Communication method and device
By uploading the communication billing values recognized by the terminal and core network equipment to the blockchain, the problem of billing accuracy in roaming networks is solved, and the recognition and accuracy of billing values are realized.
Patent Information
- Application Number
- PCT/CN2024/089670
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-04-24
- Publication Date
- 2025-10-30
AI Technical Summary
How to ensure the accuracy of terminal communication billing in roaming networks and ensure that the communication billing values agreed upon by both parties in the roaming network are consistent?
By uploading the communication billing values recognized by the first terminal and the first core network equipment to the blockchain, the decentralization and immutability of the blockchain are used to ensure the accuracy and consistency of the billing values.
This enables both the terminal and the roaming network to recognize and ensure the accuracy of communication billing values in roaming scenarios, thus guaranteeing the accuracy of billing.
Smart Images

Figure CN2024089670_30102025_PF_FP_ABST
Abstract
Description
Communication methods and devices Technical Field
[0001] This application relates to the field of communications, and more specifically, to a communication method and device. Background Technology
[0002] In related technologies, roaming protocols refer to protocols in mobile communication networks that allow terminals to switch between different operator networks and use services. These protocols enable users to continue communicating through other operators' networks even when they leave the coverage area of their original operator's network. The development and implementation of roaming protocols help improve user experience, allowing terminals to freely switch between different operator-maintained networks in different regions. However, ensuring the accuracy of billing for communications made by terminals in roaming networks becomes a problem that needs to be solved.
[0003] Summary of the Invention
[0004] This application provides a communication method and device.
[0005] This application provides a communication method executed by a first core network device, comprising:
[0006] The billing information of the first terminal is uploaded to the blockchain. The billing information of the first terminal is used to determine the first communication billing value recognized by the first terminal and the first core network device. The first core network device belongs to the first network and the first terminal belongs to the second network.
[0007] This application provides a communication method executed by a first terminal, including:
[0008] Send a first signature to determine that the first terminal acknowledges the first communication billing value, wherein the first terminal belongs to the second network.
[0009] This application provides a communication method executed by a first access network device, comprising:
[0010] Receive a first signature from a first terminal for determining that the first terminal recognizes a first communication billing value, wherein the first terminal belongs to a second network and the first access network device belongs to the first network;
[0011] The first signature is sent to the first core network device, wherein the first core network device belongs to the first network.
[0012] This application provides a first core network device, including:
[0013] The first communication unit is used to upload the billing-related information of the first terminal to the blockchain. The billing-related information of the first terminal is used to determine the first communication billing value recognized by the first terminal and the first core network device. The first core network device belongs to the first network, and the first terminal belongs to the second network.
[0014] This application provides a first terminal, including:
[0015] The second communication unit is configured to send a first signature for determining that the first terminal recognizes the first communication billing value, wherein the first terminal belongs to the second network.
[0016] This application provides a first access network device, including:
[0017] The third communication unit is configured to receive a first signature from a first terminal for determining that the first terminal recognizes a first communication billing value, wherein the first terminal belongs to a second network and the first access network device belongs to the first network; and to send the first signature to a first core network device, wherein the first core network device belongs to the first network.
[0018] By adopting the above scheme, the communication billing value, which is recognized by both the first terminal belonging to the second network and the first core network device belonging to the first network, can be uploaded to the blockchain. This ensures that the communication billing value uploaded to the blockchain is recognized and accurate by both the terminal and the roaming network, thereby guaranteeing the accuracy of billing for the terminal in roaming scenarios. Attached Figure Description
[0019] Figure 1 is a schematic diagram of an application scenario according to an embodiment of this application.
[0020] Figure 2 is a schematic flowchart of a communication method according to an embodiment of this application.
[0021] Figure 3 is a schematic flowchart of a communication method according to another embodiment of this application.
[0022] Figure 4 is a schematic flowchart of a communication method according to another embodiment of this application.
[0023] Figure 5 is a schematic flowchart of a communication method of a symmetrical scheme according to an embodiment of this application.
[0024] Figure 6 is a schematic flowchart of a communication method for an asymmetric scheme according to an embodiment of this application.
[0025] Figure 7 is a schematic flowchart of the on-chain uploading of billing aggregation information according to an embodiment of this application.
[0026] Figure 8 is a schematic flowchart of the symmetric key distribution process between the UE and the base station according to an embodiment of this application.
[0027] Figure 9 is a schematic flowchart of UE registration according to an embodiment of this application.
[0028] Figure 10 is a schematic block diagram of a first core network device according to an embodiment of the present application.
[0029] Figure 11 is a schematic block diagram of a first terminal according to an embodiment of the present application.
[0030] Figure 12 is a schematic block diagram of a first access network device according to an embodiment of the present application. Detailed Implementation
[0031] The technical solutions of this application embodiment can be applied to various communication systems, such as LTE, LTE-A, NR, NR evolution, WLAN, WiFi, or other communication systems.
[0032] This application describes various embodiments in conjunction with network devices and terminals. The terminal can be mobile or fixed, and may also be referred to as a mobile station, user unit, etc. The terminal can be a station in a WLAN, or a smart terminal, wireless modem, laptop, tablet, etc. In this application's embodiments, the terminal can be a VR / AR terminal, industrial control terminal, autonomous driving terminal, telemedicine terminal, smart grid terminal, transportation safety terminal, smart city terminal, or smart home wireless terminal, etc. By way of example and not limitation, in this application's embodiments, the terminal can also be a wearable device.
[0033] In this embodiment, the network device can be a device for communicating with a terminal. The network device can be an access point in a WLAN, an evolved base station in LTE, a relay station, a network device (gNB) in a vehicle-mounted device, wearable device, or NR network, or a network device in a future PLMN network, or a network device in a non-terrestrial network, etc. As an example and not a limitation, in this embodiment, the network device can have mobility characteristics; for example, the network device can be a mobile device.
[0034] To facilitate understanding of the technical solutions of the embodiments of this application, the relevant technologies of the embodiments of this application are described below. The following relevant technologies are optional solutions and can be combined with the technical solutions of the embodiments of this application in any way, and they all fall within the protection scope of the embodiments of this application.
[0035] Figure 1 exemplarily illustrates a communication system 100. This communication system includes a network device 110 and two terminals 120. In one possible implementation, the communication system 100 may include multiple network devices 110, and the coverage area of each network device 110 may include other numbers of terminals 120; this embodiment does not limit this. In another possible implementation, the communication system 100 may also include mobility management entities, access and mobility management functions, and other network entities; this embodiment does not limit this. The network devices may further include access network devices and core network devices. That is, the communication system may also include multiple core networks for communicating with the access network devices. The access network devices may be base stations of LTE, LTE-A, or NR systems. Taking the communication system shown in Figure 1 as an example, the communication devices may include network devices and terminals with communication functions. The communication devices may also include other devices in the communication system, such as network controllers, mobility management entities, and other network entities; this embodiment does not limit this.
[0036] Figure 2 is a schematic flowchart of a communication method performed by a first core network device according to an embodiment of this application. The method includes at least some of the following.
[0037] S210. Upload the billing-related information of the first terminal to the blockchain, wherein the billing-related information of the first terminal is used to determine the first communication billing value recognized by the first terminal and the first core network device, the first core network device belongs to the first network, and the first terminal belongs to the second network.
[0038] Figure 3 is a schematic flowchart of a communication method executed by a first terminal according to an embodiment of this application. The method includes at least a portion of the following.
[0039] S310. Send a first signature for determining that the first terminal acknowledges the first communication billing value, wherein the first terminal belongs to the second network.
[0040] Figure 4 is a schematic flowchart of a communication method performed by a first access network device according to an embodiment of this application. The method includes at least some of the following.
[0041] S410. Receive a first signature from the first terminal for determining that the first terminal recognizes the first communication billing value, wherein the first terminal belongs to the second network and the first access network device belongs to the first network.
[0042] S420. Send the first signature to the first core network device, wherein the first core network device belongs to the first network.
[0043] The first terminal is a contracted terminal of the second network, meaning the second network is the home network of the first terminal. When the first terminal, contracted with the second network, needs to access or use the resources of the first network, the first network becomes the roaming network for that first terminal.
[0044] The first access network device may be an access network device belonging to the first network and serving the first terminal.
[0045] The first core network device can be a network element within the first network (such as a control plane network element and / or a user plane network element belonging to the first network), etc. The device type of the first core network device is not limited or exhaustively listed here.
[0046] In some possible implementations, the first terminal uses a symmetrical scheme to access the first network.
[0047] In one embodiment, when the first terminal accesses the first network using a symmetrical scheme, the first core network device triggers the collection of bills, and information is exchanged between the first core network device, the first access network device, and the first terminal.
[0048] Before the first core network device uploads the billing information of the first terminal to the blockchain, it further includes: sending second encrypted information to the first access network device, wherein the second encrypted information is obtained by encrypting at least one of the following parameters based on the second key between the first access network device and the first core network device: the first communication billing value, and the relevant information of the first communication bill.
[0049] The processing before the first access network device receives the first signature may further include: receiving second encrypted information from the first core network device, wherein the second encrypted information is obtained by encrypting at least one of the following parameters based on a second key between the first access network device and the first core network device: the first communication billing value and related information of the first communication bill; and sending eighth encrypted information to the first terminal, wherein the eighth encrypted information is obtained by encrypting at least one of the following parameters based on a fourth key between the first terminal and the first access network device: the first communication billing value and related information of the first communication bill.
[0050] The processing before the first terminal sends the first signature may include: receiving eighth encrypted information from the first access network device, wherein the eighth encrypted information is obtained by encrypting at least one of the following parameters based on the fourth key between the first terminal and the first access network device: the first communication billing value, and related information of the first communication bill.
[0051] The message sent by the first core network device to the first access network device can be a first message, that is, the first message carries second encrypted information; the message sent by the first access network device to the first terminal can be a second message, that is, the second message carries eighth encrypted information, and the second message can be a downlink AS (access layer) message.
[0052] Furthermore, the first message may also carry at least one of the following: the identifier of the first core network device, and a first random number. The identifier of the first core network device is used to identify itself; the first random number is used to prevent replay attacks and can be generated by the first core network device, without any restriction on its generation method.
[0053] The first communication billing value is calculated based on the communication costs of the first terminal under the first network.
[0054] The communication billing value can also be called the commitment value, that is, the first communication billing value can also be called the first commitment value. Specifically, the first communication billing value can be calculated based on the communication cost of the first terminal under the first network and a second random number using a first calculation method. The selection method for the second random number is not limited in this embodiment.
[0055] This first calculation method can be configured according to actual conditions. Taking the Pedersen commitment calculation method as an example, the calculation of the first communication billing value can be as follows: The communication cost of the first terminal under the first network is used as the power of the first element to calculate the first value; a second random number is used as the power of the second element to calculate the second value; and the first and second values are multiplied to obtain the first communication billing value. The first and second elements can be common parameters in the Pedersen commitment, for example, the first and second elements can be selected from a multiplicative group G of order Q, and the second random number can be selected by the first terminal. For example, the calculation of the first communication billing value can be expressed as: Commit(price) = g price h r Where g, h∈G q , G q That is, a multiplicative group G of order Q, where g can be the first element mentioned above, h can be the second element mentioned above, price is the communication cost of the first terminal under the first network (price can also be represented by x alternatively), r is the second random number, and Commit(price) is the first communication billing value, which can also be abbreviated as "com".
[0056] The communication cost of the first terminal under the first network can refer to the communication cost incurred by the first terminal in completing one or more communications under the first network. The communication cost can also be alternatively expressed as the communication price.
[0057] Optionally, the communication cost of the first terminal under the first network can be calculated based on at least one of the time period of a single communication under the first network and the cost per unit time under the first network. Optionally, the communication cost of the first terminal under the first network can be calculated based on at least one of the time period of multiple communications under the first network and the cost per unit time under the first network. The number of communications can be configured according to actual circumstances, such as two communications, three communications, or more or fewer; it is not limited or exhaustively listed here.
[0058] The relevant information of the first communication bill includes at least one of the following: the identifier of the first communication bill, the content of the first communication bill, wherein the content of the first communication bill includes the communication costs of the first terminal under the first network.
[0059] The first communication bill can also be referred to as the first bill. This communication bill can also be alternatively called a "micro-bill," for example, the first communication bill can be called the micro-bill of the first terminal.
[0060] The identifier of the first communication bill may include at least one of the following: the ID of the first communication bill (such as bill ID), the index number of the first communication bill (such as bill index).
[0061] In addition to the communication costs incurred by the first terminal under the first network, the first communication bill may also include at least one of the following: the identifier of the first terminal (e.g., a temporary identifier for the first terminal), the identifier of the first core network device, the identifier (or number) of the resources used in the first network, the usage period of the resources in the first network, and a second random number. The identifier of the first terminal may be a temporary identifier for the first terminal, i.e., a temporary identifier for the first terminal under the first network. In the following text, the identifier of the first terminal mentioned in the interaction between the first terminal and the access network device and / or the first core network device in the first network may refer to the temporary identifier of the first terminal, and will not be explained again below.
[0062] After receiving the first message, the first access network device can decrypt the second encrypted information based on the second key to obtain at least one of the following: relevant information of the first communication bill and the first communication billing value.
[0063] After decrypting the second encrypted information, the first access network device can also generate an eighth encrypted information. The eighth encrypted information can be obtained by encrypting the relevant information of the first communication bill based on the fourth key, or it can be obtained by encrypting the relevant information of the first communication bill and the first communication billing value based on the fourth key, or it can be obtained by encrypting the relevant information of the first communication bill, the first communication billing value and the first random number based on the fourth key.
[0064] Optionally, the second message may also carry at least one of the following: the identifier of the first access network device, and a first random number. The identifier of the first access network device is used to identify itself.
[0065] After receiving the second message, the first terminal can decrypt the eighth encrypted information based on the fourth key to obtain at least one of the following: relevant information of the first communication bill, and the first communication billing value.
[0066] Optionally, after decryption, the first terminal can also verify the relevant information of the first communication bill and / or the first communication billing value. For example, the process of verifying the relevant information of the first communication bill and / or the first communication billing value may include: if the relevant information of the first communication bill is the identifier of the first communication bill, the first terminal can view local bills with the same identifier, calculate a first billing verification value based on the communication fees in the bills with the same identifier, and if the first billing verification value is the same as the first communication billing value, then the verification of the relevant information of the first communication bill and the first communication billing value is successful; or, if the relevant information of the first communication bill is the content of the first communication bill, the first terminal can view whether the content of the local bill is the same as the content of the first communication bill, and if they are the same, then the verification of the relevant information of the first communication bill is successful, and can also calculate a first billing verification value based on the communication fees in the local bill, and if the first billing verification value is the same as the first communication billing value, then the verification of the first communication billing value is successful.
[0067] The first terminal sends the first signature, specifically by sending the first signature to the first access network device. Correspondingly, the first access network device receives the first signature from the first terminal and sends the first signature to the first core network device. The processing of the first core network device can include receiving the first signature. Specifically, the processing of the first core network device receiving the first signature can be: receiving the first signature from the first access network device. Specifically, the first signature sent by the first terminal to the first access network device can be carried in a third message, which can be an uplink AS (Access Layer) message. The first signature sent by the first access network device to the first core network device can be carried in a fourth message.
[0068] The first signature is calculated based on the private key of the first terminal and the first communication billing value. Optionally, the calculation of the first signature can be as follows: using a signature algorithm, the first signature is calculated based on the private key of the first terminal and the first communication billing value. For example, if the first communication billing value is represented as com(price) and the private key of the first terminal is simply represented as va, the calculation of the first signature can be expressed by the following formula: Sig va (Com(price)). Optionally, the calculation of the first signature can be: performing a hash calculation based on the first communication billing value to obtain a first hash value; encrypting the first hash value based on the private key of the first terminal to obtain the first signature.
[0069] Optionally, the processing of the first terminal may further include sending at least one of the following parameters: the identifier of the first terminal, the identifier of the first core network device belonging to the first network, the identifier of the first access network device belonging to the first network, information related to the first communication bill of the first terminal under the first network, and the first communication billing value, wherein the first communication bill includes the communication costs of the first terminal under the first network.
