the network function service consumer sends a token request to the NRF, and the token request includes NPN information.

[0082] In combination with some embodiments of the sixth aspect, in some embodiments, the method further includes: the network function service consumer sends second information to the NRF; wherein, the second information includes the NPN information associated with the network function service consumer, and the NPN information includes at least one of the following: a closed access group CAG identifier associated with the NPN; location information; and an NPN identifier.

[0083] In a seventh aspect, an embodiment of the present disclosure proposes a communication method, which includes: a network function service consumer sends a token request to an NRF, wherein the token request includes NPN information.

[0084] In an eighth aspect, an embodiment of the present disclosure proposes a communication method, which includes: a network function service consumer sends second information to an NRF, where the second information includes NPN information associated with the network function service consumer.

[0085] In combination with some embodiments of the eighth aspect, in some embodiments, the NPN information in the second information includes at least one of the following: a closed access group CAG identifier associated with the NPN; location information; and an NPN identifier.

[0086] In the ninth aspect, an embodiment of the present disclosure proposes a network function service provider, including: a transceiver module for receiving a service request sent by a network function service consumer, wherein the service request includes non-public network NPN information; and a processing module for verifying the service request.

[0087] In a tenth aspect, an embodiment of the present disclosure proposes a network function service provider, including: a transceiver module, used to send first information to an NRF, where the first information includes NPN information.

[0088] In the eleventh aspect, an embodiment of the present disclosure proposes an NRF, including: a transceiver module for receiving a token request sent by a network function service consumer, wherein the token request includes NPN information; and a processing module for verifying the token request.

[0089] In a twelfth aspect, an embodiment of the present disclosure proposes an NRF, comprising: a transceiver module, configured to receive first information sent by a network function service provider, wherein the first information comprises NPN information.

[0090] In the thirteenth aspect, an embodiment of the present disclosure proposes an NRF, including: a transceiver module, used to receive second information sent by a network function consumer, where the second information includes NPN information associated with the network function service consumer.

[0091] In the fourteenth aspect, an embodiment of the present disclosure proposes a network function service consumer, including: a transceiver module, used to send a service request to a network function service provider, wherein the service request includes NPN information.

[0092] In the fifteenth aspect, an embodiment of the present disclosure proposes a network function service consumer, including: a transceiver module, used to send a token request to an NRF, and the token request includes NPN information.

[0093] In the sixteenth aspect, an embodiment of the present disclosure proposes a network function service consumer, including: a transceiver module, used to send second information to the NRF, where the second information includes NPN information associated with the network function service consumer.

[0094] In the seventeenth aspect, an embodiment of the present disclosure proposes a network function service provider, comprising: one or more processors; wherein the processor is used to execute the communication method of the first aspect or the second aspect.

[0095] In an eighteenth aspect, an embodiment of the present disclosure proposes an NRF, comprising: one or more processors; wherein the processor is used to execute the communication method of the third aspect, the fourth aspect, or the fifth aspect.

[0096] In the nineteenth aspect, an embodiment of the present disclosure proposes a network function service consumer, comprising: one or more processors; wherein the processor is used to execute the communication method of the sixth aspect, the seventh aspect, or the eighth aspect.

[0097] In the twentieth aspect, an embodiment of the present disclosure proposes a communication system, including a network function service provider, an NRF and a network function service consumer, wherein the network function service provider is configured to implement the communication method of the first aspect or the second aspect, the NRF is configured to implement the communication method of the third aspect or the fourth aspect or the fifth aspect, and the network function service consumer is configured to implement the communication method of the sixth aspect or the seventh aspect or the eighth aspect.

[0098] In the twenty-first aspect, an embodiment of the present disclosure proposes a storage medium storing instructions, characterized in that when the instructions are executed on a communication device, the communication device executes any one of the methods in the first to eighth aspects.

[0099] In aspect 22, an embodiment of the present disclosure proposes a program product, comprising: a computer program, which, when executed by a communication device, enables the communication device to execute the method described in any one of the optional implementation methods of aspect 1 to aspect 8.

[0100] On the twenty-third aspect, an embodiment of the present disclosure proposes a computer program, which, when executed on a computer, enables the computer to execute the method described in any one of the optional implementations of aspects one to eight.

[0101] In a twenty-fourth aspect, an embodiment of the present disclosure provides a chip or a chip system, wherein the chip or chip system includes a processing circuit configured to execute the method described in any optional implementation manner of the first to eighth aspects.

[0102] It is understandable that the above-mentioned network devices, communication systems, storage media, program products, computer programs, chips, or chip systems are all used to perform the methods proposed in the embodiments of the present disclosure. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects of the corresponding methods and will not be repeated here.

[0103] The embodiments of the present disclosure provide a communication method, a network function service consumer, a network function, a network function service provider, a communication system, and a storage medium. In some embodiments, the terms communication method, information transmission method, information reporting method, and information receiving method are interchangeable.

[0104] The embodiments of the present disclosure are not exhaustive and are merely illustrative of some embodiments, and are not intended to be a specific limitation on the scope of protection of the present disclosure. In the absence of contradiction, each step in a certain embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a certain embodiment can also be implemented as an independent embodiment, and the order of the steps in a certain embodiment can be arbitrarily exchanged. In addition, the optional implementation methods in a certain embodiment can be arbitrarily combined; in addition, the embodiments can be arbitrarily combined. For example, some or all steps of different embodiments can be arbitrarily combined, and a certain embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.

[0105] In each embodiment of the present disclosure, unless otherwise specified or provided for by logic, the terms and / or descriptions between the embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form a new embodiment based on their inherent logical relationships.

[0106] The terms used in the embodiments of the present disclosure are only for the purpose of describing specific embodiments and are not intended to limit the present disclosure.

[0107] In the embodiments of the present disclosure, unless otherwise specified, elements expressed in the singular, such as "a", "an", "the", "above", "said", "the", "the", etc., may mean "one and only one", or "one or more", "at least one", etc. For example, when using articles such as "a", "an", "the" in English in translation, the noun following the article may be understood as a singular expression or a plural expression.

[0108] In the embodiments of the present disclosure, “plurality” refers to two or more.

[0109] In some embodiments, the terms "at least one," "one or more," "a plurality of," "multiple," etc. may be used interchangeably.

[0110] In some embodiments, descriptions such as "at least one of A and B," "A and / or B," "A in one case, B in another case," or "in response to one case A, in response to another case B" may include the following technical solutions depending on the situation: in some embodiments, A (A is executed independently of B); in some embodiments, B (B is executed independently of A); in some embodiments, execution is selected from A and B (A and B are selectively executed); and in some embodiments, A and B (both A and B are executed). The above is also applicable when there are more branches such as A, B, and C.

[0111] In some embodiments, "A or B" and other descriptions may include the following technical solutions depending on the situation: in some embodiments, A (A is executed independently of B); in some embodiments, B (B is executed independently of A); in some embodiments, execution is selected from A and B (A and B are selectively executed). The above is also applicable when there are more branches such as A, B, C, etc.

[0112] The prefixes such as "first" and "second" in the embodiments of the present disclosure are only used to distinguish different description objects and do not constitute any restriction on the position, order, priority, quantity or content of the description objects. For the statement of the description object, please refer to the description in the context of the claims or embodiments, and no unnecessary restriction should be constituted due to the use of prefixes. For example, if the description object is a "field", the ordinal number before the "field" in the "first field" and the "second field" does not limit the position or order between the "fields". "First" and "second" do not limit whether the "fields" they modify are in the same message, nor do they limit the order of the "first field" and the "second field". For another example, if the description object is a "level", the ordinal number before the "level" in the "first level" and the "second level" does not limit the priority between the "levels". For another example, the number of description objects is not limited by the ordinal number and can be one or more. Taking "first device" as an example, the number of "devices" can be one or more. In addition, the objects modified by different prefixes can be the same or different. For example, if the description object is "device", then the "first device" and the "second device" can be the same device or different devices, and their types can be the same or different; for another example, if the description object is "information", then the "first information" and the "second information" can be the same information or different information, and their contents can be the same or different.

[0113] In some embodiments, “including A,” “comprising A,” “used to indicate A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.

[0114] In some embodiments, terms such as "in response to...", "in response to determining...", "in the case of...", "at the time of...", "when...", "if...", "if...", etc. can be used interchangeably.

[0115] In some embodiments, terms such as "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not less than", and "above" can be replaced with each other, and terms such as "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", and "below" can be replaced with each other.

[0116] In some embodiments, devices, etc. can be interpreted as physical or virtual, and their names are not limited to the names recorded in the embodiments. Terms such as "device", "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", and "subject" can be used interchangeably.

[0117] In some embodiments, "network" can be interpreted as devices included in the network (eg, access network equipment, core network equipment, etc.).

[0118] In some embodiments, the terms "access network device (AN device)", "radio access network device (RAN device)", "base station (BS)", "radio base station" "fixed station", "node", "access point", "transmission point (TP)", "reception point (RP)", "transmission / reception point (TRP)" "panel", "antenna panel", "antenna array", "cell", "macro cell", "small cell", "femto cell", "pico cell", "sector", "cell group", "serving cell", "carrier", "component carrier", "bandwidth part (BWP)" and the like may be used interchangeably.

