Communication method, and device

By using blockchain technology to upload communication billing values ​​recognized by terminals and access network equipment in roaming networks, the problem of billing accuracy in roaming networks is solved, and the billing process is made transparent and fair.

WO2025222423A1PCT designated stage Publication Date: 2025-10-30GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/089669
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-04-24
Publication Date
2025-10-30

AI Technical Summary

Technical Problem

How to ensure the accuracy of terminal communication billing in roaming networks and ensure that the communication billing values ​​agreed upon by both parties in the roaming network are consistent?

Method used

By uploading the communication billing value recognized by the first terminal and the first access network device to the blockchain, the accuracy and consistency of the billing information are ensured by using blockchain technology. This includes the terminal and the access network device calculating and signing the communication billing value respectively, and ensuring the security and integrity of the information through key verification and encryption mechanisms.

Benefits of technology

This enables both the terminal and the roaming network to recognize and ensure the accuracy of communication billing values ​​in roaming scenarios, thus guaranteeing the transparency and fairness of the billing process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024089669_30102025_PF_FP_ABST
    Figure CN2024089669_30102025_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to a communication method, and a device. The method comprises: uploading billing-related information of a first terminal to a blockchain, wherein the billing-related information of the first terminal is used for determining a first communication billing value under a first network that is recognized by the first terminal and a first access network device, the first access network device belongs to the first network, and the first terminal belongs to a second network.
Need to check novelty before this filing date? Find Prior Art

Description

Communication methods and devices Technical Field

[0001] This application relates to the field of communications, and more specifically, to a communication method and device. Background Technology

[0002] In related technologies, roaming protocols refer to protocols in mobile communication networks that allow terminals to switch between different operator networks and use services. These protocols enable users to continue communicating through other operators' networks even when they leave the coverage area of ​​their original operator's network. The development and implementation of roaming protocols help improve user experience, allowing terminals to freely switch between different operator-maintained networks in different regions. However, ensuring the accuracy of billing for communications made by terminals in roaming networks becomes a problem that needs to be solved.

[0003] Summary of the Invention

[0004] This application provides a communication method and device.

[0005] This application provides a communication method executed by a first access network device, comprising:

[0006] The billing information of the first terminal is uploaded to the blockchain. The billing information of the first terminal is used to determine the first communication billing value recognized by the first terminal and the first access network device under the first network. The first access network device belongs to the first network and the first terminal belongs to the second network.

[0007] This application provides a communication method executed by a first terminal, including:

[0008] A second message is sent to a first access network device, wherein the second message carries a first signature for determining that the first terminal acknowledges a first communication billing value under the first network, the first terminal belongs to the second network, and the first access network device belongs to the first network and serves the first terminal.

[0009] This application provides a first access network device, including:

[0010] The first communication unit is used to upload the billing-related information of the first terminal to the blockchain. The billing-related information of the first terminal is used to determine the first communication billing value recognized by the first terminal and the first access network device under the first network. The first access network device belongs to the first network, and the first terminal belongs to the second network.

[0011] This application provides a first terminal, including:

[0012] The second communication unit is configured to send a second message to the first access network device, wherein the second message carries a first signature for determining that the first terminal acknowledges the first communication billing value under the first network, the first terminal belongs to the second network, and the first access network device belongs to the first network and serves the first terminal.

[0013] By adopting the above scheme, the communication billing value, which is recognized by both the first terminal belonging to the second network and the first access network device belonging to the first network, can be uploaded to the blockchain. This ensures that the communication billing value uploaded to the blockchain is recognized and accurate by both the terminal and the roaming network, thereby guaranteeing the accuracy of billing for the terminal in roaming scenarios. Attached Figure Description

[0014] Figure 1 is a schematic diagram of an application scenario according to an embodiment of this application.

[0015] Figure 2 is a schematic flowchart of a communication method according to an embodiment of this application.

[0016] Figure 3 is a schematic flowchart of a communication method according to another embodiment of this application.

[0017] Figure 4 is a schematic flowchart of a communication method of a symmetrical scheme according to an embodiment of the present application.

[0018] Figure 5 is a schematic flowchart of a communication method for an asymmetric scheme according to an embodiment of this application.

[0019] Figure 6 is a schematic flowchart of the on-chaining of billing aggregation information according to an embodiment of this application.

[0020] Figure 7 is a schematic flowchart of the symmetric key distribution process between the UE and the base station according to an embodiment of this application.

[0021] Figure 8 is a schematic flowchart of UE registration according to an embodiment of this application.

[0022] Figure 9 is a schematic flowchart of a first terminal accessing a network according to an embodiment of this application.

[0023] Figure 10 is a schematic block diagram of a first access network device according to an embodiment of the present application.

[0024] Figure 11 is a schematic block diagram of a first terminal according to an embodiment of the present application. Detailed Implementation

[0025] The technical solutions of this application embodiment can be applied to various communication systems, such as LTE, LTE-A, NR, NR evolution, WLAN, WiFi, or other communication systems.

[0026] This application describes various embodiments in conjunction with network devices and terminals. The terminal can be mobile or fixed, and may also be referred to as a mobile station, user unit, etc. The terminal can be a station in a WLAN, or a smart terminal, wireless modem, laptop, tablet, etc. In this application's embodiments, the terminal can be a VR / AR terminal, industrial control terminal, autonomous driving terminal, telemedicine terminal, smart grid terminal, transportation safety terminal, smart city terminal, or smart home wireless terminal, etc. By way of example and not limitation, in this application's embodiments, the terminal can also be a wearable device.

[0027] In this embodiment, the network device can be a device for communicating with a terminal. The network device can be an access point in a WLAN, an evolved base station in LTE, a relay station, a network device (gNB) in a vehicle-mounted device, wearable device, or NR network, or a network device in a future PLMN network, or a network device in a non-terrestrial network, etc. By way of example and not limitation, in this embodiment, the network device can have mobility characteristics; for example, the network device can be a mobile device.

[0028] To facilitate understanding of the technical solutions of the embodiments of this application, the relevant technologies of the embodiments of this application are described below. The following relevant technologies are optional solutions and can be combined with the technical solutions of the embodiments of this application in any way, and they all fall within the protection scope of the embodiments of this application.

[0029] Figure 1 exemplarily illustrates a communication system 100. This communication system includes a network device 110 and two terminals 120. In one possible implementation, the communication system 100 may include multiple network devices 110, and the coverage area of ​​each network device 110 may include other numbers of terminals 120; this embodiment does not limit this. In another possible implementation, the communication system 100 may also include mobility management entities, access and mobility management functions, and other network entities; this embodiment does not limit this. The network devices may further include access network devices and core network devices. That is, the communication system may also include multiple core networks for communicating with the access network devices. The access network devices may be base stations of LTE, LTE-A, or NR systems. Taking the communication system shown in Figure 1 as an example, the communication devices may include network devices and terminals with communication functions. The communication devices may also include other devices in the communication system, such as network controllers, mobility management entities, and other network entities; this embodiment does not limit this.

[0030] Figure 2 is a schematic flowchart of a communication method performed by a first access network device according to an embodiment of this application. The method includes at least a portion of the following.

[0031] S210. Upload the billing-related information of the first terminal to the blockchain, wherein the billing-related information of the first terminal is used to determine the first communication billing value recognized by the first terminal and the first access network device under the first network, the first access network device belongs to the first network, and the first terminal belongs to the second network.

[0032] Figure 3 is a schematic flowchart of a communication method executed by a first terminal according to an embodiment of this application. The method includes at least a portion of the following.

[0033] S310. Send a second message to the first access network device, wherein the second message carries a first signature for determining that the first terminal acknowledges the first communication billing value under the first network, the first terminal belongs to the second network, and the first access network device belongs to the first network and serves the first terminal.

[0034] The first terminal is a contracted terminal of the second network, meaning the second network is the home network of the first terminal. When the first terminal, contracted with the second network, needs to access or use the resources of the first network, the first network becomes the roaming network for that first terminal.

[0035] The first access network device may be an access network device belonging to the first network.

[0036] In some possible implementations, the first terminal uses a symmetrical scheme to access the first network, the first access network device belongs to the first network, and the first access network device serves the first terminal.

[0037] In some embodiments, when the first terminal accesses the first network using a symmetrical scheme, the first terminal triggers the reporting of a bill to the first access network device.

[0038] In this embodiment, the first terminal directly sends the second message to the first access network device. The processing by the first access network device may include: receiving the second message from the first terminal, wherein the second message carries the first signature. After receiving the second message, the first access network device uploads the billing-related information of the first terminal to the blockchain.

[0039] The first signature is calculated by the first terminal. The first signature is calculated based on the private key of the first terminal and the first communication billing value. Optionally, the calculation of the first signature can be as follows: using a signature algorithm, the first signature is calculated based on the private key of the first terminal and the first communication billing value. For example, if the first communication billing value is represented as com(price) and the private key of the first terminal is simply represented as va, the calculation of the first signature can be expressed by the following formula: Sig va(Com(price)). Optionally, the calculation of the first signature can be: performing a hash calculation based on the first communication billing value to obtain a first hash value; encrypting the first hash value based on the private key of the first terminal to obtain the first signature.

[0040] Optionally, the second message may also carry at least one of the following: a second verification code for verifying the identity of the first terminal, the certificate of the first terminal, first encryption information, the identifier of the first access network device, a second random number, the first communication billing value, and information related to the first communication bill of the first terminal under the first network, wherein the certificate of the first terminal carries the public key of the first terminal, and the first communication bill includes the communication cost of the first terminal under the first network.

[0041] The function of the second verification code is to prevent the message (i.e., the second message) from being tampered with and to authenticate the identity of the first terminal. The second verification code is calculated based on a second key between the first access network device and the first terminal and at least one of the following parameters: the first signature, the certificate of the first terminal, the first encrypted information, the identifier of the first access network device, the second random number, the first communication billing value, and relevant information from the first communication bill. The second key is essentially a session key between the first terminal and the access network device serving the first terminal in the first network.

[0042] The first encrypted information is obtained by encrypting at least one of the following based on the second key between the first access network device and the first terminal: relevant information of the first communication bill, and the first communication billing value.

[0043] The certificate of the first terminal may also include at least one of the following: the identifier of the second core network device belonging to the second network, the identifier of the first terminal, and the seventh signature.

[0044] The second core network device can be a core network device that issues certificates for the first terminal in the second network (i.e., the home network of the first terminal).

[0045] The identifier of the first terminal can be a temporary identifier of the first terminal, which can refer to the temporary identifier of the first terminal under the first network. In the following text, the identifier of the first terminal mentioned in the interaction between the first terminal and the access network device and / or the first core network device in the first network can all refer to the temporary identifier of the first terminal, and will not be explained again below.

[0046] The seventh signature can be used to indicate that the certificate of the first terminal was issued by the second core network device. This seventh signature is calculated based on the private key of the second core network device, the temporary identifier of the first terminal, and the public key of the first terminal. The calculation method for the seventh signature is similar to that of the first signature and will not be elaborated further.

[0047] For example, the certificate for the first terminal can be as shown in Table 1:

[0048] Table 1

[0049] The second random number can be generated by the first terminal, and the method of generating the second random number is not limited in this embodiment. The function of the second random number can be to prevent replay attacks.

[0050] The first communication billing value is calculated based on the communication costs of the first terminal under the first network. In some examples, the communication billing value may also be referred to as the commitment value, that is, the first communication billing value may also be referred to as the first commitment value.

[0051] The first communication billing value can be specifically calculated based on the communication cost of the first terminal under the first network and the fifth random number using the first calculation method. The method for selecting the fifth random number is not limited in this embodiment.

[0052] This first calculation method can be configured according to actual conditions. Taking the Pedersen commitment calculation method as an example, the calculation of the first communication billing value can be as follows: The communication cost of the first terminal under the first network is used as the power of the first element to calculate the first value; the fifth random number is used as the power of the second element to calculate the second value; and the first and second values ​​are multiplied to obtain the first communication billing value. The first and second elements can be common parameters in the Pedersen commitment, for example, the first and second elements can be selected from a multiplicative group G of order Q, and the fifth random number can be selected by the first terminal. For example, the calculation of the first communication billing value can be expressed as: Commit(price) = g price h r Where g, h∈G q G q That is, a multiplicative group G of order Q, where g can be the first element mentioned above, h can be the second element mentioned above, price is the communication cost of the first terminal under the first network (price can also be represented by x alternatively), r is the fifth random number, and Commit(price) is the first communication billing value, which can also be abbreviated as "com".

[0053] The communication cost of the first terminal under the first network can refer to the communication cost incurred by the first terminal in completing one or more communications under the first network. The communication cost can also be alternatively expressed as the communication price.

[0054] Optionally, the communication cost of the first terminal under the first network can be calculated based on at least one of the time period of a single communication under the first network and the cost per unit time under the first network. Optionally, the communication cost of the first terminal under the first network can be calculated based on at least one of the time period of multiple communications under the first network and the cost per unit time under the first network. The number of communications can be configured according to actual circumstances, such as two communications, three communications, or more or fewer; it is not limited or exhaustively listed here.