[0070] Accordingly, the processing of the first access network device may further include: receiving at least one of the following parameters from the first terminal: the identifier of the first terminal, the identifier of the first core network device, the identifier of the first access network device, information related to the first communication bill of the first terminal under the first network, and the first communication billing value, wherein the first communication bill includes the communication costs of the first terminal under the first network; and sending at least one of the following parameters to the first core network device: the identifier of the first terminal, the identifier of the first core network device, the identifier of the first access network device, information related to the first communication bill, and the first communication billing value.
[0071] The processing of the first core network device further includes receiving at least one of the following parameters: the identifier of the first terminal, the identifier of the first core network device, the identifier of the first access network device belonging to the first network, information related to the first communication bill of the first terminal under the first network, and the first communication bill value, wherein the first communication bill includes the communication cost of the first terminal under the first network.
[0072] The parameters sent by the first terminal to the first access network device can be carried in a third message. The parameters sent by the first access network device to the first core network device can be carried in a fourth message.
[0073] Optionally, the processing of the first terminal may further include: sending the certificate of the first terminal, wherein the certificate of the first terminal carries the public key of the first terminal. Correspondingly, the processing of the first access network device further includes: receiving the certificate of the first terminal, wherein the certificate of the first terminal carries the public key of the first terminal; and sending the certificate of the first terminal to the first core network device. The processing of the first core network device may include: receiving the certificate of the first terminal.
[0074] The certificate of the first terminal (e.g., represented as Cert) A-a It can also be carried in the third and fourth messages.
[0075] The certificate of the first terminal may further include at least one of the following: an identifier of a second core network device belonging to the second network, an identifier of the first terminal (such as a temporary identifier of the first terminal), and a signature of the certificate used to verify the first terminal. The second core network device may be a core network device in the second network (i.e., the home network of the first terminal) that issues the certificate to the first terminal. The calculation method for the signature of the certificate used to verify the first terminal is not limited in this embodiment.
[0076] Optionally, the processing of the first terminal may further include: providing the first access network device with a third verification code for verifying the identity of the first terminal, wherein the third verification code is calculated based on a fourth key between the first terminal and the first access network device and at least one of the following parameters: the first signature, the identifier of the first terminal, the identifier of the first access network device, relevant information of the first communication bill, the first communication billing value, and the certificate of the first terminal.
[0077] Accordingly, the processing of the first access network device further includes: receiving a third verification code from the first terminal for verifying the identity of the first terminal; verifying the identity of the first terminal based on the third verification code and the third verification code, wherein the third verification code is calculated based on a fourth key between the first terminal and the first access network device and at least one of the following parameters: the first signature, the identifier of the first terminal, the identifier of the first access network device, relevant information of the first communication bill, the first communication billing value, and the certificate of the first terminal.
[0078] The third checksum can also be carried in the third message.
[0079] The third verification code and the third check code should be calculated using the same calculation method and the same parameters. It should be understood that the parameters used to calculate the third check code and the third verification code can be some or all of the parameters carried in the third message except for the third check code (encrypted or unencrypted some or all of the parameters), and no limit or exhaustive list of all cases is provided here.
[0080] Verifying the identity of the first terminal based on the third verification code and the third verification code may include at least one of the following: if the third verification code and the third verification code are consistent, determine that the verification of the identity of the first terminal is successful or passed; if the third verification code and the third verification code are inconsistent, determine that the verification of the identity of the first terminal fails or is not passed.
[0081] The function of the third verification code is to prevent the message (i.e., the third message) from being tampered with and to authenticate the identity of the first terminal. Furthermore, a third random number can also be used in the calculation of the third verification code. Correspondingly, the third message can carry this third random number, which is generated by the first terminal, and the generation method is not limited.
[0082] If the first terminal successfully verifies the relevant information (and / or the first communication bill value) received from the first communication terminal, the third message may not carry the relevant information (and / or the first communication bill value). Correspondingly, the parameters used in calculating the third checksum and the third verification code may also not include the relevant information (and / or the first communication bill value).
[0083] If the first terminal fails to verify the relevant information (and / or the first communication billing value) received from the first communication bill, the third message may carry the relevant information of the first communication bill, and may or may not carry the first communication billing value.
[0084] For example, if the first terminal sends information related to the first communication bill, the third message can carry this information, encrypted with the fourth key. Furthermore, if the first terminal also sends a first communication billing value, the third message can also carry the first communication billing value encrypted with the fourth key and related information about the first communication bill, for example, it can be represented as... The meanings of each parameter are the same as in the previous embodiments, and will not be repeated here.
[0085] The first terminal may first obtain the encrypted information of the first communication bill (and / or the first communication billing value), and then calculate the third verification code; the calculation of the third verification code may use the encrypted information of the first communication bill (and / or the first communication billing value). Correspondingly, the first access network device may first calculate the third verification code based on at least some parameters carried in the third message, and after verifying the identity of the first terminal based on the third verification code and the third verification code, decrypt the encrypted information of the first communication bill based on the fourth key to obtain the relevant information of the first communication bill.
[0086] Alternatively, the first terminal can first calculate the third verification code, and then obtain the encrypted information of the first communication bill (or the encrypted first communication billing value and the information of the first communication bill); the third verification code can be calculated using plaintext (i.e., plaintext before encryption). Correspondingly, the first access network device can first decrypt the encrypted information of the first communication bill (or the encrypted first communication billing value and the information of the first communication bill) based on the fourth key to obtain the information of the first communication bill (or the first communication billing value and the information of the first communication bill), and then calculate the third verification code, and verify the identity of the first terminal based on the third verification code and the third verification code.
[0087] It should be understood that the above is merely an illustrative example, and not all cases are limited or exhaustively listed here.
[0088] The processing of the first access network device may further include: sending a second verification code to the first core network device for verifying the identity of the first access network device, wherein the second verification code is calculated based on a second key between the first access network device and the first core network device and at least one of the following parameters: the identifier of the first core network device, the first signature, the identifier of the first terminal, the identifier of the first access network device, relevant information of the first communication bill, the first communication billing value, and the certificate of the first terminal.
[0089] Accordingly, the processing of the first core network device may include: receiving a second verification code from the first access network device for verifying the identity of the first access network device; verifying the identity of the first access network device based on the second verification code and the second verification code, wherein the second verification code is calculated based on a second key between the first access network device and the first core network device and at least one of the following parameters: the identifier of the first core network device, the first signature, the identifier of the first terminal, the identifier of the first access network device, relevant information of the first communication bill, the first communication billing value, and the certificate of the first terminal.
[0090] The second verification code can be carried in the fourth message. The function of the second verification code is to prevent the message (i.e., the fourth message) from being tampered with and to authenticate the identity of the first access network device. Additionally, a fourth random number can be used in the calculation of the second verification code, and this fourth random number can be carried in the fourth message; this fourth random number is determined by the first access network device, and it can be the same as or different from the third random number, without limitation.
[0091] The second verification code and the second check code should be calculated using the same calculation method and the same parameters.
[0092] The verification of the identity of the first access network device based on the second verification code and the second verification code may include at least one of the following: if the second verification code and the second verification code are consistent, it is determined that the verification of the identity of the first access network device is successful or passed; if the second verification code and the second verification code are inconsistent, it is determined that the verification of the identity of the first access network device fails or is not passed.
[0093] If the first terminal successfully verifies the relevant information of the first communication bill (and / or the first communication billing value), the fourth message may not carry the relevant information of the first communication bill (or may not carry the relevant information of the first communication bill and the first communication billing value). Accordingly, the parameters used in calculating the second check code and the second verification code may also not include the relevant information of the first communication bill (and / or the first communication billing value).
[0094] If the first terminal fails to verify the relevant information of the first communication bill (and / or the first communication billing value), the first terminal may send the relevant information of the first communication bill to the first access network device. That is, the fourth message may carry the relevant information of the first communication bill, and may or may not carry the first communication billing value.
[0095] For example, if the first terminal sends information related to the first communication bill, the first access network device can carry the information related to the first communication bill encrypted with the second key in the fourth message. Alternatively, the information related to the first communication bill and the first communication charge can be jointly encrypted using the second key, for example, it can be represented as... The meanings of each parameter are the same as in the previous embodiments, and will not be repeated here.
[0096] The first access network device may first obtain the relevant information of the encrypted first communication bill, and then calculate the second verification code. Correspondingly, the first core network device may first calculate the second verification code based on at least some parameters carried in the fourth message, verify the identity of the first access network device based on the second verification code and the second verification code, and after successful verification, decrypt the relevant information of the encrypted first communication bill based on the second key to obtain the relevant information of the first communication bill.
[0097] Alternatively, the first access network device can first calculate the second verification code, and then obtain the encrypted information of the first communication bill (or the encrypted first communication billing value and the information of the first communication bill). The first core network device can first decrypt the encrypted information of the first communication bill (or the encrypted first communication billing value and the information of the first communication bill) based on the second key pair to obtain the information of the first communication bill (or the first communication billing value and the information of the first communication bill), and then calculate the second verification code, and verify the identity of the first access network device based on the second verification code and the second verification code.
[0098] It should be understood that the above is merely an illustrative example, and not all cases are limited or exhaustively listed here.
[0099] The first core network device can upload the billing information of the first terminal to the blockchain after the identity of the first access network device is verified based on the second verification code and the second check code.
[0100] Optionally, the first core network device can verify the first signature. Specifically, the first core network device can verify the first signature based on the public key of the first terminal and the first communication billing value. For example, the first signature verification process can be as follows: using a signature verification algorithm, the first signature is decrypted based on the public key of the first terminal to obtain a first parameter to be verified; if the first parameter to be verified is the same as the first communication billing value, the first signature verification is determined to be successful. Alternatively, a hash calculation is performed based on the first communication billing value to obtain a first verification hash value, and the first signature is decrypted based on the public key of the first terminal to obtain a first decrypted value; if the first decrypted value and the first verification hash value are the same, the first signature verification is determined to be successful.
[0101] Optionally, if the first core network device receives and decrypts the relevant information of the first communication bill and / or the first communication billing value uploaded by the first terminal, it can also verify the relevant information of the first communication bill and / or the first communication billing value. The verification method is similar to that of the first terminal and will not be described again.
[0102] The first core network device can upload the billing information of the first terminal to the blockchain after verifying the first signature and verifying the identity of the first access network device based on the second verification code and the second check code.
[0103] The billing-related information of the first terminal includes: the first communication billing value, a first signature for determining that the first terminal recognizes the first communication billing value, and a second signature for determining that the first core network device recognizes the first communication billing value.
[0104] The second signature is calculated by the first core network device. The second signature is calculated based on the private key of the first core network device and the first communication billing value. For example, the calculation of the second signature can be as follows: using a signature algorithm, the first communication billing value is calculated based on the private key of the first core network device. For instance, assuming the first communication billing value is represented as com(price) and the private key of the first core network device is simply represented as B, the second signature can be represented by the following formula: Sig B [Com(price)]. For example, the calculation of the second signature can be as follows: perform a hash calculation based on the first communication billing value to obtain a second hash value; encrypt the second hash value based on the private key of the first core network device to obtain the second signature.
[0105] Optionally, the billing information of the first terminal may also include: the certificate of the first terminal. It should be noted that if the certificate of the first terminal is not uploaded to the blockchain, the certificate of the first terminal may be uploaded to the blockchain; otherwise, the certificate of the first terminal may not be uploaded (i.e., the billing information of the first terminal may not include the certificate of the first terminal).
[0106] In one embodiment, when the first terminal accesses the first network using a symmetrical scheme, the first core network device triggers the collection of bills. The first core network device and the first terminal interact through NAS messages (for example, the first access network device only forwards the messages).
[0107] Before the first core network device uploads the billing information of the first terminal to the blockchain, the method further includes: sending first encrypted information to the first terminal, wherein the first encrypted information is obtained by encrypting at least one of the following parameters based on the first key between the first terminal and the first core network device: the first communication billing value, and the relevant information of the first communication bill.
[0108] Before the first terminal sends the first signature, the method further includes: receiving first encrypted information from the first core network device, wherein the first encrypted information is obtained by encrypting at least one of the following parameters based on a first key between the first terminal and the first core network device: the first communication billing value, and related information of the first communication bill.
[0109] In this embodiment, the first encrypted information can be carried by the fifth message, which can be a downlink NAS message.
[0110] Furthermore, the fifth message may also carry at least one of the following: the identifier of the first core network device, and a first random number. The descriptions of each parameter are the same as in the aforementioned embodiments and will not be repeated here.
[0111] The first encrypted information may be obtained by encrypting the relevant information of the first communication bill based on the first key, or it may be obtained by encrypting the relevant information of the first communication bill and the first communication billing value based on the first key, or it may be obtained by encrypting the relevant information of the first communication bill, the first communication billing value and the first random number based on the first key.
[0112] The relevant descriptions of the first communication billing value and the first communication bill are the same as those in the previous embodiments, and will not be repeated here.
[0113] For example, the fifth message can be represented as: Where N is the first random number, ID B For the identification of the first core network equipment, This is the first encrypted information; the first encrypted information can be based on the first key (K). a-B The first random number N, bill, and com(price) are calculated.
[0114] The first terminal can decrypt the first encrypted information based on the first key to obtain at least one of the following: relevant information of the first communication bill, and the first communication billing value.
[0115] Optionally, after decryption, the first terminal can also verify the relevant information of the first communication bill and / or the first communication billing value. The process of verifying the relevant information of the first communication bill and / or the first communication billing value is the same as in the aforementioned embodiments and will not be described again.
[0116] The first terminal sends a first signature. Specifically, this can be done by the first terminal sending the first signature to the first core network device. Correspondingly, the first core network device receiving the first signature can be done by receiving the first signature from the first terminal. Specifically, the first terminal sending the first signature to the first core network device can be carried by a sixth message, which can be an uplink NAS message.
[0117] The calculation method for the first signature is the same as that in the previous embodiments, and will not be repeated here.
[0118] Optionally, the processing of the first terminal may further include: sending at least one of the following parameters to the first core network device: the identifier of the first terminal, the identifier of the first core network device, the identifier of the first access network device, relevant information of the first communication bill, and the first communication billing value. Correspondingly, the processing of the first core network device may further include: receiving at least one of the following parameters from the first terminal: the identifier of the first terminal, the identifier of the first core network device, the identifier of the first access network device, relevant information of the first communication bill, and the first communication billing value.
[0119] The parameters sent by the first terminal to the first core network device can also be carried by the sixth message.
[0120] Optionally, the processing of the first terminal may further include: sending the certificate of the first terminal. Correspondingly, the processing of the first core network device further includes: receiving the certificate of the first terminal. The certificate of the first terminal may also be carried by a sixth message.
[0121] Optionally, the processing of the first terminal may further include: sending a first verification code to the first core network device for verifying the identity of the first terminal, wherein the first verification code is calculated based on a first key between the first terminal and the first core network device and at least one of the following parameters: the first signature, the identifier of the first terminal, the identifier of the first core network device, the identifier of the first access network device, relevant information of the first communication bill, the first communication billing value, and the certificate of the first terminal.
[0122] Accordingly, the processing of the first core network device further includes: receiving a first verification code from the first terminal for verifying the identity of the first terminal; verifying the identity of the first terminal based on the first verification code and the first verification code, wherein the first verification code is calculated based on a first key between the first terminal and the first core network device and at least one of the following parameters: the identifier of the first core network device, the first signature, the identifier of the first terminal, the identifier of the first access network device, relevant information of the first communication bill, the first communication billing value, and the certificate of the first terminal.
[0123] The first verification code can also be carried in the sixth message. The function of the first verification code is to prevent the message (i.e., the sixth message) from being tampered with and to authenticate the identity of the first terminal. Additionally, a third random number can be used in the calculation of the first verification code; correspondingly, the sixth message can carry this third random number, which is generated by the first terminal, and the method of generation is not limited.
[0124] The first verification code and the first check code should be calculated using the same calculation method and the same parameters.