[0119] In some embodiments, the terms "terminal", "terminal device", "user equipment (UE)", "user terminal", "mobile station (MS)", "mobile terminal (MT)", subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, client, etc. can be used interchangeably.

[0120] In some embodiments, the access network device, the core network device, or the network device can be replaced by a terminal. For example, the various embodiments of the present disclosure can also be applied to a structure in which the communication between the access network device, the core network device, or the network device and the terminal is replaced by communication between multiple terminals (for example, device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, it is also possible to set the structure in which the terminal has all or part of the functions of the access network device. In addition, terms such as "uplink" and "downlink" can also be replaced by terms corresponding to communication between terminals (for example, "side"). For example, uplink channels, downlink channels, etc. can be replaced by side channels, and uplinks, downlinks, etc. can be replaced by side links.

[0121] In some embodiments, the terminal may be replaced by an access network device, a core network device, or a network device. In this case, the access network device, the core network device, or the network device may have a structure that has all or part of the functions of the terminal.

[0122] In some embodiments, obtaining data, information, etc. may comply with the laws and regulations of the country where the data is obtained.

[0123] In some embodiments, data, information, etc. may be obtained with the user's consent.

[0124] In addition, each element, each row, or each column in the table of the embodiment of the present disclosure can be implemented as an independent embodiment, and the combination of any elements, any rows, and any columns can also be implemented as an independent embodiment.

[0125] A non-public network (NPN) can be carried by a public land mobile network (PLMN). For performance and privacy reasons, NPN users can request the deployment of one or more dedicated network functions (NFs) on the customer premises. Deploying dedicated NFs on the customer premises can, for example, involve deploying the NFs to the customer's (e.g., Enterprise A) computer room. For example, a dedicated user plane function (UPF) and some control plane (CP) functions can be deployed on the customer premises.

[0126] FIG1A is a schematic diagram of the architecture of a public network integrated non-public network (PNI-NPN) in which a dedicated UPF and some CP functions are deployed on the client side.

[0127] As shown in Figure 1A, the PLMN network may include one or more of a network slice selection function (NSSF), a network exposure function (NEF), a network repository function (NRF), a policy control function (PCF), a unified data management (UDM) function, an application function (AF), an edge application server discovery function (EASDF), the network slice specific authentication and authorization function (NSSAAF), an authentication server function (AUSF), an access and mobility management function (AMF), a session management function (SMF), a service control point (SCP), and a network slice admission control function (NSACF). It may also include one or more of the AMF, SMF, user plane function (UPF) and data network (DN) deployed on the client side B.

[0128] It can be understood that "Nnssf", "Nnef", "Nnrf", "Npcf", "Nudm", "Naf", "Nnssaaf", "Nausf", "Namf", "Nsmf", "N4", "N6" and "N9" in Figure 1A represent the names of service interfaces. For details, please refer to the relevant description in the 3GPP standard protocol, which is not explained in detail here.

[0129] Compared to PLMN operators, NPN users may have limited resources available for network security protection. For example, the physical security of the customer side may be weaker than that of the PLMN operator's core network. If a network function deployed on the NPN customer side is compromised, it may request sensitive information about the terminal (UE), which may be unrelated to the services allowed by the NPN. For example, the Gateway Mobile Location Center (GMLC) deployed on the NPN customer side may be manipulated by an attacker, and the GMLC may attempt to obtain the location information of the victim terminal through the Location Service (LCS) service. However, currently, the PLMN cannot prevent the network function deployed on the NPN customer side from requesting / providing terminal information that is unrelated to the services allowed in the NPN.

[0130] An embodiment of the present disclosure provides a communication method, in which a network function service provider receives a service request sent by a network function service consumer, and the service request includes NPN information. The network function service provider verifies the network function service consumer based on the NPN information, which can improve communication security.

[0131] FIG1B is a schematic diagram showing a communication system architecture according to an embodiment of the present disclosure.

[0132] As shown in Figure 1B, the communication system 100 includes a network function service provider 101, an NRF 102, and a network function service consumer 103. The network function service provider 101 may be a network device capable of providing services, the NRF 102 may receive registration information and may generate and send tokens, and the network function service consumer 103 may be a network device that uses services. Of course, this disclosure is merely exemplary, and the network function service provider, the NRF, and the network function service consumer 103 may also be other types of nodes in the communication system, and this disclosure is not limited thereto.

[0133] In some embodiments, the network node may include at least one of an access network device and a core network device.

[0134] In some embodiments, the access network device is, for example, a node or device that accesses a terminal to a wireless network. The access network device may include an evolved NodeB (eNB) in a fifth generation mobile communication technology (5G) communication system, a next generation evolved NodeB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home node B (HNB), a home evolved nodeB (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an open base station (Open RAN), a cloud base station (Cloud RAN), a base station in other communication systems, and at least one of an access node in a Wi-Fi system, but is not limited thereto.

[0135] In some embodiments, the technical solution of the present disclosure can be applied to the Open RAN architecture. In this case, the interfaces between or within the access network devices involved in the embodiments of the present disclosure can be transformed into internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces can be implemented through software or programs.

[0136] In some embodiments, the access network device can be composed of a centralized unit (CU) and a distributed unit (DU), where the CU can also be called a control unit. The CU-DU structure can be used to split the protocol layer of the access network device, with the functions of some protocol layers centrally controlled by the CU, and the functions of the remaining part or all of the protocol layers distributed in the DU, which is centrally controlled by the CU, but is not limited to this.

[0137] In some embodiments, a core network device may be a device including one or more network elements, or may be multiple devices or device groups, each including all or part of the one or more network elements. The network element may be virtual or physical. The core network may include, for example, at least one of an Evolved Packet Core (EPC), a 5G Core Network (5GCN), and a Next Generation Core (NGC).

[0138] It can be understood that the communication system described in the embodiment of the present disclosure is for the purpose of more clearly illustrating the technical solution of the embodiment of the present disclosure, and does not constitute a limitation on the technical solution proposed in the embodiment of the present disclosure. Ordinary technicians in this field can know that with the evolution of the system architecture and the emergence of new business scenarios, the technical solution proposed in the embodiment of the present disclosure is also applicable to similar technical problems.

[0139] The following embodiments of the present disclosure may be applied to the communication system 100 shown in FIG1B , or a portion thereof, but are not limited thereto. The entities shown in FIG1B are illustrative only. The communication system may include all or part of the entities shown in FIG1B , or may include other entities outside of FIG1B . The number and form of the entities are arbitrary. Each entity may be physical or virtual. The connection relationship between the entities is illustrative only. The entities may be connected or disconnected, and the connection may be in any manner, including direct or indirect, wired or wireless.

[0140] The embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), future radio access (FRA), new radio access technology (RAT), new radio (NR), new radio access (NX), future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (registered trademark), Public Land Mobile Network (PLMN) networks, Device-to-Device (D2D) systems, Machine-to-Machine (M2M) systems, Internet of Things (IoT) systems, Vehicle-to-Everything (V2X), systems utilizing other communication methods, and next-generation systems based on and extending these methods. Furthermore, multiple systems may be combined (for example, a combination of LTE or LTE-A with 5G).

[0141] An embodiment of the present disclosure provides a communication method, in which a network function service provider receives a service request sent by a network function service consumer, and the service request includes NPN information. The network function service provider verifies the network function service consumer based on the NPN information, which can improve communication security.

[0142] FIG2 is an interactive diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG2 , the embodiment of the present disclosure relates to a communication method, and the method includes:

[0143] Step S2101: The network function service provider sends first information to the NRF.

[0144] In some embodiments, the NRF receives the first information sent by the network function service provider through a proxy.

[0145] In some embodiments, the NRF receives first information sent by a network function service provider.

[0146] In some embodiments, the network function service provider is any network device used to provide services.

[0147] In some embodiments, the network function service provider may register with the NFR.

[0148] In some embodiments, the first information may be registration information sent by the network function service provider.

[0149] In some embodiments, the first information may be a network function profile of the network function service provider, or may be included in a configuration file of the network function service provider.

[0150] In some embodiments, the first information may include at least one of the following:

[0151] Services and NPN information that allows requests for said services;

[0152] Resources and NPN information that allows requests for said resources;

[0153] The association between NPN information and terminal identification.

[0154] In some embodiments, the first information may include the services that the network function service consumer is allowed to use, and the NPN information associated with the network function service consumer that is allowed to request the service, for example, allowing the network service consumer associated with NPN1 to access service A, while not allowing the network service consumer associated with NPN2 to access service A.

[0155] Among them, the NPN information associated with the network function service consumer can be the NPN where the network function service consumer is located, or it can be the NPN served by the network function service consumer.

[0156] In some embodiments, the first information may include the service and NPN information that allows requesting the service, for example, allowing the network service consumer of NPN1 to access service A.