[0055] The relevant information of the first communication bill includes at least one of the following: the identifier of the first communication bill, the first communication bill, wherein the specific content of the first communication bill includes the communication costs of the first terminal under the first network.

[0056] The first communication bill can also be referred to as the first bill. This communication bill can also be alternatively called a "micro-bill," for example, the first communication bill can be called the micro-bill of the first terminal.

[0057] The identifier of the first communication bill may include at least one of the following: the ID of the first communication bill (such as bill ID), the index number of the first communication bill (such as bill index).

[0058] In addition to the communication costs of the first terminal under the first network, the first communication bill may also include at least one of the following: the identifier of the first terminal (e.g., a temporary identifier of the first terminal), the identifier of the first core network device, the identifier (or number) of the resources used in the first network, the usage period of the resources in the first network, and a fifth random number.

[0059] The first core network device can be a control plane network element within the first network, etc. The device type of the first core network device is not limited or exhaustively listed here.

[0060] For example, the contents of the first communication bill can be as shown in Table 2:

[0061] Table 2

[0062] Since this embodiment involves the first terminal directly initiating the second message to the first access network device, the second message, in addition to the first signature, must also carry at least the relevant information of the first communication bill (which can be in plaintext or encrypted) so that the first access network device can obtain or determine the communication cost reported or calculated by the first terminal this time. In this embodiment, the second message may also carry the first communication billing value (which can be in plaintext or encrypted).

[0063] Optionally, the second message may carry a first signature, first encrypted information obtained by encrypting the identifier (or content) of the first communication bill based on the second key, and the second message may also carry at least one of the following: a second verification code, the certificate of the first terminal, the identifier of the first access network device, a second random number, and the first communication billing value.

[0064] If the first terminal first encrypts the identifier (or content) of the first communication bill using the second key to obtain the first encrypted information, and then calculates the second checksum, the second checksum can be calculated based on the second key and at least one of the following parameters: the first signature, the first encrypted information, the certificate of the first terminal, the identifier of the first access network device, the second random number, and the first communication billing value. For example, the calculation of the second checksum can be expressed as: Here, "bill" refers to the contents of the first communication bill. The first encrypted information is obtained by encrypting the contents of the first communication bill based on the second key. The meanings of the remaining parameters are the same as in the previous embodiments and will not be repeated.

[0065] If the first terminal first calculates the second verification code and then encrypts the obtained first encrypted information, the second verification code can be calculated based on the second key and at least one of the following parameters: the first signature, the identifier of the first communication bill, the certificate of the first terminal, the identifier of the first access network device, the second random number, and the first communication billing value.

[0066] Optionally, in addition to carrying the first signature, the first encrypted information obtained by encrypting the first communication bill based on the second key and the first communication billing value, the second message may also carry at least one of the following: a second verification code, the certificate of the first terminal, the identifier of the first access network device, and a second random number.

[0067] The first terminal may first calculate the first encrypted information, and then calculate the second verification code based on the first encrypted information. For example, the second verification code may be calculated based on the second key and at least one of the following parameters: the first signature, the first encrypted information, the certificate of the first terminal, the identifier of the first access network device, and the second random number. Alternatively, the first terminal may first calculate the second verification code, and then calculate the encrypted information. For example, the second verification code may be calculated based on the second key and at least one of the following parameters: the first signature, the content of the first communication bill, the first communication billing value, the certificate of the first terminal, the identifier of the first access network device, and the second random number.

[0068] The above is merely an illustrative example. In actual processing, the second message, the first encrypted information, and the second verification code are not limited to the above possibilities; they are simply not limited or exhaustive.

[0069] The processing by the first access network device after receiving the second message may include: verifying the first signature based on the public key of the first terminal and the first communication billing value. For example, the verification of the first signature may involve: using a signature verification algorithm to decrypt the first signature based on the public key of the first terminal to obtain a first parameter to be verified; if the first parameter to be verified is the same as the first communication billing value, the first signature verification is confirmed to be successful. Alternatively, a hash calculation may be performed based on the first communication billing value to obtain a first verification hash value; the first signature may be decrypted based on the public key of the first terminal to obtain a first decrypted value; if the first decrypted value and the first verification hash value are the same, the first signature verification is confirmed to be successful.

[0070] Optionally, the first access network device can also verify the first communication billing value carried in the second message. For example, the first access network device can perform the following processing: calculate a first billing verification parameter; if the first billing verification parameter is the same as the first communication billing value, determine that the first communication billing value is correct or accept the first communication billing value; if the first billing verification parameter is different from the first communication billing value, determine that the first communication billing value is incorrect. The calculation method of the first billing verification parameter is the same as the calculation method of the first communication billing value, and will not be elaborated further.

[0071] Optionally, the processing by the first access network device after receiving the second message may further include: verifying the identity of the first terminal based on the second verification code and the second verification code, wherein the second verification code is calculated based on the second key between the first access network device and the first terminal and at least one of the following parameters: the first signature, the certificate of the first terminal, the first encryption information, the identifier of the first access network device, the second random number, the first communication billing value, and relevant information of the first communication bill. Verifying the identity of the first terminal based on the second verification code and the second verification code may include at least one of the following: if the second verification code and the second verification code match, determining that the verification of the first terminal's identity is successful or passed; if the second verification code and the second verification code do not match, determining that the verification of the first terminal's identity has failed or is unsuccessful.

[0072] Here, the calculation method and calculation parameters of the second verification code should be the same as those of the second check code, and will not be repeated.

[0073] Optionally, the processing after the first access network device receives the second message may further include: decrypting the first encrypted information based on the second key between the first access network device and the first terminal to obtain at least one of the following: relevant information of the first communication bill, and the first communication billing value.

[0074] It should be noted that the processing order of the first access network device decrypting the first encrypted information and verifying the second verification code is related to the order in which the first terminal generates the first encrypted information and calculates the second verification code. For example, if the first terminal calculates the second verification code first and then encrypts the first encrypted information, the first access network device will first decrypt the first encrypted information based on the second key, and then verify the identity of the first terminal based on the second verification code and the second verification code.

[0075] The billing-related information of the first terminal includes: the first communication billing value, a first signature for determining that the first terminal acknowledges the first communication billing value, and a second signature for determining that the first access network device acknowledges the first communication billing value.

[0076] The second signature is calculated by the first access network device. The second signature is calculated based on the private key of the first access network device and the first communication billing value. For example, the calculation of the second signature can be as follows: using a signature algorithm, the first communication billing value is calculated based on the private key of the first access network device. For instance, assuming the first communication billing value is represented as com(price) and the private key of the first access network device is simply represented as b1, the calculation of the second signature can be expressed by the following formula: Sig b1(Com(price)). For example, the calculation of the second signature can be as follows: perform a hash calculation based on the first communication billing value to obtain a second hash value; encrypt the second hash value based on the private key of the first access network device to obtain the second signature.

[0077] Optionally, the billing information of the first terminal may further include: the certificate of the first access network device, wherein the certificate of the first access network device carries the public key of the first access network device. If the certificate of the first access network device has been pre-uploaded to the blockchain, the billing information of the first terminal may no longer include the certificate of the first access network device.

[0078] The certificate of the first access network device may further include at least one of the following: the identifier of the first core network device, the identifier of the first access network device, and an eighth signature. The eighth signature may be used to indicate that the certificate of the first access network device was issued by the first core network device. This eighth signature is calculated based on the private key of the first core network device, the identifier of the first access network device, and the public key of the first access network device.

[0079] For example, the certificate of the first access network device can be as shown in Table 3:

[0080] Table 3

[0081] Optionally, the billing information of the first terminal may further include the certificate of the first terminal. It should be noted that if the first terminal has not uploaded its own certificate to the blockchain, it can carry the certificate of the first terminal in the second message, and then the first access network device can add the certificate of the first terminal to the billing information of the first terminal.

[0082] In some embodiments, bill collection is triggered by the first access network device when the first terminal accesses the first network using a symmetrical scheme.

[0083] The processing of the first access network device may include: sending a third message to the first terminal, wherein the third message carries at least one of the following: the first communication billing value, second encrypted information, relevant information of the first communication bill, the identifier of the first access network device, and a third random number, wherein the second encrypted information is obtained by encrypting the relevant information of the first communication bill based on a second key between the first access network device and the first terminal.

[0084] Before sending the second message, the first terminal may further include: receiving a third message from the first access network device, wherein the third message carries at least one of the following: the first communication billing value, second encryption information, relevant information of the first communication bill, the identifier of the first access network device, and a third random number, wherein the second encryption information is obtained by encrypting the relevant information of the first communication bill based on a second key between the first access network device and the first terminal.

[0085] Then, the first terminal sends the second message to the first access network device; the first access network device receives the second message from the first terminal. After receiving the second message, the first access network device uploads the billing-related information of the first terminal to the blockchain.

[0086] The third random number can be generated by the first access network device, and the generation method is not limited in this embodiment. The function of the third random number can be to prevent replay attacks. The third random number can be the same as or different from the second random number.

[0087] The third message needs to carry either the second encrypted information or the plaintext related to the first communication bill. For example, the third message can carry the second encrypted information obtained by encrypting the content of the first communication bill using the second key, without carrying the plaintext of the first communication bill content. The second encrypted information can be represented as follows: The meanings of each parameter are the same as in the previous embodiments, and will not be repeated here.

[0088] After receiving the third message, the first terminal can calculate the first signature. The process for calculating the first signature is the same as in the previous embodiment and will not be described again. Alternatively, the first terminal can first verify the first communication billing value in the third message before calculating the first signature. The process for verifying the first communication billing value is also similar to the process for the first access network device to verify the first communication billing value, and will not be described again.

[0089] Optionally, if the third message carries the second encrypted information, the processing of the first terminal after receiving the third message may further include: decrypting the second encrypted information based on the second key to obtain the relevant information of the first communication bill.

[0090] The second message may also carry at least one of the following: a second verification code, the certificate of the first terminal, the identifier of the first access network device, and a second random number. The parameters for calculating the second verification code may include at least one of the following: a first signature, the certificate of the first terminal, the identifier of the first access network device, and a second random number. The specific method for calculating the second verification code is the same as in the aforementioned embodiments and will not be repeated here.

[0091] After receiving the second message, the first access network device can perform the processing of verifying the first signature and / or the processing of verifying the identity of the first terminal based on the second verification code and the second check code. The relevant descriptions of the above two verification processes are the same as those in the previous embodiments and will not be repeated.

[0092] The first access network device uploads the billing-related information of the first terminal to the blockchain for processing. The specific description of the billing-related parameters of the first terminal is the same as in the previous embodiment and will not be repeated.

[0093] In some possible implementations, the first terminal accesses the first network using a symmetrical scheme, the second access network device is an access network device belonging to the first network and serving the first terminal, and the first access network device is an access network device belonging to the first network but not serving the first terminal.

[0094] In some embodiments, when the first terminal accesses the first network using a symmetrical scheme, the first terminal triggers the reporting of a bill to the second access network device.

[0095] In this embodiment, the processing of the first terminal may include: sending a second message to the second access network device. The processing of the second access network device may include: receiving a second message from the first terminal, wherein the second message carries the first signature.

[0096] After receiving the second message, the second access network device may perform the following processing: send a first message to the first access network device, the first message carrying at least one of the following: the first communication billing value, the first signature.

[0097] Accordingly, the processing of the first access network device may include: receiving a first message from the second access network device, wherein the first message carries at least one of the following: the first communication billing value, the first signature, and the second access network device belonging to the first network and serving the first terminal. After receiving the first message, the first access network device uploads the billing-related information of the first terminal to the blockchain.

[0098] Optionally, the second message may also carry at least one of the following: a second verification code, the certificate of the first terminal, first encryption information, the identifier of the second access network device, a second random number, and information related to the first communication bill.

[0099] Except for the identification of the second access network device, the calculation of the second check code, and the calculation of the first encryption information, which are different from the previous embodiments, the relevant descriptions of other parameters that the second message may carry are the same as those in the previous embodiments, and will not be repeated here.

[0100] The second verification code is calculated based on the session key between the second access network device and the first terminal and at least one of the following parameters: the first signature, the certificate of the first terminal, the first encryption information, the identifier of the second access network device, the second random number, the first communication billing value, and relevant information of the first communication bill. Here, the specific calculation method of the second verification code is similar to that of the aforementioned embodiments, except that the second key in the aforementioned embodiments is replaced with the session key between the second access network device and the first terminal, while the essence of this session key is the same as the second key in the aforementioned embodiments.

[0101] The first encrypted information is obtained by encrypting at least one of the following based on the session key between the second access network device and the first terminal: relevant information of the first communication bill, and the first communication billing value.

