Communication method and communication apparatus

By receiving and verifying the information of the business requester through the core network equipment, the operation authorization of the IoT device is performed based on the contract information and identification, which solves the problem of device permission management in the supply chain scenario and realizes legal and compliant operations across the network.

WO2025209304A1PCT designated stage Publication Date: 2025-10-09HUAWEI TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/085292
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-08-09
Filing Date
2025-03-27
Publication Date
2025-10-09

AI Technical Summary

Technical Problem

Existing technologies cannot fully solve the operational authority management needs of IoT devices in supply chain scenarios, especially the operational authority control of upstream enterprises' equipment by downstream enterprises.

Method used

The core network device or module receives information from the service requester, and determines whether the downstream enterprise has the authority to operate the IoT terminal based on the contract information and identification, thereby realizing cross-network operation authorization.

Benefits of technology

It realizes precise operation permission management of IoT devices, supports cross-network authorization control, and ensures the legality and security of device operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025085292_09102025_PF_FP_ABST
    Figure CN2025085292_09102025_PF_FP_ABST
Patent Text Reader

Abstract

The present application provides a communication method and a communication apparatus. According to the method, a core network receives information of a second service requester and information of a first service requester to which one or more Internet of things terminals belong, and on the basis of the information of the first service requester and the information of the second service requester, determines whether the second service requester has permission to operate the one or more Internet of things terminals. The present application is used for performing operation authorization of Internet of things devices on the basis of identifiers corresponding to upstream enterprises.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method and communication device

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of China on April 3, 2024, with application number 202410408329.5 and invention name “Communication Method and Communication Device”, the entire contents of which are incorporated by reference into this application.

[0002] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of China on August 9, 2024, with application number 202411096401.1 and application name “Communication Method and Communication Device”, the entire contents of which are incorporated by reference into this application. Technical Field

[0003] The present application relates to the field of communications, and in particular, to a communication method and a communication device. Background Art

[0004] The Internet of Things (IoT), a component of 5G, is experiencing rapidly growing market demand. In IoT scenarios, upstream enterprises provide IoT devices for use by companies across the entire supply chain. For example, a device provided by Enterprise 1 can be used by multiple companies across multiple supply chains. In this scenario, Enterprise 1 provides the device identifier and the downstream enterprise's device operation permissions to the core network. When a downstream enterprise requests to operate an upstream enterprise's IoT device, it provides the core network with the identifier of the desired IoT device. The core network then determines whether the downstream enterprise can operate the device.

[0005] However, the above-mentioned existing technical solutions cannot fully meet the actual needs of supply chain scenarios, which is a problem that needs to be solved urgently. Summary of the Invention

[0006] The present application provides a communication method and a communication device that can authorize the operation of an Internet of Things device based on the corresponding identification of an enterprise.

[0007] In a first aspect, a communication method is provided. The method can be executed by a core network device, or can be executed by a module (such as a chip or circuit) of the core network device, without limitation.

[0008] The method may include: receiving information of a second service requester and information of a first service requester to which one or more IoT terminals belong; and determining whether the second service requester has the authority to operate the one or more IoT terminals based on the information of the first service requester and the information of the second service requester.

[0009] Among them, the first service requester can be understood as: the supplier enterprise that supplies the one or more Internet of Things terminals, or the application function network element or server in the operator network signed by the supplier enterprise, or the user who owns the one or more Internet of Things terminals, or the application function network element or server corresponding to the user, wherein, when the first service requester is the application function network element, it is called the first application function network element; the second service requester can be understood as: the downstream enterprise (or supply chain enterprise) that requests to operate the one or more Internet of Things terminals, or the application function network element or server in the operator network accessed by the downstream enterprise, or the user who requests to operate the one or more Internet of Things terminals, or the application function network element or server corresponding to the user, wherein, when the second service requester is the application function network element, it is called the second application function network element.

[0010] The information of the second service requester and the information of the first service requester may be in the same message or may not be in the same message.

[0011] Optionally, the information of the second service requester is request information of the second service requester requesting to operate the one or more Internet of Things terminals.

[0012] Optionally, the information of the first service requester to which the one or more IoT terminals belong may be information on the operation permissions of the one or more IoT terminals sent by the first service requester to the core network device.

[0013] Optionally, the information of one or more IoT terminals may include information of the first service requester.

[0014] Through the above solution, the core network can determine whether the second service requester has the authority to operate the IoT device of the supplier enterprise based on the information of the first service requester, thereby supporting the operation authorization of IoT devices in a region.

[0015] Optionally, the information of the first service requester includes an identifier of the first service requester. The identifier of the first service requester may be an identifier of the first application function network element, an identifier of a supplier enterprise, an identifier of a user owning the one or more IoT terminals, an identifier of a community access gateway CAG, an IP address, etc. It should be understood that any identifier that can represent the identity of the first service requester may be used as the identifier of the first service requester, and this application does not limit the identifier of the first service requester.

[0016] Optionally, the information of the first service requester includes information of the one or more IoT terminals, and the information of the one or more IoT terminals may include identifiers of the one or more IoT terminals. Optionally, the identifiers of the one or more IoT terminals may be a serial number / identifier (device ID) assigned by the second PLMN to the IoT terminal, or a globally unique identifier (3rd party defined ID) defined by a third party enterprise.

[0017] Optionally, the information of the second service requester includes an identifier of the second service requester. The identifier of the second service requester may be an identifier of a second application function network element, an identifier of a supply chain enterprise, an identifier of a user requesting to operate the one or more IoT terminals, an identifier of a community access gateway (CAG), an IP address, etc. It should be understood that any identifier that can represent the identity of the second service requester may be used as the identifier of the second service requester, and this application does not limit the identifier of the second service requester.

[0018] In combination with the first aspect, in some implementation methods of the first aspect, receiving information of the second service requester and information of the first service requester to which one or more Internet of Things terminals belong includes: the first Internet of Things management function network element receives first request information from the second service requester, the first request information is used to request operation of one or more Internet of Things terminals of the first service requester, and the first request information includes information of the second service requester and information of the first service requester; determining whether the second service requester has the authority to operate one or more Internet of Things terminals based on the information of the first service requester and the information of the second service requester includes: the first Internet of Things management function network element obtains the contract information of the first service requester based on the information of the first service requester; the first Internet of Things management function network element determines whether the second service requester has the authority to operate one or more Internet of Things terminals based on the first request information and the contract information of the first service requester.

[0019] Through the above solution, the first IoT management function network element can obtain the contract information of the first service requester based on the information of the first service requester from the second service requester, and perform operation authorization based on the obtained contract information.

[0020] Optionally, the first request information is also used to request operation on one or more Internet of Things of the first service requester within a certain geographical area, and the first Internet of Things management function network element also determines whether the second service requester has the authority to operate one or more Internet of Things terminals within the geographical area.

[0021] In combination with the first aspect, in some implementation methods of the first aspect, the first Internet of Things management function network element obtains the contract information of the first service requester based on the information of the first service requester, including: the first Internet of Things management function network element sends a second request information to the first data management network element, the second request information is used to request to obtain the contract information of the first service requester, the first Internet of Things management function network element and the first data management network element belong to the first network, and the first service requester signs a contract with the first network; the first Internet of Things management function network element obtains the contract information of the first service requester from the first data management network element.

[0022] The first service requester has signed a contract with the first network, which can be replaced by: the first network has the contract data of the first service requester, or the first network has signed a service agreement with the first service requester.

[0023] In the present application, the first network may be a public land mobile network PLMN, a private network, a subnet, etc., and the present application does not limit this.

[0024] Through the above solution, the first IoT management function network element can request the first data management network element to obtain the contract information of the first service requester based on the information of the first service requester.

[0025] In combination with the first aspect, in some implementation methods of the first aspect, receiving information of the second service requester and information of the first service requester to which one or more Internet of Things terminals belong includes: the first Internet of Things management function network element receives first request information from the second service requester, the first request information is used to request operation of one or more Internet of Things terminals of the first service requester, and the first request information includes information of the second service requester and information of the first service requester; determining whether the second service requester has the authority to operate one or more Internet of Things terminals based on the information of the first service requester and the information of the second service requester, including: the first Internet of Things management function network element sends the first request information to the first data management network element, the first Internet of Things management function network element receives the authentication result from the first data management network element, the authentication result indicates whether the second service requester has the authority to operate one or more Internet of Things terminals, the first Internet of Things management function network element and the first data management network element belong to the first network, and the first service requester signs a contract with the first network.

[0026] The first service requester has signed a contract with the first network, which can be replaced by: the first network has the contract data of the first service requester, or the first network has signed a service agreement with the first service requester.

[0027] Through the above solution, after receiving the second request information from the first IoT management function network element, the first data management network element directly performs operation authorization.

[0028] Optionally, the first request information is also used to request operation on one or more Internet of Things of the first service requester within a certain geographical area, and the first data management network element also determines whether the second service requester has the authority to operate one or more Internet of Things terminals within the geographical area.

[0029] In combination with the first aspect, in some implementation methods of the first aspect, the first Internet of Things management function network element receives the first request information from the second service requester, including: the first Internet of Things management function network element receives the first request information from the second service requester through the second Internet of Things management function network element, and the second Internet of Things management function network element belongs to the second network accessed by the second service requester.

[0030] Among them, the second Internet of Things management function network element belongs to the second network accessed by the second service requester, which can be replaced by: the second Internet of Things management function network element is located in the PLMN of the geographical area of ​​the Internet of Things terminal requested by the second service requester to operate.

[0031] In the present application, the second network may be a public land mobile network PLMN, a private network, a subnet, etc., and the present application does not limit this.

[0032] Through the above solution, when the first network signed by the first service requester and the second network accessed by the second service requester are different, the second IoT management function network element in the second network forwards the first request message sent by the second service requester, thereby completing cross-network operation authorization.

[0033] In conjunction with the first aspect, in some implementations of the first aspect, when the first network and the second network are different, the first request information includes an identifier of the second network. The identifier of the second network can be used for authentication.

[0034] In combination with the first aspect, in some implementation methods of the first aspect, receiving information of the second service requester and information of the first service requester to which one or more Internet of Things terminals belong includes: the first data management network element receives second request information from the first Internet of Things management function network element, the second request information is used to request to obtain the contract information of the first service requester, the second request information includes information of the second service requester and information of the first service requester, the first Internet of Things management function network element and the first data management network element belong to the first network, and the first service requester signs a contract with the first network; determining whether the second service requester has the authority to operate one or more Internet of Things terminals based on the information of the first service requester and the information of the second service requester includes: the first data management network element determines whether the second service requester has the authority to operate one or more Internet of Things terminals based on the second request information and the contract information of the first service requester.

[0035] Through the above solution, after the first data management network element receives the second request information for obtaining the contract information, it can directly perform operation authentication because it has stored the contract information of the first service requester.

[0036] In combination with the first aspect, in some implementation methods of the first aspect, receiving information of the second service requester and information of the first service requester to which one or more Internet of Things terminals belong includes: the first data management network element receives second request information from the second Internet of Things management function network element, the second request information is used to request to obtain the contract information of the first service requester, the second request information includes information of the second service requester and information of the first service requester, the first data management network element belongs to the first network, the first service requester signs a contract with the first network, and the second Internet of Things management function network element belongs to the second network accessed by the second service requester; determining whether the second service requester has the authority to operate one or more Internet of Things terminals based on the information of the first service requester and the information of the second service requester includes: the first data management network element determines whether the second service requester has the authority to operate one or more Internet of Things terminals based on the second request information and the contract information of the first service requester.

[0037] Alternatively, in the solution of the present application, the first data management network element can be replaced by the authentication, authorization, and accounting AAA server corresponding to the first service requester. Optionally, the second IoT management function network element further selects the first data management network element or the AAA server corresponding to the first service requester based on the identifier of the first service requester.

[0038] The first network and the second network may be the same or different. It should be understood that when the first network and the second network are the same, the second IoT management function network element and the first IoT management function network element are the same network element.

[0039] Through the above solution, the second IoT management function network element in the second network directly sends the second request information to the first data management network element to request the contract information. Since the first data management network element stores the contract information of the first service requester, the operation authentication can be performed directly.

[0040] In conjunction with the first aspect, in some implementations of the first aspect, when the first network and the second network are different, the second request information includes an identifier of the second network. The identifier of the second network can be used for authentication.

[0041] In combination with the first aspect, in some implementations of the first aspect, the method also includes: the second Internet of Things management function network element receives a first request message from a second service requester, the first request message is used to request operation of one or more Internet of Things terminals of the first service requester, and the first request message includes information of the first service requester; determines the first network based on the information of the first service requester; and sends the second request message to the first data management network element belonging to the first network.

[0042] Through the above scheme, when the first network and the second network are different, the second IoT management function network element of the second network can determine that the network signed by the first service requester is not this network after receiving the first request information from the second service requester, and request the first data management network element in the first network to obtain the contract information of the first service requester, thereby completing cross-network operation authorization.

[0043] It should be understood that when the first network and the second network are different, the first network should have a service agreement with the second network, such as a roaming service agreement.

[0044] In combination with the first aspect, in some implementations of the first aspect, the method also includes: the second service request direction sends a first request message to the second Internet of Things management function network element, the first request message is used to request operation of one or more Internet of Things terminals of the first service request party, the first request message includes information of the second service request party and information of the first service request party, and the second Internet of Things management function network element belongs to the second network accessed by the second service request party.

[0045] Through the above solution, the second service requester can carry the information of the first service requester in the first request information, thereby completing the operation authorization.

[0046] In combination with the first aspect, in some implementations of the first aspect, the method also includes: receiving a first security key, and determining whether the second business requester has the authority to operate one or more Internet of Things terminals based on the contract information of the first business requester, including: determining whether the first security key meets the contract information of the first business requester.

[0047] The first security key is used to ensure the authenticity and reliability of the second service requester and prevent the operation request from being modified or hijacked by a third party.

[0048] On the second aspect, a communication method is provided, which can be executed by the second Internet of Things management function network element, or can also be executed by a module (such as a chip or circuit) of the second Internet of Things management function network element, without limitation.

[0049] The method may include: a second IoT management function network element receiving first request information from a second service requester, the first request information being used to request operation of one or more IoT terminals of the first service requester, the first request information including information of the first service requester; determining a first network contracted with the first service requester based on the information of the first service requester; and sending the first request information to a first IoT management function network element belonging to the first network. The second service requester is connected to a second network, and the second IoT management function network element belongs to the second network.

[0050] Through the above solution, when the first network signed by the first service requester and the second network accessed by the second service requester are different, the second Internet of Things management function network element in the second network forwards the first request message sent by the second service requester to the first Internet of Things management function network element in the first network, thereby completing cross-network operation authorization.

[0051] Alternatively, the method may include: a second IoT management function network element receiving a first request message from a second service requester, the first request message being used to request operation of one or more IoT terminals of the first service requester, the first request message including information of the first service requester; determining a first network contracted with the first service requester based on the information of the first service requester; and sending a second request message to a first data management network element belonging to the first network, the second request message being used to request acquisition of the contract information of the first service requester. The second service requester is connected to a second network, and the second IoT management function network element belongs to the second network.