[0125] Verifying the identity of the first terminal based on the first verification code and the first verification code may include at least one of the following: if the first verification code and the first verification code are consistent, determine that the verification of the identity of the first terminal is successful or passed; if the first verification code and the first verification code are inconsistent, determine that the verification of the identity of the first terminal fails or is not passed.
[0126] If the first terminal successfully verifies the relevant information of the first communication bill (and / or the first communication billing value), the sixth message may not carry the relevant information of the first communication bill (or, may not send the relevant information of the first communication bill and the first communication billing value). Correspondingly, the parameters used in calculating the third checksum and the third verification code may also not include the relevant information of the first communication bill (and / or the first communication billing value, and / or the identifier of the first core network device). It should be understood that the above is merely an illustrative example, and not all cases are limited or exhaustively described here.
[0127] If the first terminal fails to verify the information related to the first communication bill (and / or the first communication billing value) carried in the fifth message, the sixth message may carry the information related to the first communication bill. Optionally, the sixth message may or may not carry the first communication billing value. If the information related to the first communication bill and the first communication billing value are sent, they can be encrypted based on the first key. The relevant descriptions of encryption are similar to those in the aforementioned embodiments and will not be repeated here.
[0128] The first terminal may first obtain the relevant information of the encrypted first communication bill (and / or the first communication billing value), and then calculate the first verification code. Correspondingly, the first core network device may first calculate the first verification code based on at least some of the parameters carried in the third message, and after verifying the identity of the first terminal based on the first verification code and the first check code, decrypt the encrypted information based on the first key.
[0129] Alternatively, the first terminal can first calculate the first verification code, and then obtain the encrypted information of the first communication bill (or the encrypted first communication billing value and the information of the first communication bill); the first verification code can be calculated using plaintext (i.e., plaintext before encryption). Correspondingly, the first core network device can first decrypt the encrypted information of the first communication bill (or the encrypted first communication billing value and the information of the first communication bill) based on the first key pair to obtain the information of the first communication bill (or the first communication billing value and the information of the first communication bill), and then calculate the first verification code, and verify the identity of the first terminal based on the first verification code and the first verification code.
[0130] It should be understood that the above is merely an illustrative example, and not all cases are limited or exhaustively listed here.
[0131] The first core network device can upload the billing information of the first terminal to the blockchain after verifying the first signature and confirming the identity of the first terminal based on the first verification code and the first check code. The processing of verifying the first signature by the first core network device is the same as in the previous embodiments, and the description of the billing information of the first terminal in this embodiment is the same as in the previous embodiments, and will not be repeated here.
[0132] In one embodiment, when the first terminal accesses the first network using a symmetrical scheme, the first core network device triggers bill collection. The first core network device can send a fifth message to the first terminal. After receiving the fifth message, the first terminal can send the third message from the aforementioned embodiment to the first access network device. The first access network device can then send the fourth message from the aforementioned embodiment to the first core network device. Subsequently, the first core network device uploads the billing information of the first terminal to the blockchain. The processing of each message and each device is the same as in the aforementioned embodiments and will not be repeated.
[0133] In one embodiment, when the first terminal accesses the first network using a symmetrical scheme, the first core network device triggers bill collection. The first core network device can send a first message to the first access network device, and the first access network device sends the aforementioned second message to the first terminal. After receiving the second message, the first terminal performs the process of sending a sixth message to the first core network device. Subsequently, the first core network device uploads the billing-related information of the first terminal to the blockchain. The processing of each message and each device is the same as in the previous embodiments and will not be repeated.
[0134] In one embodiment, when the first terminal accesses the first network using a symmetrical scheme, the first terminal triggers the reporting of an invoice, and information exchange takes place between the first core network device, the first access network device, and the first terminal.
[0135] In this embodiment, the first terminal directly sends information such as the first signature to the first access network device. That is, the first terminal directly sends a third message to the first access network device, and the first access network device sends a fourth message to the first core network device; after receiving the fourth message, the first core network device uploads the billing-related information of the first terminal to the blockchain.
[0136] In this embodiment, the contents that the third and fourth messages can carry are similar to those in the previous embodiments, and will not be described again.
[0137] In this embodiment, since the first terminal actively triggers the reporting of the bill to the first access network device, it can send relevant information about the first communication bill to the first access network device. That is, the third and fourth messages can carry this relevant information, but may or may not carry the identifier of the first core network device, and may or may not carry the first communication billing value. The requirements for encrypting the relevant information of the first communication bill and / or the first communication billing value in the messages, as well as the calculation of the encrypted information, the calculation order of each checksum, and the related processing of each device, are the same as in the previous embodiments and will not be repeated.
[0138] In one embodiment, when the first terminal accesses the first network using a symmetrical scheme, the first terminal triggers the reporting of an invoice, and information exchange takes place between the first core network device and the first terminal.
[0139] In this embodiment, the first terminal directly sends the first signature and other information to the first access network device. That is, the first terminal directly sends the sixth message to the first core network device; after receiving the sixth message, the first core network device uploads the billing-related information of the first terminal to the blockchain.
[0140] In this embodiment, the content that the sixth message can carry is similar to that in the previous embodiments, and will not be repeated. Since the first terminal actively triggers the reporting of the bill to the first core network device, it can send relevant information about the first communication bill to the first core network device. That is, the sixth message can carry relevant information about the first communication bill, and may or may not carry the first communication billing value. Other related descriptions of the sixth message and the processing of each device are the same as in the previous embodiments, and will not be repeated.
[0141] Next, an exemplary embodiment of the above symmetrical scheme will be described with reference to Figure 5.
[0142] Step 501: Core network B (first core network device) sends a bill confirmation request (i.e., first message) to its own base station b (first access network device), which may carry the content and commitment value of the first communication bill encrypted with the key between core network B and base station b.
[0143] The bill confirmation request can be expressed as: Where N is the first random number used to prevent replay attacks, ID B The identifier for the first core network device is used to identify itself. This is the second encrypted information; the second encrypted information can be based on the second key (K). b-B The key between core network B and base station b is used to calculate N, bill (the content of the first communication bill), and com (price) (the first communication bill value, i.e., the promised value). Encryption is to protect the content of bill from being disclosed, and signature is to achieve non-repudiation and to authenticate the identity of core network B.
[0144] Step 502: Upon receiving the message, base station b first verifies the signature's correctness and then decrypts it. Then, it forwards the bill confirmation request (i.e., the second message) to UEa (the first terminal), which can carry the content and commitment value of the first communication bill encrypted based on the key between base station b and UEa.
[0145] For example, the second message can be represented as: Where N is the first random number to prevent replay attacks, and ID is... bTo identify itself as the first access network device, For the eighth encrypted message, K a-b This is the fourth key, the key between base station b and UEa. Encryption is used to protect the contents of the bill from being leaked.
[0146] After receiving the message, UEa decrypts it, verifies that the information in bill and Com(price) is correct, and also signs Com(price). Then it can proceed with step 503a or step 503b.
[0147] Step 503a: UEa can send a message (i.e., the sixth message) to core network B, which may carry UEa's certificate and first signature, and then execute step 504.
[0148] This sixth message can carry: the first signature, N (the first random number to prevent replay attacks), and ID. a Indicate UEa's identity, Cert A-a The UEa certificate is used to prove the validity of its public key, allowing core network B to verify the validity of the first signature. The first checksum is used to prevent messages from being tampered with and to authenticate the identity of UEa.
[0149] Step 503b: UEa can send a message (i.e., the third message) to base station b, and base station b can send a fourth message to core network B. Then, step 504 is executed. Both the third message and the fourth message can carry UEa's certificate and first signature.
[0150] The third message sent by UEa to base station b can be represented as: Where N is a third random number to prevent replay attacks, and ID a The identifier (or ID) of the first terminal a It can be replaced with the temporary identifier ID of the first terminal. va (Indicate your identity, ID) b The identifier of the first access network device indicates that the message was sent to b, Cert. A-a The certificate of the first terminal is used to prove the validity of its public key, so that B can verify the validity of the signature, Sig. va [Com(price)] is the first signature and the third verification code. Third verification code It can be based on the fourth key (K) a-b For N, ID a ID b Cert A-a Sig va [Com(price)] is calculated.
[0151] The fourth message can be represented as: Among them, the second check code It can be based on the second key (K) b-B For N, ID a ID b Cert A-a Sig va [Com(price)] is calculated, and the meanings of the other parameters are the same as in the aforementioned embodiments, and will not be repeated here. This is to prevent messages from being tampered with and to authenticate the identity of base station b.
[0152] Step 504: After receiving a message (e.g., the sixth or fourth message), Core Network B verifies the validity of UEa's first signature, and then uploads the first signature, Com(price) (commitment value), and Core Network B's second signature for Com(price) to the blockchain. UEa's certificate can also be uploaded to the blockchain at the same time.
[0153] In some examples, only steps 503b and 504 can be executed, meaning UEa can generate Com(price) and directly send the bill and Com(price) in the third message to base station b, which then sends the fourth message to core network B. In one example, only steps 503a and 504 can be executed. In this case, the sixth message can also carry the Com(price) generated by UEa, the bill, and UEa's first signature on Com(price). In another example, billing can be triggered by base station b. For example, steps 502, 503b, and 504 can be executed directly, or steps 502, 503a, and 504 can be executed. In this case, the way base station b generates Com(price) is the same as that of core network B or UEa, and will not be described in detail.
[0154] To ensure compatibility with existing roaming schemes and simplify billing, in this example, core network A (the second core network device) will issue a dedicated billing certificate, Cert, to its subscribed UEa. A-a This allows UEa to sign and confirm its incurred expenses. Each time UEa uses spectrum resources, it generates a micro-bill. UEa or core network B commits to the price in the micro-bill, and then both UEa and core network B sign Com(price). Finally, core network B merges Com(price) and Signit. B [Com(price)]、Sig va [Com(price)]、Cert A-a(Optional) Upload it to the blockchain for other nodes on the chain to aggregate and verify. Once verified, the smart contract will be triggered for billing.
[0155] In some possible implementations, the first terminal uses an asymmetric scheme to access the first network.
[0156] In one embodiment, the collection of bills is triggered by a first core network device, and information exchange takes place between the first core network device, the first access network device, and the first terminal.
[0157] Before uploading the billing information of the first terminal to the blockchain, the first core network device further includes at least one of the following: sending fifth encrypted information to the first access network device, wherein the fifth encrypted information is obtained by encrypting at least one of the following parameters based on the public key of the first access network device: the first communication billing value, and the relevant information of the first communication bill; sending a seventh signature to the first access network device, wherein the seventh signature is obtained by calculating at least one of the following parameters based on the private key of the first core network device: the first communication billing value, the relevant information of the first communication bill, and the fifth encrypted information.
[0158] The processing of the first access network device further includes: receiving fifth encrypted information from the first core network device, wherein the fifth encrypted information is obtained by encrypting at least one of the following parameters based on the public key of the first access network device: the first communication billing value and related information of the first communication bill; and sending fourth encrypted information to the first terminal, wherein the fourth encrypted information is obtained by encrypting at least one of the following parameters based on the public key of the first terminal: the first communication billing value and related information of the first communication bill.
[0159] The processing of the first access network device further includes: receiving a seventh signature from the first core network device, wherein the seventh signature is calculated based on the private key of the first core network device using at least one of the following parameters: the first communication billing value, information related to the first communication bill, and the fifth encrypted information; and sending an eighth signature to the first terminal, wherein the eighth signature is calculated based on the private key of the first access network device and at least one of the following parameters: the first communication billing value, information related to the first communication bill, and the fourth encrypted information.
[0160] The processing before the first terminal sends the first signature may further include: receiving fourth encrypted information, wherein the fourth encrypted information is obtained by encrypting at least one of the following parameters based on the public key of the first terminal: the first communication billing value, and related information of the first communication bill.
[0161] The processing before the first terminal sends the first signature may include: receiving an eighth signature from the first access network device; and verifying the eighth signature based on the public key of the first access network device and at least one of the following parameters: the first communication billing value, relevant information of the first communication bill, and the fourth encrypted information.
[0162] The message sent by the first core network device to the first access network device can be the seventh message, that is, the seventh message carries the fifth encryption information and / or the seventh signature; the message sent by the first access network device to the first terminal can be the eighth message, that is, the eighth message carries the fourth encryption information and / or the eighth signature, and the eighth message can be a downlink AS (access layer) message.
[0163] Furthermore, the seventh message may also carry at least one of the following: the identifier of the first core network device, and a first random number. The descriptions of the identifier of the first core network device and the first random number are the same as in the aforementioned embodiments and will not be repeated here.
[0164] The description of the relevant information of the first communication billing value and the first communication bill is the same as that in the previous embodiment, and will not be repeated here.
[0165] The fifth encrypted information can be obtained by encrypting the relevant information of the first communication bill based on the public key of the first access network device; alternatively, it can be obtained by encrypting the relevant information of the first communication bill and the first communication billing value based on the public key of the first access network device; or, it can be obtained by encrypting the relevant information of the first communication bill, the first communication billing value, and the first random number based on the public key of the first access network device. The method by which the first core network device obtains the public key of the first access network device is not limited in this embodiment.
[0166] After receiving the fifth encrypted information carried in the seventh message, the first access network device can decrypt the fifth encrypted information based on the public key of the first access network device to obtain at least one of the following: relevant information of the first communication bill, and the first communication billing value.
[0167] The first access network device can first calculate the fifth encrypted information and then calculate the seventh signature. The seventh signature is calculated based on the private key of the first core network device using the fifth encrypted information. For example, a signature algorithm can be used to calculate the seventh signature based on the private key of the first core network device using the fifth encrypted information. Alternatively, a hash calculation can be performed on the fifth encrypted information to obtain a seventh hash value; the seventh hash value can then be encrypted using the private key of the first core network device to obtain the seventh signature.
[0168] Alternatively, the first access network device may calculate the seventh signature before calculating the fifth encrypted information. The seventh signature is calculated based on the private key of the first core network device using at least one of the following: the first communication billing value, or information related to the first communication invoice.
[0169] For example, the seventh message may carry the identifier of the first core network device, a first random number, a seventh signature, and fifth encryption information.
[0170] If the first core network device calculates the fifth encrypted information before calculating the seventh signature, the first access network device can correspondingly verify the seventh signature before decrypting the fifth encrypted information. The method for decrypting the fifth encrypted information is the same as in the aforementioned embodiments and will not be repeated. Verifying the seventh signature can be done by verifying the seventh signature based on the public key of the first core network device and the fifth encrypted information. If the verification of the seventh signature is successful, the first access network device can determine that the authentication of the first core network device has been successful; otherwise, the authentication of the first core network device has failed.
[0171] If the first core network device calculates the seventh signature before calculating the fifth encrypted information, the first access network device can correspondingly decrypt the fifth encrypted information first and then verify the seventh signature. The method for decrypting the fifth encrypted information is the same as in the aforementioned embodiments and will not be repeated. The verification of the seventh signature can be performed by verifying the seventh signature based on the public key of the first core network device and the information after decryption of the fifth encrypted information. The information after decryption of the fifth encrypted information may include relevant information of the first communication bill and / or the first communication billing value.
[0172] If the first access network device successfully authenticates the first core network device, the first access network device can also calculate the fourth encrypted information and / or calculate the eighth signature.
[0173] The fourth encrypted information can be obtained by encrypting the relevant information of the first communication bill based on the public key of the first terminal, or it can be obtained by encrypting the relevant information of the first communication bill and the first communication billing value based on the public key of the first terminal, or it can be obtained by encrypting the relevant information of the first communication bill, the first communication billing value, and the first random number based on the public key of the first terminal. For example, the fourth encrypted information can be represented as Enc pka [bill, Com(price)], where pka is the public key of the first terminal, and the descriptions of other parameters are the same as in the previous embodiments. Accordingly, after the first terminal receives the fourth encrypted information carried in the eighth message, it can decrypt the fourth encrypted information based on the public key of the first terminal to obtain at least one of the following: relevant information of the first communication bill, and the first communication billing value.