[0157] In some embodiments, the first information may include information about the service and the NPN that is not allowed to request the service, for example, the network service consumer of NPN1 is not allowed to access service A.

[0158] In some embodiments, the first information may include resources that the network function service consumer is allowed to use, and NPN information associated with the network function service consumer that is allowed to request the resource.

[0159] In some embodiments, the first information may include a resource and NPN information that allows requesting the resource, for example, allowing a network service consumer of NPN1 to access resource A.

[0160] In some embodiments, the first information may include a resource and information about an NPN that is not allowed to request the resource, for example, the network service consumer of NPN1 is not allowed to access resource A.

[0161] In some embodiments, the first information may include association information between the NPN information and the terminal identifier, that is, information that allows a network function service consumer associated with the NPN to access the terminal corresponding to the terminal identifier.

[0162] The association relationship between the NPN information and the terminal identifier may be whether the terminal subscribes to the NPN or whether the terminal is served by the NPN.

[0163] In some embodiments, the NRF may store the first information.

[0164] In some embodiments, the NRF may send a registration response to the network function service provider.

[0165] Step S2102: The network function service consumer sends second information to the NRF.

[0166] In some embodiments, the NRF receives second information sent by the network function service consumer.

[0167] In some embodiments, the NRF receives the second information sent by the network function service consumer through a proxy.

[0168] In some embodiments, a network function service consumer is any network device used to use the service.

[0169] In some embodiments, a network function service consumer may register with the NFR.

[0170] In some embodiments, the second information may be registration information sent by the network function service consumer.

[0171] In some embodiments, the second information may be a network function profile (NF profile) of the network function service consumer, or may be included in a profile of the network function consumption provider.

[0172] In some embodiments, the second information includes NPN information associated with the network function service consumer, and the NPN information includes at least one of the following:

[0173] The Closed Access Group (CAG) identifier associated with the NPN;

[0174] Location information;

[0175] NPN identification.

[0176] In some embodiments, the location information in the network function profile (NF profile) indicates the location of the network function (e.g., a data center, a computer room, etc.), and the location of the network function is consistent with the deployment location of the NPN, so the location of the network function can be used as an identifier of the NPN.

[0177] Among them, the NPN information associated with the network function service consumer can be the NPN where the network function service consumer is located, or it can be the NPN served by the network function service consumer.

[0178] In some embodiments, the network function service consumer may send the network function service consumer's certificate to the NRF.

[0179] In some embodiments, the NRF may determine the NPN associated with the network function service consumer based on the first information (e.g., a configuration file) of the network function service consumer or the certificate of the network function service consumer. The NPN associated with the network function service consumer determined based on the first information or the certificate of the network function service consumer may also be referred to as the NPN actually associated with the network function service consumer.

[0180] In some embodiments, the NRF may store the second information.

[0181] In some embodiments, the NRF may send a registration response to the network function service consumer.

[0182] Step S2103: The network function service consumer sends a token request to the NRF.

[0183] In some embodiments, a token request may also be referred to as an access token request.

[0184] In some embodiments, the token request includes NPN information.

[0185] In some embodiments, the token request may be associated with data or resources related to a certain NPN.

[0186] In some embodiments, the NRF receives a token request sent by a network function service consumer, and the NRF may verify the token request.

[0187] In step S2104, the NRF verifies the token request.

[0188] In some embodiments, the NRF may verify the token request based on at least one of the first information, the second information, and the network function service consumer certificate.

[0189] In some embodiments, the NRF may verify whether the NPN information in the token request is consistent with the NPN information in the second information.

[0190] In some embodiments, the NRF may verify whether the NPN information in the token request is consistent with the NPN information in the second information. If there is an inconsistency during the verification process, the NRF does not send the token to the network function service consumer.

[0191] In some embodiments, the NRF may verify whether the NPN information in the token request is consistent with the NPN associated with the network function service consumer recorded in the certificate of the network function service consumer.

[0192] In some embodiments, the NRF may verify whether the NPN information in the token request is consistent with the NPN associated with the network function service consumer recorded in the certificate of the network function service consumer. If there is an inconsistency during the verification process, the NRF does not send a token to the network function service consumer.

[0193] In some embodiments, the NRF may verify whether the NPN information in the token request is consistent with the NPN information in the first information.

[0194] In some embodiments, the NRF may verify whether the NPN information in the token request is consistent with the NPN information in the first information. If there is an inconsistency during the verification process, the NRF does not send the token to the network function service consumer.

[0195] In an embodiment of the present disclosure, the NRF may first determine the NPN associated with the network function service consumer based on the configuration file of the network function service consumer or the certificate of the network function service consumer. If the NPN information in the token request sent by the network function service consumer (for example, the request specifies requesting data or resources related to a certain NPN), the NPN information contained in the request needs to be consistent with the NPN of the above configuration file or certificate, that is, the network function service consumer serves the NFN. At the same time, the resources requested by the network function service consumer belong to a certain network function service provider. At this time, the configuration file of the network function service provider can be checked to check whether the NPN information in the configuration file of the network function service provider (that is, which NPNs are allowed by the configuration file of the network function service provider to access their own resources) is consistent with the NPN information associated with the network function service consumer in the request. The above verification steps can be executed in an interchangeable order, and the present disclosure does not limit the execution order.

[0196] In the embodiment of the present disclosure, if the above verification is passed, the NRF may also verify other information in the token request.

[0197] Step S2105: The NRF sends a token to the network function service consumer.

[0198] In the embodiment of the present disclosure, after the NRF verifies the token request, the NRF sends the token to the network function service consumer. The network function service consumer can use the token to request related services from the network function service provider, thereby improving the security of communication under the NPN network.

[0199] Step S2106: The network function service consumer sends a service request to the network function service provider.

[0200] In some embodiments, the network function service consumer sends a service request to the network function service provider. The network function service consumer may send the service request directly to the network function service provider, or may send the service request to the network function service provider through a proxy.

[0201] In some embodiments, the network function service provider receives a service request sent by the network function service consumer.

[0202] In some embodiments, the network function service provider receives the service request sent by the network function service consumer. The network function service provider may directly receive the service request sent by the network function service consumer, or may receive the service request sent by the network function service consumer through an agent.

[0203] In some embodiments, the service request includes NPN information.

[0204] In some embodiments, the service request may include a token, and the token includes NPN information.

[0205] In some embodiments, the service request may include the certificate of the network function service consumer.

[0206] In some embodiments, the service request may include a terminal identifier, that is, the service or resource requested in the service request is related to the terminal corresponding to the terminal identifier, for example, requesting a location service of a certain terminal.

[0207] Step S2107: The network function service provider verifies the service request.

[0208] In some embodiments, the network function service provider may verify the token in the service request.

[0209] In some embodiments, the network function service provider may verify whether the NPN information in the token is consistent with the NPN information actually associated with the network function service consumer.

[0210] Among them, the NPN information actually associated with the network function service consumer can be the NPN associated with the network function service consumer recorded in the certificate of the network function service consumer.

[0211] In some embodiments, the network function service provider may verify whether the NPN information in the token is consistent with the NPN information actually associated with the network function service consumer. If there is an inconsistency during the verification process, the network function service provider will not provide services, information or resources to the network function service consumer.

[0212] In some embodiments, when the service request includes a terminal identifier, the network function service provider may verify that the NPN associated with the network function service consumer has an association with the terminal corresponding to the terminal identifier. The NPN associated with the network function service consumer may be the NPN associated with the network function service consumer recorded in the network function service consumer's certificate.

[0213] In some embodiments, the verification that the NPN associated with the network function service consumer has an association relationship with the terminal corresponding to the terminal identifier includes at least one of the following:

[0214] The network function service provider determines the NPN associated with the network function service consumer to which the terminal has subscribed based on the unified data management (UDM) or unified data repository (UDR);

[0215] The network function service provider determines, based on the UDM or UDR, that there is an association between the terminal and the NPN associated with the network function service consumer;

[0216] The network function service provider determines the NPN service associated with the network function service consumer based on UDM or UDR to serve the terminal;

[0217] The terminal identification is included in the terminal list associated with the NPN stored locally by the network function service provider.

[0218] In some embodiments, the UDM or UDR stores the NPN to which the terminal has subscribed, or the NPN serving the terminal. The network function service provider can interact with the UDM or UDR to obtain the NPN associated with the terminal from the UDM or UDR. The network function service provider verifies whether the NPN associated with the terminal is consistent with the NPN in the service request.

[0219] In some embodiments, the network function service provider can locally store a list of terminals associated with the NPN, and the network function service provider can also verify the service request based on the locally stored network function service provider. The network function service provider can verify whether the terminal in the terminal list associated with the NPN and the terminal corresponding to the terminal identifier in the service request are consistent.

[0220] In some embodiments, when the service request includes a terminal identifier, the network function service provider can verify that the NPN associated with the network function service consumer has an association with the terminal corresponding to the terminal identifier. If the NPN associated with the network function service consumer and the terminal corresponding to the terminal identifier are not subscribed to the NPN associated with the network function service consumer, the network function service provider will not provide services, information or resources to the network function service consumer.