[0102] Compared with the aforementioned embodiment where the first terminal triggers the billing report in the scenario where the first terminal accesses the first network using a symmetric scheme, the second message contains the same parameters except that the identifier of the first access network device is replaced with the identifier of the second access network device, and the generation of the first encrypted information and the calculation of the second verification code are replaced with the session key between the second access network device and the first terminal. Therefore, they will not be described in detail. The processing of the second access network device after receiving the second message is also the same except that the identifier of the first access network device is replaced with the identifier of the second access network device, and the decryption of the first encrypted information and the calculation of the second verification code are replaced with the session key between the second access network device and the first terminal. Therefore, they will not be described in detail.

[0103] In this embodiment, the second access network device may select the first access network device before sending the first message. The method of selecting the first access network device is not limited, as long as the first access network device is an access network device in the first network, it is within the protection scope of this embodiment.

[0104] The first message may also carry at least one of the following: a first verification code for verifying the identity of the second access network device, the certificate of the first terminal, the identifier of the second access network device, and a first random number, wherein the certificate of the first terminal carries the public key of the first terminal.

[0105] The first verification code is calculated based on the first key between the first access network device and the second access network device and at least one of the following parameters: the first communication billing value, the first signature, the certificate of the first terminal, the identifier of the second access network device, and the first random number.

[0106] The first random number can be generated by the second access network device. The purpose of this first random number is to prevent replay attacks. The first random number and the second random number can be the same or different; there is no limitation on their relationship.

[0107] Optionally, after receiving the first message, the first access network device can verify the first signature. The process of verifying the first signature is the same as in the previous embodiments and will not be described in detail.

[0108] Optionally, after receiving the first message, the first access network device may further include: verifying the identity of the second access network device based on the first verification code and the first check code, wherein the first verification code is calculated based on a first key between the first access network device and the second access network device and at least one of the following parameters: the first communication billing value, the first signature, the certificate of the first terminal, the identifier of the second access network device, and the first random number. Here, the calculation method and calculation parameters of the first verification code should be the same as those of the first check code, and therefore will not be repeated.

[0109] Verifying the identity of the second access network device based on the first verification code and the first check code may include at least one of the following: if the first verification code and the first check code are consistent, determine that the verification of the identity of the second access network device is successful or passed; if the first verification code and the first check code are inconsistent, determine that the verification of the identity of the second access network device fails or is not passed.

[0110] In this embodiment, the content of the billing-related information of the first terminal is the same as that in the previous embodiment, and will not be repeated.

[0111] In some embodiments, bill collection is triggered by a second access network device when the first terminal accesses the first network using a symmetrical scheme.

[0112] The processing of the second access network device may include sending a third message to the first terminal. The processing of the first terminal may further include receiving a third message from the second access network device, wherein the third message carries at least one of the following: the first communication billing value, second encryption information, information related to the first communication bill, the identifier of the second access network device, and a third random number.

[0113] Then, the first terminal sends a second message to the second access network device; the second access network device receives the second message from the first terminal. After receiving the second message, the second access network device can send a first message to the first access network device.

[0114] Accordingly, the processing of the first access network device may include: receiving a first message from the second access network device. After receiving the first message, the first access network device uploads the billing-related information of the first terminal to the blockchain.

[0115] In this embodiment, the calculation of the second encrypted information needs to be based on the session key between the second access network device and the first terminal. Apart from that, the other parameters are similar to the description of the third message in the previous embodiment, so they will not be repeated.

[0116] After receiving the third message on the first terminal side, the calculation of the first signature and / or verification of the first communication billing value, and other related processes are the same as in the above embodiments, and will not be described in detail.

[0117] In this embodiment, the second message may carry at least one of the following in addition to the first signature: a second verification code, the certificate of the first terminal, the identifier of the second access network device, and a second random number. The explanations of these parameters are the same as in the embodiment where the first terminal triggers bill collection in the scenario where the first terminal uses a symmetrical access scheme to access the first network, and will not be repeated here.

[0118] The processing of the second access network device after receiving the second message is similar to that in the aforementioned embodiments, and will not be described in detail.

[0119] The content carried in the first message, the calculation of billing aggregation information by the first access network device after receiving the first message, and the related processing of uploading the billing aggregation information to the blockchain are all the same as in the aforementioned embodiments, and will not be described again.

[0120] Next, various exemplary embodiments of the above symmetrical scheme will be described with reference to Figure 4.

[0121] One example may include the following process:

[0122] Step 401: Base station b1 sends a bill confirmation request (i.e., the aforementioned third message) to UEa (i.e., the first terminal).

[0123] The third message can be represented as follows: Base station b1 → UEa: Among them, the identifier (ID) of base station b1 b1 ) indicates its identity, N is the third random number in the aforementioned embodiment (used to prevent replay attacks), and UEa's micro-billing uses K. a-b1 Encryption is used to protect the contents of the bill from being leaked and to authenticate the identity of base station b1. Com (price) is the promised value of price in the micro-bill (i.e., the first communication billing value), where K a-b1 This is the symmetric key (or session key) between UEa and base station b1.

[0124] Step 402: After receiving the bill confirmation request, UEa decrypts it, then signs Com(price) to obtain the first signature, and sends a second message to base station b1, which carries the first signature.

[0125] The second message can be represented as follows: UEa → Base station b1:

[0126] Where N+1 is the second random number used to prevent replay attacks, ID b1 This indicates that the message receiver is base station b1, Cert A-a It's a UEa certificate, Sig va (Com(price) is the first signature of UEa on Com(price)) The second checksum is used to prevent messages from being tampered with and to authenticate the identity of UEa.

[0127] Step 403: After receiving the second message, base station b1 randomly selects a base station b2 and sends a first message to it, which carries a first signature.

[0128] Specifically, the first message can be represented as follows: Base station b1 → Base station b2:

[0129] Among them, ID b1 Identify yourself; N+2 is the first random number to prevent replay attacks; Cert A-a This is UEa's certificate (which will be uploaded to the chain by base station b2 to prove the validity of its public key so that other nodes on the chain can verify the validity of the signature), and Com (price) is the commitment value of price in the micro-bill. The first checksum is used to prevent message tampering and to authenticate b1's identity. K b1-b2 This is the first key between base station b1 and base station b2. Then, base station b2 can complete the on-chain process: base station b2 puts the commitment value Com(price) of price in the micro-bill on the chain, and at the same time, base station b2's signature (i.e., the second signature) and the first signature of Com(price) are also put on the chain. Base station b2's certificate can also be put on the chain.

[0130] In the above examples, base station b1 can be the second access network device in the aforementioned embodiments, and base station b2 can be the first access network device in the aforementioned embodiments. In one case, UEa can generate Com(price) and directly send the bill and Com(price) along with the second message to base station b1. In this case, step 401 can be ignored, that is, only steps 402 to 403 need to be executed. In another case, if the base station needs to generate Com(price) and initiate bill collection, then steps 401 to 403 need to be executed.

[0131] Another example may include the following process:

[0132] Steps 401 and 402 remain unchanged. After completing step 402, step 404 is executed: After receiving the second message, base station b1 completes the on-chain process. That is, base station b1 completes the on-chain process by uploading the promised value Com(price) of price in the micro-bill to the blockchain. At the same time, base station b1's signature (second signature), first signature, and base station b1's certificate for Com(price) are also uploaded to the blockchain.

[0133] In this example, base station b1 can be the first access network device in the aforementioned embodiment. In one case, UEa can generate Com(price) and directly send the bill and Com(price) along with the second message to base station b1. In this case, step 401 can be ignored, that is, only steps 402 and 404 need to be executed. In another case, if the base station needs to generate Com(price) and initiate bill collection, then steps 401, 402, and 404 need to be executed.

[0134] To ensure compatibility with existing roaming schemes and simplify billing, in the two examples shown in Figure 4, core network A (i.e., the second core network device of the second network) issues a dedicated billing certificate to its subscribed UEa, allowing it to sign and confirm its own charges. Each time UEa uses spectrum resources, it generates a micro-bill, commits to the price in the micro-bill, and both UEa and base station b1 sign Com(price). Base station b1 then directly uploads the data to the blockchain. Furthermore, considering that directly uploading the data to the blockchain by b1 would expose UEa's base station usage path under core network B and expose the user's location privacy information, base station b1 randomly selects another base station b2, which then uploads Com(price) and Sign... b2 [Com(price)]、Sig va [Com(price)]、Cert A-a Cert b2The data is uploaded to the blockchain for other nodes on the chain to aggregate and verify. Once verified, a smart contract is triggered for billing. This also serves as a form of obfuscation, protecting user privacy.

[0135] In some possible implementations, the first terminal uses an asymmetric scheme to access the first network, and the first access network device belongs to the first network and serves the first terminal.

[0136] In some embodiments, when the first terminal accesses the first network using an asymmetric scheme, the first terminal triggers the reporting of a bill to the first access network device.

[0137] The first terminal sends the second message to the first access network device. Correspondingly, the first access network device receives the second message from the first terminal. After receiving the second message, the first access network device uploads the billing-related information of the first terminal to the blockchain.

[0138] The second message may also carry at least one of the following: a first credential for verifying the first terminal's permission to use the resources of the first network, the identifier of the first access network device, a second random number, the first communication billing value, information related to the first communication bill of the first terminal under the first network, and third encrypted information.

[0139] The descriptions of the identifier of the first access network device, the second random number, the first communication billing value, and the relevant information of the first communication bill are the same as those in the previous embodiments and will not be repeated.

[0140] The first credential carries at least one of the following: a fifth signature for verifying the first terminal's permission to use the second network to obtain authorized resources of the first network, and a sixth signature for verifying the second network's permission to use the resources of the first network.

[0141] The first credential further includes at least one of the following: a temporary identifier of the first terminal, or a temporary public key of the first terminal.

[0142] Optionally, the fifth signature is calculated based on the private key of the second core network device and at least one of the following: the temporary identifier of the first terminal, the temporary public key of the first terminal, and the second credential.

[0143] The sixth signature is carried by the second certificate in the first certificate.

[0144] The second credential also carries at least one of the following: the identifier of the second core network device, the public key of the second core network device, the identifier of the first core network device, the public key of the first core network device, and information authorizing the second network to use resources of the first network.

[0145] Specifically, the sixth signature is calculated based on the private key of the first core network device and at least one of the following: the identifier of the first core network device, the public key of the first core network device, the identifier of the second core network device in the second network, the public key of the second core network device, and information on the resources of the first network authorized for use by the second network.

[0146] In some possible examples, the first credential is issued by the second core network device to the first terminal, and the second credential is generated by the first core network device for the second core network device and uploaded to the blockchain. This second credential can also be referred to as the first-level credential of the asymmetric scheme, and the first credential can also be referred to as the second-level credential of the asymmetric scheme.

[0147] The third encrypted information is obtained by encrypting at least one of the following based on the public key of the first access network device: the relevant information of the first communication bill, and the first communication billing value.

[0148] Optionally, the second message may carry a first signature, an identifier of the first communication bill, and may also carry at least one of the following: a first credential, an identifier of the first access network device, a second random number, and the first billing parameter.

[0149] Optionally, the second message may carry a first signature, third encrypted information obtained by encrypting the relevant information of the first communication bill based on the public key of the first access network device, and the second message may also carry at least one of the following: a first credential, the identifier of the first access network device, a second random number, and the first communication billing value.

[0150] It should be understood that the above is merely an illustrative example, and the third encrypted information and the second message are not limited to the possibilities in the examples above, nor are they limited or exhaustive.

[0151] The first access network device can verify the first signature after receiving the second message. The process of verifying the first signature is the same as in the previous embodiments and will not be described again.

[0152] Optionally, the first access network device can also verify the first communication billing value carried in the second message. The process of verifying the first communication billing value is the same as in the aforementioned embodiments and will not be described again.

[0153] Optionally, the processing after the first access network device receives the second message may further include: decrypting the third encrypted information based on the public key of the first access network device to obtain at least one of the following: relevant information of the first communication bill, and the first communication billing value.

[0154] Optionally, the processing of the first access network device after receiving the second message may further include: verifying the fifth and sixth signatures in the first credential, and if the verification of the fifth and sixth signatures is successful, determining that the first terminal has the right to use the resources of the first network.

[0155] The verification of the sixth signature can be: based on the public key of the first core network device, the sixth signature, and at least one of the following information, verifying the second network's permission to use the resources of the first network: the identifier of the first core network device, the public key of the first core network device, the identifier of the second core network device, the public key of the second core network device, and information authorizing the second network to use the resources of the first network.

[0156] The verification of the fifth signature can be based on the public key of the second core network device, the fifth signature, and at least one of the following information to verify the first terminal's permission to use the second network to obtain authorized resources of the first network: the temporary identifier of the first terminal, the temporary public key of the first terminal, and the second credential.

[0157] The processing order of the first access network device verifying the first signature, decrypting the third encrypted information, verifying the first communication billing value, and verifying the first credential is not limited.

[0158] The billing-related information of the first terminal includes: the first communication billing value, a first signature for determining that the first terminal acknowledges the first communication billing value, and a second signature for determining that the first access network device acknowledges the first communication billing value.