[0174] Optionally, the fourth encrypted information can be calculated first, followed by the eighth signature. The eighth signature is calculated based on the private key of the first access network device using the fourth encrypted information. For example, a signature algorithm can be used to calculate the eighth signature based on the private key of the first access network device using the fourth encrypted information. Alternatively, a hash calculation can be performed on the fourth encrypted information to obtain the eighth hash value; the eighth signature is then obtained by encrypting the eighth hash value using the private key of the first access network device.
[0175] Optionally, the eighth signature can be calculated first, followed by the fourth encrypted information. The eighth signature is calculated based on the private key of the first access network device using at least one of the following: the first communication billing value, and information related to the first communication invoice.
[0176] Optionally, the eighth message may also carry at least one of the following: the identifier of the first terminal, the certificate of the first access network device, and a fifth random number. The certificate of the first access network device is used to identify itself, and the content of the certificate may include the public key of the first access network device, the identifier of the first core network device, the identifier of the first access network device, and a signature used to verify the certificate of the first access network device.
[0177] If the first access network device calculates the fourth encrypted information before calculating the eighth signature, the first terminal can correspondingly verify the eighth signature before decrypting the fourth encrypted information. The method for decrypting the fourth encrypted information is the same as in the previous embodiment and will not be repeated. Verifying the eighth signature can be done by verifying the eighth signature based on the public key of the first access network device and the fourth encrypted information. If the verification of the eighth signature is successful, the first terminal can determine that the authentication of the first access network device was successful; otherwise, it determines that the authentication of the first access network device failed.
[0178] If the first access network device calculates the eighth signature before calculating the fourth encrypted information, the first terminal can correspondingly decrypt the fourth encrypted information first and then verify the eighth signature. Verifying the eighth signature can be done by verifying the eighth signature based on the public key of the first access network device and the information after decryption of the fourth encrypted information. The information after decryption of the fourth encrypted information may include relevant information from the first communication bill and / or the first communication billing value.
[0179] Optionally, after decryption, the first terminal can also verify the relevant information of the first communication bill and / or the first communication billing value. The process of verifying the relevant information of the first communication bill and / or the first communication billing value is the same as in the previous embodiments and will not be described again.
[0180] Optionally, the first terminal sending a first signature to determine that it recognizes the first communication billing value includes: the first terminal can directly send the first signature to the first access network device. Correspondingly, the first access network device can directly send the first signature to the first core network device.
[0181] Optionally, the first terminal sending a first signature for determining that the first terminal recognizes the first communication billing value includes: sending tenth encrypted information to the first access network device, wherein the tenth encrypted information is obtained by encrypting the first signature for determining that the first terminal recognizes the first communication billing value based on the public key of the first access network device.
[0182] Accordingly, the first access network device receives a first signature from the first terminal for determining the first terminal's acceptance of the first communication billing value, including: receiving tenth encrypted information from the first terminal, wherein the tenth encrypted information is obtained by encrypting the first signature for determining the first terminal's acceptance of the first communication billing value based on the public key of the first access network device.
[0183] Sending the first signature from the first access network device to the first core network device includes: sending third encrypted information to the first core network device, wherein the third encrypted information is obtained by encrypting the first signature based on the public key of the first core network device.
[0184] The first core network device receives the first signature, including: receiving third encrypted information, wherein the third encrypted information is obtained by encrypting the first signature based on the public key of the first core network device.
[0185] The tenth encrypted information (or first signature) sent by the first terminal to the first access network device can be carried by the ninth message, which can be an uplink AS (access layer) message. The third encrypted information (or first signature) sent by the first access network device to the first core network device can be carried by the tenth message.
[0186] The calculation method for the first signature is the same as that in the previous embodiments, and will not be repeated here.
[0187] The first access network device, upon receiving the tenth encrypted information, decrypts it using its public key to obtain the first signature. Then, the first access network device encrypts the first signature using the public key of the first core network device to obtain the third encrypted information. Upon receiving the third encrypted information, the first core network device decrypts it using its own public key to obtain the first signature.
[0188] It should be noted that the first terminal may encrypt or not encrypt the first signature, and the first access network device may encrypt or not encrypt the first signature. For example, the ninth and tenth messages may carry an unencrypted first signature; or the ninth message may carry ten encrypted information and the tenth message may carry third encrypted information; or the ninth message may carry an unencrypted first signature and the tenth message may carry third encrypted information. No limit or exhaustive list of all possible scenarios is provided here.
[0189] Optionally, the processing of the first access network device further includes: sending a third signature to the first core network device for verifying the identity of the first access network device, wherein the third signature is calculated based on the private key of the first access network device and at least one of the following parameters: the first signature and the third encrypted information.
[0190] The processing of the first core network device further includes: receiving a third signature from the first access network device for verifying the identity of the first access network device; and verifying the third signature based on the public key of the first access network device and at least one of the following parameters: the first signature and the third encrypted information.
[0191] The aforementioned third signature can be carried by the tenth message.
[0192] In one example, the first access network device may calculate a third signature before calculating the third encrypted information. The third signature is calculated based on the first signature using the private key of the first access network device. For example, the third signature could be represented as Sig. b [Sig va [Com(price)]].
[0193] For example, the tenth message can carry both a third signature and a first signature. The first core network device can verify the third signature based on the first access network device's public key and the first signature. If the third signature is verified, the authentication of the first access network device can be determined to be successful; otherwise, the authentication of the first access network device can be determined to have failed.
[0194] In one example, the first access network device may first calculate the third encrypted information and then calculate the third signature. The third signature is calculated based on the private key of the first access network device using the third encrypted information. For example, the third signature can be represented as Sig. b [Enc pkB [Sig va [Com(price)]]].
[0195] For example, the tenth message may carry a third signature and third encrypted information. If the first access network device calculates the third encrypted information before calculating the third signature, the first core network device may verify the third signature before decrypting the third encrypted information. The method for decrypting the third encrypted information is the same as in the previous embodiments and will not be repeated. Verifying the third signature may be based on the public key of the first access network device and the third encrypted information. If the first access network device calculates the third signature before calculating the third encrypted information, the first core network device may decrypt the third encrypted information before verifying the third signature. Verifying the third signature may be based on the public key of the first access network device and the first signature. Furthermore, if the third signature is verified successfully, the authentication of the first access network device is considered successful; otherwise, the authentication of the first access network device is considered unsuccessful.
[0196] The first core network device can verify the first signature. The process of the first core network device verifying the first signature is the same as that in the previous embodiment, and will not be described again.
[0197] Optionally, the processing of the first terminal may further include: sending a first credential for verifying the first terminal's permission to use the resources of the first network, wherein the first credential carries at least one of the following: a fourth signature for verifying the first terminal's permission to use the resources of the first network authorized by the second network, and a fifth signature for verifying the second network's permission to use the resources of the first network.
[0198] The processing of the first access network device further includes: receiving a first credential from the first terminal for verifying the first terminal's permission to use resources of the first network, wherein the first credential carries at least one of the following: a fourth signature for verifying the first terminal's permission to use the second network to obtain authorized resources of the first network, and a fifth signature for verifying the second network's permission to use resources of the first network; and sending the first credential to the first core network device.
[0199] The processing of the first core network device further includes: receiving a first credential for verifying the first terminal's permission to use the resources of the first network, wherein the first credential carries at least one of the following: a fourth signature for verifying the first terminal's permission to use the second network to obtain authorized access to the resources of the first network, and a fifth signature for verifying the second network's permission to use the resources of the first network.
[0200] Wherein, the first credential (e.g., represented as Cert) B-A-a It also includes at least one of the following: the identifier of the first terminal (such as a temporary identifier of the first terminal) and the temporary public key of the first terminal.
[0201] The fourth signature is calculated based on the private key of the second core network device and at least one of the following: the temporary identifier of the first terminal, the temporary public key of the first terminal, and the second credential.
[0202] The fifth signature is carried by the second credential in the first credential. The second credential also carries at least one of the following: the identifier of the second core network device, the public key of the second core network device, the identifier of the first core network device, the public key of the first core network device, and information authorizing the second network to use resources of the first network.
[0203] Specifically, the fifth signature is calculated based on the private key of the first core network device and at least one of the following: the identifier of the first core network device, the public key of the first core network device, the identifier of the second core network device in the second network, the public key of the second core network device, and information on the resources of the first network authorized for use by the second network.
[0204] The first credential is issued by the second core network device to the first terminal, and the second credential is generated by the first core network device for the second core network device and uploaded to the blockchain. This second credential can also be referred to as the first-level credential of the asymmetric scheme, and the first credential can also be referred to as the second-level credential of the asymmetric scheme.
[0205] The aforementioned first credential can be carried by the ninth message and the tenth message respectively.
[0206] After receiving the first credential, the first core network device may further include: verifying the fourth and fifth signatures in the first credential; and if the verification of the fourth and fifth signatures is successful, determining that the first terminal has the authority to use the resources of the first network.
[0207] The verification of the fifth signature can be: based on the public key of the first core network device, the fifth signature, and at least one of the following information, verifying the second network's permission to use the resources of the first network: the identifier of the first core network device, the public key of the first core network device, the identifier of the second core network device, the public key of the second core network device, and information authorizing the second network to use the resources of the first network.
[0208] The verification of the fourth signature can be based on the public key of the second core network device, the fourth signature, and at least one of the following information to verify the first terminal's permission to use the second network to obtain authorized resources of the first network: the temporary identifier of the first terminal, the temporary public key of the first terminal, and the second credential.
[0209] Optionally, the processing of the first terminal may further include sending at least one of the following parameters to the first access network device: the identifier of the first access network device, relevant information of the first communication bill, and the first communication billing value.
[0210] Accordingly, the processing of the first access network device may further include: receiving at least one of the following parameters from the first terminal: the identifier of the first access network device, the relevant information of the first communication bill, and the first communication billing value; and sending at least one of the following parameters to the first core network device: the identifier of the first core network device, the relevant information of the first communication bill, the first communication billing value, and the certificate of the first access network device.
[0211] The processing of the first core network device also includes receiving at least one of the following parameters sent by the first access network device: the identifier of the first core network device, relevant information of the first communication bill, the first communication billing value, and the certificate of the first access network device.
[0212] The parameters sent by the first terminal to the first access network device can be carried in the ninth message. The parameters sent by the first access network device to the first core network device can be carried in the tenth message.
[0213] If the first terminal verifies the relevant information of the received first communication bill (and / or the first communication billing value), the ninth and tenth messages may not carry the relevant information of the first communication bill (or, may not carry the relevant information of the first communication bill and the first communication billing value).
[0214] If the first terminal fails to verify the relevant information of the received first communication bill (and / or the first communication billing value), the ninth and tenth messages may carry the relevant information of the first communication bill, and may or may not carry the first communication billing value.
[0215] For example, if the first terminal sends information related to the first communication bill, it can include this information, encrypted with the public key of the first access network device, in the ninth message. Furthermore, if the first terminal also sends a first communication billing value, it can also include the first communication billing value, encrypted with the public key of the first access network device, and the information related to the first communication bill in the ninth message.
[0216] It should be understood that the above is merely an illustrative example, and not all cases are limited or exhaustively listed here.
[0217] Optionally, if the first core network device receives and decrypts the relevant information of the first communication bill and / or the first communication billing value uploaded by the first terminal, it can also verify the relevant information of the first communication bill and / or the first communication billing value. The verification method is similar to that of the first terminal and will not be described again.
[0218] The first core network device can upload the billing information of the first terminal to the blockchain after verifying the first signature, and / or verifying the third signature, and / or verifying the first credential.
[0219] The billing-related information of the first terminal includes: the first communication billing value, a first signature for determining that the first terminal recognizes the first communication billing value, and a second signature for determining that the first core network device recognizes the first communication billing value.
[0220] The calculation method for the second signature is the same as that in the aforementioned embodiments, and will not be repeated here.
[0221] Optionally, the billing-related information of the first terminal may also include: the first credential.
[0222] In one embodiment, in a scenario where the first terminal accesses the first network using an asymmetric scheme, the first core network device triggers the collection of bills, and the first core network device and the first terminal interact through NAS messages (for example, the first access network device only forwards the messages).
[0223] Before uploading the billing information of the first terminal to the blockchain, the first core network device may include at least one of the following: sending fourth encrypted information to the first terminal, wherein the fourth encrypted information is obtained by encrypting at least one of the following parameters based on the public key of the first terminal: the first communication billing value, and the relevant information of the first communication bill; sending a sixth signature to the first terminal, wherein the sixth signature is obtained by calculating at least one of the following parameters based on the private key of the first core network device: the first communication billing value, the relevant information of the first communication bill, and the fourth encrypted information.
[0224] The processing before the first terminal sends the first signature may include: receiving fourth encrypted information, wherein the fourth encrypted information is obtained by encrypting at least one of the following parameters based on the first terminal's public key: the first communication billing value, and related information of the first communication bill.
[0225] The processing before the first terminal sends the first signature may further include: receiving a sixth signature from the first core network device; and verifying the sixth signature based on the public key of the first core network device and at least one of the following parameters: the first communication billing value, relevant information of the first communication bill, and the fourth encrypted information.
[0226] In this embodiment, the fourth encryption information and / or the sixth signature can be carried by the eleventh message, which can be a downlink NAS message.
[0227] Furthermore, the eleventh message may also carry at least one of the following: the identifier of the first core network device, and a first random number. The descriptions of each parameter are the same as in the aforementioned embodiments and will not be repeated here.
[0228] In this embodiment, the fourth encrypted information is calculated by the first core network device. The specific calculation method for the fourth encrypted information is the same as in the previous embodiment and will not be repeated here. After receiving the fourth encrypted information carried in the eleventh message, the first terminal can decrypt the fourth encrypted information based on the public key of the first terminal to obtain at least one of the following: relevant information of the first communication bill, and the first communication billing value.
[0229] The first core network device can first calculate the fourth encrypted information and then calculate the sixth signature. The sixth signature is calculated based on the private key of the first core network device using the fourth encrypted information. For example, a signature algorithm can be used to calculate the sixth signature based on the private key of the first core network device using the fourth encrypted information. This sixth signature can be represented as: Sig B [Enc pka [bill, Com(price)]], where the parameters are described in the same way as in the previous embodiment. For example, a sixth hash value is obtained by performing a hash calculation based on the fourth encrypted information; the sixth signature is obtained by encrypting the sixth hash value based on the private key of the first core network device.
[0230] Alternatively, the first core network device may first calculate the sixth signature and then calculate the fourth encrypted information. The fourth signature is calculated based on the private key of the first core network device using at least one of the following: the first communication billing value, or information related to the first communication invoice.
[0231] For example, the eleventh message can carry the identifier of the first core network device, the first random number, and the sixth signature, which can be represented as: ID B ,N,Sig B [Enc pka [bill,Com(price)]].
[0232] If the first core network device calculates the fourth encrypted information before calculating the sixth signature, the first terminal can correspondingly verify the sixth signature before decrypting the fourth encrypted information. The method for decrypting the fourth encrypted information is the same as in the previous embodiment and will not be repeated here. Verifying the sixth signature can be done by verifying the sixth signature based on the public key of the first core network device and the fourth encrypted information. If the verification of the sixth signature is successful, the first terminal can determine that the authentication of the first core network device was successful; otherwise, the authentication of the first core network device failed.
[0233] If the first core network device calculates the sixth signature before calculating the fourth encrypted information, the corresponding terminal can first decrypt the fourth encrypted information and then verify the sixth signature. The verification of the sixth signature can be performed by verifying the sixth signature based on the public key of the first core network device and the information after decryption of the fourth encrypted information. The information after decryption of the fourth encrypted information may include relevant information from the first communication bill and / or the first communication billing value.
[0234] Optionally, after decryption, the first terminal can also verify the relevant information of the first communication bill and / or the first communication billing value. The process of verifying the relevant information of the first communication bill and / or the first communication billing value is the same as in the aforementioned embodiments and will not be described again.
[0235] The first terminal sends a first signature for determining that the first terminal recognizes the first communication billing value, including: sending third encrypted information to the first core network device, wherein the third encrypted information is obtained by encrypting the first signature for determining that the first terminal recognizes the first communication billing value based on the public key of the first core network device.