[0221] In some embodiments, when the service request includes a terminal identifier, the network function service provider can verify that the NPN associated with the network function service consumer has an association relationship with the terminal corresponding to the terminal identifier. If the NPN associated with the network function service consumer and the terminal corresponding to the terminal identifier are not served by the NPN associated with the network function service consumer, the network function service provider does not provide services, information, or resources to the network function service consumer. In some embodiments, the network function service provider verifies the service request, which may include at least one of the following:

[0222] Verify that the NPN information in the service request is consistent with the NPN information actually associated with the network function service consumer;

[0223] Verify whether the NPN information in the service request is consistent with the NPN information in the first information.

[0224] Among them, the NPN information actually associated with the network function service consumer is the NPN associated with the network function service consumer recorded in the certificate of the network function service consumer.

[0225] The first information may be a configuration file of the network function service provider or information in the configuration file.

[0226] In some embodiments, the network function service provider verifies the service request to verify whether the NPN information in the service request is consistent with the NPN information actually associated with the network function service consumer. If the NPN information in the service request is inconsistent with the NPN information actually associated with the network function service consumer, the network function service provider does not provide services, information or resources to the network function service consumer.

[0227] In some embodiments, the network function service provider verifies the service request to verify whether the NPN information in the service request is consistent with the NPN information in the first information. If the NPN information in the service request is inconsistent with the NPN information in the first information, the network function service provider does not provide services, information or resources to the network function service consumer.

[0228] In some embodiments, if the network function service provider successfully verifies the service request, the service in the service request may be provided to the network function service provider.

[0229] In some embodiments, if the network function service provider fails to authenticate the service request, the network function service provider may respond according to the OAuth 2.0 error response defined in RFC 6749

[0043] .

[0230] The communication method involved in the embodiment of the present disclosure may include at least one of steps S2101 to S2107. For example, step S2104 may be implemented as an independent embodiment, and step S2107 may be implemented as an independent embodiment, but the present invention is not limited thereto.

[0231] In some embodiments, steps S2101 and S2102 may be executed in an interchanged order or simultaneously.

[0232] In some embodiments, steps S2101, S2102, S2103, S2104, and S2105 are optional, and one or more of these steps may be omitted or replaced in different embodiments.

[0233] In some embodiments, steps S2101 and S2102 are optional, and one or more of these steps may be omitted or replaced in different embodiments.

[0234] In some embodiments, steps S2104 and S2105 are optional, and one or more of these steps may be omitted or replaced in different embodiments.

[0235] In some embodiments, reference may be made to other optional implementations described before or after the description corresponding to FIG. 2 .

[0236] In some embodiments, the names of information, etc. are not limited to the names described in the embodiments, and terms such as "information", "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "domain", "field", "symbol", "symbol", "codeword", "codebook", "codeword", "codepoint", "bit", "data", "program", and "chip" can be used interchangeably.

[0237] In some embodiments, terms such as "moment", "time point", "time", and "time position" can be replaced with each other, and terms such as "duration", "period", "time window", "window", and "time" can be replaced with each other.

[0238] In some embodiments, "obtain", "get", "get", "receive", "transmit", "bidirectional transmission", "send and / or receive" can be interchangeable, and can be interpreted as receiving from other entities, obtaining from protocols, obtaining from higher layers, obtaining by self-processing, autonomous implementation, etc.

[0239] In some embodiments, terms such as "send", "transmit", "report", "download", "transmit", "bidirectional transmission", "send and / or receive" can be used interchangeably.

[0240] In some embodiments, terms such as "certain", "preset", "preset", "setting", "indicated", "a certain", "any", and "first" can be interchangeable. "Specific A", "preset A", "preset A", "setting A", "indicated A", "a certain A", "any A", and "first A" can be interpreted as A pre-specified in a protocol, etc., or as A obtained through setting, configuration, or indication, etc., or as specific A, a certain A, any A, or first A, etc., but not limited to this.

[0241] In some embodiments, the determination or judgment can be performed by a value represented by 1 bit (0 or 1), or by a true or false value (Boolean value (bool)) represented by true (true) or false (false), or by comparison of numerical values ​​(for example, comparison with a predetermined value), but is not limited thereto.

[0242] In some embodiments, "not expecting to receive" can be interpreted as not receiving on time domain resources and / or frequency domain resources, or as not performing subsequent processing on the data after receiving it; "not expecting to send" can be interpreted as not sending, or as sending but not expecting the recipient to respond to the content sent.

[0243] FIG3A is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in FIG3A , the embodiment of the present disclosure relates to a communication method, which includes:

[0244] Step S3101, sending the first information.

[0245] The optional implementation of step S3101 can refer to the optional implementation of step S2101 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.

[0246] In some embodiments, the network function service provider sends the first information to the NRF.

[0247] Step S3102: Obtain service request.

[0248] The optional implementation of step S3102 can refer to the optional implementation of step S2106 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.

[0249] In some embodiments, the network function service provider receives a service request sent by the network function service consumer.

[0250] Step S3103: Verify the service request.

[0251] The optional implementation of step S3103 can refer to the optional implementation of step S2107 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.

[0252] In some embodiments, the network function service provider authenticates the service request.

[0253] The communication method involved in the embodiment of the present disclosure may include at least one of steps S3101 to S3103. For example, step S3101 may be implemented as an independent embodiment, and step S3103 may be implemented as an independent embodiment, but the present invention is not limited thereto.

[0254] In some embodiments, step S3101 is optional, and one or more of these steps may be omitted or replaced in different embodiments.

[0255] FIG3B is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in FIG3B , the embodiment of the present disclosure relates to a communication method, and the method includes:

[0256] Step S3201, obtain service request.

[0257] The optional implementation of step S3201 can refer to the optional implementation of step S2106 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.

[0258] In some embodiments, the network function service provider receives a service request sent by the network function service consumer.

[0259] Step S3202: Verify the service request.

[0260] The optional implementation of step S3202 can refer to the optional implementation of step S2107 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.

[0261] In some embodiments, the network function service provider authenticates the service request.

[0262] The communication method involved in the embodiment of the present disclosure may include at least one of steps S3201 to S3202. For example, step S3202 may be implemented as an independent embodiment, but is not limited thereto.

[0263] In some embodiments, step S3201 is optional, and one or more of these steps may be omitted or replaced in different embodiments.

[0264] FIG3C is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in FIG3C , the embodiment of the present disclosure relates to a communication method, which includes:

[0265] Step S3301, obtain service request.

[0266] The optional implementation of step S3301 can refer to the optional implementation of step S2106 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.

[0267] In some embodiments, the network function service provider receives a service request sent by the network function service consumer.

[0268] FIG4A is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in FIG4 , the embodiment of the present disclosure relates to a communication method, which includes:

[0269] Step S4101, obtain first information.

[0270] The optional implementation of step S4101 can refer to the optional implementation of step S2101 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.

[0271] In some embodiments, the NRF receives first information sent by a network function service provider.

[0272] Step S4102, obtaining second information.

[0273] The optional implementation of step S4102 can refer to the optional implementation of step S2102 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.

[0274] In some embodiments, the NRF receives second information sent by the network function service consumer.

[0275] Step S4103: Get token request.

[0276] The optional implementation of step S4103 can refer to the optional implementation of step S2103 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.

[0277] In some embodiments, the NRF receives a token request sent by a network function service consumer.

[0278] Step S4104: verify the token request.

[0279] The optional implementation of step S4104 can refer to the optional implementation of step S2104 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.

[0280] In some embodiments, the NRF authenticates the token request.

[0281] Step S4105, sending token.

[0282] The optional implementation of step S4105 can refer to the optional implementation of step S2105 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.

[0283] In some embodiments, the NRF sends a token to the network function service consumer.

[0284] The communication method involved in the embodiment of the present disclosure may include at least one of steps S4101 to S4105. For example, step S4104 may be implemented as an independent embodiment, but is not limited thereto.

[0285] In some embodiments, steps S4101, S4102, and S4105 are optional, and one or more of these steps may be omitted or replaced in different embodiments.

[0286] FIG4B is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in FIG4B , the embodiment of the present disclosure relates to a communication method, and the method includes:

[0287] Step S4201, obtain first information.

[0288] The optional implementation of step S4201 can refer to the optional implementation of step S2101 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.

[0289] In some embodiments, the NRF receives first information sent by a network function service provider.

[0290] FIG4C is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in FIG4C , the embodiment of the present disclosure relates to a communication method, and the method includes:

[0291] Step S4301, obtain second information.

[0292] The optional implementation of step S4301 can refer to the optional implementation of step S2102 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.

[0293] In some embodiments, the NRF receives second information sent by the network function service consumer.

[0294] FIG4D is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in FIG4D , the embodiment of the present disclosure relates to a communication method, and the method includes:

[0295] Step S4401, obtain token request.

[0296] The optional implementation of step S4401 can refer to the optional implementation of step S2103 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.