[0159] Optionally, the billing-related information of the first terminal may also include: the certificate of the first access network device.

[0160] Optionally, the billing information of the first terminal may further include: the first credential. Here, the function of uploading the first credential to the blockchain is mainly for the on-chain nodes of the blockchain to determine whether the first terminal has the right to use the resources of the first network and to obtain the public key of the first terminal based on the first credential.

[0161] In some embodiments, in scenarios where the first terminal uses an asymmetric scheme to access the first network, the collection of bills is triggered by the first access network device.

[0162] The processing of the first access network device may include: sending a third message to the first terminal, wherein the third message carries a fourth signature, wherein the fourth signature is calculated based on the private key of the first access network device to obtain fourth encrypted information, and the fourth encrypted information is obtained by encrypting at least one of the relevant information of the first communication bill and the first communication billing value based on the public key of the first terminal.

[0163] The processing of the first terminal may further include: receiving a third message from the first access network device, wherein the third message carries a fourth signature, wherein the fourth signature is calculated based on the private key of the first access network device to obtain fourth encrypted information, and the fourth encrypted information is obtained by encrypting at least one of the relevant information of the first communication bill and the first communication billing value based on the public key of the first terminal.

[0164] Then, the first terminal sends a second message to the first access network device. After receiving the second message from the first terminal, the first access network device uploads the billing-related information of the first terminal to the blockchain.

[0165] Optionally, the third message may further carry at least one of the following: the identifier of the first access network device, a third random number, and the certificate of the first access network device. The third random number may be generated by the first access network device.

[0166] For example, the fourth encrypted information can be obtained by encrypting the relevant information of the first communication bill and the first communication charge value based on the public key of the first terminal. For instance, the fourth encrypted information can be represented as Enc pkva [bil,Com(price)], where pkva is the public key of the first terminal, and the meanings of the other parameters are the same as in the previous embodiments, and will not be repeated.

[0167] The fourth signature can be calculated as follows: using a signature algorithm, the fourth signature is calculated based on the private key of the first access network device on the fourth encrypted information. For example, the calculation of the fourth signature can be expressed by the following formula: Sig b1 REnc pkva [bill,Com(price)]S, where b1 represents the private key of the first access network device. Alternatively, the fourth signature can be calculated as follows: perform a hash calculation based on the fourth encrypted information to obtain a fourth hash value; encrypt the fourth hash value based on the private key of the first access network device to obtain the fourth signature.

[0168] In this case, the third message may carry a fourth signature; furthermore, the third message may also carry at least one of the following: the identifier of the first access network device, a third random number, the certificate of the first access network device, and fourth encrypted information.

[0169] For example, the fourth encrypted information can be obtained by encrypting the relevant information of the first communication bill based on the public key of the first terminal. In this case, the first communication billing value can be carried in plaintext in the third message; for example, the third message may carry a fourth signature. Furthermore, the third message may also carry at least one of the following: the identifier of the first access network device, a third random number, the certificate of the first access network device, the first communication billing value, and the fourth encrypted information. The calculation of the fourth signature is similar to the previous example and will not be described in detail.

[0170] Optionally, the processing after the first terminal receives the third message may further include: if the third message carries fourth encrypted information, then decrypting the fourth encrypted information based on the public key of the first terminal to obtain at least one of the relevant information of the first communication bill and the first communication billing value.

[0171] Optionally, after receiving the third message, the first terminal can also verify the fourth signature. If the first terminal verifies the fourth signature successfully, the authentication of the first access network device is determined to be successful; otherwise, the authentication of the first access network device is determined to be unsuccessful.

[0172] If the third message carries fourth encrypted information, the processing of the first terminal may include: verifying the fourth signature based on the public key of the first access network device and the fourth encrypted information. For example, the verification of the fourth signature may involve: using a signature verification algorithm to decrypt the fourth signature based on the public key of the first access network device to obtain a fourth parameter to be verified; if the fourth parameter to be verified is the same as the fourth encrypted information, the fourth signature verification is confirmed to be successful. Alternatively, the verification of the fourth signature may involve: performing a hash calculation based on the fourth encrypted information to obtain a fourth verification hash value; decrypting the fourth signature based on the public key of the first access network device to obtain a fourth decrypted value; if the fourth decrypted value and the fourth verification hash value are the same, the fourth signature verification is confirmed to be successful.

[0173] In one scenario, the processing by the first terminal may include: encrypting at least one of the relevant information of a locally generated first communication bill and a locally generated first communication billing value using the first terminal's public key to obtain verification information; and verifying the fourth signature based on the verification information and the public key of the first access network device. For example, verifying the fourth signature may involve: using a signature verification algorithm to decrypt the fourth signature using the public key of the first access network device to obtain a fourth parameter to be verified; and determining that the fourth signature verification is successful if the fourth parameter to be verified matches the verification information. Alternatively, verifying the fourth signature may involve: performing a hash calculation based on the verification information to obtain a fourth verification hash value; decrypting the fourth signature using the public key of the first access network device to obtain a fourth decrypted value; and determining that the fourth signature verification is successful if the fourth decrypted value and the fourth verification hash value match. The process of encrypting at least one of the relevant information of the locally generated first communication bill and the locally generated first communication billing value based on the public key of the first terminal to obtain the verification information should be the same as the process of the first access network device calculating the fourth encrypted information. For example, if the fourth encrypted information is obtained by encrypting the relevant information of the first communication bill and the first communication billing value, then the verification information should also be obtained by encrypting the relevant information of the locally generated first communication bill and the locally generated first communication billing value of the first terminal.

[0174] In addition to carrying the first signature, the second message in this embodiment may also carry at least one of the following: a first credential, the identifier of the first access network device, and a second random number.

[0175] After receiving the second message, the first access network device can perform the verification of the first signature. This verification process is the same as that in the previous embodiment and will not be described in detail.

[0176] In this embodiment, the specific description of the billing-related parameters of the first terminal, the calculation of billing aggregation information by the first access network device, and the related processing of uploading the billing aggregation information to the blockchain are the same as in the previous embodiment, and will not be repeated here.

[0177] In some possible implementations, the first terminal accesses the first network using an asymmetric scheme, the second access network device is an access network device belonging to the first network and serving the first terminal, and the first access network device is an access network device belonging to the first network but not serving the first terminal.

[0178] In some embodiments, when the first terminal uses an asymmetric scheme to access the first network, the first terminal triggers the reporting of a bill to the second access network device.

[0179] In this embodiment, the processing of the first terminal can be: sending a second message to the second access network device. Correspondingly, the processing of the second access network device can include: receiving a second message from the first terminal, wherein the second message carries the first signature. After receiving the second message, the second access network device can send a first message to the first access network device, the first message carrying at least one of the following: the first communication billing value, and the first signature.

[0180] Accordingly, the processing of the first access network device may include: receiving a first message from the second access network device, wherein the first message carries at least one of the following: the first communication billing value, and the first signature. After receiving the first message, the first access network device uploads the billing-related information of the first terminal to the blockchain.

[0181] The second message may also carry at least one of the following: a first credential for verifying the first terminal's permission to use the resources of the first network, an identifier of the second access network device, a second random number, the first communication billing value, information related to the first communication bill of the first terminal under the first network, and third encrypted information.

[0182] The third encrypted information is obtained by encrypting at least one of the following based on the public key of the second access network device: relevant information of the first communication bill, and the first communication billing value. The relationship between the third encrypted information carried in the second message and the plaintext is the same as that described in the aforementioned asymmetric key embodiment, and will not be repeated here.

[0183] Compared with the aforementioned asymmetric scheme in which the first terminal directly triggers the reporting of bills to the first access network device, the second message in this embodiment is identical except that the identifier of the first access network device is replaced with the identifier of the second access network device, and the generation of the third encrypted information is replaced with the public key of the second access network device. Therefore, it will not be described in detail. The processing of the second access network device after receiving the second message in this embodiment is identical except that the identifier of the first access network device is replaced with the identifier of the second access network device, and the decryption of the third encrypted information is replaced with the public key of the second access network device. Therefore, it will not be described in detail.

[0184] In this embodiment, the first access network device can be selected before the second access network device sends the first message.

[0185] Optionally, the first message may also carry at least one of the following: a third signature for verifying the identity of the second access network device, a certificate of the second access network device, a first credential for verifying the first terminal's permission to use the resources of the first network, an identifier of the second access network device, and a first random number, wherein the certificate of the second access network device carries the public key of the second access network device.

[0186] The specific calculation method for the third signature can be as follows: The third signature is calculated based on the private key of the second access network device and the first signature. For example, the calculation of the third signature can be: using a signature algorithm, based on the private key of the second access network device, the first signature is calculated. For instance, the calculation of the third signature can be expressed as: Sig b1 [Sig va [Com(price)]]], where b1 represents the private key of the second access network device. For example, the calculation of the third signature can be as follows: perform a hash calculation based on the first signature to obtain the third hash value; encrypt the third hash value based on the private key of the second access network device to obtain the third signature.

[0187] The description of the certificate of the second access network device is similar to that of the certificate of the first access network device in the previous embodiment, and will not be repeated here.

[0188] The first random number can be generated by the second access network device.

[0189] The processing after the first access network device receives the first message further includes: verifying the identity of the second access network device based on the public key of the second access network device, the first signature, and the third signature. For example, verifying the third signature may involve: using a signature verification algorithm to decrypt the third signature based on the public key of the second access network device to obtain a third parameter to be verified; if the third parameter to be verified is the same as the first signature, the third signature verification is confirmed to be successful. Alternatively, verifying the third signature may involve: performing a hash calculation based on the first signature to obtain a third verification hash value; decrypting the third signature based on the public key of the second access network device to obtain a third decrypted value; if the third decrypted value and the third verification hash value are the same, the third signature verification is confirmed to be successful.

[0190] After the first access network device completes the above processing, it can upload the billing information of the first terminal to the blockchain. The content of the billing information of the first terminal and the related instructions for uploading to the blockchain are the same as those in the aforementioned asymmetric scheme embodiment, and will not be repeated here.

[0191] In some embodiments, in a scenario where the first terminal accesses the first network using an asymmetric scheme, the billing process is triggered by the second access network device.

[0192] In this embodiment, the processing of the second access network device may include sending a third message to the first terminal. The processing of the first terminal may further include receiving a third message from the second access network device, wherein the third message carries a fourth signature, wherein the fourth signature is calculated based on the private key of the second access network device on fourth encrypted information, and the fourth encrypted information is obtained by encrypting at least one of the relevant information of the first communication bill and the first communication billing value based on the public key of the first terminal.

[0193] Then, the first terminal sends a second message to the second access network device. The second access network device receives the second message from the first terminal. After receiving the second message, the second access network device can send a first message to the first access network device. The first access network device receives the first message from the second access network device; after receiving the first message, the first access network device uploads the billing-related information of the first terminal to the blockchain.

[0194] Optionally, the third message may also carry at least one of the following: the identifier of the second access network device, a third random number, and the certificate of the second access network device. In this embodiment, apart from the calculation of the fourth signature being replaced by the private key of the second access network device, the descriptions of other relevant parameters of the third message are similar to those in the aforementioned asymmetric scheme embodiments, and therefore will not be repeated.

[0195] The processing from receiving the third message on the first terminal side until the generation of the second message is the same as in the above asymmetric scheme implementation, and will not be described in detail.

[0196] Optionally, in addition to carrying the first signature, the second message may also carry at least one of the following: a first credential, the identifier of the second access network device, and a second random number. The explanation of each parameter is similar to that in the aforementioned embodiments and will not be repeated here.

[0197] After receiving the second message, the second access network device can verify the first signature.

[0198] The processing of the first access network device after receiving the first message is the same as in the previous embodiments and will not be repeated. The processing of the first access network device uploading the billing aggregation information to the blockchain, and the processing of the on-chain nodes of the blockchain, are all the same as in the previous embodiments and will not be described in detail.

[0199] Next, an exemplary embodiment of the above asymmetric scheme will be described with reference to Figure 5.

[0200] Step 501: Base station b1 sends a bill confirmation request (i.e., the aforementioned third message) to UEa (the first terminal).

[0201] The third message can be represented as follows: Base station b1 → UEa: Cert b1 ID va ,N,Sig b1 [Enc pkva [bill,Com(price)]].

[0202] Among them, Cert b1 This is the certificate of base station b1, used to prove the validity of its public key so that a can verify the validity of the signature; ID va It is the identifier (or temporary identifier) ​​of UEa used to indicate that the message recipient is UEa; N is a third random number to prevent replay attacks; ig b1 [Enc pkva [bill, Com(price)]] is the fourth signature, used to transfer the micro-bill of UEa and the commitment value Com(price) of price in the bill using pk. va The bill is obtained by encrypting and signing (i.e., using UEa's public key). The encryption is to protect the contents of the bill from being leaked, and the fourth signature is to achieve non-repudiation and to authenticate the identity of base station b1.