[0052] Through the above scheme, when the first network and the second network are different, the second IoT management function network element of the second network can determine that the network signed by the first service requester is not this network after receiving the first request information from the second service requester, and request the first data management network element in the first network to obtain the contract information of the first service requester, thereby completing cross-network operation authorization.

[0053] Alternatively, the method may include: a second IoT management function network element receiving a first request message from a second service requester, the first request message being used to request operation of one or more IoT terminals of the first service requester, the first request message including information of the first service requester; determining a first network contracted with the first service requester based on the information of the first service requester; and sending a second request message to a first data management network element belonging to the first network, the second request message being used to request acquisition of contract information of the one or more IoT terminals. The second service requester is connected to a second network, and the second IoT management function network element belongs to the second network.

[0054] Through the above scheme, when the first network and the second network are different, the second IoT management function network element of the second network can determine that the network signed by the first service requester is not this network after receiving the first request information from the second service requester, and request the first data management network element in the first network to obtain the contract information of one or more IoT terminals, thereby completing cross-network operation authorization.

[0055] On the third aspect, a communication method is provided, which can be executed by a core network device within the first network, or can also be executed by a module (such as a chip or circuit) of the core network device, without limitation.

[0056] The method may include: receiving information of a second service requester and first identification information from a second Internet of Things management function network element, the first identification information including at least one of the following identifications: information of the first service requester to which one or more Internet of Things terminals belong, information of one or more Internet of Things terminals, wherein the first service requester signs a contract with the first network, the second service requester accesses the second network, and the second Internet of Things management function network element belongs to the second network; and determining whether the second service requester has the authority to operate one or more Internet of Things terminals based on the information of the second service requester and the first identification information.

[0057] Through the above solution, when the first network signed by the first service requester and the second network accessed by the second service requester are different, the second Internet of Things management function network element in the second network forwards the second service requester's information and first identification information sent by the second service requester, thereby completing cross-network operation authorization.

[0058] In combination with the third aspect, in some implementation methods of the third aspect, receiving information of the second service requester and first identification information from the second Internet of Things management function network element includes: the first Internet of Things management function network element receives first request information from the second Internet of Things management function network element, the first request information is used by the second service requester to request operation of one or more Internet of Things terminals, the first request information includes information of the second service requester and first identification information, and the first Internet of Things management function network element belongs to the first network; determining whether the second service requester has the authority to operate one or more Internet of Things terminals based on the information of the second service requester and the first identification information includes: the first Internet of Things management function network element obtains the contract information of the first service requester based on the information of the first service requester; the first Internet of Things management function network element determines whether the second service requester has the authority to operate one or more Internet of Things terminals based on the first request information and the contract information of the first service requester.

[0059] Through the above solution, the first IoT management function network element can obtain the contract information of the first service requester based on the first identification information from the second service requester, and perform operation authorization based on the obtained contract information.

[0060] In combination with the third aspect, in some implementation methods of the third aspect, receiving the information of the second service requester and the first identification information from the second Internet of Things management function network element includes: the first Internet of Things management function network element receives the first request information from the second Internet of Things management function network element, the first request information is used by the second service requester to request operation of one or more Internet of Things terminals, the first request information includes the information of the second service requester and the first identification information, and the first Internet of Things management function network element belongs to the first network; determining whether the second service requester has the authority to operate one or more Internet of Things terminals based on the information of the second service requester and the first identification information includes: the first Internet of Things management function network element sends the first request information to the first data management network element, the first Internet of Things management function network element receives the authentication result from the first data management network element, the authentication result indicates whether the second service requester has the authority to operate one or more Internet of Things terminals, the first Internet of Things management function network element and the first data management network element belong to the first network, and the first service requester signs a contract with the first network.

[0061] Through the above solution, after receiving the second request information from the first IoT management function network element, the first data management network element directly performs operation authorization.

[0062] In combination with the third aspect, in some implementation methods of the third aspect, receiving the information of the second service requester and the first identification information from the second Internet of Things management function network element includes: the first Internet of Things management function network element receives the first request information from the second Internet of Things management function network element, the first request information is used by the second service requester to request operation of one or more Internet of Things terminals, the first request information includes the information of the second service requester and the first identification information, and the first Internet of Things management function network element belongs to the first network; determining whether the second service requester has the authority to operate one or more Internet of Things terminals based on the information of the second service requester and the first identification information includes: the first Internet of Things management function network element obtains the contract information of one or more Internet of Things terminals based on the information of one or more Internet of Things terminals; the first Internet of Things management function network element determines whether the second service requester has the authority to operate one or more Internet of Things terminals based on the first request information and the contract information of one or more Internet of Things terminals.

[0063] Through the above solution, the first IoT management function network element can obtain the contract information of the IoT terminal based on the first identification information from the second service requester, and perform operation authorization based on the obtained contract information.

[0064] In combination with the third aspect, in some implementation methods of the third aspect, the first Internet of Things management function network element obtains the contract information of the first service requester based on the information of the first service requester, including: the first Internet of Things management function network element sends a second request information to the first data management network element, the second request information is used to request to obtain the contract information of the first service requester, and the first data management network element belongs to the first network; the first Internet of Things management function network element obtains the contract information of the first service requester from the first data management network element.

[0065] In combination with the third aspect, in some implementations of the third aspect, the method further includes: the first data management network element sends the contract information of the first service requester to the first Internet of Things management function network element.

[0066] In combination with the third aspect, in some implementation methods of the third aspect, the first IoT management function network element obtains the contract information of one or more IoT terminals based on the information of one or more IoT terminals, including: the first IoT management function network element sends a second request information to the first data management network element, the second request information is used to request to obtain the contract information of one or more IoT terminals, and the first data management network element belongs to the first network; the first IoT management function network element obtains the contract information of one or more IoT terminals from the first data management network element.

[0067] In combination with the third aspect, in some implementations of the third aspect, the method further includes: the first data management network element sends the contract information of one or more Internet of Things terminals to the first Internet of Things management function network element.

[0068] In combination with the third aspect, in some implementation methods of the third aspect, receiving information of the second service requester and first identification information from the second Internet of Things management function network element includes: the first data management network element receives the second request information from the second Internet of Things management function network element, the second request information is used to request to obtain the contract information of the first service requester, the second request information includes the information of the second service requester and the first identification information, and the first data management network element belongs to the first network; determining whether the second service requester has the authority to operate one or more Internet of Things terminals based on the information of the second service requester and the first identification information includes: the first data management network element determines whether the second service requester has the authority to operate one or more Internet of Things terminals based on the second request information and the contract information of the first service requester.

[0069] Through the above solution, the second IoT management function network element in the second network directly sends the second request information to the first data management network element to request the contract information. Since the first data management network element stores the contract information of the first service requester, the operation authentication can be performed directly.

[0070] In combination with the third aspect, in some implementation methods of the third aspect, receiving information of the second service requester and first identification information from the second Internet of Things management function network element includes: the first data management network element receives second request information from the second Internet of Things management function network element, the second request information is used to request to obtain the contract information of one or more Internet of Things terminals, the second request information includes information of the second service requester and information of one or more Internet of Things terminals, and the first data management network element belongs to the first network; determining whether the second service requester has the authority to operate one or more Internet of Things terminals based on the information of the second service requester and the information of one or more Internet of Things terminals includes: the first data management network element determines whether the second service requester has the authority to operate one or more Internet of Things terminals based on the second request information and the contract information of one or more Internet of Things terminals.

[0071] Through the above solution, the second IoT management function network element in the second network directly sends the second request information to the first data management network element to request the contract information. Since the first data management network element stores the contract information of one or more IoT terminals, operation authentication can be performed directly.

[0072] In combination with the third aspect, in some implementations of the third aspect, the method also includes: the second IoT management function network element receives a first request message from the second service requester, the first request message is used to request operation of one or more IoT terminals of the first service requester, and the first request message includes first identification information; determines the first network based on the first identification information; and sends the second request message to the first data management network element belonging to the first network.

[0073] In combination with the third aspect, in some implementations of the third aspect, the first request information includes an identifier of the second network.

[0074] In combination with the third aspect, in some implementations of the third aspect, the second request information includes an identifier of the second network.

[0075] In conjunction with the third aspect, in some implementations of the third aspect, the method further includes:

[0076] The second service requester sends a first request message to the second IoT management function network element. The first request message is used to request an operation on one or more IoT terminals of the first service requester. The first request message includes information of the second service requester and first identification information.

[0077] In combination with the third aspect, in some implementations of the third aspect, the method also includes: receiving a first security key, and determining whether the second business requester has the authority to operate one or more Internet of Things terminals based on the contract information of the first business requester, including: determining whether the first security key meets the contract information of the first business requester.

[0078] In a fourth aspect, a communication method is provided, which can be executed by the second application function network element, or can also be executed by a module (such as a chip or circuit) of the second application function network element, without limitation.

[0079] The method may include: sending first request information, which is used by the second service requester to request operation of one or more Internet of Things terminals of the first service requester, and the first request information includes information of the second service requester and information of the first service requester, wherein the first service requester signs a contract with the first network, the second service requester accesses the second network, and the second application function network element belongs to the second network.

[0080] Alternatively, the method may include: sending a first request message, which is used by the second service requester to request operation of one or more Internet of Things terminals of the first service requester, the first request message including information of the second service requester and information of one or more Internet of Things terminals, wherein the first service requester signs a contract with the first network, the second service requester accesses the second network, and the second application function network element belongs to the second network.

[0081] In the fifth aspect, a communication device is provided, which may include modules or units corresponding to the methods / operations / steps / actions described in the first aspect. The modules or units may be hardware circuits, software, or a combination of hardware circuits and software.

[0082] In the sixth aspect, a communication device is provided, which may include modules or units corresponding to the methods / operations / steps / actions described in the second aspect. The modules or units may be hardware circuits, software, or a combination of hardware circuits and software.

[0083] In the seventh aspect, a communication device is provided, which may include modules or units corresponding to the methods / operations / steps / actions described in the third aspect. The modules or units may be hardware circuits, software, or a combination of hardware circuits and software.

[0084] In the eighth aspect, a communication device is provided, which may include modules or units corresponding to the methods / operations / steps / actions described in the fourth aspect. The modules or units may be hardware circuits, software, or a combination of hardware circuits and software.

[0085] In a ninth aspect, a communication device is provided, comprising a processor. The processor is coupled to a memory and configured to execute instructions in the memory to implement the method of the first and third aspects, and any possible implementation of the first and third aspects. Optionally, the communication device further comprises a memory. Optionally, the communication device further comprises a communication interface, the processor being coupled to the communication interface.

[0086] In one implementation, the communication device is a core network device. When the communication device is a core network device, the communication interface may be a transceiver, or an input / output interface.

[0087] In another implementation, the communication device is a chip configured in a core network device. When the communication device is a chip configured in a core network device, the communication interface may be an input / output interface.

[0088] Optionally, the transceiver may be a transceiver circuit. Optionally, the input / output interface may be an input / output circuit.

[0089] In a tenth aspect, a communication device is provided, comprising a processor. The processor is coupled to a memory and configured to execute instructions in the memory to implement the method of the second aspect and any possible implementation thereof. Optionally, the communication device further comprises a memory. Optionally, the communication device further comprises a communication interface, the processor being coupled to the communication interface.

[0090] In one implementation, the communication device is an Internet of Things management function network element. When the communication device is an Internet of Things management function network element, the communication interface may be a transceiver, or an input / output interface.

[0091] In another implementation, the communication device is a chip configured in an IoT management function network element. When the communication device is a chip configured in an IoT management function network element, the communication interface may be an input / output interface.

[0092] In an eleventh aspect, a communication device is provided, comprising a processor. The processor is coupled to a memory and configured to execute instructions in the memory to implement the method of the fourth aspect and any possible implementation thereof. Optionally, the communication device further comprises a memory. Optionally, the communication device further comprises a communication interface, the processor being coupled to the communication interface.

[0093] In one implementation, the communication device is an application function network element. When the communication device is an application function network element, the communication interface may be a transceiver or an input / output interface.

[0094] In another implementation, the communication device is a chip configured in an application function network element. When the communication device is a chip configured in an application function network element, the communication interface may be an input / output interface.

[0095] In a twelfth aspect, a processor is provided, comprising: an input circuit, an output circuit, and a processing circuit. The processing circuit is configured to receive a signal through the input circuit and transmit a signal through the output circuit, so that the processor executes the method of any possible implementation of aspects 1 to 4.

[0096] In a specific implementation, the processor may be one or more chips, the input circuit may be an input pin, the output circuit may be an output pin, and the processing circuit may be a transistor, a gate circuit, a trigger, or various logic circuits. The input signal received by the input circuit may be received and input by a receiver, and the signal output by the output circuit may be output to and transmitted by a transmitter. The input circuit and the output circuit may be the same circuit, which functions as an input circuit and an output circuit at different times. The embodiments of the present application do not limit the specific implementation of the processor and various circuits.

[0097] In a thirteenth aspect, a processing device is provided, comprising a processor and a memory. The processor is configured to read instructions stored in the memory and receive signals via a receiver and transmit signals via a transmitter to execute the method of any possible implementation of aspects 1 to 4.

[0098] Optionally, there are one or more processors and one or more memories.

[0099] Optionally, the memory may be integrated with the processor, or be provided separately from the processor.

[0100] In the specific implementation process, the memory can be a non-transitory memory, such as a read-only memory (ROM). The memory can be integrated with the processor on the same chip, or can be set on different chips. The embodiments of the present application do not limit the type of memory and the setting method of the memory and the processor.

[0101] It should be understood that related data interaction processes, such as sending indication information, can be the process of outputting indication information from the processor, and receiving capability information can be the process of receiving input capability information from the processor. Specifically, data output by the processor can be output to the transmitter, and input data received by the processor can be received from the receiver. The transmitter and receiver can be collectively referred to as a transceiver.

[0102] The processing device in the aforementioned aspect 13 may be one or more chips. The processor in the processing device may be implemented in hardware or software. When implemented in hardware, the processor may be a logic circuit, an integrated circuit, or the like; when implemented in software, the processor may be a general-purpose processor implemented by reading software code stored in a memory, which may be integrated into the processor or located independently of the processor.

[0103] In the fourteenth aspect, a computer program product is provided, which includes: a computer program (also referred to as code, or instructions), which, when executed, enables a computer to execute a method in any possible implementation of the first to fourth aspects above.

[0104] In the fifteenth aspect, a computer-readable storage medium is provided, which stores a computer program (also referred to as code, or instructions) which, when run on a computer, enables the method in any possible implementation of the first to fourth aspects above to be executed.

[0105] In the sixteenth aspect, a communication system is provided, comprising at least one of the aforementioned core network equipment, application function network elements and Internet of Things management function network elements. BRIEF DESCRIPTION OF THE DRAWINGS

[0106] FIG1 is a schematic diagram of an example of a communication system to which the present application is applied.

[0107] FIG2 is a schematic flowchart of a communication method provided in an embodiment of the present application.

[0108] FIG3 is a schematic flowchart of a communication method provided in an embodiment of the present application.

[0109] FIG4 is a schematic flowchart of a communication method provided in an embodiment of the present application.