[0297] In some embodiments, the NRF receives a token request sent by a network function service consumer.

[0298] Step S4402: Verify the token request.

[0299] The optional implementation of step S4402 can refer to the optional implementation of step S2104 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.

[0300] The communication method involved in the embodiment of the present disclosure may include at least one of steps S4401 and S4402. For example, step S4401 may be implemented as an independent embodiment, and step S4402 may be implemented as an independent embodiment, but the present invention is not limited thereto.

[0301] In some embodiments, step S4401 is optional, and one or more of these steps may be omitted or replaced in different embodiments.

[0302] FIG5A is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in FIG5A , the embodiment of the present disclosure relates to a communication method, and the method includes:

[0303] Step S5101, sending the second information.

[0304] The optional implementation of step S5101 can refer to the optional implementation of step S2102 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.

[0305] In some embodiments, the network function service consumer sends second information to the NRF.

[0306] FIG5B is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in FIG5B , the embodiment of the present disclosure relates to a communication method, and the method includes:

[0307] Step S5201, sending a token request.

[0308] The optional implementation of step S5201 can refer to the optional implementation of step S2103 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.

[0309] In some embodiments, the network function service consumer sends a token request to the NRF.

[0310] FIG5C is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in FIG5C , the embodiment of the present disclosure relates to a communication method, and the method includes:

[0311] Step S5301, sending a service request.

[0312] The optional implementation of step S5301 can refer to the optional implementation of step S2106 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.

[0313] In some embodiments, the network function service consumer sends a service request to the network function service provider.

[0314] Figure 6 is an interactive diagram of a communication method according to an embodiment of the present disclosure. As shown in Figure 6, the embodiment of the present disclosure relates to a communication method, which includes:

[0315] Step S6101: The network function service consumer sends a service request to the network function service provider.

[0316] The optional implementation of step S6101 can be found in step S2106 of FIG2 and other related parts of the embodiment involved in the figure, which will not be repeated here.

[0317] Step S6102: The network function service provider verifies the service request.

[0318] The optional implementation of step S6102 can be found in step S2107 of FIG2 and other related parts of the embodiment involved in the figure, which will not be described again here.

[0319] In some embodiments, the above method may include the method of the above-mentioned embodiments on the communication system side, network device side, etc., which will not be repeated here.

[0320] FIG7A is an interactive diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG7A , the embodiment of the present disclosure relates to a communication method, and the method includes:

[0321] In step S7101, the NF service consumer sends a registration request to the NRF.

[0322] In some embodiments, when the NF service consumer runs for the first time, the NF service consumer may send a registration request to the NRF. For example, the NF service consumer may send an Nnrf_NFManagement_NFRegister Request message to the NRF.

[0323] In some embodiments, the registration request may include an NF profile of the NF service consumer.

[0324] In some embodiments, the NF configuration file may include NPN information served by the NF service consumer, wherein the NPN served by the NF service consumer may also be referred to as the NPN to which the NF service consumer belongs, or as the NPN associated with the NF service consumer.

[0325] In some embodiments, the NPN information may include at least one of the following:

[0326] CAG logo of NPN;

[0327] Location information (e.g., NF's geographic location, data center);

[0328] NPN identification.

[0329] In some embodiments, the location information may be location information that can identify a specific NPN. For example, the NPN corresponding to the geographical location or data center where the NF is located may be determined based on the geographical location or data center where the NF is located.

[0330] In some embodiments, the NF profile of the NF service consumer may be configured by an Operation Administration and Maintenance (OAM) system.

[0331] In step S7102, the NRF stores the NF configuration file of the NF service consumer.

[0332] In some embodiments, the NRF stores the NF profile of the NF service consumer and marks the NF service consumer as available.

[0333] In some embodiments, the NF configuration file sent by the NF service consumer to the NRF needs to be integrity protected by the NF service consumer and verified by the NRF.

[0334] Step S7103: The NRF sends a registration response to the NF service consumer.

[0335] In some embodiments, the NRF may confirm acceptance of the NF registration via a Nnrf_NFManagement_NFRegister response.

[0336] In some embodiments, the NRF may send an Nnrf_NFManagement_NFRegister_Response to the NR service consumer.

[0337] The communication method involved in the embodiments of the present disclosure may include at least one of steps S7101 to S7103. In the embodiments of the present disclosure, any one of steps S7101 to S7103 can be implemented independently. For example, step S7101 can be implemented as an independent embodiment, step S7102 can be implemented as an independent embodiment, and step S7103 can be implemented as an independent embodiment, but the present disclosure is not limited thereto.

[0338] In some embodiments, steps S7101 to S7103 can be performed in an interchangeable order or simultaneously. Under no conflicting conditions, each step can be combined arbitrarily and the order of each step can be interchanged arbitrarily, which is not limited in this disclosure.

[0339] In some embodiments, the NF service provider may register with the NRF. For example, the NF service provider may send a registration request to the NRF, and the registration request may include a configuration file of the NF service provider.

[0340] In some embodiments, during the NF service registration process, the configuration data of the NF profile of the NF service provider may include "additional scopes." The "additional scope" information indicates resources and the operations (e.g., service operations) that the NF service consumer is allowed to perform on these resources. These resources can be the NF type of each NF service consumer or the NF instance ID of each NF service consumer. These resources can also be one or more NPNs served by the NF service consumer. The operations allowed for the NF service consumer deployed on the NPN client side are restricted only to the NPN.

[0341] In some embodiments, a list of terminals associated with the NPN served by the NF service consumer may also be configured in the NF configuration file.

[0342] FIG7B is an interactive diagram illustrating a communication method according to an embodiment of the present disclosure.

[0343] FIG7B shows a process in which an NF service consumer obtains an access token before accessing the services of an NF service provider of a specific NF type.

[0344] As shown in FIG7B , an embodiment of the present disclosure relates to a communication method, which includes:

[0345] Step S7201: The NF service consumer sends a token request to the NRF.

[0346] In some embodiments, the NF service consumer sends a token request to an authorization server, which may be, for example, an NRF.

[0347] In some embodiments, the NF service consumer can directly request an access token from the NRF using the Nnrf_AccessToken_Get request operation.

[0348] In some embodiments, the NF service consumer may request an access token from the NRF through a proxy by sending an Nnrf_AccessToken_Get request operation.

[0349] In some embodiments, the NF service consumer may send a token request message to the NRF.

[0350] In some embodiments, the message may include the NF instance ID of the NF service consumer, the "scope" of the request (e.g., the desired NF service name) and optional "additional scope" information (the requested resources and the operations requested on the resources (service operations), the requested resources or other parts of the request (e.g., the certificate part) may include the identity of the NPN served by the NF service consumer), the desired NF service provider instance and the NF type of the NF service consumer.

[0351] In some embodiments, the message may also include a Network Slice Selection Assistant Information (NSSAI) list or a NSSAI ID list for the intended NF service provider instances.

[0352] In some embodiments, the message may include the NF set ID and / or NF service set ID of the desired NF service provider instance.

[0353] In some embodiments, the message may include a list of S-NSSAIs of NF service consumers.

[0354] In some embodiments, the message may include the PLMN ID of the NF service consumer.

[0355] In some embodiments, the message may include a client identification (client ID).

[0356] In some embodiments, the message may include relevant information about the NPN served by the NF service consumer.

[0357] In some embodiments, when registering with the NRF, the NF profile may include information about the NPN provided by the NF service consumer. The NPN information may include at least one of the following:

[0358] CAG logo related to NPN;

[0359] Location information (e.g., NF's geographic location, data center);

[0360] NPN identification.

[0361] Step S7202: The NRF verifies the token request.

[0362] In some embodiments, the NRF may check whether the NF service consumer can be authorized.

[0363] In some embodiments, if the NF service consumer can be authorized, the NRF generates an access token.

[0364] In some embodiments, the NRF may verify whether the input parameters "NF instance ID, NPN information served by the NF service consumer, NF type, and PLMN ID" in the access token request match the corresponding parameters in the public key certificate of the NF service consumer or the NF configuration file of the NF service consumer.

[0365] In some embodiments, if the parameter validation in the access token request fails, the access token request is not processed further.

[0366] In some embodiments, the NRF may also verify the S-NSSAI of the NF service consumer.

[0367] In some embodiments, the NRF may check whether the NF service consumer is authorized to access the requested service. For example, the NRF may verify whether the NF service consumer can provide a slice included in the slices allowed by the NF service provider.

[0368] In some embodiments, if the NF service consumer is authorized, the NRF should generate an access token including appropriate claims.

[0369] In some embodiments, the NRF may digitally sign the generated access token based on a shared key or a private key.

[0370] In some embodiments, if the NF service consumer is not authorized, the NRF does not issue an access token to the NF service consumer.

[0371] In some embodiments, the declaration in the token may include at least one of the following: the NF instance ID of the NRF (issuer), the NF instance ID of the NF service consumer (subject), the NF type of the NF service provider (audience), the expected service name, scope, expiration time and optional "additional scope" information (allowed resources and allowed operations (service operations on resources)). The declaration may include the NSSAI or a list of NSSAI IDs of the expected NF service provider instance. The declaration may include the NF set ID and / or NF service set ID of the expected NF service provider instance. The declaration may also include relevant information about the NPN served by the NF service consumer.