[0236] Accordingly, the first core network device receives the first signature, including: receiving third encrypted information, wherein the third encrypted information is obtained by encrypting the first signature based on the public key of the first core network device.
[0237] Specifically, the third encrypted information can be carried by the twelfth message, which can be an uplink NAS message. The calculation of the third encrypted information is the same as in the previous embodiments and will not be repeated. The method by which the first core network device decrypts the third encrypted information is also the same as in the previous embodiments and will not be described in detail.
[0238] The calculation method for the first signature is the same as that in the previous embodiments, and will not be repeated here.
[0239] Optionally, the processing of the first terminal may further include: sending a first credential to verify the first terminal's permission to use the resources of the first network. The processing of the first core network device further includes: receiving the first credential. This first credential is also carried by the twelfth message.
[0240] Regarding the explanation of the first credential, the processing of the first core network device to verify the first credential is the same as in the aforementioned embodiments, and will not be repeated here.
[0241] Optionally, the processing of the first terminal may further include: sending at least one of the following parameters to the first core network device: the identifier of the first core network device, relevant information of the first communication bill, and the first communication billing value. Correspondingly, the processing of the first core network device may further include: receiving at least one of the following parameters from the first terminal: the identifier of the first core network device, relevant information of the first communication bill, and the first communication billing value.
[0242] The parameters sent by the first terminal to the first core network device can also be carried by the twelfth message.
[0243] If the first terminal verifies the relevant information of the received first communication bill (and / or the first communication billing value), the twelfth message may not carry the relevant information of the first communication bill (or, may not carry the relevant information of the first communication bill and the first communication billing value).
[0244] If the first terminal fails to verify the received information related to the first communication bill (and / or the first communication billing value), the twelfth message may carry the information related to the first communication bill, and may or may not carry the first communication billing value. For example, if the first terminal sends the information related to the first communication bill, the twelfth message may carry the information related to the first communication bill encrypted with the public key of the first core network device. Furthermore, if the first terminal also sends the first communication billing value, the twelfth message may also carry the first communication billing value encrypted with the public key of the first core network device and the information related to the first communication bill.
[0245] For example, the twelfth message may carry the identifier ID of the first core network device. B First voucher Cert B-A-a The eighth random number, the first signature.
[0246] The first core network device may upload the billing information of the first terminal to the blockchain after verifying the first signature. The processing of verifying the first signature by the first core network device is the same as in the previous embodiments. The description of the billing information of the first terminal in this embodiment is the same as in the previous asymmetric scheme embodiments, and will not be repeated here.
[0247] In one embodiment, when a first terminal accesses the first network using an asymmetric scheme, the first core network device triggers bill collection. The first core network device can send an eleventh message to the first terminal. After receiving the eleventh message, the first terminal can send the ninth message (as described in the previous embodiment) to the first access network device. The first access network device can then send the tenth message (as described in the previous embodiment) to the first core network device. Subsequently, the first core network device uploads the billing information of the first terminal to the blockchain. The processing of each message and each device after receiving the message is the same as in the embodiments related to the aforementioned asymmetric scheme and will not be repeated here.
[0248] In one embodiment, when the first terminal accesses the first network using an asymmetric scheme, the first core network device triggers bill collection. The first core network device can send a seventh message to the first access network device, and the first access network device sends the aforementioned eighth message to the first terminal. After receiving the eighth message, the first terminal executes the process of sending a twelfth message to the first core network device. Subsequently, the first core network device uploads the billing-related information of the first terminal to the blockchain. The processing of each message and each device after receiving the message is the same as in the aforementioned embodiments related to the asymmetric scheme, and will not be described in detail here.
[0249] In one embodiment, when the first terminal accesses the first network using an asymmetric scheme, the first terminal triggers the reporting of an invoice, and information exchange takes place between the first core network device, the first access network device, and the first terminal.
[0250] In this embodiment, the first terminal directly sends the first signature and other information to the first access network device. That is, the first terminal directly sends the ninth message to the first access network device, and the first access network device sends the tenth message to the first core network device; after receiving the fourth message, the first core network device uploads the billing-related information of the first terminal to the blockchain.
[0251] In this embodiment, the content that the ninth and tenth messages can carry is similar to that in the previous embodiments, and will not be described again.
[0252] It should be noted that in this embodiment, the first terminal can send information related to the first communication bill to the first access network device. That is, the ninth message can carry information related to the first communication bill, and the ninth message may or may not carry the first communication billing value. The processing of each message and each device after receiving the message is the same as in the aforementioned embodiments related to the asymmetric scheme, and will not be repeated here.
[0253] In one embodiment, when the first terminal accesses the first network using a symmetrical scheme, the first terminal triggers the reporting of an invoice, and information exchange takes place between the first core network device and the first terminal.
[0254] In this embodiment, the first terminal directly sends the first signature and other information to the first access network device. That is, the first terminal directly sends the twelfth message to the first core network device; after receiving the twelfth message, the first core network device uploads the billing-related information of the first terminal to the blockchain.
[0255] In this embodiment, the content that the twelfth message can carry is similar to that in the previous embodiments, and will not be described again. Since the first terminal actively triggers the reporting of the bill to the first core network device, it can send relevant information about the first communication bill to the first core network device. That is, the twelfth message can carry relevant information about the first communication bill, and can carry or not carry the first communication billing value. Regarding the above messages, and the processing of each device after receiving the messages, they are the same as those in the embodiments related to the aforementioned asymmetric scheme, and will not be described again.
[0256] Next, an exemplary embodiment of the above asymmetric scheme will be described with reference to Figure 6.
[0257] Step 601: Core network B (first core network device) sends a billing confirmation request (seventh message) to its own base station b (first access network device). For example, this seventh message can be represented as: ID B ,N,Sig B [Enc pkb [bill, Com(price)]], where ID B Indicate your identity, N is the first random number to prevent replay attacks, then use PK on the micro-bill of UEa and the promised value Com(price) of price in the bill. b (Public key of the first access network device) Encryption (i.e., the fifth encrypted information Enc) pkb [bill,Com(price)]) sign again (i.e., the seventh signature Sig) B [Enc pkb After [bill,Com(price)]]), it is sent to its own base station b. Encryption is to protect the content of bill from being leaked, and signature is to achieve non-repudiation and to authenticate the identity of core network B.
[0258] Step 602: Upon receiving the message, base station b first verifies the signature's correctness and then decrypts it. Then, it forwards the bill confirmation request (eighth message) to UEa (first terminal).
[0259] For example, the eighth message can be represented as: Cert b ,n+1,ID va Sig b [Enc pka[bill, Com(price)]]. Where N+1 is the fifth random number, and Cert... b The certificate for the first access network device is used to declare its identity, and then the micro-billing of UEa and the promised value Com(price) of the price in the bill are used with pk. a (The public key of the first terminal) encrypts (the fourth encrypted information Enc) pka [bill, Com(price)]) is then re-signed (the eighth signature) and sent to UEa. Encryption is used to protect the contents of bill from being leaked, and signing is used to achieve non-repudiation and authenticate the identity of base station b. The eighth message can also carry an ID. va That is, the identifier (temporary identifier) of the first terminal indicates that UEa is the message receiver.
[0260] When UEa receives a message, it first verifies the signature's correctness and then decrypts it. After verifying that the information of bill and Com(price) is correct, it generates a first signature for the Com(price) signature and then executes step 603a or step 603b.
[0261] Step 603a: UEa sends the twelfth message to core network B, which may carry Cert. B-A-a That is, the secondary credential and primary signature of UEa (Sig va [Com(price)]), and can further carry ID. B This indicates that core network B is the message receiver, and a random number N+2 is used. After step 603 is completed, proceed to step 604.
[0262] Step 603b1: UEa sends a ninth message to base station b, which carries Cert B-A-a First signature.
[0263] For example, the ninth message can be represented as: ID b Cert B-A-a ,N+2,Sig va [Com(price)]. Where N+2 is the sixth random number (which can be generated by the first terminal to prevent replay attacks), and ID. b This indicates that base station b is the message receiver, Cert. B-A-a The first credential for the first terminal, Sig va [Com(price)] is the first signature. The tenth message can be represented as: Cert b ID b Cert B-A-a ,N+3,Sig b [Sig va[Com(price)]]. Where N+3 is the seventh random number (which can be generated by the first access network device to prevent replay attacks), and Cert... b For the certificate of the first access network device, SIG b [Sig va [Com(price)]] is the third signature.
[0264] Step 603b2: Base station b receives the message, first verifies the signature's correctness, and then forwards it via the tenth message to Cert. B-A-a First Signature Sig va [Com(price)] is sent to core network B. This tenth message can also carry: Cert b It is the certificate of base station b that declares its identity, ID. B This indicates that core network B is the message receiver, Cert B-A-a It is a secondary credential for UEa. N+3 is a random number to prevent replay attacks. Sig b [Sig va [Com(price)]] is the base station b's pair with Sig va The signature of [Com(price)] is used to achieve non-repudiation and to authenticate the identity of base station b.
[0265] Step 604: After receiving the message, Core Network B first verifies the signature's correctness, and then sets the first signature Sig... va [Com(price)] and its own local commitment value Com(price), second signature Sig B [Com(price)] is uploaded to the blockchain; at the same time, secondary credentials of UEa can also be uploaded to the blockchain.
[0266] In some cases, UEa directly sends the twelfth message, that is, only executes steps 603a and 604. In this case, the twelfth message may carry the first signature, bill, and Com(price) information of the commitment value Com(price) generated by UEa. In another case, UEa directly sends the ninth message, that is, only executes steps 603b1, 603b2, and 604. In this case, the ninth message may also carry the first signature, bill, and Com(price) information of the commitment value Com(price) generated by UEa. In another example, billing can also be triggered by base station b. For example, it can directly execute steps 602, 603a, and 604, or it can execute steps 602, 603b1, 603b2, and 604. In this case, the way base station b generates Com(price) is the same as that of core network B or UEa, and will not be described in detail.
[0267] In some possible embodiments, the processing of the first core network device further includes: uploading billing aggregation information to the blockchain, wherein the billing aggregation information is used to verify the aggregated communication costs of one or more terminals belonging to the second network under the first network, the billing aggregation information is obtained by aggregating the communication billing values of the one or more terminals under the first network, and the one or more terminals include the first terminal.
[0268] Specifically, the billing aggregation information is used by the blockchain's on-chain nodes to verify the aggregated communication costs of one or more terminals belonging to the second network under the first network.
[0269] Specifically, the calculation method for the billing aggregation information may be as follows: extract one or more communication billing values for each terminal belonging to the second network within a first time period under the first network, and aggregate the total communication billing values of each terminal under the first network to obtain billing aggregation information. This billing aggregation information is related to the aggregated communication cost and the aggregated random number. For example, the billing aggregation information may include the aggregated communication cost and the aggregated random number, or it may be a commitment value corresponding to the aggregated communication cost and the aggregated random number. The first time period may be set or determined according to actual circumstances.
[0270] Referring to Figure 7 as an example, suppose that within a certain time interval (i.e., the first time period), user a (the first terminal) of core network A (i.e., the second core network device under the second network) generates multiple micro-bills (i.e., multiple communication bills, which may include the first communication bill in the aforementioned embodiment); the amount value Price (i.e., the communication fee in each communication bill) of each micro-bill of user a under the first network are a1, a2, a3, ..., and the random number corresponding to each micro-bill is r. a1 ,r a2 ,r a3 ...; User b (i.e., another terminal) in core network A also generated multiple micro-bills under the first network. The price of each micro-bill for user b under the first network are b1, b2, b3..., and the random number corresponding to each micro-bill is r. b1 ,r b2 ,r b3 ...; and so on, the price of each micro-bill for user n in the first network is n1, n2, n3..., and the random number corresponding to each micro-bill is r. n1 ,r n2 ,r n3 ,……
[0271] Step 701: Core Network B (the first core network device) uploads the billing aggregation information to the blockchain. This billing aggregation information includes the aggregated price and the aggregated r, in order to trigger the smart contract.
[0272] Specifically, billing aggregation information is calculated based on the communication billing value (commit(price)) corresponding to each micro-bill for each user. Specifically, due to the additive homomorphic property of Pedersen commitments, the calculation of billing aggregation information can be expressed as: Commit(a1, r a1 )×Commit(a2,r a2 )×Commit(a3,r a3 )×……×Commit(c1,r c1 )×Commit(c2,r c2 )×Commit(c3,r c3 )×……×Commit(n1,r n1 )×Commit(n2,r n2 )×Commit(n3,r n3 )×……=Commit(∑ai+∑ci+……+∑ni,∑r ai +∑r ci +……+∑r ni = Commit(aggregatePrice, aggregater).
[0273] Step 702: After the billing aggregation information is uploaded to the blockchain, the on-chain nodes of the blockchain trigger a smart contract to charge core network A (the second core network device of the second network). Specifically, the processing of the on-chain nodes of the blockchain may include: extracting one or more communication billing values of each terminal belonging to the second network uploaded by the first access network device within the first time period; aggregating all communication billing values of each terminal under the first network to obtain billing aggregation verification information; if the billing aggregation verification information is the same as the billing aggregation information, it is determined that the billing aggregation information has been verified and the smart contract is triggered to charge. Here, triggering the smart contract to charge can refer to the on-chain nodes of the blockchain triggering a smart contract to charge core network A (the second core network device of the second network).
[0274] In this way, core network B aggregates all micro-bills and puts the final aggregated Price and aggregated r on the blockchain, protecting the privacy of users' account information. On-chain nodes verify whether the local aggregation result is consistent with the aggregated Price and aggregated r published by core network B. Once the verification is successful, the smart contract is triggered to process the payment.
[0275] In some possible implementations, in the scenario where the first terminal uses a symmetric scheme to access the first network, the first terminal needs to obtain a symmetric key (or session key) between itself and the access network device serving the first terminal under the first network.
[0276] In some embodiments, the processing of the first terminal (e.g., at least before the first terminal sends the first signature) further includes: sending a key allocation request, wherein the key allocation request carries a third credential for verifying the first terminal's right to use the resources of the first network; and receiving sixth encrypted information, wherein the sixth encrypted information is obtained by encrypting one or more fourth keys based on a first key between the first terminal and the first core network device, wherein the one or more fourth keys are keys between one or more terminals and the first access network device, and the one or more terminals include the first terminal.
[0277] Accordingly, the processing of the first core network device may include: receiving a key allocation request, wherein the key allocation request carries a third credential for verifying the first terminal's permission to use the resources of the first network.
[0278] The processing of the first core network device may include: sending a key allocation message to the first access network device, wherein the key allocation message carries at least one of the following: one or more fourth keys, the one or more fourth keys being keys between one or more terminals and the first access network device, the one or more terminals including the first terminal; and sixth encryption information, the sixth encryption information being obtained by encrypting the one or more fourth keys based on the first key between the first terminal and the first core network device.
[0279] Optionally, the processing of the first core network device may further include: sending the sixth encrypted information to the first terminal.
[0280] The processing by the first access network device may further include: receiving a key allocation request from the first terminal, wherein the key allocation request carries a third credential for verifying the first terminal's permission to use resources of the first network; and forwarding the key allocation request to the first core network device. Furthermore, the processing after the first access network device sends the key allocation request may further include: receiving a key allocation message from the first core network device, wherein the key allocation message carries at least one of the following: one or more fourth keys, wherein the one or more fourth keys are keys between one or more terminals and the first access network device, and the one or more terminals include the first terminal; and sixth encryption information, wherein the sixth encryption information is obtained by encrypting the one or more fourth keys based on a first key between the first terminal and the first core network device.
[0281] Optionally, the processing of the first access network device may further include: sending the sixth encrypted information to the first terminal.
[0282] The third credential is generated based on a third key between the first core network device and the second core network device, and the second core network device belongs to the second network.