[0110] FIG5 is a schematic flowchart of a communication method provided in an embodiment of the present application.

[0111] FIG6 is a schematic flowchart of a communication method provided in an embodiment of the present application.

[0112] FIG7 is a schematic flowchart of a communication method provided in an embodiment of the present application.

[0113] FIG8 is a schematic block diagram of a communication device provided in an embodiment of the present application.

[0114] FIG9 is a schematic block diagram of a communication device provided in an embodiment of the present application.

[0115] FIG10 is a schematic block diagram of a chip system provided in an embodiment of the present application. DETAILED DESCRIPTION

[0116] The technical solution in this application will be described below with reference to the accompanying drawings.

[0117] The technical solutions provided in this application can be applied to various communication systems, such as new radio (NR) systems, long term evolution (LTE) systems, LTE frequency division duplex (FDD) systems, LTE time division duplex (TDD) systems, etc. The technical solutions provided in this application can also be applied to device-to-device (D2D) communication, vehicle-to-everything (V2X) communication, machine-to-machine (M2M) communication, machine type communication (MTC), and Internet of Things (IoT) communication systems or other communication systems.

[0118] In a communication system, the part operated by an operator may be referred to as a public land mobile network (PLMN), or an operator network, etc. A PLMN is a network established and operated by an operator for the purpose of providing land mobile communication services to the public. It is mainly a public network in which a mobile network operator (MNO) provides mobile broadband access services to users. The PLMN described in the embodiments of the present application may specifically be a network that complies with the standards of the 3rd Generation Partnership Project (3GPP), referred to as a 3GPP network. 3GPP networks generally include but are not limited to fifth-generation mobile communication (5th-generation, 5G) networks, fourth-generation mobile communication (4th-generation, 4G) networks, and other future communication systems.

[0119] For ease of description, the embodiments of the present application will be described using PLMN or 5G network as an example.

[0120] Figure 1 is a schematic diagram of a network architecture 100, using the 5G network architecture based on a service-based architecture (SBA) in a non-roaming scenario as defined in the 3GPP standardization process as an example. As shown in Figure 1 , the network architecture may include a terminal device component, a data network (DN) component, and a carrier network (PLMN) component. The carrier network PLMN component may include, but is not limited to, a (radio) access network (R)AN) 120 and a core network (CN) component.

[0121] The following is a brief description of the functions of the network elements in each part.

[0122] The terminal device portion may include a terminal device 110, which is a device that provides voice and / or data connectivity to the user. The terminal device 110 may also be referred to as a user equipment UE. The terminal device 110 in this application is a device with wireless transceiver functions, which can communicate with one or more core network (CN) devices via an access network device (or also referred to as an access device) in a (radio) access network (R)AN 120. The terminal device 110 may also be referred to as an access terminal, terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, user agent or user device, etc. The terminal device 110 may be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; it may also be deployed on water (such as a ship, etc.); it may also be deployed in the air (such as an airplane, balloon and satellite, etc.). The terminal device 110 may be a cellular phone, a cordless phone, a Session Initiation Protocol (SIP) phone, a smartphone, a mobile phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), or the like. Alternatively, the terminal device 110 may be a handheld device with wireless communication capabilities, a computing device, or other device connected to a wireless modem, an in-vehicle device, a wearable device, an unmanned aerial vehicle device, or a terminal in the Internet of Things (IoT), the Internet of Vehicles (IoV), any terminal in a 5G network or future networks, a relay user device, or a terminal in a future-evolved communication network. The relay user device may be, for example, a 5G residential gateway (RG). For example, the terminal device 110 may be a virtual reality (VR) terminal, an augmented reality (AR) terminal, a wireless terminal in industrial control, a wireless terminal in unmanned driving, a wireless terminal in telemedicine, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, or a wireless terminal in a smart home. The terminal device here refers to a 3GPP terminal. The embodiments of the present application do not limit the type or category of terminal devices. For ease of explanation, the present application will use UE to represent terminal devices as an example for explanation.

[0123] (R)AN 120 may include one or more access network elements or access network devices, and the interface between the access network device and the terminal device may be a Uu interface (or air interface, i.e., the messages exchanged between the access network device and the terminal device may be called air interface messages). Of course, in future communications, the interface name may remain unchanged or may be replaced by other names, and this application does not limit this. (R)AN 120 is a device that provides wireless communication functions for the terminal device 110, which can connect the terminal device to a node or device of a wireless network, and may also be called a network device. (R)AN 120 can be regarded as a subnet of the operator network, and is an implementation system between a service node in the operator network and the terminal device 110. For example, the terminal device 110 can connect to a service node of the operator network through (R)AN 120, thereby obtaining the services provided by the service node. For the convenience of description, in all embodiments of this application, the above-mentioned device that provides wireless communication functions for the terminal device 110 is collectively referred to as an access network device or simply referred to as RAN. It should be understood that this document does not limit the specific type of access network device.

[0124] The CN part may include but is not limited to the following network functions (NF): user plane function (UPF) 130, network exposure function (NEF) 131, network function repository function (NRF) 132, policy control function (PCF) 133, unified data management function (UDM) 134, unified data repository function (UDR) 135, application function (AF) 136, authentication server function (AUSF) 137, access and mobility management function (AMF) 138, and session management function (SMF) 139.

[0125] The data network DN 140, also called a packet data network (PDN), is typically a network outside the operator's network, such as a third-party network.

[0126] The following is a brief description of the NF functions included in CN.

[0127] 1. UPF 130 is a gateway provided by the operator, serving as the gateway for communication between the operator network and DN 140. UPF 130 network functions include packet routing and transmission, packet detection, service usage reporting, Quality of Service (QoS) processing, uplink packet detection, downlink packet storage, and other user-plane-related functions.

[0128] 2. NEF 131 is a control plane function provided by the operator. It mainly enables third parties to use the services provided by the network, supports the network to open its capabilities, event and data analysis, provide PLMN security configuration information from external applications, and convert interactive information within and outside the PLMN.

[0129] 3. NRF 132 is a control plane function provided by the operator, which can be used to maintain real-time information of network functions and services in the network.

[0130] 4. PCF 133 is the control plane function provided by the operator. It mainly supports providing a unified policy framework to control network behavior, provides policy rules to the control layer network function, and is responsible for obtaining user subscription information related to policy decisions.

[0131] 5. UDM 134 is a control plane function provided by the operator and is responsible for storing information such as the subscriber permanent identifier (SUPI), the generic public subscription identifier (GPSI), and credentials of subscribers in the operator's network.

[0132] 6. UDR 135 is a control plane function provided by the operator. It provides the UDM with the function of saving and retrieving subscription data, the PCF with the function of saving and retrieving policy data, and the user's NF group ID information.

[0133] 7. AF 136 is a control plane function provided by the operator. It mainly provides corresponding services by interacting with other NFs in the PLMN, such as providing roaming UE with visitor network selection information, guiding the routing of data flows, and accessing NEF 131.

[0134] 8. AUSF 137 is a control plane function provided by the operator, and is usually used for level 1 authentication, i.e., authentication between the terminal device 110 (subscriber) and the operator's network.

[0135] 9. AMF 138 is a control plane network function provided by the operator network, responsible for access control and mobility management of the terminal device 110 accessing the operator network, such as mobility status management, allocation of user temporary identity, authentication and authorization of users, etc.

[0136] 10. SMF 139 is a control plane network function provided by the operator network. It is responsible for managing the protocol data unit (PDU) sessions of the terminal device 110 (including session establishment, modification, and release). This function is used for the selection and reselection of user plane function network elements, the allocation of Internet Protocol (IP) addresses for the terminal device, and quality of service (QoS) control. A PDU session is a channel for transmitting PDUs. The terminal device exchanges PDUs with the DN 140 through a PDU session. The SMF network function 139 is responsible for establishing, maintaining, and deleting PDU sessions. The SMF network function 139 includes session management (such as session establishment, modification, and release, including tunnel maintenance between the user plane function (UPF) 130 and the (R)AN 120), selection and control of the UPF network function 130, service and session continuity (SSC) mode selection, roaming, and other session-related functions.

[0137] It is understood that the above network elements or functions can be physical entities in hardware devices, software instances running on dedicated hardware, or virtualized functions instantiated on a shared platform (e.g., a cloud platform). Simply put, an NF can be implemented by hardware or software.

[0138] In Figure 1, Nnef, Nnrf, Npcf, Nudm, Nudr, Naf, Nausf, Namf, Nsmf, N1, N2, N3, N4, and N6 are interface serial numbers. For example, the meaning of the above interface serial numbers can be found in the meaning defined in the 3GPP standard protocol, and this application does not limit the meaning of the above interface serial numbers. It should be noted that the interface name between the various network functions in Figure 1 is only an example. In a specific implementation, the interface name of the system architecture may also be other names, which is not limited by this application. In addition, the name of the message (or signaling) transmitted between the above-mentioned network elements is only an example and does not constitute any limitation on the function of the message itself.

[0139] It should be noted that in the architecture shown in Figure 1, the interface between the (R)AN and CN can also be called the NG interface (not shown in the figure), and the (R)AN and CN are connected via the NG interface. The NG interface can include the NG-C interface and the NG-U interface. The NG-C interface is a control plane interface, connecting the (R)AN and AMF, and is used to transmit control plane data; the NG-U interface is a user plane interface, connecting the (R)AN and UPF, and is used to transmit user plane data.

[0140] It should be understood that the above network architecture 100 is only described from the perspective of a service-based architecture. In this service-based architecture, the PLMN can combine some or all network functions in an orderly manner according to specific scenario requirements, realizing customized network capabilities and services, thereby deploying dedicated networks for different services, that is, realizing 5G network slicing. Network slicing technology enables operators to respond to customer needs more flexibly and quickly, and supports flexible allocation of network resources.

[0141] For ease of explanation, in the embodiments of the present application, network functions (such as NEF 131...SMF 139) are collectively referred to as NFs. That is, the NFs described later in the embodiments of the present application can be replaced by any network function. In addition, in the embodiments of the present application, the session management function SMF 139 is referred to as SMF, and the terminal device 110 is referred to as UE. That is, the SMFs described later in the embodiments of the present application can be replaced by session management functions, and the UE can be replaced by a terminal device. Figure 1 only schematically illustrates some network functions, and the NFs described later are not limited to the network functions shown in Figure 1.

[0142] It should be understood that the AMF, SMF, UPF, NEF, AUSF, NRF, PCF, and UDM shown in Figure 1 can be understood as network elements used to implement different functions in the core network, for example, they can be combined into network slices as needed. These core network network elements can be independent devices or integrated into the same device to implement different functions. This application does not limit the specific form of the above network elements.

[0143] It should also be understood that the above naming is defined only to facilitate the distinction between different functions and should not constitute any limitation on this application. This application does not exclude the possibility of adopting other naming in 5G networks and other future networks. For example, in future communication networks, some or all of the above network elements may continue to use 5G terminology, or may adopt other names.

[0144] In order to facilitate understanding of the technical solution of this application, the following first briefly describes several technical names involved in this application.

[0145] 1. Internet of Things (IoT)

[0146] Through information sensing devices such as radio frequency identification, infrared sensors, global positioning systems, laser scanners, and according to agreed protocols, any object can be connected to the Internet for information exchange and communication to achieve intelligent identification, positioning, tracking, monitoring and management. The IoT network architecture can include IoT terminals (also called IoT devices or IoT terminal devices), readers (or readers and writers), and servers.

[0147] The IoT architecture can be a Passive IoT (P-IoT) or Ambient IoT (A-IoT), hereinafter collectively referred to as the Ambient IoT, but not limited to the name. Some network nodes can be passive, semi-passive, or active. Passive and semi-passive terminals can communicate via reflected carrier waves, meaning they rely on an external carrier source. Passive terminals may or may not have energy storage capacitors. If they do not have energy storage capacitors, they must obtain energy from the external environment, such as radio frequency energy, for communication. Semi-passive terminals may have power amplifiers, thereby increasing their communication range compared to passive terminals. Semi-passive terminals typically have energy storage capacitors that store energy from the environment, such as solar energy or radio frequency energy. Active devices can actively generate carrier waves (or have carrier recovery capabilities), eliminating the need for external carrier sources for communication and thus possessing active communication capabilities. At the same time, active terminals are also backward compatible with the communication mechanisms of passive or semi-passive terminals. This means they can be triggered by external stimuli to initiate a random access procedure and send identification information. In one possible implementation, they can also include energy storage capacitors, which can be powered by solar energy, radio frequency, wind energy, hydropower, or tidal energy, with no restrictions on the energy source. These nodes do not have their own power sources or rely on batteries, but instead draw energy from the environment to support data perception, transmission, and distributed computing. The nodes can also store the energy they harvest.

[0148] Among them, the Internet of Things terminal can be an environment-aware Internet of Things device (AIoT device), and the environment-aware Internet of Things device can be in the form of an environment-aware terminal (for example, a tag form) or any other terminal form. This application does not impose any restrictions on this.

[0149] 2. Reader or reader / writer

[0150] The reader can be understood as a device that communicates with the IoT terminal. The reader can be an access network device, such as a base station, a pole station, a micro base station, a macro station, etc.; or, the reader can be a terminal device, such as a mobile phone, an IoT device, a handheld reader, etc., and this application does not limit this. The reader interacts with the environment-aware IoT device (AIoT device) through a radio frequency signal or a wireless signal. It should be understood that this application does not limit the name of the reader. The reader can also be named a reader or other name, that is, it can be understood that the names of the reader and the reader are interchangeable. The reader here has the functions involved in the reader in this application, such as the reader having the function of performing the operations described in this application on the terminal (such as the environment-aware IoT device) (such as obtaining environment-aware IoT device information, inventory operation, read operation, write operation or, failure operation or message interaction operation with the environment-aware IoT device, etc.), having the function of obtaining billing-related information and / or billing information, sending billing information to CHF, etc. In one possible implementation, the reader may send an instruction from a server or an application function to the context-aware IoT device, or the reader may send a message from the context-aware IoT device to the server or the application function. In one possible implementation, the reader may obtain information stored in a specified context-aware IoT device according to the instruction issued by the server. For example, if it is an inventory operation (or it may be called an inventory operation), the reader obtains the identification information of the context-aware IoT device; the identification information may be a unique identifier of the context-aware IoT device, or it may be a temporary identifier of the context-aware IoT device. For example, if it is a read operation, the reader reads the data in the storage area of ​​the context-aware IoT device. Optionally, in some cases where it is necessary to rewrite the information stored in the context-aware IoT device, the reader may also have a write function. For example, if it is a write operation, the reader writes the data into the storage area of ​​the context-aware IoT device. In addition, the reader may also perform an invalidation operation on the context-aware IoT device. After the invalidation operation is executed, the environment-aware IoT device becomes invalid and cannot be used to perform operations such as obtaining environment-aware IoT device information, inventory operations, read operations, message interaction operations with the environment-aware IoT device, or write operations. In one possible implementation, the invalidation of the environment-aware IoT device and the inability to obtain environment-aware IoT device information can be understood as the reader being unable to obtain the environment-aware IoT device information of the invalid environment-aware IoT device after the environment-aware IoT device fails. In another possible implementation, the invalidation of the environment-aware IoT device and the inability to message interaction operations with the environment-aware IoT device can be understood as the reader being unable to exchange messages with the invalid environment-aware IoT device after the environment-aware IoT device fails.In this application, the reader can be a terminal device, or an access network device, a pole station, an eNodeB, a gNodeB, an integrated access and backhaul (IAB) node, etc. This application does not limit the form of the reader.