[0203] Step 502: After receiving the bill confirmation request, UEa decrypts it, verifies that the information of bill and Com (price) is correct, signs Com (price) to obtain the first signature, and sends a second message to base station b1. The second message carries the first signature, UEa's secondary certificate (or secondary credential, i.e. the first credential in the aforementioned embodiment), etc.

[0204] The second message can be represented as follows: UEa→Base station b1:Cert B-A-a ID b1 ,N+1,Sig va [Com(price)]. Where, Cert B-A-a It is a Level 2 certificate of UEa, ID b1 This indicates that base station b1 is the message receiver, N+1 is a second random number to prevent replay attacks, and Sig va [Com(price)] is UEa's first signature of Com(price).

[0205] UEa can generate Com(price) and directly send bill and Com(price) information. In this case, UEa sends the message directly. Otherwise, in the second message sent to base station b1...

[0206] Step 503: Upon receiving the second message, base station b1 first verifies the signature's correctness and then decrypts it. It then randomly selects a base station b2 and sends it the first message, which carries the first signature Sig.va [Com(price)], a Level 2 certificate for UEa.

[0207] Specifically, the first message can be represented as follows: Base station b1 → Base station b2: Cert b1 ,ID b2 ,N+2,Cert B-A-a Sig b1 [Sig va [Com(price)]]]. Here, Certb1 is the certificate of base station b1, used to prove the validity of its public key so that b2 can verify the validity of the signature; ID b2 This indicates that the message was sent to b2; N+2 is a random number to prevent replay attacks. b1 [Sig va [Com(price)]] is the base station b1 pair Sig va The signature of [Com(price)] is used to achieve non-repudiation and to authenticate the identity of b1.

[0208] Step 504: Base station b2 sends the commitment value Com(price) and the second signature Sig b2 [Com(price)]、First Signature Sig va [Com(price)], UEa's secondary certificate Cert B-A-a Cert certificate for base station b2 b2 It is uploaded to the blockchain for other nodes on the chain to aggregate and verify, so as to trigger the smart contract for billing after the verification is successful.

[0209] In the above examples, base station b1 can be the second access network device in the aforementioned embodiments, and base station b2 can be the first access network device in the aforementioned embodiments. In one case, UEa can directly send bill and Com (price) information. In this case, step 501 is not executed, only steps 502 to 504 are executed. In another case, the bill collection is initiated by base station b1, then steps 501 to 504 need to be executed.

[0210] In some other possible examples, base station b1 can be the first access network device in the aforementioned embodiments. In one case, UEa can directly send bill and Com(price) information. In this case, step 501 is not executed, only step 502 is executed. Then, upon receiving the second message, base station b1 first verifies the signature's correctness, then decrypts it, and then performs the on-chain processing. In another case, base station b1 initiates bill collection. In this case, steps 501 to 502 need to be executed. Then, upon receiving the second message, base station b1 first verifies the signature's correctness, then decrypts it, and then performs the on-chain processing. The on-chain processing performed by base station b1 refers to storing the commitment value Com(price) and the second signature Sig... b1 [Com(price)]、First Signature Sig va [Com(price)], UEa's secondary certificate Cert B-A-a Certification for base station b1 b1 Upload it to the blockchain together.

[0211] In other words, each time UEa uses spectrum resources, it generates a micro-bill, commits to the price in the micro-bill, and then both UEa and base station b1 sign Com(price). Base station b1 directly uploads the data to the blockchain. However, since directly uploading the data to the blockchain by b1 would expose the base station usage path of UEa under core network B, base station b1 randomly selects another base station b2 of B to upload the data, serving as an obfuscation function. That is, base station b2 copies Com(price) and Sig... b2 [Com(price)]、Sig va [Com(price)]、Cert B-A-a Cert b2 It is uploaded to the blockchain for other nodes on the chain to aggregate and verify. Once the verification is successful, the smart contract is triggered for billing.

[0212] In some possible embodiments, the processing of the first access network device further includes: uploading billing aggregation information to the blockchain, wherein the billing aggregation information is used to verify the aggregated communication costs of one or more terminals belonging to the second network under the first access network device, the billing aggregation information is obtained by aggregating the communication billing values ​​of the one or more terminals under the first network, and the one or more terminals include the first terminal.

[0213] Specifically, the billing aggregation information is used by the blockchain's on-chain nodes to verify the aggregated communication costs of one or more terminals belonging to the second network under the first access network device.

[0214] Specifically, the calculation method for the billing aggregation information may be as follows: extract one or more communication billing values ​​for each terminal belonging to the second network within a first time period under the first network, and aggregate the total communication billing values ​​of each terminal under the first network to obtain billing aggregation information. This billing aggregation information is related to the aggregated communication cost and the aggregated random number. For example, the billing aggregation information may include the aggregated communication cost and the aggregated random number, or it may be a commitment value corresponding to the aggregated communication cost and the aggregated random number. The first time period may be set or determined according to actual circumstances.

[0215] Referring to Figure 6 as an example, suppose that within a certain time interval (i.e., the first time period), user a (first terminal) of core network A (i.e., the second core network device under the second network) generates multiple micro-bills (i.e., multiple communication bills, which may include the first communication bill in the aforementioned embodiment) under the first network; the amount value Price (i.e., the communication fee in each communication bill) of each micro-bill under the first network of UEa are a1, a2, a3, ..., and the random number corresponding to each micro-bill is r. a2 ,r a2 ,r a3 ...; User c (i.e., another terminal) in core network A also generated multiple micro-bills under the first network. The price of each micro-bill under the first network is b1, b2, b3..., and the random number corresponding to each micro-bill is r. b1 ,r b2 ,r b3 ...; and so on, the price of each micro-bill for user n in the first network is n1, n2, n3..., and the random number corresponding to each micro-bill is r. n1 ,r n2 ,r n3 ,……

[0216] Step 601: The base station (e.g., the first access network device) uploads the billing aggregation information to the blockchain. This billing aggregation information includes the aggregated price and the aggregated r, thereby triggering the smart contract.

[0217] Specifically, the base station can calculate the billing aggregation information based on the communication billing value (commit(price)) corresponding to each micro-bill of each user. Specifically, due to the additive homomorphic property of Pedersen commitments, the calculation of billing aggregation information can be expressed as: Commit(a1, r a1 )×Commit(a2,r a2 )×Commit(a3,r a3)×……×Commit(c1,r c1 )×Commit(c2,r c2 )×Commit(c3,r c3 )×……×Commit(n1,r n1 )×Commit(n2,r n2 )×Commit(n3,r n3 )×……=Commit(∑ai+∑ci+……+∑ni,∑r ai +∑r ci +……+∑r ni = Commit(aggregatePrice, aggregater).

[0218] Step 602: After the base station uploads the billing aggregation information to the blockchain, the on-chain nodes of the blockchain trigger a smart contract to charge the core network A (the second core network device of the second network). Specifically, the processing of the on-chain nodes of the blockchain may include: extracting one or more communication billing values ​​of each terminal belonging to the second network uploaded by the first access network device within the first time period; aggregating all communication billing values ​​of each terminal under the first network to obtain billing aggregation verification information; if the billing aggregation verification information is the same as the billing aggregation information, it is determined that the billing aggregation information has been verified and the smart contract is triggered to charge. Here, triggering the smart contract to charge can refer to the on-chain nodes of the blockchain triggering a smart contract to charge the second core network device of the second network.

[0219] In this way, all micro-bills are collected by the base station (such as base station b1 or base station b2 in the examples of Figure 4 or Figure 5 above), and the base station publishes the final aggregated price and aggregated value r on the blockchain, protecting the privacy of users' account information. On-chain nodes verify whether the local aggregation result is consistent with the aggregated price and aggregated value r published by the base station. After successful verification, the smart contract is triggered to process the payment.

[0220] Optionally, the on-chain nodes of the blockchain can also verify the first and second signatures in the billing information received from each terminal (any terminal, such as the first terminal) to determine that the communication billing value of the terminal is acceptable to both the terminal and the first access network device. The method by which the on-chain nodes of the blockchain verify the first signature is the same as the process by which the first access network device verifies the first signature in the aforementioned embodiment, and will not be described in detail here.

[0221] In some possible implementations, in the scenario where the first terminal uses a symmetric scheme to access the first network, the first terminal needs to obtain a symmetric key (or session key) (such as the second key in the aforementioned embodiment) between itself and the access network device serving the first terminal under the first network.

[0222] This embodiment takes the access network device serving the first terminal under the first network as the first access network device as an example for subsequent explanation, and will not be explained again below.

[0223] In some embodiments, the processing of the first terminal further includes one of the following: sending a key allocation request to the first core network device, wherein the key allocation request carries a third credential for authenticating the first terminal's permission to use resources of the first network; and sending the key allocation request to the first access network device. Correspondingly, the processing of the first terminal further includes one of the following: receiving fifth encrypted information from the first core network device, wherein the first core network device belongs to the first network; and receiving fifth encrypted information from the first access network device.

[0224] The third credential is generated based on the fifth key between the first core network device and the second core network device, and the second core network device belongs to the second network.

[0225] The third credential is issued by a second core network device in the second network. The specific calculation method for the third credential may include: encrypting at least one of the fourth key between the first terminal and the first core network device, and the temporary identifier of the first terminal, based on the fifth key between the first and second core network devices, to obtain the third credential. For example, the third credential can be represented as: Ticket a K is a third document (or a second-level document in a symmetrical scheme), a-B That is, the fourth key, ID va It is a temporary identifier for the first terminal, K. A-B This is the fifth key.

[0226] Before the second core network device issues the third credential to the first terminal, the first and second core network devices need to first perform a process to generate and issue a fourth credential. This fourth credential may be generated and uploaded to the blockchain by the first core network device, and then obtained from the blockchain by the second core network device. This fourth credential can be used to indicate authorization for the second network to use the resources of the first network. The fourth credential includes a fifth key encrypted based on the public key of the second core network device. In some possible examples, this fourth credential can also be referred to as a first-level credential of a symmetric scheme, and the third credential can also be referred to as a second-level credential of a symmetric scheme.

[0227] Optionally, the key distribution request issued by the first terminal may also carry at least one of the following: a fifth check code for verifying the identity of the first terminal, an identifier of the first resource of the first network to be used, an identifier of one or more terminals, an identifier of the first group, an identifier of the first access network device, an identifier of the first core network device, and an eighth random number.

[0228] Among them, one or more terminals include a first terminal. The one or more terminals may belong to a first group (i.e., the first terminal also belongs to the first group), and the home network of the one or more terminals is the second network.

[0229] Optionally, the fifth verification code is calculated based on the fourth key and at least one of the following: the identifier of the first resource, the identifier of one or more terminals, the identifier of the first group, the identifier of the first access network device, the identifier of the first core network device, the eighth random number, and the third credential.

[0230] When the first terminal sends a key allocation request to the first access network device (e.g., via an AS message), the key allocation request carries the identifier of the first access network device; when the first terminal sends a key allocation request to the first core network device (e.g., via a NAS message), the key allocation request carries the identifier of the first core network device.

[0231] In one embodiment, the first terminal sends a key allocation request to the first access network device.

[0232] The processing after the first access network device receives a key allocation request further includes: forwarding the key allocation request of the first terminal to the first core network device, wherein the key allocation request carries a third credential for authenticating the first terminal's right to use the resources of the first network; receiving a key allocation message from the first core network device, wherein the first core network device belongs to the first network, and the key allocation message carries at least one of the following: one or more third keys, wherein the one or more third keys are keys between one or more terminals and the first access network device, wherein the one or more terminals include the first terminal, and the one or more third keys include a second key between the first access network device and the first terminal; and fifth encryption information, wherein the fifth encryption information is obtained by encrypting the one or more third keys based on the fourth key.

[0233] The key distribution request forwarded by the first access network device to the first core network device may also carry at least one of the following: a seventh check code for verifying the identity of the first access network device, an identifier of the first resource, an identifier of one or more terminals, an identifier of the first group, an identifier of the first access network device, and an eighth random number.

[0234] The seventh verification code is calculated based on the seventh key between the first access network device and the first core network device and at least one of the following: the identifier of the first resource, the identifier of one or more terminals, the identifier of the first group, the identifier of the first access network device, the eighth random number, and the third credential.

[0235] Optionally, the processing by the first core network device after receiving the key allocation request can be based on authenticating the first terminal using a third credential. Specifically, this can include: decrypting the third credential using the fifth key to obtain a decryption result; and authenticating the first terminal based on the decryption result. Authenticating the first terminal based on the decryption result can include: determining successful authentication of the first terminal if the decryption result is correct; and determining authentication failure if the decryption result is incorrect. Specifically, the decryption result includes at least one of the following: the fourth key, and the identifier of the first terminal (i.e., the temporary identifier of the first terminal). Further, if the decryption result is correct, the first core network device can save the content or parameters contained in the decryption result.