[0283] The third credential is issued by a second core network device in the second network. The specific calculation method for the third credential may include: encrypting at least one of the first key between the first terminal and the first core network device, and the temporary identifier of the first terminal, based on a third key between the first and second core network devices, to obtain the third credential. For example, the third credential can be represented as: Ticket a K is a third document (or a second-level document in a symmetrical scheme), a-B That is, the first key, ID va It is a temporary identifier for the first terminal, K. A-B This is the third key.
[0284] Before the second core network device issues the third credential to the first terminal, the first and second core network devices need to first perform a process to generate and issue a fourth credential. This fourth credential can be generated and uploaded to the blockchain by the first core network device, and then obtained from the blockchain by the second core network device. This fourth credential can be used to indicate authorization for the second network to use the resources of the first network. The fourth credential includes a third key encrypted based on the public key of the second core network device. In some possible examples, this fourth credential can also be referred to as a first-level credential of a symmetric scheme, and the third credential can also be referred to as a second-level credential of a symmetric scheme.
[0285] Optionally, the key distribution request issued by the first terminal may also carry at least one of the following: a fifth check code for verifying the identity of the first terminal, an identifier of the first resource of the first network to be used, an identifier of one or more terminals, an identifier of the first group, an identifier of the first access network device, an identifier of the first core network device, and an eighth random number.
[0286] Among them, one or more terminals include a first terminal. The one or more terminals may belong to a first group (i.e., the first terminal belongs to the first group), and the home network of the one or more terminals is the second network.
[0287] Optionally, the fifth verification code is calculated based on the first key between the first terminal and the first core network device and at least one of the following: the identifier of the first resource, the identifier of one or more terminals, the identifier of the first group, the identifier of the first access network device, the identifier of the first core network device, the eighth random number, and the third credential.
[0288] The first terminal can send a key allocation request to the first access network device, which will then forward it to the first core network device. Alternatively, the first terminal can directly send the key allocation request to the first core network device. When the first terminal sends a key allocation request to the first access network device (e.g., via an AS message), the key allocation request carries the identifier of the first access network device. When the first terminal sends a key allocation request to the first core network device (e.g., via a NAS message), the key allocation request carries the identifier of the first core network device.
[0289] In one embodiment, the first terminal sends a key allocation request to the first access network device.
[0290] The key distribution request forwarded by the first access network device to the first core network device may carry at least one of the following: a third credential, a seventh checksum used to verify the identity of the first access network device, an identifier of a first resource, identifiers of one or more terminals, an identifier of a first group, an identifier of the first access network device, and an eighth random number. That is, the first access network device may not send the fifth checksum to the first core network device, but instead generate a new seventh checksum and send it to the first core network device along with other data.
[0291] The seventh verification code is calculated based on the second key between the first access network device and the first core network device and at least one of the following: the identifier of the first resource, the identifier of one or more terminals, the identifier of the first group, the identifier of the first access network device, the eighth random number, and the third credential.
[0292] Optionally, after receiving a key allocation request, the first core network device can authenticate the first terminal based on a third credential. Specifically, this may include: decrypting the third credential based on the third key to obtain a decryption result; and authenticating the first terminal based on the decryption result. Authenticating the first terminal based on the decryption result may include: determining successful authentication of the first terminal if the decryption result is correct; and determining authentication failure if the decryption result is incorrect. Specifically, the decryption result includes at least one of the following: a first key between the first terminal and the first core network device, and an identifier of the first terminal (i.e., a temporary identifier of the first terminal). Further, if the decryption result is correct, the first core network device can save the content or parameters contained in the decryption result.
[0293] Optionally, after receiving the key allocation request from the first access network device, the first core network device may perform the following processing: verify the message integrity of the key allocation request based on the seventh checksum. The verification method may include: verifying the message integrity based on the seventh verification code and the seventh checksum. The calculation method and parameters used by the first core network device to calculate the seventh verification code should be the same as those used by the first access network device to calculate the seventh checksum, and will not be repeated here.
[0294] Optionally, if the key allocation request only includes the identifier of the first terminal, then the first core network device only generates a fourth key between the first terminal and the first access network device. The fourth key can be generated by using a second calculation method to calculate at least one of the following based on the first key between the first terminal and the first core network device: the temporary identifier of the first terminal, the identifier of the first access network device, the tenth random number, and the count value.
[0295] The second calculation method can be configured according to the actual situation, and may include at least one of the following: KDF (Key Derivation Function), Key Derivation Function, Advanced Encryption Standard (AES), SNOW 3G, ZUC, XOR calculation, direct connection calculation, etc.
[0296] For example, the calculation of the fourth key between the first terminal and the first access network device can be expressed as: Ka-b = KDF Ka-B (IDva, IDb, Nonce or counter), where Ka-b is the fourth key between the first terminal and the first access network device, Ka-B is the first key, IDva is the temporary identifier of the first terminal, IDb is the identifier of the first access network device, Nonce is the tenth random number, and Counter is the counter value. The tenth random number and the counter value are generated by the first core network device, and either the tenth random number or the counter value can be used in the key generation calculation.
[0297] Optionally, if the key allocation request includes the identifiers of multiple terminals, the first core network device generates a fourth key between the multiple terminals and the first access network device. Taking the second terminal among one or more terminals as an example, the fourth key between the second terminal and the first access network device can be generated by using a second calculation method based on the first key between the first terminal and the first core network device to calculate at least one of the following: the temporary identifier of the second terminal, the identifier of the first access network device, the identifier of the first group, the tenth random number, and the count value.
[0298] For example, the calculation of the fourth key between the second terminal and the first access network device can be expressed as: Ka-b-2 = KDF Ka-B(IDva2, IDb, IDg, Nonce or counter), where Ka-b-2 is the fourth key between the second terminal and the first access network device, IDva2 is the temporary identifier of the second terminal, IDg is the identifier of the first group, and the remaining parameters are the same as those in the previous embodiment, and will not be repeated.
[0299] When the first core network device distributes one or more fourth keys (i.e., one or more session keys) to the first access network device via a key distribution message, it also carries the key identifier corresponding to each fourth key in the key distribution message. For example, the first core network device can distribute session keys K between i users (i.e., i terminals) and base station b. a-b (1…i), Key identifier ID corresponding to each session key Ka-b (1…i), where i is an integer greater than or equal to 1, and the key identifier corresponding to each session key is used to indicate or associate with or correspond to the session key, such as ID. Ka-b 1 is used to indicate the session key K a-b 1.
[0300] Optionally, the sixth encrypted information can be obtained by encrypting one or more fourth keys and the key identifier corresponding to each fourth key based on the first key.
[0301] Optionally, the key allocation message may also carry a fifth verification code. The calculation method of the fifth verification code should be the same as that of the fifth verification code in the aforementioned embodiments, and therefore will not be repeated. After the first access network device receives the key allocation message, the method further includes: verifying the identity of the first terminal based on the fifth verification code and the fifth verification code. For example, if the fifth verification code and the fifth verification code match, the authentication of the first terminal is determined to be successful; if the fifth verification code and the fifth verification code do not match, the authentication of the first terminal is determined to be unsuccessful.
[0302] Optionally, after receiving the key allocation message from the first core network device, the first access network device may further include: sending the sixth encrypted information to the first terminal. Correspondingly, the first terminal's processing may include: receiving the sixth encrypted information from the first access network device. For example, if the key allocation message carries one or more fourth keys and the sixth encrypted information, the first access network device may locally store one or more fourth keys and send the sixth encrypted information to the first terminal.
[0303] Optionally, the key allocation message may carry only one or more fourth keys. Accordingly, after receiving the key allocation message, the first access network device only needs to store one or more fourth keys locally. In this case, the first core network device may also send sixth encrypted information to the first terminal; correspondingly, the first terminal's processing can be: receiving the sixth encrypted information from the first core network device.
[0304] Furthermore, after receiving the sixth encrypted information, the first terminal can decrypt the sixth encrypted information based on the first key to obtain one or more fourth keys. Optionally, the first terminal can obtain one or more fourth keys, each with a corresponding key identifier. Then, the first terminal can extract the key it needs from the one or more fourth keys and distribute the remaining fourth keys to one or more other terminals in the first group.
[0305] In one embodiment, the first terminal sends a key allocation request to the first core network device (e.g., via a NAS message). The processing of the first core network device further includes: receiving the key allocation request sent by the first terminal. The processing of the first core network device may also include at least one of the following: sending sixth encryption information to the first terminal; sending a key allocation message to the first access network device, the key allocation message carrying at least one of the following: one or more fourth keys, and sixth encryption information.
[0306] Optionally, after receiving the key allocation request, the first core network device can authenticate the first terminal based on the third credential. The specific processing method is the same as that in the aforementioned embodiments, and will not be repeated here.
[0307] Optionally, after receiving the key allocation request, the first core network device can verify the identity of the first terminal based on the fifth verification code and the fifth check code. The calculation method of the fifth verification code should be the same as that of the fifth check code in the previous embodiments, and therefore will not be repeated.
[0308] The processing after the first core network device generates one or more fourth keys is the same as in the previous embodiments, and will not be repeated here.
[0309] In one embodiment, after the first terminal obtains the fourth key between itself and the first access network device, the first terminal's processing may include: sending a registration request to the first access network device, wherein the registration request carries seventh encrypted information obtained by encrypting at least one of the following based on the fourth key: a fourth verification code for verifying the first terminal, the identifier of the first terminal, the identifier of the first access network device, and the identifier of the first resource of the first network to be used, wherein the fourth verification code is calculated based on the fourth key and at least one of the following: the identifier of the first terminal, the identifier of the first access network device, and the identifier of the first resource. Correspondingly, the first access network device's processing may further include: receiving the registration request from the first terminal.
[0310] The processing of the first access network device may include: receiving a registration request from the first terminal, wherein the registration request carries seventh encrypted information obtained by encrypting at least one of the following based on the fourth key: a fourth verification code for verifying the first terminal, the identifier of the first terminal, the identifier of the first access network device, and the identifier of the first resource of the first network to be used, wherein the fourth verification code is calculated based on the second key and at least one of the following: the identifier of the first terminal, the identifier of the first access network device, and the identifier of the first resource.
[0311] After the first access network device receives the registration request, the method further includes: decrypting the seventh encrypted information based on the fourth key to obtain at least one of the following: a fourth verification code for verifying the first terminal, the identifier of the first terminal, the identifier of the first access network device, and the identifier of the first resource.
[0312] Optionally, the processing of the first access network device may further include: verifying the first terminal based on the fourth verification code and the fourth check code, wherein the fourth verification code is calculated based on the fourth key and at least one of the following: the identifier of the first terminal, the identifier of the first access network device, and the identifier of the first resource. The method and parameters used by the first access network device to calculate the fourth verification code should be the same as the method and parameters used by the first terminal to calculate the fourth check code.
[0313] On the first access network device side, if the fourth verification code and the fourth check code are the same, it can be determined that the verification of the first terminal has passed. Further, the processing of the first access network device may also include: the first access network device can send a registration success response to the first terminal. The processing of the first terminal may include: receiving the registration success response. Optionally, the registration success response may also be encrypted with the fourth key and sent to the first terminal, and the first terminal decrypts it based on the fourth key to obtain the registration success response.
[0314] The process of the UE requesting the symmetric key between the UE and the base station is illustrated in Figure 8:
[0315] Step 801a: UEa (first terminal) sends a key allocation request to core network B (first core network equipment). This request may carry: a random number N to indicate message freshness, and an ID. va It is the temporary identity, ID, of the requester, i.e., UEa. b This indicates the base station b (the first access network device) to be accessed. UEa hashes the above message using the key material between UEa and core network B to obtain the verification code HMAC. HMAC ensures that the source of the core network B's authentication message is UEa (ID). va And the message was not tampered with.
[0316] In this case, after completing step 801a, step 802 is not required; proceed directly to steps 803 to 804.
[0317] Step 801b: UEa sends a key allocation request to base station b. The key allocation request sent by UEa to base station b may carry a random number N to indicate message freshness, ID. va It is the temporary identity, ID, of the requester, i.e., UEa. b This indicates the base station b to be accessed and the HMAC checksum.
[0318] Optionally, a session key K can be requested between i UEs and base station b in a group. a-b (1…i), in this case, the key distribution request can also carry: IDg, i.e., group ID, ID va (1…i) is the temporary identifier of the requester, i.e., UE (1…i).
[0319] Step 802: Base station b forwards a key allocation request to core network B. The key allocation request sent by base station b to core network B may carry a random number N and an ID. va ID b The checksum HMAC is calculated based on the key pair between base station b and core network B. In other words, the key allocation request is forwarded by base station b. After verifying the received message, base station b uses its own key pair with core network B to hash the received message and obtain the checksum HMAC before sending it to core network B. This HMAC allows core network B to verify that the message indeed originated from base station b and has not been tampered with (core network B hashes the received message using its own key pair with base station b and compares the received HMAC).
[0320] Step 803: After core network B verifies the key allocation request sent by base station b or UEa (e.g., to verify reliability), it generates a symmetric session key K for communication between UEa and base station b. a-b (i.e., the fourth key in the aforementioned embodiment). The core network B sends a key allocation message to the base station b, which may carry the fourth key and encrypted information obtained by encrypting the fourth key based on the key between UEa and the core network B. Optionally, to ensure message confidentiality, the message can be sent through a secure channel between the core network B and the base station b, that is, the message content to be sent is encrypted using the key between the core network B and the base station b. The content of this message is...
[0321] Step 804: After base station b verifies the reliability of the received message (the source is core network B and the message has not been tampered with), it encrypts the information obtained by encrypting the fourth key based on the key pair between UEa and core network B. The message is forwarded to UEa. Then, UEa uses the key material between itself and the core network to decrypt and obtain the session key with base station b. The decrypted N+1 also indicates that the message is not a replay. At this point, UEa can use the received session key to access base station b and successfully use the spectrum resources of the network where base station b is located (UEa's roaming network).
[0322] Referring to Figure 9, the UEa registration process is illustrated by example:
[0323] Step 901: When UEa (first terminal) requests access to resources of base station b (first access network device), UEa sends a registration request to base station b, which carries information encrypted with the following: UEa's identifier IDva, base station b's identifier IDb, random number N, the identifier or number Nom of the requested first network resource, and a checksum HMAC obtained by hashing the above information (or parameters) using the key material between UEa and base station b. The content of this registration request can be encrypted using key Ka-b; for example, the encrypted content of this message can be represented as: Enc Ka-b [IDva,IDb,N,Nom,HMAC].
[0324] Step 902: After decrypting the registration request using key Ka-b, base station b verifies the identity of UEa based on the verification code. If it is determined that UEa can use Nom spectrum resources, step 903 is executed.
[0325] Step 903: Base station b returns a registration success notification, which can be encrypted using Ka-b.
[0326] In some embodiments, the first terminal sends an authentication request to the first core network device or the first access network device and requests to use resources. In this embodiment, the authentication process initiated by the authentication request can complete the verification of the first terminal's permission to use resources under the first network, obtain one or more fourth keys, and access the first network through the first access network device.
[0327] The first terminal may send an authentication request carrying a third credential to the first access network device or the first core network device.
[0328] The authentication request also carries at least one of the following: a fifth verification code for verifying the identity of the first terminal, an identifier of the first resource of the first network to be used, an identifier of one or more terminals, an identifier of the first group, an identifier of the first access network device, and an identifier of the first core network device.
[0329] In one embodiment, the processing by the first access network device after receiving the authentication request may further include: sending an authentication request to the first core network device, wherein the authentication request carries the third credential; receiving an authentication response from the first core network device, wherein the authentication response carries a fifth verification code; and verifying the identity of the first terminal based on the fifth verification code and the fifth verification code. Optionally, the authentication request may further carry at least one of the following: an identifier of a first resource, an identifier of one or more terminals, an identifier of a first group, an identifier of the first access network device, and an identifier of the first core network device.
[0330] After receiving the authentication request, the first core network device can authenticate the first terminal based on the third credential. The specific authentication method is the same as that in the previous embodiment and will not be described in detail.
[0331] Optionally, the authentication response may also carry at least one of the following: one or more fourth keys, or sixth encryption information.