[0151] 3. Equipment identification

[0152] The IoT terminals belong to third-party companies. The third-party companies reach a service agreement (or sign a contract) with the operators, and the operators manage the IoT terminals of the third-party companies.

[0153] The device identifier of an IoT terminal includes one or more of the following: the identifier of the operator network contracted with the third-party user to which the IoT device belongs (Home Network identifier), the identifier of the third-party user to which the IoT device belongs (Owner ID / Enterprise ID), and the serial number / identifier of the IoT terminal assigned by the operator to the third-party enterprise (Owner) (Instance ID, which is unique for each operator and each third-party enterprise of an operator).

[0154] Optionally, the device identifier of the IoT terminal also includes an identifier defined by a third-party enterprise (3rd party defined ID), which may be an identifier assigned by a third-party user, may be globally unique, or may be repeated.

[0155] 4. Operation requester (also known as business requester or third party)

[0156] The operation requester can be a server or an application function. In the embodiment of the present application, the operation requester can be understood as a device that sends an operation instruction, for example, the operation requester can be a server (server) or an A-IoT server or an application function (AF) or other device that sends an operation instruction. The operation requester can correspond to a certain type of user, and this type of user can include enterprises, tenants, third parties or companies, without restriction. Among them, the operation requester corresponding to a certain type of user can be understood as the operation requester belonging to this type of user and being managed by this type of user. For the sake of convenience of description, the embodiment of the present application mainly uses AF as the operation requester for illustrative explanation.

[0157] The AF can interact with the IoT terminal management function through core network functions (such as NEF). The core network functions can be used to expose the services and capabilities of the 3rd Generation Partnership Project (3GPP) network functions to the AF, and also allow the AF to provide information to the 3GPP network functions. For ease of description, the embodiments of this application are mainly introduced using the NEF as an example.

[0158] 5. IoT management function

[0159] The IoT management function (or passive IoT device management function), for example, the IoT management function may be the passive IoT device management function (tag management function, TMF) of FIG1 , or the IoT management function may be the ambient IoT management function (AIoTMF), and the IoT management function is used to execute the transmission of business data of the terminal device 101 or to execute IoT terminal (or passive IoT device) management. For example, when the terminal device is a passive IoT device, the transmission and / or management of business data of the passive IoT device may be executed. This application does not limit the naming of the IoT terminal management function (or passive IoT device management function), which may be other names.

[0160] In this application, the IoT management function network element may be an AMF network element or a tag management function (TMF) network element or a network element jointly established by AMF and TMF, and this application does not limit this.

[0161] The following introduces the technical problems and technical solutions to be solved by this application.

[0162] For the IoT scenario of the entire supply chain, the IoT devices provided by upstream enterprises can be used by all or part of the downstream enterprises in the entire supply chain. Upstream enterprises can provide the IoT terminal device information they provide to the core network. The core network equipment deployed by operators does not belong to any one enterprise and can serve any enterprise.

[0163] In the use scenario of IoT, such as the problem described in the background technology, if the operation request of the downstream enterprise does not contain the identification information of the specific device (for example, if you want to operate the equipment in a certain area), how to carry out the operation authorization process is an urgent problem to be solved.

[0164] In addition, when the operator accessed by the downstream enterprise requesting to operate the equipment is different from the operator signed by the supplier enterprise, the downstream enterprise can no longer complete the operation authorization process within the operator network it has accessed.

[0165] In light of this, this application provides a communication method whereby core network equipment can query a supplier enterprise's whitelist based on supplier enterprise information provided by a downstream enterprise, thereby determining whether the downstream enterprise is permitted to operate the supplier enterprise's IoT device. Furthermore, a communication method is provided for situations where the downstream enterprise requesting device operation accesses a different operator than the supplier enterprise's contracted operator, designing a method for cross-network operation authorization.

[0166] It should be understood that the description of the specific scenarios in the embodiments of the present application is only an example. In addition to being applicable to the application scenarios described above, the methods provided in the embodiments of the present application are also applicable to application scenarios with similar problems.

[0167] In the description of the embodiments of the present application, unless otherwise specified, "a plurality of" or "a plurality of" means two or more. In addition, "at least one" can be replaced by "one or more".

[0168] The ordinal numbers "first" and "second" mentioned in the embodiments of this application are used to distinguish multiple objects and are not used to limit the size, content, order, timing, priority, or importance of the multiple objects. For example, the first indication information and the second indication information can be the same information or different information, and such names do not indicate differences in the content, size, application scenario, sender / receiver, priority, or importance of the two messages. In addition, the numbering of the steps in the various embodiments introduced in this application is only for distinguishing different steps and is not used to limit the order of the steps.

[0169] It should be understood that the names of all nodes and messages in this application are merely names set for the convenience of description in this application. The names in the actual network may be different. This application should not be understood as limiting the names of various nodes and messages. On the contrary, any name with the same or similar function as the node or message used in this application is regarded as a method or equivalent replacement of this application, and is within the scope of protection of this application. No further details will be given below.

[0170] In this application, "sending information to...(XX device)" can be understood as the destination of the information being the XX device, and may include directly or indirectly sending information to the XX device. "Receiving information from...(XX device)" or "receiving information from...(XX device)" can be understood as the source of the information being the XX device, and may include directly or indirectly receiving information from the XX device. The information may undergo necessary processing between the source and destination of the information, such as format changes, but the destination can understand the valid information from the source. Similar expressions in this application can be understood similarly and will not be repeated here.

[0171] The following describes in detail various communication methods provided in the embodiments of the present application with reference to the accompanying drawings.

[0172] For ease of understanding and explanation, the communication method of the embodiment of the present application is described below using a core network device as an example. However, this does not limit the execution subject of the communication method of the embodiment of the present application. For example, the method executed by the core network device may also be executed by a module of the core network device (such as a circuit, chip, or chip system), or may be implemented by a logical node, logical module, or software that can implement all or part of the functions of the terminal device.

[0173] Figure 2 shows a communication method 200 provided in the present application. The method 200 includes at least some of the steps shown in Figure 2. In the method 200, the core network can determine whether the downstream enterprise can operate the Internet of Things device of the supplier enterprise based on the information of the supplier enterprise provided by the downstream enterprise.

[0174] S201: A core network device receives information about a second service requester and information about a first service requester to which one or more IoT terminals belong.

[0175] Among them, the first service requester can be understood as: the supplier enterprise that supplies the one or more Internet of Things terminals, or the application function network element or server (called the first application function network element) in the operator network signed by the supplier enterprise, or the user who owns the one or more Internet of Things terminals, or the application function network element or server corresponding to the user. Among them, when the first service requester is an application function network element, it is called the first application function network element.

[0176] The second service requester can be understood as: a downstream enterprise (or supply chain enterprise) requesting to operate the one or more IoT terminals, or an application function network element or server in the operator network accessed by the downstream enterprise, or a user requesting to operate the one or more IoT terminals, or the application function network element or server corresponding to the user. When the second service requester is an application function network element, it is called a second application function network element (referred to as a second application function network element).

[0177] In a first implementation, the information of the first service requester includes an identifier of the first service requester. The identifier of the first service requester may be an identifier of a first application function network element, an identifier of a supplier enterprise, an identifier of a user owning one or more IoT terminals, an identifier of a community access gateway (CAG), an IP address, etc. It should be understood that any identifier that can represent the identity of the first service requester may be used as the identifier of the first service requester, and this application does not limit the identifier of the first service requester.

[0178] In a second implementation, the information of the first service requester includes information of the one or more IoT terminals, which may include identifiers of the one or more IoT terminals. Optionally, the identifiers of the one or more IoT terminals may be a device ID assigned by the second PLMN to the IoT terminal, or a globally unique identifier defined by a third party (3rd party defined ID).

[0179] Optionally, the information of the first service requester further includes an identifier of a first PLMN to which the first service requester subscribes.

[0180] Optionally, the information of the second service requester includes an identifier of the second service requester. The identifier of the second service requester may be an identifier of a second application function network element, an identifier of a supply chain enterprise, an identifier of a user requesting to operate the one or more IoT terminals, an identifier of a community access gateway (CAG), an IP address, etc. It should be understood that any identifier that can represent the identity of the second service requester may be used as the identifier of the second service requester, and this application does not limit the identifier of the second service requester.

[0181] Specifically, the above-mentioned core network device is a core network device in the first network, and the first network is the network signed by the first service requester. In addition, the network accessed by the second service requester is the second network. Among them, the first network can be a PLMN, a private network, a subnet, etc., and this application does not limit this; the identifier of the first network can be a PLMN ID, a network identification code (NID), a subnet identifier, etc., and this application does not limit this. Similarly, the second network can be a PLMN, a private network, a subnet, etc., and this application does not limit this; the identifier of the second network can be a PLMN ID, a network identification code (NID), a subnet identifier, etc., and this application does not limit this.

[0182] For the convenience of description, the method of the present application is described below by taking the first network as the first PLMN and the second network as the second PLMN as an example.

[0183] Optionally, the information of the first service requester further includes an identifier of a first PLMN to which the first service requester subscribes.

[0184] It should be understood that when the operator network (second PLMN) accessed by the second service requester is the same as the first PLMN, cross-network operation authorization is not required; when the second PLMN is different from the first PLMN, cross-network operation authorization is required. Optionally, the one or more IoT terminals may be IoT terminals within a region, so that the operator network accessed by the second service requester is determined based on the region where the one or more IoT terminals are located.

[0185] It should be understood that when the first PLMN and the second PLMN are different, the first PLMN should have a service agreement with the second PLMN, such as a roaming service agreement.

[0186] Specifically, the core network device may be a first IoT management function network element in the first PLMN, or a first data management network element in the first PLMN. Furthermore, the IoT management function network element in the second PLMN is referred to as a second IoT management function network element, and the data management network element in the second PLMN is referred to as a second data management network element. In other words, the first IoT management function network element and the first data management network element belong to the first PLMN, while the second IoT management function network element and the second data management network element belong to the second PLMN.

[0187] In this application, the IoT management function network element may be an AMF network element or a tag management function (TMF) network element or a network element jointly established by AMF and TMF, and this application does not limit this.

[0188] In one implementation, when the second PLMN is the same as the first PLMN, the first IoT management function network element and the second IoT management function network element are the same network element, and the first data management network element and the second data management network element are the same network element. In this case, the IoT management function network element receives the second service requester information and the first service requester information sent by the second service requester.

[0189] For example, the first IoT management function network element receives the first request information sent by the second service requester, and the first request information is used to request operation of the one or more IoT terminals of the first service requester. The first request information includes information of the second service requester and information of the first service requester.

[0190] Optionally, the first request information sent by the second service requesting direction to the first IoT management function network element also includes a first security key for subsequent security checks.

[0191] In another implementation, when the second PLMN is different from the first PLMN, the first IoT management function network element of the first PLMN receives the information of the second service requester and the information of the first service requester sent by the second IoT management function network element.

[0192] For example, the first Internet of Things management function network element receives the first request information sent by the second Internet of Things management function network element, and the first request information is used to request operation of the one or more Internet of Things terminals of the first service requester. The first request information includes information of the second service requester and information of the first service requester.

[0193] Specifically, the second service requester first sends a first request message to the second Internet of Things management function network element in the second PLMN; the second Internet of Things management function network element determines, based on the information of the first service requester in the first request message, that the first service requester has not signed a contract with the second PLMN to which the second Internet of Things management function network element belongs, determines the first PLMN based on the information of the first service requester, and forwards the first request message to the first Internet of Things management function network element in the first PLMN.

[0194] Optionally, the first request information sent by the second IoT management function network element to the first IoT management function network element also includes information of the second PLMN, which is used for subsequent authentication judgment.

[0195] Optionally, the first request information sent by the second IoT management function network element to the first IoT management function network element also includes a first security key for subsequent security checks.

[0196] In another implementation, when the second PLMN is different from the first PLMN, the first data management network element of the first PLMN receives the information of the second service requester and the information of the first service requester sent by the second Internet of Things management function network element.

[0197] For example, the first data management network element receives the second request information sent by the second IoT management function network element, where the second request information is used to request the contract information of the first service requester, and the second request information includes information of the second service requester and information of the first service requester.

[0198] Specifically, the second service requester first sends a first request message to the second Internet of Things management function network element in the second PLMN; the second Internet of Things management function network element determines, based on the information of the first service requester in the first request message, that the first service requester has not signed a contract with the second PLMN to which the second Internet of Things management function network element belongs, determines the first PLMN based on the information of the first service requester, and sends a second request message to the first data management network element in the first PLMN.

[0199] Optionally, the second request information sent by the second IoT management function network element to the first data management network element also includes information of the second PLMN, which is used for subsequent authentication judgment.

[0200] Optionally, the second request information sent by the second IoT management function network element to the first IoT management function network element also includes a first security key for subsequent security checks.

[0201] Generally speaking, information interaction between a service requester (such as an application function network element) and an IoT management function network element may pass through an NEF network element. For the sake of brevity, this application does not show it in the accompanying drawings.

[0202] S202: The core network device determines whether the second service requester has the authority to operate the one or more IoT terminals based on the information of the first service requester and the information of the second service requester.

[0203] In one implementation, the second PLMN is the same as the first PLMN, and the first request information sent by the second service requester is received by the first IoT management function network element.

[0204] In this case, the first IoT management function network element first determines the contract information of the first service requester based on the information of the first service requester in the first request message.

[0205] Specifically, the first IoT management function network element sends a second request message to the first data management network element. The second request message is used to request the contract information of the first service requester. The second request message includes information of the second service requester and information of the first service requester.

[0206] Optionally, after receiving the second request information, the first data management network element determines whether the second service requester has the authority to operate the one or more IoT terminals according to the second request information and the contract information of the first service requester.

[0207] Optionally, the second request information further includes a first security key. The first data management network element determines, based on the second request information and the contract information of the first service requester, whether the second service requester has permission to operate the one or more IoT terminals, including: the first data management network element determines whether the first security key satisfies the contract information of the first service requester.

[0208] The first security key satisfies the contract information of the first service requester, which can be understood as: in the contract information of the first service requester, the security key corresponding to the first service requester is the first security key.

[0209] Optionally, when the first data management network element receives the second request information, it sends the contract information of the first service requester to the first Internet of Things management function network element, so that the first Internet of Things management function network element determines whether the second service requester has the authority to operate the above-mentioned one or more Internet of Things terminals based on the first request information and the contract information of the first service requester.

[0210] Optionally, after receiving the second request information, the first data management network element may directly determine whether the second service requester has permission to operate the one or more IoT terminals based on the first request information and the contract information of the first service requester. Determine whether the second service requester has permission to operate the one or more IoT terminals based on the first request information and the contract information of the first service requester.