[0236] Optionally, after receiving the key allocation request from the first access network device, the first core network device may perform the following processing: verify the message integrity of the key allocation request based on the seventh checksum. The verification method may include: verifying the message integrity of the authentication request based on the seventh verification code and the seventh checksum. The calculation method and parameters used by the first core network device to calculate the seventh verification code should be the same as those used by the first access network device to calculate the seventh checksum, and will not be repeated here.

[0237] Optionally, if the key allocation request only includes the identifier of the first terminal, then the first core network device only generates the second key. The second key can be generated by using the second calculation method to calculate based on the fourth key at least one of the following: the temporary identifier of the first terminal, the identifier of the first access network device, the tenth random number, and the count value.

[0238] The second calculation method can be configured according to the actual situation, and may include at least one of the following: KDF (Key Derivation Function), Key Derivation Function, Advanced Encryption Standard (AES), SNOW 3G, ZUC, XOR calculation, direct connection calculation, etc.

[0239] For example, the calculation of the second key can be expressed as: Ka-b = KDF Ka-B(IDva, IDb, Nonce or counter), where Ka-b is the second key, Ka-B is the fourth key, IDva is the temporary identifier of the first terminal, IDb is the identifier of the first access network device, Nonce is the tenth random number, and Counter is the counter value. The tenth random number and the counter value are generated by the first core network device, and either the tenth random number or the counter value can be used in the calculation of generating the second key.

[0240] Optionally, if the key allocation request includes the identifiers of multiple terminals, the first core network device generates multiple third keys. Taking the allocation of a third key to a second terminal among one or more terminals as an example, the third key allocated to the second terminal can be generated by using a second calculation method based on the fourth key to calculate at least one of the following: the temporary identifier of the second terminal, the identifier of the first access network device, the identifier of the first group, the tenth random number, and the count value.

[0241] For example, the calculation of the third key can be expressed as: Ka-b-2 = KDF Ka-B (IDva2, IDb, IDg, Nonce or counter), where Ka-b-2 is the third key assigned to the second terminal, Ka-B is the fourth key, IDva2 is the temporary identifier of the second terminal, IDb is the identifier of the first access network device, IDg is the identifier of the first group, Nonce is the tenth random number, and Counter is the count value.

[0242] When the first core network device distributes one or more third keys (i.e., one or more session keys) to the first access network device via a key distribution message, it also carries the key identifier corresponding to each third key in the key distribution message. For example, the first core network device can distribute session keys K between i users (i.e., i terminals) and base station b. a-b (1…i), Key identifier ID corresponding to each session key Ka-b (1…i), where i is an integer greater than or equal to 1, and the key identifier corresponding to each session key is used to indicate or associate with or correspond to the session key, such as ID. Ka-b 1 is used to indicate the session key K a-1 1.

[0243] Optionally, the fifth encrypted information can be obtained by encrypting one or more third keys and the key identifier corresponding to each third key based on the fourth key.

[0244] Optionally, the key allocation message may also carry a fifth verification code. The calculation method of the fifth verification code should be the same as that of the fifth verification code in the aforementioned embodiments, and therefore will not be repeated. After the first access network device receives the key allocation message, the method further includes: verifying the identity of the first terminal based on the fifth verification code and the fifth verification code. For example, if the fifth verification code and the fifth verification code match, the authentication of the first terminal is determined to be successful; if the fifth verification code and the fifth verification code do not match, the authentication of the first terminal is determined to be unsuccessful.

[0245] Optionally, after receiving the key allocation message from the first core network device, the first access network device may further include: sending the fifth encrypted information to the first terminal. Correspondingly, the first terminal's processing may include: receiving the fifth encrypted information from the first access network device.

[0246] For example, the key distribution message carries one or more third keys and fifth encryption information. The first access network device can locally decrypt the sixth encryption information based on the seventh key to obtain and save one or more third keys, and send the fifth encryption information to the first terminal.

[0247] Optionally, the key allocation message may carry only one or more third keys. Accordingly, after receiving the key allocation message, the first access network device only needs to store one or more third keys locally. In this case, the first core network device may also send fifth encrypted information to the first terminal; correspondingly, the first terminal's processing can be: receiving the fifth encrypted information from the first core network device.

[0248] Furthermore, after receiving the fifth encrypted information, the first terminal can decrypt the fifth encrypted information based on the fourth key to obtain one or more third keys. Optionally, the first terminal can obtain one or more third keys, each with a corresponding key identifier. Then, the first terminal can extract the second key it needs from the one or more third keys and distribute the remaining third keys (excluding the second keys) to one or more other terminals in the first group.

[0249] In one embodiment, the first terminal sends a key allocation request (e.g., via a NAS message) to the first core network device. The processing of the first core network device further includes: receiving the key allocation request sent by the first terminal. The processing of the first core network device may also include at least one of the following: sending fifth encryption information to the first terminal; sending a key allocation message to the first access network device, the key allocation message carrying at least one of the following: one or more third keys, and the fifth encryption information.

[0250] Optionally, after receiving the key allocation request, the first core network device can authenticate the first terminal based on the third credential. The specific processing method is the same as that in the aforementioned embodiments, and will not be repeated here.

[0251] Optionally, after receiving the key allocation request, the first core network device can verify the fifth verification code. Specifically, it can verify the identity of the first terminal based on the fifth verification code and the fifth checksum. The calculation method of the fifth verification code should be the same as that of the fifth checksum in the previous embodiments, and therefore will not be repeated.

[0252] The processing after the first core network device generates one or more third keys is the same as in the previous embodiments, and will not be repeated here.

[0253] In one embodiment, after the first terminal obtains the second key between itself and the first access network device, the processing of the first terminal may include: sending a registration request to the first access network device, wherein the registration request carries eighth encrypted information, the eighth encrypted information being obtained by encrypting at least one of the following based on the second key: a third verification code for verifying the first terminal, the identifier of the first terminal, the identifier of the first access network device, a fourth random number, and the identifier of a first resource of the first network to be used, wherein the third verification code is calculated based on the second key and at least one of the following: the identifier of the first terminal, the identifier of the first access network device, the fourth random number, and the identifier of the first resource. The processing of the first access network device further includes: receiving the registration request from the first terminal.

[0254] After the first access network device receives the registration request, the method further includes: decrypting the eighth encrypted information based on the second key to obtain at least one of the following: a third verification code for verifying the first terminal, the identifier of the first terminal, the identifier of the first access network device, a fourth random number, and the identifier of the first resource of the first network to be used.

[0255] Optionally, the processing of the first access network device may further include: verifying the first terminal based on the third verification code and the third check code, wherein the third verification code is calculated based on the second key and at least one of the following: the identifier of the first terminal, the identifier of the first access network device, the fourth random number, and the identifier of the first resource. The method and parameters used by the first access network device to calculate the third verification code should be the same as the method and parameters used by the first terminal to calculate the third check code.

[0256] On the first access network device side, if the third verification code and the third check code are the same, it can be determined that the verification of the first terminal has passed. Further, the processing of the first access network device may also include: the first access network device can send a registration success response to the first terminal. The processing of the first terminal may include: receiving the registration success response. Optionally, the registration success response may also be encrypted with a second key and sent to the first terminal, and the first terminal decrypts it based on the second key to obtain the registration success response.

[0257] The process of the UE requesting the symmetric key between the UE and the base station is illustrated in Figure 7:

[0258] Step 701a: UEa (first terminal) sends a key allocation request to core network B (first core network equipment). This request may carry: an eighth random number N to indicate message freshness, and an ID. va It is the temporary identity, ID, of the requester, i.e., UEa. b This indicates the base station b (the first access network device) to be accessed. UEa hashes the above message using the key material between UEa and core network B to obtain the fifth verification code HMAC. HMAC ensures that the source of the core network B's authentication message is UEa (ID). va And the message was not tampered with.

[0259] In this case, after completing step 701a, step 702 is not required; proceed directly to steps 703 to 704.

[0260] Step 701b: UEa requests key Ka-b, and this key allocation request is sent to base station b. The key allocation request sent by UEa to base station b may carry an eighth random number N to indicate message freshness, ID. va It is the temporary identity, ID, of the requester, i.e., UEa. b This indicates the base station b to be accessed and the fifth checksum HMAC.

[0261] Optionally, a session key K can be requested between i UEs and base station b in a group. a-b (1…i), in this case, the key distribution request can also carry: IDg, i.e., group ID, ID va (1…i) is the temporary identifier of the requester, i.e., UE (1…i).

[0262] Step 702: Base station b forwards a key allocation request to core network B. The key allocation request sent by base station b to core network B may carry an eighth random number N, ID. va ID bThe seventh checksum (HMAC) is obtained based on the seventh key between base station b and core network B. In other words, the key allocation request is forwarded by base station b. After verifying the received message, base station b uses the key material between itself and core network B to hash the received message and obtain the seventh checksum (HMAC), which is then sent to core network B. This HMAC allows core network B to verify that the message indeed originated from base station b and has not been tampered with (core network B hashes the received message using the key material between itself and base station b and compares it with the received HMAC).

[0263] Step 703: After core network B verifies the key allocation request sent by base station b or UEa (e.g., to verify reliability), it generates a symmetric session key K for communication between UEa and base station b. a-b (i.e., the second key in the aforementioned embodiment). The core network B sends a key allocation message to the base station b, which may carry the second key and the fifth encrypted information obtained by encrypting the second key based on the key between UEa and the core network B.

[0264] Optionally, to ensure message confidentiality, the message can be sent through a secure channel between core network B and base station b. Specifically, the message content can be encrypted using the seventh key between core network B and base station b. The message content is K. a-b , (i.e., the fifth encrypted information).

[0265] Step 704: After base station b verifies the reliability of the received message (the source is core network B and the message has not been tampered with), it will... The message is forwarded to UEa. Then, UEa uses its own key material with the core network to decrypt and obtain the session key with base station b. The decrypted N+1 also indicates that the message is not a replay. At this point, UEa can use the received session key to access base station b and successfully use the spectrum resources of the network where base station b is located (UEa's roaming network).

[0266] Referring to Figure 8, the UEa registration process is illustrated by example:

[0267] Step 801: When UEa (first terminal) requests access to the resources of base station b (first access network equipment), UEa sends a registration request to base station b, which carries information encrypted with the following: UEa's identifier IDva, base station b's identifier IDb, a fourth random number N, the identifier or number Nom of the requested first network resource, and a third checksum HMAC obtained by hashing the above message using the second key Ka-b between UEa and base station b. The content of this registration request can be encrypted using the second key Ka-b; for example, the encrypted content of the message can be represented as: Enc Ka-b[IDva,IDb,N,Nom,HMAC]

[0268] Step 802: After decrypting the registration request using the second key Ka-b, base station b verifies the identity of UEa based on the third verification code. If it is determined that UEa can use the Nom spectrum resources, step 803 is executed.

[0269] Step 803: Base station b returns a notification that the user registration was successful. This notification can be encrypted using Ka-b.

[0270] In some embodiments, the first terminal sends an authentication request to the first core network device or the first access network device and requests to use resources. In this embodiment, the authentication process initiated by the authentication request can complete the verification of the first terminal's permission to use resources under the first network, obtain one or more third keys, and access the first network through the first access network device.

[0271] The first terminal may send an authentication request carrying a third credential to the first access network device or the first core network device.

[0272] The authentication request also carries at least one of the following: a fifth verification code for verifying the identity of the first terminal, an identifier of the first resource of the first network to be used, an identifier of one or more terminals, an identifier of the first group, an identifier of the first access network device, and an identifier of the first core network device.

[0273] In one embodiment, the authentication request is sent to the first access network device.

[0274] The processing by the first access network device after receiving the authentication request may further include: sending an authentication request to the first core network device, wherein the authentication request carries the third credential; receiving an authentication response from the first core network device, wherein the authentication response carries a fifth verification code; and verifying the identity of the first terminal based on the fifth verification code and the fifth verification code. Optionally, the authentication request may further carry at least one of the following: an identifier of a first resource, an identifier of one or more terminals, an identifier of a first group, an identifier of the first access network device, and an identifier of the first core network device.

[0275] After receiving the authentication request, the first core network device can authenticate the first terminal based on the third credential. The specific authentication method is the same as that in the previous embodiment and will not be described in detail.

[0276] Optionally, the authentication response may also carry at least one of the following: one or more third keys, or fifth encryption information.

[0277] The processing after the first access network device receives the authentication response may further include: sending an authentication response to the first terminal, wherein the authentication response carries fifth encrypted information. Correspondingly, the processing after the first terminal receives the authentication response may include: extracting the fifth encrypted information from the authentication response, decrypting the fifth encrypted information based on the fourth key, and obtaining one or more third keys. The processing after the first terminal obtains one or more third keys is the same as in the aforementioned embodiments and will not be described again.

[0278] In one embodiment, the authentication request is sent to the first core network device.

[0279] After receiving the authentication request, the first core network device can authenticate the first terminal based on the third credential. The specific authentication method is the same as in the previous embodiment and will not be described in detail.

[0280] Optionally, the first core network device can also verify the identity of the first terminal based on the fifth verification code and the fifth check code. The specific verification process is the same as in the aforementioned embodiments and will not be described in detail.