[0372] Step S7203: NRF sends a token to the NF service consumer.

[0373] In some embodiments, if the authorization is successful, the NRF may send an access token to the NF service consumer in an Nnrf_AccessToken_Get response operation.

[0374] In some embodiments, the token includes NPN information associated with the network function service consumer.

[0375] In some embodiments, if authorization fails, the NRF may respond according to an Open Authorization (OAuth) 2.0 error response.

[0376] The communication method involved in the embodiments of the present disclosure may include at least one of steps S7201 to S7203. In the embodiments of the present disclosure, any one of steps S7201 to S7203 can be implemented independently. For example, step S7201 can be implemented as an independent embodiment, step S7202 can be implemented as an independent embodiment, and step S7203 can be implemented as an independent embodiment, but the present disclosure is not limited thereto.

[0377] In some embodiments, steps S7201 to S7203 can be performed in an interchangeable order or simultaneously. Under no conflicting conditions, each step can be combined arbitrarily and the order of each step can be interchanged arbitrarily, which is not limited in this disclosure.

[0378] FIG7C is an interactive diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG7C , the embodiment of the present disclosure relates to a communication method, and the method includes:

[0379] Step S7301: The NF service consumer sends a service request to the NF service provider.

[0380] In some embodiments, before the NF service consumer requests service access from the NF service provider, the NF service consumer has a valid access token.

[0381] In some embodiments, the NF service consumer sends a service request to the NF service provider, and the service request may include an access token.

[0382] In some embodiments, the NF service consumer and the NF service provider may perform mutual authentication in accordance with clause 13.3 of 3GPP TS 33.501[1].

[0383] In step S7302, the NF service provider verifies the service request.

[0384] In some embodiments, the NF service provider may verify the token in the service request in the following manner.

[0385] In some embodiments, the NF service provider can use the public key of the NRF to verify the signature or use a shared key to check the MAC (Message Authentication Code) value to ensure the integrity of the token.

[0386] In some embodiments, if the integrity check succeeds, the NF service provider may verify the claims in the token.

[0387] In some embodiments, in case of direct communication, it may be possible to check whether the NF instance ID in the subject claim in the access token matches the NF instance ID in the subjectAltName (Subject Alternative Name) in the TLS client certificate of the NF service consumer.

[0388] In some embodiments, the NF service provider can check whether the audience claim in the access token matches its own identity or the type of NF service provider. If there is an NSSAI list or NSSAI ID list, the NF service provider can check whether the corresponding slice is provided.

[0389] In some embodiments, when requesting information related to a specific terminal, the NF service provider may check whether the NF service consumer is allowed to access (as indicated by the NF service provider's NSSAI in the access token provided by the NF service consumer) at least one slice to which the terminal is currently registered. For example, by verifying whether the NSSAI allowed by the terminal is consistent with the NSSAI of the NF service provider in the access token.

[0390] In some embodiments, if the token includes a NF set ID, the NF service provider may check whether the NF set ID in the token matches its own NF set ID.

[0391] In some embodiments, if the token includes an NF service set ID, the NF service provider may check whether the NF service consumer is authorized to access the requested service based on the NF service provider service set ID in the access token claim.

[0392] In some embodiments, if a scope is included in the token, the NF service provider may check whether the scope matches the requested service operation.

[0393] In some embodiments, if the token includes "additional scope" information (i.e., allowed resources and allowed operations on the resources (service operations)), the NF service provider can check the additional scope for the requested service operation. If the requested service operation is for requesting / providing information related to a specific UE, it can be processed as follows.

[0394] In some embodiments, the NF service provider checks whether the "additional scope" information included in the access token matches the operation (eg, the requested service or resource should only be requestable by NPNs within the additional scope).

[0395] In some embodiments, the NF service provider may check whether an operation running in the NPN (eg, an NF service consumer in the NPN requests services or resources from the NF service provider) is allowed by the terminal.

[0396] In some embodiments, the NF service provider can use the UE ID (such as the user permanent identifier (SUPI, Subscription Permanent Identifier), the general public user identifier (GPSI, Generic Public Subscription Identifier), the user hidden identifier (SUCI, Subscription Concealed Identifier)) to retrieve the NPN information subscribed by the UE or the NPN information serving the UE from the UDM / UDR.

[0397] In some embodiments, if the NPN information provided by the NF service consumer is consistent with the NPN subscribed by the terminal, verification should continue. Otherwise, verification fails.

[0398] In some embodiments, if the NPN information provided by the NF service consumer is consistent with the NPN serving the UE, verification should proceed. Otherwise, verification fails.

[0399] In some embodiments, if the NPN information provided by the NF service consumer is inconsistent with the NPN subscribed by the terminal, the verification fails.

[0400] In some embodiments, if the NPN information provided by the NF service consumer is inconsistent with the NPN serving the terminal, the verification fails.

[0401] In some embodiments, if there is no NPN information in the terminal's subscription information, or the NF service provider cannot interact with the UDM / UDR, the NF service provider can use the terminal list associated with the locally configured NPN information to verify whether the operation running in the NPN (for example, the NF service consumer in the NPN requests the NF service provider's services or resources) is allowed by the terminal.

[0402] In some embodiments, to verify whether an operation running in an NPN (e.g., a request from an NF service consumer in an NPN for services or resources from an NF service provider) is permitted by a terminal, the NF service provider queries a terminal list associated with the locally configured NPN information to verify whether the terminal is included in the terminal list corresponding to the NPN. If so, verification should proceed. Otherwise, verification fails.

[0403] In some embodiments, to verify whether an operation running in an NPN (e.g., an NF service consumer in an NPN requests a service or resource from an NF service provider) is permitted by a terminal, the NF service provider queries a terminal list associated with the locally configured NPN information to verify whether the NPN is included in the NPN list corresponding to the terminal. If so, verification should proceed. Otherwise, verification fails.

[0404] FIG7D is a schematic diagram showing the relationship among a UE, an NF service consumer, and an NPN according to an embodiment of the present disclosure.

[0405] As shown in Figure 7D, the intersection of the circle representing the NF service consumer and the circle representing the NPN indicates that the NPN is served by the NF service consumer, the intersection of the circle representing the UE and the circle representing the NPN indicates that the UE is served by the NPN, and the intersection of the circle representing the NF service consumer, the circle representing the NPN, and the circle representing the UE indicates that the UE is served by the NPN and the NPN is served by the NF service consumer.

[0406] In an embodiment of the present disclosure, as shown in FIG7D , if the request received by the NF service provider includes a terminal identifier and NPN information, the NF service provider should determine that the UE is served by the NPN (for example, the UE has subscribed to the NPN), and that the NPN is served by the NF service consumer (for example, the NF service consumer is a network function deployed in the NPN).

[0407] In some embodiments, the NF service provider checks whether the access token is expired by verifying the expiration time in the access token against the current date / time.

[0408] In some embodiments, if a CCA (Client Credentials Assertion) is present in the service request, the CCA specified in Section 13.3.8.3 and the subject claim in the access token (i.e., the NF instance ID of the NF service consumer) can be verified to match the subject claim in the CCA.

[0409] In step S7303, the NF service provider obtains the NPN information subscribed by the UE from the UDM / UDR.

[0410] In some embodiments, the NF service provider may obtain the NPN information subscribed by the UE from the UDM / UDR to perform the above verification based on the NPN information subscribed by the UE.

[0411] Step S7304: The NF service provider sends a service response to the NF service consumer.

[0412] In some embodiments, if the verification is successful, the NF service provider performs the requested service and responds to the NF service consumer. Otherwise, an OAuth 2.0 error response may be made.

[0413] The communication method involved in the embodiments of the present disclosure may include at least one of steps S7301 to S7304. In the embodiments of the present disclosure, any one of steps S7301 to S7304 can be implemented independently. For example, step S7301 can be implemented as an independent embodiment, step S7302 can be implemented as an independent embodiment, step S7303 can be implemented as an independent embodiment, and step S7304 can be implemented as an independent embodiment, but the present disclosure is not limited thereto.

[0414] In some embodiments, steps S7301 to S7304 can be performed in an interchangeable order or simultaneously. Under no conflicting conditions, each step can be combined arbitrarily and the order of each step can be interchanged arbitrarily, which is not limited in this disclosure.

[0415] The communication method provided by the embodiments of the present disclosure enables the PLMN to authorize the network functions deployed on the NPN client side by considering the NPN information related to a specific terminal.

[0416] In the embodiments of the present disclosure, some or all of the steps and their optional implementations may be arbitrarily combined with some or all of the steps in other embodiments, or may be arbitrarily combined with the optional implementations of other embodiments.