[0211] Optionally, the first request information also includes a first security key. The first IoT management function network element determines whether the second service requester has the authority to operate the one or more IoT terminals based on the first request information and the contract information of the first service requester, including: the first IoT management function network element determines whether the first security key satisfies the contract information of the first service requester, or the first IoT management function network element / first data management network element determines whether the first security key provided by the second service requester is located in the contract information of the first service requester, such as the part of the first service requester's contract related to the second service requester.

[0212] In another implementation manner, the second PLMN is different from the first PLMN, and the first Internet of Things Management Function Network Element of the first PLMN receives the first request information sent by the second Internet of Things Management Function Network Element.

[0213] In this case, the first IoT management function network element first determines the contract information of the first service requester based on the information of the first service requester in the first request message.

[0214] Specifically, the first IoT management function network element sends a second request message to the first data management network element. The second request message is used to request the contract information of the first service requester. The second request message includes information of the second service requester and information of the first service requester.

[0215] Optionally, when the first data management network element receives the second request information, it sends the contract information of the first service requester to the first Internet of Things management function network element, so that the first Internet of Things management function network element determines whether the second service requester has the authority to operate the above-mentioned one or more Internet of Things terminals based on the first request information and the contract information of the first service requester.

[0216] Optionally, the first request information further includes a first security key. The first IoT management function network element determines, based on the first request information and the contract information of the first service requester, whether the second service requester has permission to operate the one or more IoT terminals, including: the first IoT management function network element determines whether the first security key satisfies the contract information of the first service requester.

[0217] Optionally, after receiving the second request information, the first data management network element determines whether the second service requester has the authority to operate the one or more IoT terminals according to the second request information and the contract information of the first service requester.

[0218] Optionally, the second request information further includes a first security key. The first data management network element determines, based on the second request information and the contract information of the first service requester, whether the second service requester has permission to operate the one or more IoT terminals, including: the first data management network element determines whether the first security key satisfies the contract information of the first service requester.

[0219] In another implementation, when the second PLMN is different from the first PLMN, the first data management network element of the first PLMN receives the second request information sent by the second Internet of Things management function network element.

[0220] In this case, the first data management network element determines whether the second service requester has the authority to operate the one or more IoT terminals according to the second request information and the contract information of the first service requester.

[0221] Optionally, the second request information further includes a first security key. The first data management network element determines, based on the second request information and the contract information of the first service requester, whether the second service requester has permission to operate the one or more IoT terminals, including: the first data management network element determines whether the first security key satisfies the contract information of the first service requester.

[0222] It should be understood that the above-mentioned first data management network element can provide contract information to the first Internet of Things management function network element, or directly determine whether the second service requester has the authority to operate the above-mentioned one or more Internet of Things terminals, because the first data network element stores the contract information sent by the first service requester in the first data management network element.

[0223] Exemplarily, Table 1 is a storage format for contract information, in which the first service requester sends the contract information of the first service requester to the first data management network element. Optionally, the contract information of the first service requester includes a retrieval keyword key (for example, the identifier AF1 ID of the first service requester), identifiers of other service requesters that can operate the IoT terminal of the first service requester (such as the identifier of the supply chain AFs), networks accessed by other service requesters (Supported PLMN), security keys (Security key), identifiers of IoT terminals that can be operated by other service requesters (Supported device ID (range)), supported operation types (Supported operation), identifiers of the networks contracted by the first service requester, and geographical locations where IoT terminals can be operated (Permitted location). It should be understood that Table 1 is only an example of the storage format of contract information, and the contract information can also be in any other form, such as a collection, and this application does not limit this.

[0224] For example, using AF1 ID as the search keyword, AF2 and AF3 of the IoT terminal that supports AF1 operation can be determined. Taking AF2 as an example, the contract information also includes the network PLMN2 that supports AF2 operation of the IoT terminal, the device ID that supports AF2 operation (for example, the ID defined for the local network, the identifier defined by the network for the device of a third-party enterprise, etc.), the type of AF2 operation supported is inventory, the security key Key1 of the AF2 operation device, the location Location1 of the device that supports AF2 operation, etc.

[0225] Table 1

[0226] It should be understood that the parameters in the above-mentioned contract information (such as Supply chain AFs, Supported PLMN, Supported device ID (range), Supported operation, Permitted location, etc.) are all optional parameters. It should be understood that when one of the parameters is not included in the contract information, it can be regarded as not restricting the parameter.

[0227] For example, using AF1 ID as the search keyword, when the contract information shown in Table 1 does not include the item "Supply chain AFs", it means that AF1's IoT terminal can be operated by other service requesters, without limiting the specific service requester.

[0228] For another example, using AF1 ID as the search keyword, when the subscription information shown in Table 1 does not include the Supported PLMN item, it means that the IoT terminal of AF1 can be requested to operate by other PLMNs without limiting the specific PLMN information.

[0229] For another example, using AF1 ID as the search keyword, when the contract information shown in Table 1 does not include the item Supported device ID (range), it means that all IoT terminals of AF1 can be operated.

[0230] For another example, using AF1 ID as the search keyword, when the contract information shown in Table 1 does not include the item "Supported operation", it means that AF1's IoT terminal supports all operation types.

[0231] For another example, using AF1 ID as the search keyword, when the contract information shown in Table 1 does not include the item "Permitted location", it means that AF1's IoT terminal can be operated at any location.

[0232] Optionally, the contract information may also include parameters such as supported operation time and supported service requester types. It should be understood that when the contract information does not include supported operation time, it means that the AF1 IoT terminal can be operated at any time; when the contract information does not include supported service requester types, it means that the AF1 IoT terminal can be operated by all types of service requesters.

[0233] It should be understood that when the contract information does not contain multiple parameters, it can be understood that there are no restrictions on these parameters. For example, the contract information shown in Table 2 does not include parameters such as Supply chain AFs and Permitted location, indicating that IoT terminals within the supported device range of AF1 can be inventoried by other service requesters at any location through PLMN2.

[0234] Table 2

[0235] In some cases, an IoT terminal can be opened to other service requesters for operation. In this case, if the Supply Chain Afs parameter is used to indicate the supported service requesters, the contract information needs to include the identifiers of a large number of service requesters. Therefore, it is possible to directly indicate in the contract information that the IoT terminal of the first service requester can be operated by other service requesters.

[0236] For example, using AF1 ID as the search keyword, when the contract information is as shown in Table 3, if the supply chain AFs column is marked as NULL, it means that the IoT terminal of AF1 cannot be operated by any service requester other than AF1; if the supply chain AFs column is marked as ALL, it means that the IoT terminal of AF1 can be operated by other service requesters.

[0237] Table 3

[0238] The supply chain AFs in Table 3 above can also be replaced by Allowed other AF to indicate whether the device of the AF / owner can be operated by other business requesters. If the Allowed other AF column is marked as All allowed, it can be regarded as that the IoT terminal of AF1 can be operated by other business requesters; if the Allowed other AF column is marked as partially allowed, it means that the IoT terminal of AF1 can be operated by some business requesters, and it can be further determined by querying the Supply chain AFs which business requesters can be operated; if the Allowed other AF column is marked as not allowed, it can be regarded as that the IoT terminal of AF1 cannot be operated by any business requester other than AF1.

[0239] It should be understood that the names in all the above contract information are examples and the actual names are not limited. For example, allowed other AF can be replaced with permitted AF / enterprise, etc.

[0240] Exemplarily, Table 4 is another storage format for contract information, in which the first service requester sends the contract information of one or more IoT terminals to the first data management network element. Optionally, the contract information of the one or more IoT terminals includes a search keyword key (for example, device ID), an identifier of the owner or supplier of the one or more IoT terminals, an identifier of other service requesters that can operate the IoT terminal (such as an identifier of the supply chain AFs), a network accessed by other service requesters (Supported PLMN), a security key, a supported operation type (Supported operation), an identifier of the network contracted by the first service requester, a geographical location where the IoT terminal can be operated (Permitted location), etc.

[0241] For example, using device1 ID as the search keyword, AF2 and AF3 that support operating device1 can be determined. Taking AF2 as an example, the contract information also includes the network PLMN2 that supports AF2 operating device1, the type of AF2 operation supported is inventory, the security key Key1 for AF2 operating device1, the location Location1 that supports AF2 operating device1, etc.

[0242] Table 4

[0243] It should be understood that, similar to the contract information of the first service requester, the parameters in the above contract information are all optional parameters. When a certain parameter is not included in the contract information, it can be regarded as not restricting the parameter.

[0244] Optionally, the contract information may also include parameters such as supported operation time and supported service requester types. In some cases, an IoT terminal may be open to operation by other service requesters. In this case, if the Supply Chain Afs parameter is used to indicate supported service requesters, the contract information will need to include the identifiers of a large number of service requesters. Therefore, it is possible to directly indicate in the contract information that one or more IoT terminals can be operated by other service requesters.

[0245] For example, using device1 ID as the search keyword, when the contract information is as shown in Table 5, if the supply chain AFs column is marked as NULL, it means that the IoT terminal identified by device1 ID cannot be operated by any service requester other than AF1; if the supply chain AFs column is marked as ALL, it means that the IoT terminal identified by device1 ID can be operated by other service requesters.

[0246] Table 5

[0247] The supply chain AFs in Table 5 above can also be replaced by Allowed other AF to indicate whether the device of the AF / owner can be operated by other business requesters. If the Allowed other AF column is marked as All allowed, it can be regarded that the IoT terminal identified by the device1 ID can be operated by other business requesters; if the Allowed other AF column is marked as partially allowed, it means that the IoT terminal identified by the device1 ID can be operated by some business requesters, and it can be further determined by querying the Supply chain AFs which business requesters can operate it; if the Allowed other AF column is marked as not allowed, it can be regarded that the IoT terminal identified by the device1 ID cannot be operated by any business requester except AF1.

[0248] It should be understood that the names in all the above contract information are examples and the actual names are not limited. For example, allowed other AF can be replaced with permitted AF / enterprise, etc.

[0249] It should be noted that, in the solution of this application, the first data management network element can be replaced by the authentication, authorization, and accounting AAA server corresponding to the first service requester. Optionally, the second IoT management function network element further selects the first data management network element or the AAA server corresponding to the first service requester based on the identifier of the first service requester.

[0250] FIG3 shows a communication method 300 provided in the present application. The method 300 includes at least some of the steps shown in FIG3 . Through the method 300 , cross-network operation authorization can be implemented.

[0251] S301, the core network device receives information of a second service requester and first identification information from a second IoT management function network element, wherein the first identification information includes at least one of the following identifications: information of the first service requester to which one or more IoT terminals belong, and information of the one or more IoT terminals.

[0252] For an introduction to the second service requester and the first service requester, reference may be made to method 200 .

[0253] Optionally, the information of the first service requester may be an identifier of the first service requester, the information of the second service requester may be an identifier of the second service requester, and the information of the one or more IoT terminals may be an identifier of the one or more IoT terminals. The identifier of the one or more IoT terminals may be a serial number / identifier assigned by the second PLMN to the IoT terminal, or a globally unique identifier defined by a third party (3rd party defined ID).

[0254] Specifically, the core network device is a core network device in a first PLMN, and the first PLMN is an operator network subscribed by the first service requester.

[0255] It should be noted that in this method 300, if the operator network (second PLMN) accessed by the second service requester is different from the first PLMN, cross-network operation authorization is required. Optionally, the one or more IoT terminals may be IoT terminals within a region, so that the operator network accessed by the second service requester is determined based on the region where the one or more IoT terminals are located.

[0256] Specifically, the core network device may be a first IoT management function network element in the first PLMN, or a first data management network element in the first PLMN. Furthermore, the IoT management function network element in the second PLMN is referred to as a second IoT management function network element, and the data management network element in the second PLMN is referred to as a second data management network element. In other words, the first IoT management function network element and the first data management network element belong to the first PLMN, while the second IoT management function network element and the second data management network element belong to the second PLMN.

[0257] In one implementation, a first IoT management function network element of a first PLMN receives information about a second service requester and first identification information sent by a second IoT management function network element.

[0258] For example, the first Internet of Things management function network element receives the first request information sent by the second Internet of Things management function network element, and the first request information is used to request the operation of the one or more Internet of Things terminals of the first service requester. The first request information includes the information of the second service requester and the first identification information.

[0259] Specifically, the second service requester first sends a first request message to the second Internet of Things management function network element in the second PLMN; the second Internet of Things management function network element determines, based on the information of the first service requester in the first request message, that the first service requester has not signed a contract with the second PLMN to which the second Internet of Things management function network element belongs, determines the first PLMN based on the information of the first service requester, and forwards the first request message to the first Internet of Things management function network element in the first PLMN.

[0260] Optionally, the first request information sent by the second IoT management function network element to the first IoT management function network element also includes information of the second PLMN, which is used for subsequent authentication judgment.

[0261] Optionally, the first request information sent by the second IoT management function network element to the first IoT management function network element also includes a first security key for subsequent security checks.

[0262] In another implementation manner, the first data management network element of the first PLMN receives the information of the second service requester and the first identification information sent by the second Internet of Things management function network element.

[0263] For example, the first data management network element receives second request information sent by the second IoT management function network element, where the second request information is used to request the contract information of the first service requester, and the second request information includes information of the second service requester and first identification information.

[0264] Specifically, the second service requester first sends a first request message to the second Internet of Things management function network element in the second PLMN; the second Internet of Things management function network element determines, based on the information of the first service requester in the first request message, that the first service requester has not signed a contract with the second PLMN to which the second Internet of Things management function network element belongs, determines the first PLMN based on the information of the first service requester, and sends a second request message to the first data management network element in the first PLMN.

[0265] Optionally, the second request information sent by the second IoT management function network element to the first data management network element also includes information of the second PLMN, which is used for subsequent authentication judgment.

[0266] Optionally, the second request information sent by the second IoT management function network element to the first IoT management function network element also includes a first security key for subsequent security checks.

[0267] Generally speaking, information interaction between a service requester (such as an application function network element) and an IoT management function network element may pass through an NEF network element. For the sake of brevity, this application does not show it in the accompanying drawings.

[0268] S303: The core network device determines whether the second service requester has the authority to operate the one or more IoT terminals based on the information of the first service requester and the first identification information.

[0269] If the first IoT management function network element of the first PLMN receives the first request information sent by the second IoT management function network element in S301, in this case, the first IoT management function network element first determines the subscription information corresponding to the first identification information in the first request information.

[0270] In one implementation, the first identification information includes information of the first service requester, and the first IoT management function network element first determines the contract information of the first service requester based on the information of the first service requester in the first request message.

[0271] Specifically, the first IoT management function network element sends a second request message to the first data management network element. The second request message is used to request the contract information of the first service requester. The second request message includes information of the second service requester and first identification information.

[0272] Optionally, when the first data management network element receives the second request information, it sends the contract information of the first service requester to the first Internet of Things management function network element, so that the first Internet of Things management function network element determines whether the second service requester has the authority to operate the above-mentioned one or more Internet of Things terminals based on the first request information and the contract information of the first service requester.

[0273] Optionally, the first request information further includes a first security key. The first IoT management function network element determines, based on the first request information and the contract information of the first service requester, whether the second service requester has permission to operate the one or more IoT terminals, including: the first IoT management function network element determines whether the first security key satisfies the contract information of the first service requester.