[0281] After the first core network device completes the above authentication and the authentication is successful, it also includes at least one of the following: sending an authentication response to the first terminal, carrying fifth encryption information; or sending one or more third keys to the first access network device.

[0282] Accordingly, the processing of the first terminal may include: receiving an authentication response from the first core network device. The decryption of the fifth encrypted information and subsequent processing by the first terminal are the same as in the aforementioned embodiments and will not be described in detail.

[0283] The following explanation, with reference to Figure 9, details the process of accessing the first network using a third credential.

[0284] Step 901: UEa (first terminal) sends an authentication request to base station b (first access network device) under core network device B (first core network device) to request the use of spectrum resources. The authentication request may include: Nom2 indicating the identifier (or number) of the first resource requested by UE-a, and Ticket. a The second-level voucher of the symmetric scheme, the eighth random number N2 indicates the freshness of the message, ID va It is the temporary identity, ID, of the requester, i.e., UE-a. b The identifier of the base station to be accessed is indicated. The above message is hashed using the key material between UE-a and core network equipment B to obtain the fifth check code HMAC.

[0285] Step 902: After receiving the authentication request from UE-a, base station b initiates an authentication request to core network device B.

[0286] Specifically, base station b will use the key material K between itself and core network device B to retrieve the parameters contained in the received authentication request. b-B After hashing to obtain the seventh checksum HMAC, the parameters contained in the authentication request and the HMAC are added to the authentication request and sent to core network device B.

[0287] Step 903: After verifying the authentication request sent by base station b, core network device B sends an authentication response to base station b.

[0288] Core network equipment B uses key material K with base station b b-B The parameters in the authentication response to be sent will be encrypted before transmission. The parameters in the authentication response include: the session key K between UE-a and base station b. a-b Encrypted session key And the fifth verification code

[0289] Step 904: Base station b compares the HMAC received from UE-a with the HMAC received from core network equipment B. If they match, it indicates that UE-a is legitimate. Base station b sends an authentication response to UE-a, which carries an encrypted session key.

[0290] By adopting the above scheme, the communication billing value, which is recognized by both the first terminal belonging to the second network and the first access network device belonging to the first network, is uploaded to the blockchain. This ensures that the communication billing value uploaded to the blockchain is recognized and accurate by both the terminal and the roaming network, thereby guaranteeing the accuracy of billing for the terminal in roaming scenarios.

[0291] Figure 10 is a schematic diagram of the composition structure of a first access network device according to an embodiment of this application, including:

[0292] The first communication unit 1001 is used to upload the billing-related information of the first terminal to the blockchain. The billing-related information of the first terminal is used to determine the first communication billing value recognized by the first terminal and the first access network device under the first network. The first access network device belongs to the first network, and the first terminal belongs to the second network.

[0293] The billing-related information of the first terminal includes: the first communication billing value, a first signature for determining that the first terminal acknowledges the first communication billing value, and a second signature for determining that the first access network device acknowledges the first communication billing value.

[0294] The second signature is calculated based on the private key of the first access network device and the first communication billing value.

[0295] The billing-related information of the first terminal also includes: the certificate of the first access network device, wherein the certificate of the first access network device carries the public key of the first access network device.

[0296] The first communication billing value is calculated based on the communication costs of the first terminal under the first network.

[0297] The first communication unit is used to upload billing aggregation information to the blockchain, wherein the billing aggregation information is used to verify the aggregated communication costs of one or more terminals belonging to the second network under the first access network device, and the billing aggregation information is obtained by aggregating the communication billing values ​​of the one or more terminals under the first network, including the first terminal.

[0298] The first communication unit is configured to receive a first message from a second access network device, wherein the first message carries at least one of the following: the first communication billing value, the first signature, and the second access network device belongs to the first network and serves the first terminal.

[0299] The first message also carries at least one of the following: a first verification code for verifying the identity of the second access network device, the certificate of the first terminal, the identifier of the second access network device, and a first random number, wherein the certificate of the first terminal carries the public key of the first terminal.

[0300] The first access network device further includes: a first processing unit 1002, used to verify the identity of the second access network device based on a first verification code and a first check code, wherein the first verification code is calculated based on a first key between the first access network device and the second access network device and at least one of the following parameters: the first communication billing value, the first signature, the certificate of the first terminal, the identifier of the second access network device, and the first random number.

[0301] The first message also carries at least one of the following: a third signature for verifying the identity of the second access network device, a certificate of the second access network device, a first credential for verifying the first terminal's permission to use the resources of the first network, an identifier of the second access network device, and a first random number, wherein the certificate of the second access network device carries the public key of the second access network device.

[0302] The first processing unit is used to verify the identity of the second access network device based on the public key of the second access network device, the first signature, and the third signature.

[0303] The first access network device serves the first terminal.

[0304] The first communication unit is configured to receive a second message from the first terminal, wherein the second message carries the first signature.

[0305] The second message also carries at least one of the following: a second verification code for verifying the identity of the first terminal, the certificate of the first terminal, first encrypted information, the identifier of the first access network device, a second random number, the first communication billing value, and information related to the first communication bill of the first terminal under the first network, wherein the certificate of the first terminal carries the public key of the first terminal, and the first communication bill includes the communication cost of the first terminal under the first network.

[0306] The first processing unit is configured to verify the identity of the first terminal based on the second verification code and the second check code, wherein the second verification code is calculated based on the second key between the first access network device and the first terminal and at least one of the following parameters: the first signature, the certificate of the first terminal, the first encryption information, the identifier of the first access network device, the second random number, the first communication billing value, and the relevant information of the first communication bill.

[0307] The first processing unit is configured to decrypt the first encrypted information based on the second key between the first access network device and the first terminal, and obtain at least one of the following: relevant information of the first communication bill, and the first communication billing value.

[0308] The first communication unit is configured to send a third message to the first terminal, wherein the third message carries at least one of the following: the first communication billing value, second encryption information, relevant information of the first communication bill, the identifier of the first access network device, and a third random number, wherein the second encryption information is obtained by encrypting the relevant information of the first communication bill based on a second key between the first access network device and the first terminal.

[0309] The second message also carries at least one of the following: a first credential for verifying the first terminal's permission to use the resources of the first network, an identifier of the first access network device, a second random number, a first communication billing value, information related to the first terminal's first communication bill under the first network, and third encrypted information, wherein the first communication bill includes the communication costs of the first terminal under the first network.

[0310] The first processing unit is configured to decrypt the third encrypted information based on the public key of the first access network device to obtain at least one of the following: relevant information of the first communication bill, and the first communication billing value.

[0311] The first communication unit is configured to send a third message to the first terminal, wherein the third message carries a fourth signature, wherein the fourth signature is calculated based on the private key of the first access network device to obtain fourth encrypted information, and the fourth encrypted information is obtained by encrypting at least one of the relevant information of the first communication bill and the first communication billing value based on the public key of the first terminal.

[0312] The third message also carries at least one of the following: the identifier of the first access network device, a third random number, and the certificate of the first access network device.

[0313] The billing information of the first terminal also includes: the certificate of the first terminal.

[0314] The billing information of the first terminal also includes: the first voucher.

[0315] The first credential carries at least one of the following: a fifth signature for verifying the first terminal's permission to use the second network to obtain authorized access to the resources of the first network, and a sixth signature for verifying the second network's permission to use the resources of the first network.

[0316] The first communication unit is configured to forward a key allocation request from the first terminal to the first core network device, wherein the key allocation request carries a third credential for authenticating the first terminal's right to use resources of the first network; and to receive a key allocation message from the first core network device, wherein the first core network device belongs to the first network, and the key allocation message carries at least one of the following: one or more third keys, wherein the one or more third keys are keys between one or more terminals and the first access network device, wherein the one or more terminals include the first terminal, and the one or more third keys include a second key between the first access network device and the first terminal; and fifth encryption information, wherein the fifth encryption information is obtained by encrypting the one or more third keys based on a fourth key between the first terminal and the first core network device.

[0317] The first communication unit is used to send the fifth encrypted information to the first terminal.

[0318] The first communication unit is configured to receive a registration request from the first terminal, wherein the registration request carries eighth encrypted information, the eighth encrypted information being obtained by encrypting at least one of the following based on the second key: a third verification code for verifying the first terminal, the identifier of the first terminal, the identifier of the first access network device, a fourth random number, and the identifier of the first resource of the first network to be used, the third verification code being calculated based on the second key and at least one of the following: the identifier of the first terminal, the identifier of the first access network device, the fourth random number, the identifier of the first resource, and the eighth encrypted information.

[0319] The first processing unit is configured to verify the first terminal based on the third verification code and the third check code, wherein the third verification code is calculated based on the second key and at least one of the following: the identifier of the first terminal, the identifier of the first access network device, the fourth random number, and the identifier of the first resource.

[0320] Figure 11 is a schematic diagram of the composition structure of a first terminal according to an embodiment of this application, including:

[0321] The second communication unit 1101 is used to send a second message to the first access network device, wherein the second message carries a first signature for determining that the first terminal recognizes the first communication billing value under the first network, the first terminal belongs to the second network, and the first access network device belongs to the first network and serves the first terminal.

[0322] The first signature is calculated based on the private key of the first terminal and the first communication billing value.

[0323] The first communication billing value is calculated based on the communication costs of the first terminal under the first network.

[0324] The second message also carries at least one of the following: a second verification code for verifying the identity of the first terminal, the certificate of the first terminal, first encrypted information, the identifier of the first access network device, a second random number, the first communication billing value, and information related to the first communication bill of the first terminal under the first network, wherein the certificate of the first terminal carries the public key of the first terminal, and the first communication bill includes the communication cost of the first terminal under the first network.

[0325] The second verification code is calculated based on the second key between the first access network device and the first terminal and at least one of the following parameters: the first signature, the certificate of the first terminal, the first encryption information, the identifier of the first access network device, the second random number, the first communication billing value, and the relevant information of the first communication bill.

[0326] The first encrypted information is obtained by encrypting at least one of the following based on the second key between the first access network device and the first terminal: relevant information of the first communication bill, and the first communication billing value.

[0327] The second communication unit is configured to receive a third message from the first access network device, wherein the third message carries at least one of the following: the first communication billing value, second encryption information, relevant information of the first communication bill, the identifier of the first access network device, and a third random number, wherein the second encryption information is obtained by encrypting the relevant information of the first communication bill based on a second key between the first access network device and the first terminal.

[0328] The second message also carries at least one of the following: a first credential for verifying the first terminal's permission to use the resources of the first network, an identifier of the first access network device, a second random number, a first communication billing value, information related to the first terminal's first communication bill under the first network, and third encrypted information, wherein the first communication bill includes the communication costs of the first terminal under the first network.

[0329] The third encrypted information is obtained by encrypting at least one of the following based on the public key of the first access network device: the relevant information of the first communication bill, and the first communication billing value.

[0330] The second communication unit is configured to receive a third message from the first access network device, wherein the third message carries a fourth signature, wherein the fourth signature is calculated based on the private key of the first access network device to obtain fourth encrypted information, and the fourth encrypted information is obtained by encrypting at least one of the relevant information of the first communication bill and the first communication billing value based on the public key of the first terminal.

[0331] The first terminal further includes a second processing unit 1102, used to verify the fourth signature based on the public key of the first access network device and the fourth encryption information.

[0332] The third message also carries at least one of the following: the identifier of the first access network device, a third random number, and the certificate of the first access network device.

[0333] The first credential carries at least one of the following: a fifth signature for verifying the first terminal's permission to use the second network to obtain authorized access to the resources of the first network, and a sixth signature for verifying the second network's permission to use the resources of the first network.

[0334] The second communication unit is configured to perform one of the following: receive fifth encrypted information from a first core network device, wherein the first core network device belongs to the first network; or receive fifth encrypted information from a first access network device.

[0335] The second processing unit is configured to decrypt the fifth encrypted information based on the fourth key between the first terminal and the first core network device to obtain one or more third keys. The one or more third keys are keys between one or more terminals and the first access network device. The one or more terminals include the first terminal. The one or more third keys include the second key between the first access network device and the first terminal.

[0336] The second communication unit is configured to perform one of the following: send a key allocation request to the first core network device, wherein the key allocation request carries a third credential for authenticating the first terminal's permission to use the resources of the first network; or send the key allocation request to the first access network device.

[0337] The second communication unit is configured to send a registration request to the first access network device, wherein the registration request carries eighth encrypted information, the eighth encrypted information being obtained by encrypting at least one of the following based on the second key: a third verification code for verifying the first terminal, the identifier of the first terminal, the identifier of the first access network device, a fourth random number, and the identifier of the first resource of the first network to be used, wherein the third verification code is calculated based on the second key and at least one of the following: the identifier of the first terminal, the identifier of the first access network device, the fourth random number, and the identifier of the first resource.