[0417] The embodiments of the present disclosure further provide an apparatus for implementing any of the above methods. For example, an apparatus is provided, comprising units or modules for implementing each step performed by a terminal in any of the above methods. For another example, another apparatus is provided, comprising units or modules for implementing each step performed by a network device (e.g., an access network device, a core network function node, a core network device, etc.) in any of the above methods.

[0418] It should be understood that the division of the various units or modules in the above device is merely a division of logical functions. In actual implementation, they may be fully or partially integrated into a physical entity, or they may be physically separated. In addition, the units or modules in the device may be implemented in the form of a processor calling software: for example, the device includes a processor, the processor is connected to a memory, and the memory stores instructions. The processor calls the instructions stored in the memory to implement any of the above methods or implement the functions of the various units or modules of the above device, wherein the processor is, for example, a general-purpose processor, such as a central processing unit (CPU) or a microprocessor, and the memory is a memory within the device or a memory outside the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits, and the functions of some or all of the units or modules can be realized by designing the hardware circuits. The above-mentioned hardware circuits can be understood as one or more processors; for example, in one implementation, the above-mentioned hardware circuit is an application-specific integrated circuit (ASIC), which realizes the functions of some or all of the above units or modules by designing the logical relationship of the components in the circuit; for example, in another implementation, the above-mentioned hardware circuit can be realized by a programmable logic device (PLD). Taking a field programmable gate array (FPGA) as an example, it can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by configuring the configuration file, thereby realizing the functions of some or all of the above units or modules. All units or modules of the above devices can be realized in the form of software called by the processor, or in the form of hardware circuits, or in part by the form of software called by the processor, and the rest by hardware circuits.

[0419] In the embodiments of the present disclosure, the processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction reading and execution capabilities, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationship of the hardware circuit. The logical relationship of the above-mentioned hardware circuit is fixed or reconfigurable. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document and implementing the hardware circuit configuration can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. In addition, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), etc.

[0420] Figure 8A is a structural diagram of the network function service provider proposed in an embodiment of the present disclosure. As shown in Figure 8A, the network function service provider 8100 may include: at least one of a transceiver module 8101 and a processing module 8102. In some embodiments, the transceiver module 8101 is used to receive a service request, and the processing module 8102 is used to verify the service request. In other embodiments, the transceiver module 8101 is used to send the first information. Optionally, the transceiver module is used to execute at least one of the steps (such as step S2101, but not limited to this) of the processing performed by the network function service provider in any of the above methods, and the processing module is used to execute at least one of the steps (such as step S2107, but not limited to this) of the processing performed by the network function service provider in any of the above methods, which will not be repeated here.

[0421] Figure 8B is a structural diagram of the NRF proposed in an embodiment of the present disclosure. As shown in Figure 8B, NRF8200 may include: at least one of a transceiver module 8201 and a processing module 8202. In some embodiments, the transceiver module 8201 is used to receive a token request, and the processing module 8202 is used to verify the token request. In some embodiments, the transceiver module 8201 is used to receive the first information. In other embodiments, the transceiver module 8201 is used to receive the second information. Optionally, the transceiver module is used to execute at least one of the steps (such as step S2105, but not limited to this) of the processing performed by the NRF in any of the above methods, and the processing module is used to execute at least one of the steps (such as step S2104, but not limited to this) of the processing performed by the NRF in any of the above methods, which will not be repeated here.

[0422] Figure 8C is a schematic diagram of the structure of the network function service consumer proposed in an embodiment of the present disclosure. As shown in Figure 8C, the network function service consumer 8300 may include: a transceiver module 8301. In some embodiments, the above-mentioned transceiver module 8101 is used to send a token request. In some embodiments, the above-mentioned transceiver module 8101 is used to send a service request. In some embodiments, the above-mentioned transceiver module 8101 is used to send a second message. Optionally, the above-mentioned transceiver module is used to perform at least one of the steps (such as steps S2102, S2103, S2106, but not limited to this) of the processing performed by the network function service consumer in any of the above methods, which will not be repeated here.

[0423] In some embodiments, the processing module can be a single module or include multiple submodules. Optionally, the multiple submodules each execute all or part of the steps required to be executed by the processing module. Optionally, the processing module and the processor can be interchangeable.

[0424] Figure 9A is a schematic diagram of the structure of a communication device 9100 proposed in an embodiment of the present disclosure. Communication device 9100 can be a network device (e.g., an access network device, a core network device, etc.), a terminal (e.g., a user equipment, etc.), a chip, a chip system, or a processor that supports a network device to implement any of the above methods, or a chip, a chip system, or a processor that supports a terminal to implement any of the above methods. Communication device 9100 can be used to implement the methods described in the above method embodiments. For details, please refer to the description of the above method embodiments.

[0425] As shown in Figure 9A, the communication device 9100 includes one or more processors 9101. The processor 9101 can be a general-purpose processor or a dedicated processor, for example, a baseband processor or a central processing unit. The baseband processor can be used to process the communication protocol and communication data, and the central processing unit can be used to control the communication device (such as a base station, a baseband chip, a terminal device, a terminal device chip, a DU or a CU, etc.), execute programs, and process program data. Optionally, the communication device 9100 is used to perform any of the above methods. Optionally, one or more processors 9101 are used to call instructions to enable the communication device 9100 to perform any of the above methods.

[0426] In some embodiments, the communication device 9100 further includes one or more transceivers 9102. When the communication device 9100 includes one or more transceivers 9102, the transceiver 9102 performs at least one of the communication steps such as sending and / or receiving in the above method (e.g., step S2101, step S2102, step S2103, step S2105, step S2106, but not limited thereto), and the processor 9101 performs at least one of the other steps (e.g., step S2104, step S2107, but not limited thereto). In an optional embodiment, the transceiver may include a receiver and / or a transmitter, and the receiver and transmitter may be separate or integrated. Optionally, the terms transceiver, transceiver unit, transceiver, transceiver circuit, interface circuit, and interface may be interchangeable, the terms transmitter, transmitting unit, transmitter, and transmitting circuit may be interchangeable, and the terms receiver, receiving unit, receiver, and receiving circuit may be interchangeable.

[0427] In some embodiments, the communication device 9100 further includes one or more memories 9103 for storing data. Alternatively, all or part of the memories 9103 may be located outside the communication device 9100. In alternative embodiments, the communication device 9100 may include one or more interface circuits 9104. Optionally, the interface circuits 9104 are connected to the memories 9103 and may be configured to receive data from the memories 9103 or other devices, or to send data to the memories 9103 or other devices. For example, the interface circuits 9104 may read data stored in the memories 9103 and send the data to the processor 9101.

[0428] The communication device 9100 described in the above embodiments may be a network device or a terminal, but the scope of the communication device 9100 described in the present disclosure is not limited thereto, and the structure of the communication device 9100 may not be limited by FIG. 9A. The communication device may be an independent device or may be part of a larger device. For example, the communication device may be: 1) an independent integrated circuit IC, or a chip, or a chip system or subsystem; (2) a collection of one or more ICs, optionally, the above IC collection may also include a storage component for storing data or programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, a terminal device, an intelligent terminal device, a cellular phone, a wireless device, a handheld device, a mobile unit, an in-vehicle device, a network device, a cloud device, an artificial intelligence device, etc.; (6) others, etc.

[0429] 9B is a schematic diagram of the structure of a chip 9200 according to an embodiment of the present disclosure. If the communication device 9100 can be a chip or a chip system, please refer to the schematic diagram of the structure of the chip 9200 shown in FIG9B , but the present disclosure is not limited thereto.

[0430] The chip 9200 includes one or more processors 9201. The chip 9200 is configured to execute any of the above methods.

[0431] In some embodiments, chip 9200 further includes one or more interface circuits 9202. Terms such as interface circuit, interface, and transceiver pins may be used interchangeably. In some embodiments, chip 9200 further includes one or more memories 9203 for storing data. Alternatively, all or part of memory 9203 may be located external to chip 9200. Optionally, interface circuit 9202 is connected to memory 9203 and may be used to receive data from memory 9203 or other devices, or may be used to send data to memory 9203 or other devices. For example, interface circuit 9202 may read data stored in memory 9203 and send the data to processor 9201.

[0432] In some embodiments, the interface circuit 9202 performs at least one of the communication steps (e.g., steps S2101, S2102, S2103, S2105, and S2106) of the aforementioned method. For example, the interface circuit 9202 performing the communication steps (e.g., steps S2101, S2102, S2103, S2105, and S2106) of the aforementioned method means that the interface circuit 9202 performs data exchange between the processor 9201, chip 9200, memory 9203, or a transceiver device. In some embodiments, the processor 9201 performs at least one of the other steps (e.g., steps S2104 and S2107, but not limited thereto).

[0433] The modules and / or devices described in various embodiments, such as virtual devices, physical devices, and chips, can be arbitrarily combined or separated according to circumstances. Optionally, some or all steps can also be performed collaboratively by multiple modules and / or devices, which is not limited here.

[0434] The present disclosure also proposes a storage medium having instructions stored thereon, which, when executed on the communication device 9100, causes the communication device 9100 to execute any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but is not limited thereto and may also be a storage medium readable by other devices. Optionally, the storage medium may be a non-transitory storage medium, but is not limited thereto and may also be a temporary storage medium.