[0332] The processing after the first access network device receives the authentication response may further include: sending an authentication response to the first terminal, wherein the authentication response carries sixth encrypted information. Correspondingly, the processing after the first terminal receives the authentication response may include: extracting the sixth encrypted information from the authentication response, decrypting the sixth encrypted information based on the first key, and obtaining one or more fourth keys. The processing after the first terminal obtains one or more fourth keys is the same as in the aforementioned embodiments and will not be described again.
[0333] In one embodiment, after receiving the authentication request, the first core network device can authenticate the first terminal based on the third credential. The specific authentication method is the same as in the previous embodiment and will not be described in detail.
[0334] Optionally, the first core network device can also verify the identity of the first terminal based on the fifth verification code and the fifth check code. The specific verification process is the same as in the aforementioned embodiments and will not be described in detail.
[0335] After the first core network device completes the above authentication and the authentication is successful, it also includes at least one of the following: sending an authentication response to the first terminal, carrying sixth encryption information; or sending one or more fourth keys to the first access network device.
[0336] Accordingly, the processing of the first terminal may include: receiving an authentication response from the first core network device. The decryption of the sixth encrypted information and subsequent processing by the first terminal are the same as in the aforementioned embodiments and will not be described in detail.
[0337] By adopting the above scheme, the communication billing value, which is recognized by both the first terminal belonging to the second network and the first core network device belonging to the first network, is uploaded to the blockchain. This ensures that the communication billing value uploaded to the blockchain is recognized and accurate by both the terminal and the roaming network, thereby guaranteeing the accuracy of billing for the terminal in roaming scenarios.
[0338] Figure 10 is a schematic diagram of the composition structure of a first core network device according to an embodiment of this application, including:
[0339] The first communication unit 1001 is used to upload the billing-related information of the first terminal to the blockchain. The billing-related information of the first terminal is used to determine the first communication billing value recognized by the first terminal and the first core network device. The first core network device belongs to the first network, and the first terminal belongs to the second network.
[0340] The billing-related information of the first terminal includes: the first communication billing value, a first signature for determining that the first terminal recognizes the first communication billing value, and a second signature for determining that the first core network device recognizes the first communication billing value.
[0341] The second signature is calculated based on the private key of the first core network device and the first communication billing value.
[0342] The first communication billing value is calculated based on the communication costs of the first terminal under the first network.
[0343] The first communication unit is used to upload billing aggregation information to the blockchain, wherein the billing aggregation information is used to verify the aggregated communication costs of one or more terminals belonging to the second network under the first network, and the billing aggregation information is obtained by aggregating the communication billing values of the one or more terminals under the first network, including the first terminal.
[0344] The first communication unit is used to receive the first signature.
[0345] The first communication unit is configured to receive at least one of the following parameters: the identifier of the first terminal, the identifier of the first core network device, the identifier of the first access network device belonging to the first network, information related to the first communication bill of the first terminal under the first network, and the first communication bill value, wherein the first communication bill includes the communication cost of the first terminal under the first network.
[0346] The first communication unit is configured to receive the certificate of the first terminal, wherein the certificate of the first terminal carries the public key of the first terminal.
[0347] The billing information of the first terminal also includes: the certificate of the first terminal.
[0348] The first core network device further includes: a first processing unit 1002, used to verify the identity of the first terminal based on a first verification code and a first check code, wherein the first verification code is calculated based on a first key between the first terminal and the first core network device and at least one of the following parameters: the identifier of the first core network device, the first signature, the identifier of the first terminal, the identifier of the first access network device, relevant information of the first communication bill, the first communication billing value, and the certificate of the first terminal;
[0349] The first communication unit is configured to receive a first verification code from the first terminal for verifying the identity of the first terminal.
[0350] The first communication unit is configured to receive a second verification code from the first access network device for verifying the identity of the first access network device;
[0351] The first processing unit is configured to verify the identity of the first access network device based on the second verification code and the second check code, wherein the second verification code is calculated based on the second key between the first access network device and the first core network device and at least one of the following parameters: the identifier of the first core network device, the first signature, the identifier of the first terminal, the identifier of the first access network device, the relevant information of the first communication bill, the first communication billing value, and the certificate of the first terminal.
[0352] The first communication unit is configured to perform one of the following: send first encrypted information to the first terminal, wherein the first encrypted information is obtained by encrypting at least one of the following parameters based on a first key between the first terminal and the first core network device: the first communication billing value and related information of the first communication bill; send second encrypted information to the first access network device, wherein the second encrypted information is obtained by encrypting at least one of the following parameters based on a second key between the first access network device and the first core network device: the first communication billing value and related information of the first communication bill.
[0353] The first communication unit is configured to receive third encrypted information, wherein the third encrypted information is obtained by encrypting the first signature based on the public key of the first core network device.
[0354] The first communication unit is configured to receive a third signature from the first access network device for verifying the identity of the first access network device;
[0355] The first processing unit is configured to verify the third signature based on the public key of the first access network device and at least one of the following parameters: the first signature and the third encrypted information.
[0356] The first communication unit is configured to receive a first credential for verifying the first terminal's permission to use resources of the first network, wherein the first credential carries at least one of the following: a fourth signature for verifying the first terminal's permission to use the second network to obtain authorized access to resources of the first network, and a fifth signature for verifying the second network's permission to use resources of the first network.
[0357] The billing-related information of the first terminal also includes: the first voucher.
[0358] The first communication unit is configured to perform at least one of the following: sending fourth encrypted information to the first terminal, wherein the fourth encrypted information is obtained by encrypting at least one of the following parameters based on the public key of the first terminal: the first communication billing value, and related information of the first communication bill; sending a sixth signature to the first terminal, wherein the sixth signature is obtained by calculating at least one of the following parameters based on the private key of the first core network device: the first communication billing value, related information of the first communication bill, and the fourth encrypted information; sending fifth encrypted information to the first access network device, wherein the fifth encrypted information is obtained by encrypting at least one of the following parameters based on the public key of the first access network device: the first communication billing value, and related information of the first communication bill; and sending a seventh signature to the first access network device, wherein the seventh signature is obtained by calculating at least one of the following parameters based on the private key of the first core network device: the first communication billing value, related information of the first communication bill, and the fifth encrypted information.
[0359] The first communication unit is configured to send a key allocation message to the first access network device, wherein the key allocation message carries at least one of the following: one or more fourth keys, the one or more fourth keys being keys between one or more terminals and the first access network device, the one or more terminals including the first terminal; and sixth encryption information, the sixth encryption information being obtained by encrypting the one or more fourth keys based on a first key between the first terminal and the first core network device.
[0360] The first communication unit is used to send the sixth encrypted information to the first terminal.
[0361] The first communication unit is configured to receive a key allocation request, wherein the key allocation request carries a third credential for verifying the first terminal's permission to use the resources of the first network.
[0362] Figure 11 is a schematic diagram of the composition structure of a first terminal according to an embodiment of this application, including:
[0363] The second communication unit 1101 is used to send a first signature for determining that the first terminal recognizes the first communication billing value, wherein the first terminal belongs to the second network.
[0364] The first signature is calculated based on the private key of the first terminal and the first communication billing value.
[0365] The first communication billing value is calculated based on the communication costs of the first terminal under the first network.
[0366] The second communication unit is configured to send at least one of the following parameters: the identifier of the first terminal, the identifier of the first core network device belonging to the first network, the identifier of the first access network device belonging to the first network, information related to the first communication bill of the first terminal under the first network, and the first communication bill value, wherein the first communication bill includes the communication cost of the first terminal under the first network.
[0367] The second communication unit is used to send the certificate of the first terminal, wherein the certificate of the first terminal carries the public key of the first terminal.
[0368] The second communication unit is configured to perform one of the following: send a first verification code to the first core network device for verifying the identity of the first terminal, wherein the first verification code is calculated based on a first key between the first terminal and the first core network device and at least one of the following parameters: the first signature, the identifier of the first terminal, the identifier of the first core network device, the identifier of the first access network device, relevant information of the first communication bill, the first communication billing value, and the certificate of the first terminal; send a third verification code to the first access network device for verifying the identity of the first terminal, wherein the third verification code is calculated based on a fourth key between the first terminal and the first access network device and at least one of the following parameters: the first signature, the identifier of the first terminal, the identifier of the first access network device, relevant information of the first communication bill, the first communication billing value, and the certificate of the first terminal.
[0369] The second communication unit is configured to perform one of the following: receiving first encrypted information from the first core network device, wherein the first encrypted information is obtained by encrypting at least one of the following parameters based on a first key between the first terminal and the first core network device: the first communication billing value and related information of the first communication bill; receiving eighth encrypted information from the first access network device, wherein the eighth encrypted information is obtained by encrypting at least one of the following parameters based on a fourth key between the first terminal and the first access network device: the first communication billing value and related information of the first communication bill.
[0370] The second communication unit is configured to perform one of the following: send third encrypted information to the first core network device, wherein the third encrypted information is obtained by encrypting the first signature used to determine the first terminal's acceptance of the first communication billing value based on the public key of the first core network device; send tenth encrypted information to the first access network device, wherein the tenth encrypted information is obtained by encrypting the first signature used to determine the first terminal's acceptance of the first communication billing value based on the public key of the first access network device.
[0371] The second communication unit is configured to send a first credential for verifying the first terminal's permission to use the resources of the first network, wherein the first credential carries at least one of the following: a fourth signature for verifying the first terminal's permission to use the second network to obtain authorized access to the resources of the first network, and a fifth signature for verifying the second network's permission to use the resources of the first network.
[0372] The second communication unit is configured to receive fourth encrypted information, wherein the fourth encrypted information is obtained by encrypting at least one of the following parameters based on the public key of the first terminal: the first communication billing value, and related information of the first communication bill.
[0373] The first terminal further includes: a second processing unit 1102, configured to verify the sixth signature based on the public key of the first core network device and at least one of the following parameters: the first communication billing value, relevant information of the first communication bill, and the fourth encrypted information;
[0374] The second communication unit is used to receive a sixth signature from the first core network device.
[0375] The second communication unit is used to receive the eighth signature from the first access network device;
[0376] The second processing unit is configured to verify the eighth signature based on the public key of the first access network device and at least one of the following parameters: the first communication billing value, the relevant information of the first communication bill, and the fourth encrypted information.
[0377] The second communication unit is configured to send a key allocation request, wherein the key allocation request carries a third credential for verifying the first terminal's permission to use the resources of the first network; and to receive sixth encrypted information, wherein the sixth encrypted information is obtained by encrypting one or more fourth keys based on a first key between the first terminal and the first core network device, wherein the one or more fourth keys are keys between one or more terminals and the first access network device, and the one or more terminals include the first terminal.
[0378] The second communication unit is configured to send a registration request to the first access network device, wherein the registration request carries seventh encrypted information obtained by encrypting at least one of the following based on the fourth key: a fourth verification code for verifying the first terminal, the identifier of the first terminal, the identifier of the first access network device, and the identifier of the first resource of the first network to be used, wherein the fourth verification code is calculated based on the fourth key and at least one of the following: the identifier of the first terminal, the identifier of the first access network device, and the identifier of the first resource.
[0379] Figure 12 is a schematic diagram of the composition structure of a first access network device according to an embodiment of the present application, including:
[0380] The third communication unit 1201 is configured to receive a first signature from a first terminal for determining that the first terminal recognizes a first communication billing value, wherein the first terminal belongs to a second network and the first access network device belongs to the first network; and to send the first signature to a first core network device, wherein the first core network device belongs to the first network.
[0381] The third communication unit is configured to receive at least one of the following parameters from the first terminal: the identifier of the first terminal, the identifier of the first core network device, the identifier of the first access network device, information related to the first communication bill of the first terminal under the first network, and the first communication billing value, wherein the first communication bill includes the communication costs of the first terminal under the first network; and to send at least one of the following parameters to the first core network device: the identifier of the first terminal, the identifier of the first core network device, the identifier of the first access network device, information related to the first communication bill, and the first communication billing value.
[0382] The third communication unit is used to receive the certificate of the first terminal, wherein the certificate of the first terminal carries the public key of the first terminal; and to send the certificate of the first terminal to the first core network device.
[0383] The first access network device further includes: a third processing unit 1202, used to verify the identity of the first terminal based on a third verification code and the third verification code, wherein the third verification code is calculated based on a fourth key between the first terminal and the first access network device and at least one of the following parameters: the first signature, the identifier of the first terminal, the identifier of the first access network device, relevant information of the first communication bill, the first communication billing value, and the certificate of the first terminal.
[0384] The third communication unit is used to receive a third verification code from the first terminal for verifying the identity of the first terminal.
[0385] The third communication unit is used to send a second verification code to the first core network device for verifying the identity of the first access network device. The second verification code is calculated based on a second key between the first access network device and the first core network device and at least one of the following parameters: the identifier of the first core network device, the first signature, the identifier of the first terminal, the identifier of the first access network device, relevant information of the first communication bill, the first communication billing value, and the certificate of the first terminal.
[0386] The third communication unit is configured to receive second encrypted information from the first core network device, wherein the second encrypted information is obtained by encrypting at least one of the following parameters based on a second key between the first access network device and the first core network device: the first communication billing value and related information of the first communication bill; and to send eighth encrypted information to the first terminal, wherein the eighth encrypted information is obtained by encrypting at least one of the following parameters based on a fourth key between the first terminal and the first access network device: the first communication billing value and related information of the first communication bill.
[0387] The third communication unit is configured to receive tenth encrypted information from the first terminal, wherein the tenth encrypted information is obtained by encrypting the first signature used to determine the first communication billing value recognized by the first terminal based on the public key of the first access network device.
[0388] The third communication unit is used to send third encrypted information to the first core network device, wherein the third encrypted information is obtained by encrypting the first signature based on the public key of the first core network device.
[0389] The third communication unit is configured to send a third signature to the first core network device for verifying the identity of the first access network device, wherein the third signature is calculated based on the private key of the first access network device and at least one of the following parameters: the first signature and the third encrypted information.
[0390] The third communication unit is configured to receive a first credential from the first terminal for verifying the first terminal's permission to use resources of the first network, wherein the first credential carries at least one of the following: a fourth signature for verifying the first terminal's permission to use the second network to obtain authorized resources of the first network, and a fifth signature for verifying the second network's permission to use resources of the first network; and to send the first credential to the first core network device.
[0391] The third communication unit is configured to receive fifth encrypted information from the first core network device, wherein the fifth encrypted information is obtained by encrypting at least one of the following parameters based on the public key of the first access network device: the first communication billing value and related information of the first communication bill; and to send fourth encrypted information to the first terminal, wherein the fourth encrypted information is obtained by encrypting at least one of the following parameters based on the public key of the first terminal: the first communication billing value and related information of the first communication bill.
[0392] The third communication unit is configured to receive a seventh signature from the first core network device, wherein the seventh signature is calculated based on the private key of the first core network device using at least one of the following parameters: the first communication billing value, relevant information of the first communication bill, and the fifth encrypted information; and to send an eighth signature to the first terminal, wherein the eighth signature is calculated based on the private key of the first access network device and at least one of the following parameters: the first communication billing value, relevant information of the first communication bill, and the fourth encrypted information.
[0393] The third communication unit is configured to receive a key allocation message from the first core network device, wherein the key allocation message carries at least one of the following: one or more fourth keys, the one or more fourth keys being keys between one or more terminals and the first access network device, the one or more terminals including the first terminal; and sixth encryption information, the sixth encryption information being obtained by encrypting the one or more fourth keys based on the first key between the first terminal and the first core network device.
[0394] The third communication unit is used to send the sixth encrypted information to the first terminal.
[0395] The third communication unit is configured to receive a key allocation request from the first terminal, wherein the key allocation request carries a third credential for verifying the first terminal's permission to use resources of the first network; and forward the key allocation request to the first core network device.
[0396] The third communication unit is configured to receive a registration request from the first terminal, wherein the registration request carries seventh encrypted information obtained by encrypting at least one of the following based on the fourth key: a fourth verification code for verifying the first terminal, the identifier of the first terminal, the identifier of the first access network device, and the identifier of the first resource of the first network to be used, wherein the fourth verification code is calculated based on the second key and at least one of the following: the identifier of the first terminal, the identifier of the first access network device, and the identifier of the first resource.