[0338] The device in this application embodiment can realize the corresponding functions of the various devices in the foregoing communication method embodiments. The processes, functions, implementation methods, and beneficial effects of each module (sub-module, unit, or component, etc.) in this device can be found in the corresponding descriptions in the above method embodiments, and will not be repeated here. It should be noted that the functions described for each module (sub-module, unit, or component, etc.) in the device of this application embodiment can be implemented by different modules (sub-modules, units, or components, etc.) or by the same module (sub-module, unit, or component, etc.).

[0339] It should be understood that in the various embodiments of this application, the order of the above-mentioned processes does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0340] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0341] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A communication method executed by a first access network device, comprising: The billing information of the first terminal is uploaded to the blockchain. The billing information of the first terminal is used to determine the first communication billing value recognized by the first terminal and the first access network device under the first network. The first access network device belongs to the first network and the first terminal belongs to the second network.

2. The method according to claim 1, wherein, The billing-related information of the first terminal includes: the first communication billing value, a first signature for determining that the first terminal acknowledges the first communication billing value, and a second signature for determining that the first access network device acknowledges the first communication billing value.

3. The method according to claim 2, wherein, The second signature is calculated based on the private key of the first access network device and the first communication billing value.

4. The method according to claim 2 or 3, wherein, The billing-related information of the first terminal also includes: the certificate of the first access network device, wherein the certificate of the first access network device carries the public key of the first access network device.

5. The method according to any one of claims 1-4, wherein, The first communication billing value is calculated based on the communication costs of the first terminal under the first network.

6. The method according to any one of claims 1-5, wherein, The method further includes: The billing aggregation information is uploaded to the blockchain, wherein the billing aggregation information is used to verify the aggregated communication costs of one or more terminals belonging to the second network under the first access network device, and the billing aggregation information is obtained by aggregating the communication billing values ​​of the one or more terminals under the first network, including the first terminal.

7. The method according to any one of claims 2-4, wherein, The method further includes: A first message is received from a second access network device, wherein the first message carries at least one of the following: the first communication billing value, the first signature, and the second access network device belongs to the first network and serves the first terminal.

8. The method according to claim 7, wherein, The first message also carries at least one of the following: a first verification code for verifying the identity of the second access network device, the certificate of the first terminal, the identifier of the second access network device, and a first random number, wherein the certificate of the first terminal carries the public key of the first terminal.

9. The method according to claim 8, wherein, The method further includes: The identity of the second access network device is verified based on the first verification code and the first check code. The first verification code is calculated based on the first key between the first access network device and the second access network device and at least one of the following parameters: the first communication billing value, the first signature, the certificate of the first terminal, the identifier of the second access network device, and the first random number.

10. The method according to claim 7, wherein, The first message also carries at least one of the following: a third signature for verifying the identity of the second access network device, a certificate of the second access network device, a first credential for verifying the first terminal's permission to use the resources of the first network, an identifier of the second access network device, and a first random number, wherein the certificate of the second access network device carries the public key of the second access network device.

11. The method according to claim 10, wherein, The method further includes: The identity of the second access network device is verified based on the public key of the second access network device, the first signature, and the third signature.

12. The method according to any one of claims 2-4, wherein, The first access network device serves the first terminal.

13. The method according to claim 12, wherein, The method further includes: Receive a second message from the first terminal, wherein the second message carries the first signature.

14. The method according to claim 13, wherein, The second message also carries at least one of the following: a second verification code for verifying the identity of the first terminal, the certificate of the first terminal, first encrypted information, the identifier of the first access network device, a second random number, the first communication billing value, and information related to the first communication bill of the first terminal under the first network, wherein the certificate of the first terminal carries the public key of the first terminal, and the first communication bill includes the communication cost of the first terminal under the first network.

15. The method according to claim 14, wherein, The method further includes: The identity of the first terminal is verified based on the second verification code and the second check code. The second verification code is calculated based on the second key between the first access network device and the first terminal and at least one of the following parameters: the first signature, the certificate of the first terminal, the first encryption information, the identifier of the first access network device, the second random number, the first communication billing value, and the relevant information of the first communication bill.

16. The method according to claim 14 or 15, wherein, The method further includes: Based on the second key between the first access network device and the first terminal, the first encrypted information is decrypted to obtain at least one of the following: relevant information of the first communication bill, and the first communication billing value.

17. The method according to any one of claims 14-16, wherein, The method further includes: Send a third message to the first terminal, wherein the third message carries at least one of the following: the first communication billing value, the third... The second encrypted information consists of the information related to the first communication bill, the identifier of the first access network device, and a third random number. The second encrypted information is obtained by encrypting the information related to the first communication bill based on the second key between the first access network device and the first terminal.

18. The method according to claim 13, wherein, The second message also carries at least one of the following: a first credential for verifying the first terminal's permission to use the resources of the first network, an identifier of the first access network device, a second random number, a first communication billing value, information related to the first terminal's first communication bill under the first network, and third encrypted information, wherein the first communication bill includes the communication costs of the first terminal under the first network.

19. The method according to claim 18, wherein, The method further includes: The third encrypted information is decrypted based on the public key of the first access network device, yielding at least one of the following: relevant information of the first communication bill, and the first communication billing value.

20. The method according to claim 18 or 19, wherein, The method further includes: A third message is sent to the first terminal, wherein the third message carries a fourth signature, wherein the fourth signature is calculated based on the private key of the first access network device to obtain fourth encrypted information, and the fourth encrypted information is obtained by encrypting at least one of the relevant information of the first communication bill and the first communication billing value based on the public key of the first terminal.

21. The method according to claim 20, wherein, The third message also carries at least one of the following: the identifier of the first access network device, a third random number, and the certificate of the first access network device.

22. The method according to any one of claims 8, 9, and 14-17, wherein, The billing information of the first terminal also includes: the certificate of the first terminal.

23. The method according to any one of claims 10, 11, 18-21, wherein, The billing information of the first terminal also includes: the first voucher.

24. The method according to any one of claims 10, 11, 18-21, 23, wherein, The first credential carries at least one of the following: a fifth signature for verifying the first terminal's permission to use the second network to obtain authorized access to the resources of the first network, and a sixth signature for verifying the second network's permission to use the resources of the first network.

25. The method according to any one of claims 15-17, wherein, The method further includes: The key allocation request of the first terminal is forwarded to the first core network device, wherein the key allocation request carries a third credential for authenticating the first terminal's right to use the resources of the first network. Receive a key allocation message from a first core network device, wherein the first core network device belongs to the first network, and the key allocation message carries at least one of the following: One or more third keys, wherein the one or more third keys are keys between one or more terminals and the first access network device, wherein the one or more terminals include the first terminal, and the one or more third keys include a second key between the first access network device and the first terminal; The fifth encryption information is obtained by encrypting one or more third keys based on the fourth key between the first terminal and the first core network device.

26. The method of claim 25, wherein, The method further includes: The fifth encrypted information is sent to the first terminal.

27. The method according to claim 25 or 26, wherein, The method further includes: A registration request is received from the first terminal, wherein the registration request carries eighth encrypted information, which is obtained by encrypting at least one of the following based on the second key: a third verification code for verifying the first terminal, the identifier of the first terminal, the identifier of the first access network device, a fourth random number, and the identifier of the first resource of the first network to be used. The third verification code is calculated based on the second key and at least one of the following: the identifier of the first terminal, the identifier of the first access network device, the fourth random number, the identifier of the first resource, and the eighth encrypted information.

28. The method according to claim 27, wherein, The method further includes: The first terminal is verified based on the third verification code and the third check code, wherein the third verification code is calculated based on the second key and at least one of the following: the identifier of the first terminal, the identifier of the first access network device, the fourth random number, and the identifier of the first resource.

29. A communication method executed by a first terminal, comprising: A second message is sent to a first access network device, wherein the second message carries a first signature for determining that the first terminal acknowledges a first communication billing value under the first network, the first terminal belongs to the second network, and the first access network device belongs to the first network and serves the first terminal.

30. The method according to claim 29, wherein, The first signature is calculated based on the private key of the first terminal and the first communication billing value.

31. The method according to claim 29 or 30, wherein, The first communication billing value is calculated based on the communication costs of the first terminal under the first network.

32. The method according to any one of claims 29-31, wherein, The second message also carries at least one of the following: a second verification code for verifying the identity of the first terminal, the certificate of the first terminal, first encrypted information, the identifier of the first access network device, a second random number, the first communication billing value, and information related to the first communication bill of the first terminal under the first network, wherein the certificate of the first terminal carries the public key of the first terminal, and the first communication bill includes the communication cost of the first terminal under the first network.

33. The method according to claim 32, wherein, The second verification code is calculated based on the second key between the first access network device and the first terminal and at least one of the following parameters: the first signature, the certificate of the first terminal, the first encryption information, the identifier of the first access network device, the second random number, the first communication billing value, and the relevant information of the first communication bill.

34. The method according to claim 32 or 33, wherein, The first encrypted information is obtained by encrypting at least one of the following based on the second key between the first access network device and the first terminal: relevant information of the first communication bill, and the first communication billing value.

35. The method according to any one of claims 32-34, wherein, The method further includes: A third message is received from the first access network device, wherein the third message carries at least one of the following: the first communication billing value, second encryption information, relevant information of the first communication bill, the identifier of the first access network device, and a third random number, wherein the second encryption information is obtained by encrypting the relevant information of the first communication bill based on a second key between the first access network device and the first terminal.

36. The method according to any one of claims 29-31, wherein, The second message also carries at least one of the following: a first credential for verifying the first terminal's permission to use the resources of the first network, an identifier of the first access network device, a second random number, a first communication billing value, information related to the first terminal's first communication bill under the first network, and third encrypted information, wherein the first communication bill includes the communication costs of the first terminal under the first network.

37. The method of claim 36, wherein, The third encrypted information is obtained by encrypting at least one of the following based on the public key of the first access network device: the relevant information of the first communication bill, and the first communication billing value.

38. The method according to claim 36 or 37, wherein, The method further includes: A third message is received from the first access network device, wherein the third message carries a fourth signature, wherein the fourth signature is calculated based on the private key of the first access network device to obtain fourth encrypted information, and the fourth encrypted information is obtained by encrypting at least one of the relevant information of the first communication bill and the first communication billing value based on the public key of the first terminal.

39. The method according to claim 38, wherein, The method further includes: The fourth signature is verified based on the public key of the first access network device and the fourth encrypted information.

40. The method according to claim 38 or 39, wherein, The third message also carries at least one of the following: the identifier of the first access network device, a third random number, and the certificate of the first access network device.

41. The method according to any one of claims 36-40, wherein, The first credential carries at least one of the following: a fifth signature for verifying the first terminal's permission to use the second network to obtain authorized access to the resources of the first network, and a sixth signature for verifying the second network's permission to use the resources of the first network.

42. The method according to any one of claims 33-35, wherein, The method also includes one of the following: Receive fifth encrypted information from a first core network device, wherein the first core network device belongs to the first network; Receive the fifth encrypted information from the first access network device.

43. The method according to claim 42, wherein, The method further includes: The fifth encrypted information is decrypted based on the fourth key between the first terminal and the first core network device to obtain one or more third keys. The one or more third keys are keys between one or more terminals and the first access network device. The one or more terminals include the first terminal. The one or more third keys include the second key between the first access network device and the first terminal.

44. The method according to claim 42 or 43, wherein, The method also includes one of the following: Send a key allocation request to the first core network device, wherein the key allocation request carries a third credential for authenticating the first terminal's right to use the resources of the first network; Send the key allocation request to the first access network device.

45. The method according to any one of claims 42-44, wherein, The method further includes: A registration request is sent to the first access network device, wherein the registration request carries eighth encrypted information, the eighth encrypted information being obtained by encrypting at least one of the following based on the second key: a third verification code for verifying the first terminal, the identifier of the first terminal, the identifier of the first access network device, a fourth random number, and the identifier of the first resource of the first network to be used, the third verification code being calculated based on the second key and at least one of the following: the identifier of the first terminal, the identifier of the first access network device, the fourth random number, and the identifier of the first resource.

46. ​​A first access network device, comprising: The first communication unit is used to upload the billing-related information of the first terminal to the blockchain, wherein the billing-related information of the first terminal... The information is used to determine the first communication billing value recognized by the first terminal and the first access network device under the first network, wherein the first access network device belongs to the first network and the first terminal belongs to the second network.

47. A first terminal, comprising: The second communication unit is configured to send a second message to the first access network device, wherein the second message carries a first signature for determining that the first terminal acknowledges the first communication billing value under the first network, the first terminal belongs to the second network, and the first access network device belongs to the first network and serves the first terminal.

Citation Information

Patent Citations

  • Communication process and communication network comprising a local access network discovery and selection function

    CN104041130A

  • Roaming settlement method and roaming settlement node based on block chain

    CN111866781A

  • Block chain-based roaming transaction method and device

    CN112785299A

  • Self provisioning of wireless terminals in wireless networks

    US20120142314A1

  • A mobile station and method for registering the mobile station to a network

    WO2018010802A1