[0274] Optionally, after receiving the second request information, the first data management network element determines whether the second service requester has the authority to operate the one or more IoT terminals according to the second request information and the contract information of the first service requester.

[0275] Optionally, the second request information further includes a first security key. The first data management network element determines, based on the second request information and the contract information of the first service requester, whether the second service requester has permission to operate the one or more IoT terminals, including: the first data management network element determines whether the first security key satisfies the contract information of the first service requester.

[0276] In another implementation, the first identification information includes information of one or more IoT terminals, and the first IoT management function network element first determines the contract information of one or more IoT terminals based on the information of one or more IoT terminals in the first request message.

[0277] Specifically, the first IoT management function network element sends a second request message to the first data management network element, where the second request message is used to request the contract information of the one or more IoT terminals. The second request message includes information of the second service requester and the first identification information.

[0278] Optionally, when the first data management network element receives the second request information, it sends the contract information of one or more Internet of Things terminals to the first Internet of Things management function network element, so that the first Internet of Things management function network element determines whether the second service requester has the authority to operate the above-mentioned one or more Internet of Things terminals based on the first request information and the contract information of one or more Internet of Things terminals.

[0279] Optionally, the first request information further includes a first security key. The first IoT management function network element determines, based on the first request information and the contract information of the one or more IoT terminals, whether the second service requester has permission to operate the one or more IoT terminals, including: the first IoT management function network element determines whether the first security key satisfies the contract information of the one or more IoT terminals.

[0280] Optionally, after receiving the second request information, the first data management network element determines whether the second service requester has the authority to operate the one or more IoT terminals based on the second request information and the contract information of the one or more IoT terminals.

[0281] Optionally, the second request information further includes a first security key. The first data management network element determines, based on the second request information and contract information of the one or more IoT terminals, whether the second service requester has permission to operate the one or more IoT terminals, including: the first data management network element determines whether the first security key satisfies the contract information of the one or more IoT terminals.

[0282] If in S301, the first data management network element of the first PLMN receives the second request information sent by the second Internet of Things management function network element.

[0283] In one implementation, the first data management network element determines whether the second service requester has the authority to operate the one or more IoT terminals based on the second request information and the contract information of the first service requester.

[0284] Optionally, the second request information further includes a first security key. The first data management network element determines, based on the second request information and the contract information of the first service requester, whether the second service requester has permission to operate the one or more IoT terminals, including: the first data management network element determines whether the first security key satisfies the contract information of the first service requester.

[0285] In another implementation, the first data management network element determines whether the second service requester has the authority to operate the one or more IoT terminals based on the second request information and the contract information of the one or more IoT terminals.

[0286] Optionally, the second request information further includes a first security key. The first data management network element determines, based on the second request information and contract information of the one or more IoT terminals, whether the second service requester has permission to operate the one or more IoT terminals, including: the first data management network element determines whether the first security key satisfies the contract information of the first service requester.

[0287] It should be understood that the above-mentioned first data management network element can provide contract information to the first Internet of Things management function network element, or directly determine whether the second service requester has the authority to operate the above-mentioned one or more Internet of Things terminals, because the first data network element stores the contract information sent by the first service requester in the first data management network element.

[0288] For example, the storage format of the contract information may refer to Tables 1 to 3 and the description of method 200.

[0289] FIG4 shows a communication method 400 provided by the present application. The method 400 includes at least some of the steps shown in FIG4 . The method 400 is combined with the method 200 and further describes the method of the present application by taking the core network including the IoT management function network element (AMF as an example) and the UDM network element, the first service requester being AF1, and the second service requester being AF2 as an example. It should be understood that the method 400 is a specific implementation of the method 200, and its concepts and terminology can be used. The method 400 only considers the scenario of non-cross-network operation authorization. It should be understood that in the method 400, AF2 sends the identifier of AF1 to the AMF, that is, the operation authorization of the IoT device is performed using the identifier corresponding to the enterprise. Alternatively, AF2 can also send the identifier of the IoT terminal to the AMF and perform the operation authorization of the IoT device using the identifier of the IoT terminal. In this case, the identifier of AF1 in the method 400 is replaced with the identifier of the IoT terminal, and the contract information of AF1 is replaced with the contract information of the IoT terminal, which corresponds to the solution of performing operation authorization of the IoT device using the identifier of the IoT terminal.

[0290] S401, AF2 sends a service request (service request, an example of the first request information) to AMF. The service request is used to request operation of one or more IoT terminals of the provider corresponding to AF1. The service request includes the identifier of AF1 (owner AF) and the identifier of AF2.

[0291] AF2 accesses the second PLMN, and AF1 subscribes to the first PLMN. It should be noted that the first PLMN and the second PLMN are the same network, collectively referred to as PLMN, which includes NE and UDM.

[0292] Optionally, the service request further includes spatial location information to be operated, such as latitude and longitude information, coordinate value information, cell information (cell ID), tracking area information (tracking area ID), etc.

[0293] Optionally, the service request also includes identification information of the Internet of Things terminal. Optionally, the identification information can be a range of IDs, such as the identification information can include the identifications of multiple Internet of Things terminals (such as forming an identification list), or can be a list consisting of partial identifications of multiple Internet of Things terminals.

[0294] Optionally, the service request may include a security key (an example of a first security key) for subsequent security checks.

[0295] S402: AMF requests UDM to obtain AF1's contract information based on the AF1 identifier in the service request.

[0296] Optionally, AMF2 determines the first PLMN to which AF1 has subscribed based on AF1's identifier, and then requests UDM to obtain AF1's subscription information.

[0297] One method of determining the UDM is that the AMF sends the identification information of AF1 to the NRF to request the instance information of the UDM. It is understandable that the UDM needs to provide the corresponding AF information to the NRF in advance, such as in the NF registration or NF update process.

[0298] Optionally, UDM may send the contract information of AF1 to AMF, and then AMF executes step S403.

[0299] Exemplarily, the format of the contract information stored in the UDM is shown in Table 6.

[0300] Table 6

[0301] It should be understood that by searching using the owner ID as a keyword, one can query the supply chain enterprises corresponding to that owner ID, information about the devices that can be operated, supported operation types, corresponding security information, supported operation areas, etc. For example, by searching using the identifier AF1, one can determine that AF2 is the supply chain enterprise corresponding to AF1, meaning that AF2 can use the IoT terminals supplied by AF1.

[0302] It should be understood that the contract information is sent in advance by AF1 to UDM and stored in UDM for subsequent authentication.

[0303] Optionally, AF1 can include a security key in the contract information to verify the authenticity of subsequent service requests sent by downstream AFs. This security key can be at the owner AF level or the supply chain AF level.

[0304] After AMF requests UDM to obtain the contract information of AF1, UDM can send the contract information to AMF and AMF can perform authentication (i.e., execute S403 (option 1)), or UDM can directly perform authentication (i.e., execute S403 (option 2)).

[0305] S403 (option 1), AMF receives the contract information of AF1 sent by UDM, and determines whether AF2 can operate AF1's IoT terminal based on the contract information of AF1 and the identifier of AF2.

[0306] Optionally, if the service request includes the spatial location information of the IoT terminal, AMF can also determine whether AF2 can operate AF1's IoT terminal at the corresponding location.

[0307] Optionally, if the service request includes the ID range of the IoT terminal, AMF can also determine whether AF2 can operate the IoT terminal corresponding to the ID range.

[0308] S403 (option 2): The UDM retrieves AF1's contract information based on AF1's identifier and determines whether AF2 can operate AF1's IoT terminal based on AF1's contract information and AF2's identifier. AF2's identifier may also be sent by the AMF to the UDM.

[0309] Optionally, if the service request includes spatial location information of the IoT terminal, the UDM may also determine whether AF2 can operate AF1's IoT terminal at the corresponding location.

[0310] Optionally, if the service request includes an ID range of IoT terminals, UDM can also determine whether AF2 can operate the IoT terminals corresponding to the ID range.

[0311] S404: When the AMF or UDM determines that AF2 can operate the IoT terminal of AF1, it generates mask information MASK, which includes the identifier of AF1 and the identifier of the IoT terminal, and sends the generated mask information to the IoT terminal, so that the IoT terminal that meets the mask can access the network.

[0312] S405, AMF receives the ID of the IoT terminal that successfully accesses the network and performs ID validation to determine whether the received ID belongs to AF1.

[0313] Optionally, ID verification is also used to determine whether the AF requesting the operation (i.e., AF2) is authorized to obtain the information of the IoT terminal. In this case, the IoT terminal's contract information can be queried to determine whether the IoT terminal can be operated by AF2; or the IoT terminal's validation policy can be queried to indicate whether the IoT terminal can be accessed by any service requester or only by some service requesters.

[0314] It should be understood that the verification policy may indicate that other service requesters are supported to obtain IoT terminal information, or that other service requesters are not supported to obtain IoT terminal information, or that only some service requesters are supported to obtain IoT terminal information. The information of these service requesters can be queried in the IoT terminal's contract information or stored in the credential holder.

[0315] Optionally, the credential holder may be a core network element, such as UDM, UDR, PCF, etc., or a third-party server, such as an authentication, authorization and accounting server (AAA server).

[0316] FIG5 illustrates a communication method 500 provided by the present application. This method 500 includes at least some of the steps shown in FIG5 . This method 500, in conjunction with method 300, further describes the method of the present application, taking as an example a core network including an AMF network element and a UDM network element, AF1 as the first service requester, and AF2 as the second service requester. It should be understood that this method 500 is a specific implementation of method 300, and its concepts and terminology can be used interchangeably. This method 500 only considers the scenario of cross-network operation authorization. It should be understood that in this method 500, AF2 sends AF1's identifier to the AMF, i.e., authorizing the operation of the IoT device using the identifier corresponding to the enterprise. Alternatively, AF2 can also send the identifier of the IoT terminal to the AMF and authorize the operation of the IoT device using the identifier of the IoT terminal. In this case, replacing AF1's identifier in method 500 with the identifier of the IoT terminal and replacing AF1's contract information with the contract information of the IoT terminal corresponds to a solution for authorizing the operation of the IoT device using the identifier of the IoT terminal.

[0317] S501, AF2 sends a service request (service request, an example of the first request information) to AMF2. The service request is used to request operation of one or more IoT terminals of the supplier corresponding to AF1. The service request includes the identifier of AF1 (owner AF) and the identifier of AF2.

[0318] AF2 accesses the second PLMN, and AF1 subscribes to the first PLMN. It should be noted that the first PLMN and the second PLMN are different networks. The first PLMN includes AMF1 and UDM1, and the second PLMN includes AMF2.

[0319] Optionally, the service request also includes an identifier of the first PLMN.

[0320] Optionally, the service request also includes spatial location information of the IoT terminal.

[0321] Optionally, the service request also includes identification information of the IoT terminal. Optionally, the identification information may be a range of IDs.

[0322] Optionally, the service request may include a security key (an example of a first security key) for subsequent security checks.

[0323] S502: AMF2 determines the first PLMN subscribed by AF1 based on the identifier of AF1 and the identifier of PLMN1.

[0324] After AMF2 determines the first PLMN, it can forward the service request to AMF1.

[0325] Specifically, AMF2 can discover AMF1 through the NRF of the first PLMN, or discover AMF1 by configuring the relationship between PLMN and AMF.

[0326] S503, AMF2 forwards the above service request to AMF1.

[0327] Optionally, AMF2 carries the identifier of the second PLMN in the service request.

[0328] S504, AMF1 requests UDM1 to obtain AF1's contract information.

[0329] Optionally, UDM1 can send AF1's contract information to AMF, and AMF executes step S505 (option 1).

[0330] Illustratively, the format of the contract information stored in UDM1 is shown in Table 7.

[0331] Table 7

[0332] It should be understood that by searching using the owner ID as a keyword, one can query the supply chain enterprises corresponding to that owner ID, the corresponding PLMN information of that supply chain enterprise, information about operable devices, supported operation types, etc. For example, by searching using the identifier AF1, one can determine that AF2 is the supply chain enterprise corresponding to AF1, meaning that AF2 can use the IoT terminals supplied by AF1.

[0333] It should be understood that the contract information is sent in advance by AF1 to UDM1 and stored in UDM for subsequent authentication.

[0334] Optionally, AF1 can include a security key in the contract information to verify the authenticity of subsequent service requests sent by downstream AFs. This security key can be at the owner AF level or the supply chain AF level.

[0335] After AMF1 requests UDM1 to obtain AF1's contract information, UDM1 can send the contract information to AMF1 and AMF1 can perform authentication (i.e., execute S505 (option 1)), or UDM1 can directly perform authentication (i.e., execute S505 (option 2)).

[0336] S505 (option 1), AMF1 receives the contract information of AF1 sent by UDM1, and determines whether AF2 can operate the IoT terminal of AF1 based on the contract information of AF1 and the identifier of AF2.

[0337] Optionally, if the service request includes the spatial location information of the IoT terminal, AMF1 can also determine whether AF2 can operate AF1's IoT terminal at the corresponding location.

[0338] Optionally, if the service request includes the ID range of the IoT terminal, AMF1 can also determine whether AF2 can operate the IoT terminal corresponding to the ID range.

[0339] Optionally, if the service request includes the identifier of the second PLMN, AMF1 can also determine whether AF2 can operate AF1's IoT terminal in the second PLMN.

[0340] S505 (option 2): UDM1 retrieves AF1's contract information based on AF1's identifier and determines whether AF2 can operate AF1's IoT terminal based on AF1's contract information and AF2's identifier. AF2's identifier may also be sent by the AMF to UDM1.

[0341] Optionally, if the service request includes spatial location information of the IoT terminal, UDM1 may also determine whether AF2 can operate AF1's IoT terminal at the corresponding location.

[0342] Optionally, if the service request includes an ID range of IoT terminals, UDM1 may also determine whether AF2 can operate the IoT terminals corresponding to the ID range.

[0343] Optionally, if the service request includes an identifier of the second PLMN, UDM1 may also determine whether AF2 can operate the IoT terminal of AF1 in the second PLMN.

[0344] S506: When AMF1 or UDM1 determines that AF2 can operate AF1's IoT terminal, it generates mask information MASK, which includes the identifier of AF1 and the identifier of the IoT terminal, and sends the generated mask information to AMF2. AMF uses the mask information to enable IoT terminals that meet the mask to access the network.

[0345] S507, AMF2 receives the ID of the IoT terminal that successfully accesses the network and performs ID validation to determine whether the received ID belongs to AF1.

[0346] Figure 6 shows a communication method 600 provided by the present application. The method 600 includes at least some of the steps shown in Figure 6. The method 600 is combined with the method 300, and takes the core network including the AMF network element and the UDM network element, the first service requester being AF1, and the second service requester being AF2 as an example to further describe the method of the present application. It should be understood that the method 600 is a specific implementation of the method 300, and its concepts and terms can be used. The method 600 only considers the scenario of cross-network operation authorization.

[0347] S601, AF2 sends a service request (service request, an example of the first request information) to AMF2. The service request is used to request operation of one or more IoT terminals of the supplier corresponding to AF1. The service request includes the identifiers of one or more IoT terminals and the identifier of AF2.