[0435] The present disclosure also provides a program product, which, when executed by the communication device 9100, enables the communication device 9100 to perform any of the above methods. Optionally, the program product is a computer program product.

[0436] The present disclosure also proposes a computer program, which, when executed on a computer, causes the computer to perform any one of the above methods.

Claims

1. A communication method, characterized in that: The method comprises: The network function service provider receives a service request sent by the network function service consumer, wherein the service request includes non-public network NPN information; The network function service provider verifies the service request.

2. The method according to claim 1, characterized in that The service request includes a token, and the token includes NPN information; The network function service provider verifies the service request, including: Verify whether the NPN information in the token is consistent with the NPN information actually associated with the network function service consumer.

3. The method according to claim 2, characterized in that The NPN information actually associated with the network function service consumer is the NPN associated with the network function service consumer recorded in the certificate of the network function service consumer.

4. The method according to claim 1, wherein The service request includes a terminal identifier; The network function service provider verifies the service request, including: Verify that the NPN associated with the network function service consumer has an association relationship with the terminal corresponding to the terminal identifier.

5. The method according to claim 4, characterized in that The NPN associated with the network function service consumer is the NPN associated with the network function service consumer recorded in the certificate of the network function service consumer.

6. The method according to claim 4, characterized in that The verifying that the NPN associated with the network function service consumer has an association relationship with the terminal corresponding to the terminal identifier includes at least one of the following: The network function service provider determines, based on a unified data management (UDM) or a unified data repository (UDR), that the terminal has subscribed to an NPN associated with the network function service consumer; The network function service provider determines, based on the UDM or UDR, that there is an association relationship between the terminal and the NPN associated with the network function service consumer; The network function service provider determines, based on the UDM or UDR, that the NPN associated with the network function service consumer serves the terminal; The terminal identifier is included in a terminal list associated with the NPN and stored locally by the network function service provider.

7. The method according to any one of claims 1 to 6, characterized in that The method further comprises: The network function service provider sends the first information to the network storage function NRF; The first information includes at least one of the following: Services and NPN information that allows requests for said services; Resources and NPN information that allows requests for said resources; The association between NPN information and terminal identification.

8. The method according to claim 7, characterized in that The verifying of the service request includes at least one of the following: Verify whether the NPN information in the service request is consistent with the NPN information actually associated with the network function service consumer; Verify whether the NPN information in the service request is consistent with the NPN information in the first information.

9. The method according to claim 8, characterized in that The NPN information actually associated with the network function service consumer is the NPN associated with the network function service consumer recorded in the certificate of the network function service consumer.

10. The method according to claim 7, characterized in that The NRF verifies the token request based on at least one of the first information, the second information of the network function service consumer, and the certificate of the network function service consumer.

11. The method according to claim 10, characterized in that The second information includes NPN information associated with the network function service consumer, and the NPN information includes at least one of the following: CAG identifier associated with the NPN; Location information; NPN identification.

12. A communication method, characterized in that: The method comprises: The network function service provider sends first information to the NRF, where the first information includes NPN information.

13. The method according to claim 12, characterized in that The NPN information in the first information includes at least one of the following: Services and NPN information that allows requests for said services; Resources and NPN information that allows requests for said resources; The association between NPN information and terminal identification.

14. A communication method, characterized in that: The method comprises: The NRF receives a token request sent by a network function service consumer, where the token request includes NPN information; The NRF verifies the token request.

15. The method according to claim 14, characterized in that The method further comprises: The NRF receives first information sent by the network function provider and second information sent by the network function service consumer; The NRF verifies the token request, including: The token request is verified based on at least one of the first information, the second information, and a network function service consumer certificate.

16. The method according to claim 15, characterized in that Verifying the token request based on at least one of the first information, the second information, and a network function service consumer certificate, comprising: Verify whether the NPN information in the token request is consistent with the NPN in the second information; Verify whether the NPN information in the token request is consistent with the NPN associated with the network function service consumer recorded in the network function service consumer certificate; Verify whether the NPN information in the token request is consistent with the NPN information in the first information.

17. The method according to claim 15, characterized in that The second information includes NPN information associated with the network function service consumer, and the NPN information includes at least one of the following: CAG identifier associated with the NPN; Location information; NPN identification.

18. The method according to claim 15, characterized in that The first information includes at least one of the following: Services and NPN information that allows requests for said services; Resources and NPN information that allows requests for said resources; The association between NPN information and terminal identification.

19. The method according to any one of claims 14 to 18, characterized in that Also includes: The NRF sends a token to the network function service consumer, where the token includes NPN information.

20. A communication method, characterized in that: The method comprises: The NRF receives first information sent by the network function service provider, where the first information includes NPN information.

21. The method according to claim 20, characterized in that The NPN information in the first information includes at least one of the following: Services and NPN information that allows requests for said services; Resources and NPN information that allows requests for said resources; The association between NPN information and terminal identification.

22. A communication method, characterized in that: The method comprises: The NRF receives second information sent by the network function consumer, where the second information includes NPN information associated with the network function service consumer.

23. The method according to claim 22, characterized in that The NPN information in the second information includes at least one of the following: CAG identifier associated with the NPN; Location information; NPN identification.

24. A communication method, characterized in that: The method comprises: The network function service consumer sends a service request to the network function service provider, where the service request includes NPN information.

25. The method according to claim 24, characterized in that The service request includes a token and NPN information of the token.

26. The method according to claim 24, characterized in that The service request includes a terminal identifier.

27. The method according to any one of claims 24 to 26, characterized in that The method further comprises: The network function service consumer sends a token request to the NRF, where the token request includes NPN information.

28. The method according to any one of claims 24 to 26, characterized in that The method further comprises: The network function service consumer sends second information to the NRF; The second information includes NPN information associated with the network function service consumer, and the NPN information includes at least one of the following: CAG identifier associated with the NPN; Location information; NPN identification.

29. A communication method, characterized in that: The method comprises: The network function service consumer sends a token request to the NRF, where the token request includes NPN information.

30. The method according to claim 29, wherein The method further comprises: The network function service consumer receives the token sent by the NRF, where the token includes NPN information.

31. A communication method, characterized in that: The method comprises: The network function service consumer sends second information to the NRF, where the second information includes NPN information associated with the network function service consumer.

32. The method according to claim 31, characterized in that The NPN information in the second information includes at least one of the following: CAG identifier associated with the NPN; Location information; NPN identification.

33. A network function service provider, characterized in that: include: The transceiver module is used to receive a service request sent by a network function service consumer, wherein the service request includes non-public network NPN information; A processing module is used to verify the service request.

34. A network function service provider, characterized in that: include: The transceiver module is configured to send first information to the NRF, where the first information includes NPN information.

35. An NRF, characterized in that include: A transceiver module is configured to receive a token request sent by a network function service consumer, wherein the token request includes NPN information; A processing module is used to verify the token request.

36. An NRF, characterized in that include: The transceiver module is used to receive first information sent by a network function service provider, where the first information includes NPN information.

37. An NRF, characterized in that include: The transceiver module is used to receive second information sent by the network function consumer, where the second information includes NPN information associated with the network function service consumer.

38. A network function service consumer, characterized in that: include: The transceiver module is used to send a service request to the network function service provider, where the service request includes NPN information.

39. A network function service consumer, characterized in that: include: The transceiver module is used to send a token request to the NRF, where the token request includes NPN information.

40. A network function service consumer, characterized in that: include: The transceiver module is used to send second information to the NRF, where the second information includes the NPN information associated with the network function service consumer.

41. A network function service provider, characterized in that: include: one or more processors; The network function service provider is configured to execute the method according to any one of claims 1 to 13.

42. An NRF, characterized in that include: one or more processors; The NRF is used to perform the method according to any one of claims 14 to 23.

43. A network function service consumer, characterized in that: include: one or more processors; The network function service consumer is configured to execute the method described in any one of claims 24 to 32.

44. A communication system, characterized in that The invention comprises a network function service provider, an NRF and a network function service consumer, wherein the network function service provider is configured to implement the method according to any one of claims 1 to 13, the NRF is configured to implement the method according to any one of claims 14 to 23, and the network function service consumer is configured to implement the method according to any one of claims 24 to 32.

45. A storage medium storing instructions, characterized in that: When the instruction is executed on a communication device, the communication device is caused to execute the method according to any one of claims 1 to 11, the method according to any one of claims 14 to 23, or the method according to any one of claims 24 to 32.

46. ​​A program product, characterized in that include: A computer program, which, when executed by a communication device, causes the communication device to perform the method according to any one of claims 1 to 11, the method according to any one of claims 14 to 23, or the method according to any one of claims 24 to 32.

Citation Information

Patent Citations

  • Service authorization method, device and system

    CN113438196A

  • Communication network arrangement and method for providing machine learning model for performing communication network analysis

    CN117223268A

  • Base station selection for timing resiliency service

    WO2023043728A1