[0348] AF2 accesses the second PLMN, and AF1 subscribes to the first PLMN. It should be noted that the first PLMN and the second PLMN are different networks. The first PLMN includes AMF1 and UDM1, and the second PLMN includes AMF2.

[0349] The identifier of the one or more IoT terminals may be a serial number / identifier (device ID) assigned by the second PLMN and belonging to the IoT terminal, or a globally unique identifier (3rd party defined ID) defined by a third party enterprise.

[0350] Optionally, the service request also includes an identifier of the first PLMN.

[0351] Optionally, the service request also includes spatial location information of the IoT terminal.

[0352] Optionally, the identification information of the one or more IoT terminals may be a range of IDs, such as a range of device IDs or a range of 3rd party defined IDs.

[0353] Optionally, the service request may include a security key (an example of a first security key) for subsequent security checks.

[0354] S602, AMF2 determines the first PLMN subscribed by AF1 based on the identifiers of one or more IoT terminals.

[0355] After AMF2 determines the first PLMN, it can forward the service request to AMF1.

[0356] Optionally, when the first PLMN and the second PLMN are the same, that is, a scenario where cross-network authentication is not performed, reference may be made to method 400 .

[0357] Specifically, AMF2 can discover AMF1 through the NRF of the first PLMN, or discover AMF1 by configuring the relationship between PLMN and AMF.

[0358] S603, AMF2 forwards the above service request to AMF1.

[0359] Optionally, AMF2 carries the identifier of the second PLMN in the service request.

[0360] S604, AMF1 requests UDM1 to obtain the contract information of one or more IoT terminals.

[0361] Optionally, UDM1 can send the contract information of one or more IoT terminals to AMF, and AMF executes step S605 (option 1).

[0362] For example, the format of the contract information stored in UDM1 can refer to Table 1.

[0363] After AMF1 requests UDM1 to obtain the contract information of one or more IoT terminals, UDM1 can send the contract information to AMF1 and AMF1 can perform authentication (i.e., execute S605 (option 1)), or UDM1 can directly perform authentication (i.e., execute S605 (option 2)).

[0364] S605 (option 1), AMF1 receives the contract information of one or more IoT terminals sent by UDM1, and determines whether AF2 can operate the IoT terminal of AF1 based on the contract information of one or more IoT terminals and the identifier of AF2.

[0365] Optionally, if the service request includes the spatial location information of the IoT terminal, AMF1 can also determine whether AF2 can operate AF1's IoT terminal at the corresponding location.

[0366] Optionally, if the service request includes the ID range of the IoT terminal, AMF1 can also determine whether AF2 can operate the IoT terminal corresponding to the ID range.

[0367] Optionally, if the service request includes the identifier of the second PLMN, AMF1 can also determine whether AF2 can operate AF1's IoT terminal in the second PLMN.

[0368] S605 (option 2): UDM1 retrieves the contract information of one or more IoT terminals based on AF1's identifier and determines whether AF2 can operate AF1's IoT terminal based on the contract information of the one or more IoT terminals and AF2's identifier. The AF2 identifier may also be sent by the AMF to UDM1.

[0369] Optionally, if the service request includes spatial location information of the IoT terminal, UDM1 may also determine whether AF2 can operate AF1's IoT terminal at the corresponding location.

[0370] Optionally, if the service request includes an ID range of IoT terminals, UDM1 may also determine whether AF2 can operate the IoT terminals corresponding to the ID range.

[0371] Optionally, if the service request includes an identifier of the second PLMN, UDM1 may also determine whether AF2 can operate the IoT terminal of AF1 in the second PLMN.

[0372] S606: When AMF1 or UDM1 determines that AF2 can operate AF1's IoT terminal, it generates mask information MASK, which includes the identifier of AF1 and the identifier of the IoT terminal, and sends the generated mask information to AMF2. AMF uses the mask information to enable IoT terminals that meet the mask to access the network.

[0373] S607, AMF2 receives the ID of the IoT terminal that successfully accesses the network and performs ID validation to determine whether the received ID belongs to AF1.

[0374] FIG7 illustrates a communication method 700 provided by the present application. This method 700 includes at least some of the steps shown in FIG7 . This method 700, in conjunction with method 300, further describes the method of the present application, taking as an example a core network including an AMF network element and a UDM network element, AF1 as the first service requester, and AF2 as the second service requester. It should be understood that this method 700 is a specific implementation of method 300, and its concepts and terminology can be used interchangeably. This method 700 only considers the scenario of cross-network operation authorization. It should be understood that in this method 700, AF2 sends AF1's identifier to the AMF, i.e., authorizing the operation of the IoT device using the identifier corresponding to the enterprise. Alternatively, AF2 can also send the identifier of the IoT terminal to the AMF and authorize the operation of the IoT device using the identifier of the IoT terminal. In this case, replacing AF1's identifier in method 700 with the identifier of the IoT terminal and replacing AF1's contract information with the contract information of the IoT terminal corresponds to a solution for authorizing the operation of the IoT device using the identifier of the IoT terminal.

[0375] S701, AF2 sends a service request (service request, an example of the first request information) to AMF2. The service request is used to request operation of one or more IoT terminals of the supplier corresponding to AF1. The service request includes the identifier of AF1 (owner AF) and the identifier of AF2.

[0376] AF2 accesses the second PLMN, and AF1 subscribes to the first PLMN. It should be noted that the first PLMN and the second PLMN are different networks. The first PLMN includes AMF1 and UDM1, and the second PLMN includes AMF2.

[0377] Optionally, the service request also includes an identifier of the first PLMN.

[0378] Optionally, the service request also includes spatial location information of the IoT terminal.

[0379] Optionally, the service request also includes identification information of the IoT terminal. Optionally, the identification information may be a range of IDs.

[0380] Optionally, the service request may include a security key (an example of a first security key) for subsequent security checks.

[0381] S702, AMF2 determines the first PLMN subscribed by AF1 based on the identifier of AF1 and the identifier of PLMN1.

[0382] Optionally, when the first PLMN and the second PLMN are the same, that is, a scenario where cross-network authentication is not performed, reference may be made to method 400 .

[0383] After AMF2 determines the first PLMN, it may forward the service request to UDM1.

[0384] Specifically, in the method 700 , UDM1 of the first PLMN has registered with NRF1 belonging to the first PLMN, and has sent the ID of AF1 or the ID of the supplier enterprise to NRF1 .

[0385] After AMF2 obtains AF1's ID, it can request NRF2 to obtain UDM1 information and carry AF1's ID or the supplier's ID in the request message, so that NRF1 can obtain UDM1 instance information from NRF2.

[0386] S703, AMF2 requests UDM1 to obtain AF1's contract information.

[0387] Optionally, AMF2 may send the identifier of the second PLMN to UDM1.

[0388] After AMF2 requests UDM1 to obtain the contract information of one or more IoT terminals, UDM1 can send the contract information to AMF2 and AMF2 can perform authentication (i.e., execute S704 (option 1)), or UDM1 can directly perform authentication (i.e., execute S704 (option 2)).

[0389] S704 (option 1), AMF2 receives the contract information of AF1 sent by UDM1, and determines whether AF2 can operate the IoT terminal of AF1 based on the contract information of AF1 and the identifier of AF2.

[0390] Optionally, if the service request includes the spatial location information of the IoT terminal, AMF2 can also determine whether AF2 can operate AF1's IoT terminal at the corresponding location.

[0391] Optionally, if the service request includes the ID range of the IoT terminal, AMF2 can also determine whether AF2 can operate the IoT terminal corresponding to the ID range.

[0392] Optionally, if the service request includes the identifier of the second PLMN, AMF2 can also determine whether AF2 can operate AF1's IoT terminal in the second PLMN.

[0393] S704 (option 2): UDM1 retrieves AF1's contract information based on AF1's identifier and determines whether AF2 can operate AF1's IoT terminal based on AF1's contract information and AF2's identifier. AF2's identifier may also be sent by the AMF to UDM1.

[0394] Optionally, if the service request includes spatial location information of the IoT terminal, UDM1 may also determine whether AF2 can operate AF1's IoT terminal at the corresponding location.

[0395] Optionally, if the service request includes an ID range of IoT terminals, UDM1 may also determine whether AF2 can operate the IoT terminals corresponding to the ID range.

[0396] Optionally, if the service request includes an identifier of the second PLMN, UDM1 may also determine whether AF2 can operate the IoT terminal of AF1 in the second PLMN.

[0397] S705. When UDM1 determines that AF2 can operate AF1's IoT terminal, it generates mask information MASK, which includes the identifier of AF1 and the IoT terminal, and sends the generated mask information to AMF2. AMF uses the mask information to enable IoT terminals that meet the mask to access the network.

[0398] S706: AMF2 receives the ID of the IoT terminal that has successfully connected to the network and performs ID validation to determine whether the received ID belongs to AF1. For example, AMF2 may route the ID back to UDM1 for ID validation.

[0399] The above description, in conjunction with Figures 1 to 7 , details the communication method embodiment of the present application. The following description, in conjunction with Figures 8 to 10 , details the communication device embodiment of the present application. It should be understood that the description of the device embodiment corresponds to the description of the method embodiment. Therefore, for portions not described in detail, reference can be made to the preceding method embodiment.

[0400] Figure 8 is a schematic diagram of the structure of a communication device 1000 provided in an embodiment of the present application. As shown in Figure 8, the device 1000 may include a transceiver unit 1010 and a processing unit 1020. The transceiver unit 1010 can communicate with the outside world, and the processing unit 1020 is used to process data. The transceiver unit 1010 may also be referred to as a communication interface or a transceiver unit.

[0401] In one possible design, the device 1000 can implement the steps or processes corresponding to those performed by the first IoT management function network element in the above method embodiment, wherein the processing unit 1020 is used to perform the processing-related operations of the first IoT management function network element in the above method embodiment, and the transceiver unit 1010 is used to perform the transceiver-related operations of the first IoT management function network element in the above method embodiment. For example, in Figure 2, the processing unit 1020 performs the processing operation of determining whether the second service requester has the authority to operate the above-mentioned one or more IoT terminals based on the information of the first service requester and the information of the second service requester in S202, and the transceiver unit 1010 performs the receiving operation of receiving the information of the second service requester and the information of the first service requester to which the one or more IoT terminals belong in S201. For another example, in Figure 3, the processing unit 1020 performs the processing operation of determining whether the second service requester has the authority to operate the above-mentioned one or more IoT terminals based on the information of the first service requester and the first identification information in S303, and the transceiver unit 1010 performs the receiving operation of receiving the information of the second service requester and the first identification information from the second IoT management function network element in S301.

[0402] In another possible design, the device 1000 can implement the steps or processes corresponding to those performed by the first data management network element in the above method embodiment, wherein the transceiver unit 1010 is used to perform the transceiver-related operations of the first data management network element in the above method embodiment, and the processing unit 1020 is used to perform the processing-related operations of the first data management network element in the above method embodiment. For example, in Figure 2, the processing unit 1020 performs the processing operation of determining whether the second service requester has the authority to operate the above-mentioned one or more Internet of Things terminals based on the information of the first service requester and the information of the second service requester in S202, and the transceiver unit 1010 performs the receiving operation of receiving the information of the second service requester and the information of the first service requester to which the one or more Internet of Things terminals belong in S201. For another example, in Figure 3, the processing unit 1020 performs the processing operation of determining whether the second service requester has the authority to operate the above-mentioned one or more Internet of Things terminals based on the information of the first service requester and the first identification information in S303, and the transceiver unit 1010 performs the receiving operation of receiving the information of the second service requester and the first identification information from the second Internet of Things management function network element in S301.

[0403] It should be understood that the device 1000 here is embodied in the form of a functional unit. The term "unit" here can refer to an application specific integrated circuit (ASIC), an electronic circuit, a processor (such as a shared processor, a dedicated processor or a group processor, etc.) and a memory for executing one or more software or firmware programs, a merging logic circuit and / or other suitable components that support the described functions. In an optional example, those skilled in the art can understand that the device 1000 can be specifically the transmitting end in the above embodiment, and can be used to execute the various processes and / or steps corresponding to the transmitting end in the above method embodiment, or the device 2000 can be specifically the receiving end in the above embodiment, and can be used to execute the various processes and / or steps corresponding to the receiving end in the above method embodiment. To avoid repetition, it will not be repeated here.

[0404] The apparatus 1000 of each of the above-mentioned solutions has the function of implementing the corresponding steps performed by the transmitting end in the above-mentioned method, or the apparatus 1000 of each of the above-mentioned solutions has the function of implementing the corresponding steps performed by the receiving end in the above-mentioned method. The functions can be implemented by hardware, or can be implemented by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above-mentioned functions; for example, the transceiver unit can be replaced by a transceiver (for example, the transmitting unit in the transceiver unit can be replaced by a transmitter, and the receiving unit in the transceiver unit can be replaced by a receiver), and other units, such as the processing unit, can be replaced by a processor to respectively perform the transceiver operations and related processing operations in each method embodiment.

[0405] In addition, the above-mentioned transceiver unit can also be a transceiver circuit (for example, it can include a receiving circuit and a transmitting circuit), and the processing unit can be a processing circuit. In an embodiment of the present application, the device in Figure 8 can be the receiving end or the transmitting end in the aforementioned embodiment, or it can be a chip or a chip system, such as a system on chip (SoC). Among them, the transceiver unit can be an input and output circuit or a communication interface. The processing unit is a processor or microprocessor or integrated circuit integrated on the chip. This is not limited here.

[0406] Figure 9 is a schematic diagram of the structure of a communication device 2000 provided in an embodiment of the present application. As shown in Figure 9, the device 2000 includes a processor 2010 and a transceiver 2020. The processor 2010 and the transceiver 2020 communicate with each other via an internal connection path. The processor 2010 is used to execute instructions to control the transceiver 2020 to send and / or receive signals.

[0407] Optionally, the apparatus 2000 may further include a memory 2030, which communicates with the processor 2010 and the transceiver 2020 via an internal connection path. The memory 2030 is used to store instructions, and the processor 2010 may execute the instructions stored in the memory 2030.

[0408] In a possible implementation, the device 2000 is used to implement the various processes and steps corresponding to the first IoT management function network element in the above method embodiment.

[0409] In another possible implementation, the device 2000 is used to implement various processes and steps corresponding to the first data management network element in the above method embodiment.

[0410] It should be understood that the device 2000 can be specifically the transmitting end or receiving end in the above-mentioned embodiments, or can also be a chip or chip system. Correspondingly, the transceiver 2020 can be the transceiver circuit of the chip, which is not limited here. Specifically, the device 2000 can be used to perform the various steps and / or processes corresponding to the transmitting end or receiving end in the above-mentioned method embodiments.

[0411] Optionally, the memory 2030 may include a read-only memory and a random access memory, and provide instructions and data to the processor. A portion of the memory may also include non-volatile random access memory. For example, the memory may also store device type information. The processor 2010 may be configured to execute instructions stored in the memory. When the processor 2010 executes the instructions stored in the memory, the processor 2010 is configured to perform the various steps and / or processes of the above-described method embodiments corresponding to the transmitting end or the receiving end.

[0412] During implementation, each step of the above method can be completed by an integrated logic circuit of the hardware in the processor or an instruction in the form of software. The steps of the method disclosed in conjunction with the embodiments of the present application can be directly embodied as being executed by a hardware processor, or can be executed by a combination of hardware and software modules in the processor. The software module can be located in a storage medium mature in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, etc. The storage medium is located in a memory, and the processor reads the information in the memory and completes the steps of the above method in conjunction with its hardware. To avoid repetition, it will not be described in detail here.

[0413] It should be noted that the processor in the embodiments of the present application can be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above-mentioned method embodiment can be completed by hardware integrated logic circuits in the processor or by software instructions. The above-mentioned processor can be a general-purpose processor, a digital signal processor, an application-specific integrated circuit, a field-programmable gate array or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component. The processor in the embodiments of the present application can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in the embodiments of the present application can be directly implemented and executed by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium well-known in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, etc. The storage medium is located in the memory, and the processor reads the information in the memory and, in conjunction with its hardware, completes the steps of the above-mentioned method.

[0414] It will be understood that the memory in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static random access memory, dynamic random access memory, synchronous dynamic random access memory, double data rate synchronous dynamic random access memory, enhanced synchronous dynamic random access memory, synchronous linked dynamic random access memory, and direct memory bus random access memory. It should be noted that the memory of the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0415] FIG10 is a schematic diagram of the structure of a chip system 3000 provided in an embodiment of the present application. As shown in FIG10 , the chip system 3000 (or also referred to as a processing system) includes a logic circuit 3010 and an input / output interface 3020 .

[0416] The logic circuit 3010 may be a processing circuit in the chip system 3000. The logic circuit 3010 may be coupled to a storage unit and call instructions in the storage unit so that the chip system 3000 can implement the methods and functions of the various embodiments of the present application. The input / output interface 3020 may be an input / output circuit in the chip system 3000, outputting information processed by the chip system 3000 or inputting data or signaling information to be processed into the chip system 3000 for processing.

[0417] As a solution, the chip system 3000 is used to implement the operations performed by the first data management network element in the above various method embodiments.

[0418] As a solution, the chip system 3000 is used to implement the operations performed by the first IoT management function network element in the above method embodiments.

[0419] An embodiment of the present application also provides a computer-readable storage medium on which computer instructions are stored for implementing the methods executed by the first IoT management function network element and / or the first data management network element in the above-mentioned method embodiments.

[0420] An embodiment of the present application also provides a computer program product, comprising computer program code or instructions. When the computer program code or instructions are executed on a computer, the computer implements the method executed by at least one of the first IoT management function network element and the first data management network element in the above-mentioned method embodiments.

[0421] An embodiment of the present application also provides a communication system, including the aforementioned first Internet of Things management function network element and the first data management network element.

[0422] The explanation of the relevant contents and beneficial effects of any of the above-mentioned devices can be referred to the corresponding method embodiments provided above, which will not be repeated here.

[0423] To facilitate understanding of the above embodiments provided in this application, the following points are explained:

[0424] 1) In this application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.

[0425] 2) The arrows or boxes indicated by dotted lines in the schematic diagrams in the accompanying drawings of this specification represent optional steps or optional modules.

[0426] 3) In the embodiments of this application, ordinal numbers such as "first" and "second" are used to distinguish multiple objects and are not used to define the size, content, sequence, timing, priority, or importance of the multiple objects. For example, the first message and the second message can be the same message or different messages, and such names do not indicate differences in content, size, application scenario, sender / receiver, priority, or importance between the two messages.

[0427] 4) In this application, "indicate" or "used to indicate" can include direct indication and indirect indication. When describing that a certain indication information is used to indicate A, it can include that the indication information directly indicates A or indirectly indicates A, and does not necessarily mean that the indication information carries A.

[0428] The indication methods involved in the embodiments of this application should be understood to encompass various methods that enable the party to be indicated to obtain information about the information to be indicated. The information to be indicated can be sent as a whole or divided into multiple sub-information and sent separately. The transmission period and / or timing of these sub-information can be the same or different. This application does not limit the transmission method, for example.

[0429] In the embodiments of the present application, the "indication information" may be an explicit indication, i.e., a direct indication via signaling, or may be obtained based on parameters indicated by the signaling, in combination with other rules, other parameters, or by deduction. It may also be an implicit indication, i.e., based on a rule or relationship, or based on other parameters, or by deduction. This application does not impose specific limitations on this.

[0430] 5) The “protocol” referred to in this application may refer to a standard protocol in the field of communications, such as the fourth generation (4G) th generation, 4G) network, fifth generation (5 th This application does not limit the use of 5G network protocols, NR protocols, 5.5G network protocols, and related protocols used in future communication systems.

[0431] 6) In this application, "communication" may also be described as "data transmission", "information transmission", "data processing", etc. "Transmission" includes "sending" and "receiving".

[0432] 7) The terms "comprise," "include," and "have," and any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus comprising a series of steps or elements is not limited to the listed steps or elements but may optionally include steps or elements not listed, or may optionally include other steps or elements inherent to the process, method, product, or apparatus.

[0433] 8) In this application, "at least one" means one or more, and "more" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. In the text description of this application, the character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b and c can mean: a, or b, or c, or a and b, or a and c, or b and c, or a, b and c. Where a, b and c can be single or multiple, respectively.

[0434] 9) In this application, under the premise of no logical contradiction, the examples can reference each other, for example, the methods and / or terms between method embodiments can reference each other, for example, the functions and / or terms between device embodiments can reference each other, for example, the functions and / or terms between device examples and method examples can reference each other.

[0435] It should be understood that in some of the above embodiments, the devices in the existing network architecture are mainly used as examples for illustrative description, and the specific form of the devices is not limited in the embodiments of the present application. For example, devices that can achieve the same functions in the future are applicable to the embodiments of the present application.

[0436] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0437] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be described again here.

[0438] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0439] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0440] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0441] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or an RDMA link target node, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a ROM, a RAM, a magnetic disk, or an optical disk.

[0442] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. A communication method, characterized in that: Applied to core network equipment, the method includes: receiving information of a second service requester and information of a first service requester to which one or more IoT terminals belong; Based on the information of the first service requester and the information of the second service requester, it is determined whether the second service requester has the authority to operate the one or more IoT terminals.

2. The method according to claim 1, characterized in that The receiving of information about the second service requester and information about the first service requester to which one or more IoT terminals belong includes: The first IoT management function network element receives first request information from the second service requester, where the first request information is used to request an operation on the one or more IoT terminals of the first service requester, and the first request information includes information about the second service requester and information about the first service requester; The determining, based on the information of the first service requester and the information of the second service requester, whether the second service requester has the authority to operate the one or more IoT terminals includes: The first IoT management function network element obtains the contract information of the first service requester or the contract information of the one or more IoT terminals based on the information of the first service requester; The first IoT management function network element determines whether the second service requester has the authority to operate the one or more IoT terminals based on the first request information and the contract information of the first service requester or the contract information of the one or more IoT terminals.

3. The method according to claim 2, characterized in that The first IoT management function network element acquiring the contract information of the first service requester or the contract information of the one or more IoT terminals based on the information of the first service requester includes: The first IoT management function network element sends a second request message to the first data management network element, where the second request message is used to request the contract information of the first service requester or the contract information of the one or more IoT terminals. The first IoT management function network element and the first data management network element belong to a first network, and the first service requester is subscribed to the first network. The first IoT management function network element obtains the contract information of the first service requester or the contract information of the one or more IoT terminals from the first data management network element.

4. The method according to claim 2 or 3, characterized in that The first IoT management function network element receives the first request information from the second service requester, including: The first Internet of Things Management Function Network Element receives the first request information from the second service requester through the second Internet of Things Management Function Network Element, and the second Internet of Things Management Function Network Element belongs to a second network accessed by the second service requester.

5. The method according to claim 1, wherein The receiving of information about the second service requester and information about the first service requester to which one or more IoT terminals belong includes: The first data management network element receives a second request message from the first Internet of Things management function network element, where the second request message is used to request the contract information of the first service requester or the contract information of the one or more Internet of Things terminals, and the second request message includes information of the second service requester and information of the first service requester. The first Internet of Things management function network element and the first data management network element belong to a first network, and the first service requester is subscribed to the first network. The determining, based on the information of the first service requester and the information of the second service requester, whether the second service requester has the authority to operate the one or more IoT terminals includes: The first data management network element determines whether the second service requester has the authority to operate the one or more IoT terminals based on the second request information and the contract information of the first service requester or the contract information of the one or more IoT terminals.

6. The method according to claim 1, characterized in that The receiving of information about the second service requester and information about the first service requester to which one or more IoT terminals belong includes: The first data management network element receives a second request message from the second IoT management function network element, where the second request message is used to request the contract information of the first service requester or the contract information of the one or more IoT terminals, and the second request message includes information of the second service requester and information of the first service requester. The first data management network element belongs to a first network, the first service requester has signed a contract with the first network, and the second IoT management function network element belongs to a second network accessed by the second service requester. The determining, based on the information of the first service requester and the information of the second service requester, whether the second service requester has the authority to operate the one or more IoT terminals includes: The first data management network element determines whether the second service requester has the authority to operate the one or more IoT terminals based on the second request information and the contract information of the first service requester or the contract information of the one or more IoT terminals.

7. The method according to claim 6, characterized in that The method further comprises: The second IoT management function network element receives first request information from the second service requester, where the first request information is used to request an operation on one or more IoT terminals of the first service requester, and the first request information includes information of the first service requester; determining the first network based on information of the first service requester; The second request information is sent to the first data management network element belonging to the first network.

8. The method according to claim 4, characterized in that The first request information includes an identifier of the second network.

9. The method according to claim 6 or 7, characterized in that The second request information includes an identifier of the second network.

10. The method according to any one of claims 2 to 9, characterized in that The method further comprises: The second service requester sends a first request message, where the first request message is used to request operation of the one or more IoT terminals of the first service requester. The first request message includes information of the second service requester and information of the first service requester. The second IoT management function network element belongs to a second network accessed by the second service requester.

11. The method according to claim 1, wherein The method further comprises: Receiving a first security key and determining whether the second service requester has permission to operate the one or more Internet of Things terminals based on the contract information of the first service requester or the contract information of the one or more Internet of Things terminals includes: Determine whether the first security key meets the contract information of the first service requester or the contract information of the one or more Internet of Things terminals.

12. The method according to any one of claims 2 to 11, characterized in that The contract information of the first service requester or the contract information of the one or more Internet of Things terminals indicates whether the one or more Internet of Things terminals support being operated by other service requesters.

13. A communication method, characterized in that: Applied to a core network device within a first network, the method includes: receiving information of a second service requester and first identification information from a second IoT management function network element, where the first identification information includes at least one of the following identifications: information of the first service requester to which one or more IoT terminals belong, and information of the one or more IoT terminals, wherein the first service requester is subscribed to the first network, the second service requester is connected to the second network, and the second IoT management function network element belongs to the second network; Determine whether the second service requester has the authority to operate the one or more IoT terminals based on the information of the second service requester and the first identification information.

14. The method according to claim 13, wherein: The receiving of information of the second service requester and the first identification information from the second IoT management function network element includes: The first IoT management function network element receives a first request message from the second IoT management function network element, where the first request message is used by the second service requester to request operation of the one or more IoT terminals, the first request message includes information of the second service requester and the first identification information, and the first IoT management function network element belongs to the first network; The determining, based on the information of the second service requester and the first identification information, whether the second service requester has the authority to operate the one or more IoT terminals includes: The first IoT management function network element obtains the contract information of the first service requester or the contract information of the one or more IoT terminals based on the information of the first service requester; The first IoT management function network element determines whether the second service requester has the authority to operate the one or more IoT terminals based on the first request information and the contract information of the first service requester or the contract information of the one or more IoT terminals.

15. The method according to claim 14, characterized in that The first IoT management function network element acquiring the contract information of the first service requester or the contract information of the one or more IoT terminals based on the information of the first service requester includes: The first IoT management function network element sends a second request message to the first data management network element, where the second request message is used to request the contract information of the first service requester or the contract information of the one or more IoT terminals, and the first data management network element belongs to the first network; The first IoT management function network element obtains the contract information of the first service requester or the contract information of the one or more IoT terminals from the first data management network element.

16. The method according to claim 13, characterized in that The receiving of information of the second service requester and the first identification information from the second IoT management function network element includes: The first data management network element receives a second request message from the second IoT management function network element, where the second request message is used to request the contract information of the first service requester or the contract information of the one or more IoT terminals, and the second request message includes information of the second service requester and the first identification information. The first data management network element belongs to the first network. The determining, based on the information of the second service requester and the first identification information, whether the second service requester has the authority to operate the one or more IoT terminals includes: The first data management network element determines whether the second service requester has the authority to operate the one or more IoT terminals based on the second request information and the contract information of the first service requester or the contract information of the one or more IoT terminals.

17. The method according to claim 16, characterized in that The method further comprises: The second IoT management function network element receives first request information from the second service requester, where the first request information is used to request an operation on one or more IoT terminals of the first service requester, and the first request information includes the first identification information; determining the first network based on the first identification information; The second request information is sent to the first data management network element belonging to the first network.

18. The method according to claim 14 or 15, characterized in that The first request information includes an identifier of the second network.

19. The method according to claim 16 or 17, characterized in that The second request information includes an identifier of the second network.

20. The method according to any one of claims 14 to 19, characterized in that The method further comprises: The second service requester sends a first request message to the second IoT management function network element, where the first request message is used to request operation of the one or more IoT terminals of the first service requester, and the first request message includes information of the second service requester and the first identification information.

21. The method according to claim 13, wherein The method further comprises: Receiving a first security key and determining whether the second service requester has permission to operate the one or more Internet of Things terminals based on the contract information of the first service requester or the contract information of the one or more Internet of Things terminals includes: Determine whether the first security key meets the contract information of the first service requester or the contract information of the one or more Internet of Things terminals.

22. The method according to any one of claims 13 to 21, characterized in that The contract information of the first service requester or the contract information of the one or more Internet of Things terminals indicates whether the one or more Internet of Things terminals support being operated by other service requesters.

23. A communication device, characterized in that: include: A unit for implementing the method of any one of claims 1 to 12; or a unit for implementing the method of any one of claims 13 to 22.

24. A communication device, characterized in that: The device comprises a processor coupled to a memory, wherein the processor is configured to execute a computer program or instruction stored in the memory so as to enable the communication device to perform the method according to any one of claims 1 to 12, or to perform the method according to any one of claims 13 to 22.

25. A computer program product, characterized in that Contains instructions that, when executed on a computer, causing the method of any one of claims 1 to 12 to be performed; or, Such that the method according to any one of claims 13 to 22 is performed.

26. A computer-readable storage medium, characterized in that The computer readable storage medium stores a computer program or instruction. When the computer program or instruction is executed, Performing the method according to any one of claims 1 to 12, or Perform the method according to any one of claims 13 to 22.

Citation Information

Patent Citations

  • Access control system and access control method thereof

    CN104135459A

  • Communication method and communication device

    CN113938879A

  • Communication method and communication device

    CN114980094A