[0397] The device in this application embodiment can realize the corresponding functions of the various devices in the foregoing communication method embodiments. The processes, functions, implementation methods, and beneficial effects of each module (sub-module, unit, or component, etc.) in this device can be found in the corresponding descriptions in the above method embodiments, and will not be repeated here. It should be noted that the functions described for each module (sub-module, unit, or component, etc.) in the device of this application embodiment can be implemented by different modules (sub-modules, units, or components, etc.) or by the same module (sub-module, unit, or component, etc.).
[0398] It should be understood that in the various embodiments of this application, the order of the above-mentioned processes does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0399] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0400] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A communication method executed by a first core network device, comprising: The billing information of the first terminal is uploaded to the blockchain. The billing information of the first terminal is used to determine the first communication billing value recognized by the first terminal and the first core network device. The first core network device belongs to the first network and the first terminal belongs to the second network.
2. The method according to claim 1, wherein, The billing-related information of the first terminal includes: the first communication billing value, a first signature for determining that the first terminal recognizes the first communication billing value, and a second signature for determining that the first core network device recognizes the first communication billing value.
3. The method according to claim 2, wherein, The second signature is calculated based on the private key of the first core network device and the first communication billing value.
4. The method according to any one of claims 1-3, wherein, The first communication billing value is calculated based on the communication costs of the first terminal under the first network.
5. The method according to any one of claims 1-4, wherein, The method further includes: The billing aggregation information is uploaded to the blockchain, wherein the billing aggregation information is used to verify the aggregated communication costs of one or more terminals belonging to the second network under the first network, and the billing aggregation information is obtained by aggregating the communication billing values of the one or more terminals under the first network, including the first terminal.
6. The method according to claim 2 or 3, wherein, The method further includes: Receive the first signature.
7. The method according to claim 6, wherein, The method further includes: The system receives at least one of the following parameters: the identifier of the first terminal, the identifier of the first core network device, the identifier of the first access network device belonging to the first network, information related to the first communication bill of the first terminal under the first network, and the first communication bill value, wherein the first communication bill includes the communication costs of the first terminal under the first network.
8. The method according to claim 7, wherein, The method further includes: Receive the certificate of the first terminal, wherein the certificate of the first terminal carries the public key of the first terminal.
9. The method according to claim 8, wherein, The billing information of the first terminal also includes: the certificate of the first terminal.
10. The method according to any one of claims 7-9, wherein, The method further includes: Receive a first verification code from the first terminal to verify the identity of the first terminal; The identity of the first terminal is verified based on the first verification code and the first check code. The first verification code is calculated based on the first key between the first terminal and the first core network device and at least one of the following parameters: the identifier of the first core network device, the first signature, the identifier of the first terminal, the identifier of the first access network device, the relevant information of the first communication bill, the first communication billing value, and the certificate of the first terminal.
11. The method according to any one of claims 7-9, wherein, The method further includes: Receive a second verification code from the first access network device to verify the identity of the first access network device; The identity of the first access network device is verified based on the second verification code and the second check code. The second verification code is calculated based on the second key between the first access network device and the first core network device and at least one of the following parameters: the identifier of the first core network device, the first signature, the identifier of the first terminal, the identifier of the first access network device, the relevant information of the first communication bill, the first communication billing value, and the certificate of the first terminal.
12. The method according to any one of claims 7-11, wherein, The method also includes one of the following: Send first encrypted information to the first terminal, wherein the first encrypted information is obtained by encrypting at least one of the following parameters based on the first key between the first terminal and the first core network device: the first communication billing value, and the relevant information of the first communication bill; Send second encrypted information to the first access network device, wherein the second encrypted information is obtained by encrypting at least one of the following parameters based on the second key between the first access network device and the first core network device: the first communication billing value, and related information of the first communication bill.
13. The method according to claim 7, wherein, Receiving the first signature includes: Receive third encrypted information, wherein the third encrypted information is obtained by encrypting the first signature based on the public key of the first core network device.
14. The method according to claim 13, wherein, The method further includes: Receive a third signature from the first access network device to verify the identity of the first access network device; The third signature is verified based on the public key of the first access network device and at least one of the following parameters: the first signature and the third encrypted information.
15. The method according to any one of claims 7, 13, and 14, wherein, The method further includes: The system receives a first credential for verifying the first terminal's permission to use resources of the first network, wherein the first credential carries at least one of the following: a fourth signature for verifying the first terminal's permission to use the second network to obtain authorized access to resources of the first network, and a fifth signature for verifying the second network's permission to use resources of the first network.
16. The method according to claim 15, wherein, The billing-related information of the first terminal also includes: the first voucher.
17. The method according to any one of claims 7, 13-16, wherein, The method further includes at least one of the following: Send a fourth encrypted message to the first terminal, wherein the fourth encrypted message is obtained by encrypting at least one of the following parameters based on the public key of the first terminal: the first communication billing value, and related information of the first communication bill; A sixth signature is sent to the first terminal, wherein the sixth signature is calculated based on the private key of the first core network device for at least one of the following parameters: the first communication billing value, the relevant information of the first communication bill, and the fourth encrypted information; Send a fifth encrypted message to the first access network device, wherein the fifth encrypted message is obtained by encrypting at least one of the following parameters based on the public key of the first access network device: the first communication billing value, and related information of the first communication bill; A seventh signature is sent to the first access network device, wherein the seventh signature is calculated based on the private key of the first core network device using at least one of the following parameters: the first communication billing value, the relevant information of the first communication bill, and the fifth encrypted information.
18. The method according to any one of claims 7-12, wherein, The method further includes: Send a key allocation message to the first access network device, wherein the key allocation message carries at least one of the following: One or more fourth keys, wherein the one or more fourth keys are keys between one or more terminals and the first access network device, and the one or more terminals include the first terminal; The sixth encryption information is obtained by encrypting one or more fourth keys based on the first key between the first terminal and the first core network device.
19. The method according to claim 18, wherein, The method further includes: The sixth encrypted information is sent to the first terminal.
20. The method according to claim 18 or 19, wherein, The method further includes: A key allocation request is received, wherein the key allocation request carries a third credential for verifying the first terminal's permission to use the resources of the first network.
21. A communication method executed by a first terminal, comprising: Send a first signature to determine that the first terminal acknowledges the first communication billing value, wherein the first terminal belongs to the second network.
22. The method according to claim 21, wherein, The first signature is calculated based on the private key of the first terminal and the first communication billing value.
23. The method according to claim 21 or 22, wherein, The first communication billing value is calculated based on the communication costs of the first terminal under the first network.
24. The method according to any one of claims 21-23, wherein, The method further includes: Send at least one of the following parameters: the identifier of the first terminal, the identifier of the first core network device belonging to the first network, the identifier of the first access network device belonging to the first network, information related to the first communication bill of the first terminal under the first network, and the first communication bill value, wherein the first communication bill includes the communication costs of the first terminal under the first network.
25. The method according to claim 24, wherein, The method further includes: Send the certificate of the first terminal, wherein the certificate of the first terminal carries the public key of the first terminal.
26. The method of claim 25, wherein, The method also includes one of the following: Send a first verification code to the first core network device to verify the identity of the first terminal, wherein the first verification code is calculated based on a first key between the first terminal and the first core network device and at least one of the following parameters: the first signature, the identifier of the first terminal, the identifier of the first core network device, the identifier of the first access network device, relevant information of the first communication bill, the first communication billing value, and the certificate of the first terminal. A third verification code for verifying the identity of the first terminal is sent to the first access network device, wherein the third verification code is calculated based on a fourth key between the first terminal and the first access network device and at least one of the following parameters: the first signature, the identifier of the first terminal, the identifier of the first access network device, relevant information of the first communication bill, the first communication billing value, and the certificate of the first terminal.
27. The method according to any one of claims 24-26, wherein, The method also includes one of the following: The device receives first encrypted information from the first core network device, wherein the first encrypted information is obtained by encrypting at least one of the following parameters based on a first key between the first terminal and the first core network device: the first communication billing value, and related information of the first communication bill. The system receives eighth encrypted information from the first access network device, wherein the eighth encrypted information is obtained by encrypting at least one of the following parameters based on the fourth key between the first terminal and the first access network device: the first communication billing value, and related information of the first communication bill.
28. The method according to claim 24, wherein, The sending of the first signature used to determine that the first terminal acknowledges the first communication billing value includes one of the following: Send a third encrypted message to the first core network device, wherein the third encrypted message is obtained by encrypting the first signature used to determine the first terminal's acceptance of the first communication billing value based on the public key of the first core network device; Send a tenth encrypted message to the first access network device, wherein the tenth encrypted message is obtained by encrypting the first signature used to determine the first terminal's acceptance of the first communication billing value based on the public key of the first access network device.
29. The method according to claim 24 or 28, wherein, The method further includes: Send a first credential for verifying the first terminal's permission to use the resources of the first network, wherein the first credential carries at least one of the following: a fourth signature for verifying the first terminal's permission to use the second network to obtain authorized access to the resources of the first network, and a fifth signature for verifying the second network's permission to use the resources of the first network.
30. The method according to any one of claims 24, 28, and 29, wherein, The method further includes: Receive fourth encrypted information, wherein the fourth encrypted information is obtained by encrypting at least one of the following parameters based on the public key of the first terminal: the first communication billing value, and related information of the first communication bill.
31. The method according to claim 30, wherein, The method further includes: Receive the sixth signature from the first core network device; The sixth signature is verified based on the public key of the first core network device and at least one of the following parameters: the first communication billing value, the relevant information of the first communication bill, and the fourth encrypted information.
32. The method according to claim 30, wherein, The method further includes: Receive the eighth signature from the first access network device; The eighth signature is verified based on the public key of the first access network device and at least one of the following parameters: the first communication billing value, the relevant information of the first communication bill, and the fourth encrypted information.
33. The method according to any one of claims 21-32, wherein, The method further includes: Send a key allocation request, wherein the key allocation request carries a third credential for verifying the first terminal's permission to use the resources of the first network; The sixth encrypted information is received, wherein the sixth encrypted information is obtained by encrypting one or more fourth keys based on the first key between the first terminal and the first core network device, and the one or more fourth keys are keys between one or more terminals and the first access network device, and the one or more terminals include the first terminal.
34. The method according to claim 33, wherein, The method further includes: A registration request is sent to the first access network device, wherein the registration request carries seventh encrypted information obtained by encrypting at least one of the following based on the fourth key: a fourth verification code for verifying the first terminal, the identifier of the first terminal, the identifier of the first access network device, and the identifier of the first resource of the first network to be used, wherein the fourth verification code is calculated based on the fourth key and at least one of the following: the identifier of the first terminal, the identifier of the first access network device, and the identifier of the first resource.
35. A communication method performed by a first access network device, comprising: Receive a first signature from a first terminal for determining that the first terminal recognizes a first communication billing value, wherein the first terminal belongs to a second network and the first access network device belongs to the first network; The first signature is sent to the first core network device, wherein the first core network device belongs to the first network.
36. The method according to claim 35, wherein, The method further includes: Receive at least one of the following parameters from the first terminal: the identifier of the first terminal, the identifier of the first core network device, the identifier of the first access network device, information related to the first communication bill of the first terminal under the first network, and the first communication bill value, wherein the first communication bill includes the communication cost of the first terminal under the first network. Send at least one of the following parameters to the first core network device: the identifier of the first terminal, the identifier of the first core network device, the identifier of the first access network device, the relevant information of the first communication bill, and the first communication billing value.
37. The method of claim 36, wherein, The method further includes: Receive the certificate of the first terminal, wherein the certificate of the first terminal carries the public key of the first terminal; Send the certificate of the first terminal to the first core network device.
38. The method according to claim 36 or 37, wherein, The method further includes: Receive a third verification code from the first terminal to verify the identity of the first terminal; The identity of the first terminal is verified based on the third verification code and the third verification code, wherein the third verification code is calculated based on the fourth key between the first terminal and the first access network device and at least one of the following parameters: the first signature, the identifier of the first terminal, the identifier of the first access network device, the relevant information of the first communication bill, the first communication billing value, and the certificate of the first terminal.
39. The method according to claim 38, wherein, The method further includes: A second verification code is sent to the first core network device to verify the identity of the first access network device. The second verification code is calculated based on a second key between the first access network device and the first core network device and at least one of the following parameters: the identifier of the first core network device, the first signature, the identifier of the first terminal, the identifier of the first access network device, relevant information of the first communication bill, the first communication billing value, and the certificate of the first terminal.
40. The method according to any one of claims 37-39, wherein, The method further includes: Receive second encrypted information from the first core network device, wherein the second encrypted information is obtained by encrypting at least one of the following parameters based on a second key between the first access network device and the first core network device: the first communication billing value, and related information of the first communication bill; The eighth encrypted information is sent to the first terminal, wherein the eighth encrypted information is obtained by encrypting at least one of the following parameters based on the fourth key between the first terminal and the first access network device: the first communication billing value and related information of the first communication bill.
41. The method according to claim 36, wherein, Receiving a first signature from the first terminal for determining that the first terminal approves the first communication billing value includes: The system receives tenth encrypted information from the first terminal, wherein the tenth encrypted information is obtained by encrypting the first signature used to determine the first communication billing value recognized by the first terminal based on the public key of the first access network device.
42. The method according to claim 41, wherein, Sending the first signature to the first core network device includes: Send a third encrypted message to the first core network device, wherein the third encrypted message is obtained by encrypting the first signature based on the public key of the first core network device.
43. The method according to claim 42, wherein, The method further includes: A third signature is sent to the first core network device to verify the identity of the first access network device, wherein the third signature is calculated based on the private key of the first access network device and at least one of the following parameters: the first signature and the third encrypted information.
44. The method according to any one of claims 36, 41-43, wherein, The method further includes: Receive a first credential from the first terminal for verifying the first terminal's permission to use the resources of the first network, wherein the first credential carries at least one of the following: a fourth signature for verifying the first terminal's permission to use the second network to obtain authorized access to the resources of the first network, and a fifth signature for verifying the second network's permission to use the resources of the first network. Send the first credential to the first core network device.
45. The method according to any one of claims 36, 41-44, wherein, The method further includes: The system receives fifth encrypted information from the first core network device, wherein the fifth encrypted information is obtained by encrypting at least one of the following parameters based on the public key of the first access network device: the first communication billing value, and related information of the first communication bill. Send a fourth encrypted message to the first terminal, wherein the fourth encrypted message is obtained by encrypting at least one of the following parameters based on the public key of the first terminal: the first communication billing value, and related information of the first communication bill.
46. The method according to claim 45, wherein, The method further includes: Receive a seventh signature from the first core network device, wherein the seventh signature is calculated based on the private key of the first core network device for at least one of the following parameters: the first communication billing value, the relevant information of the first communication bill, and the fifth encrypted information; Send an eighth signature to the first terminal, wherein the eighth signature is calculated based on the private key of the first access network device and at least one of the following parameters: the first communication billing value, the relevant information of the first communication bill, and the fourth encrypted information.
47. The method according to any one of claims 38-40, wherein, The method further includes: Receive a key allocation message from the first core network device, wherein the key allocation message carries at least one of the following: One or more fourth keys, wherein the one or more fourth keys are keys between one or more terminals and the first access network device, and the one or more terminals include the first terminal; The sixth encryption information is obtained by encrypting one or more fourth keys based on the first key between the first terminal and the first core network device.
48. The method according to claim 47, wherein, The method further includes: The sixth encrypted information is sent to the first terminal.
49. The method according to claim 47 or 48, wherein, The method further includes: Receive a key allocation request from the first terminal, wherein the key allocation request carries a third credential for verifying the first terminal's permission to use the resources of the first network; The key allocation request is forwarded to the first core network device.
50. The method according to any one of claims 47-49, wherein, The method further includes: A registration request is received from the first terminal, wherein the registration request carries seventh encrypted information obtained by encrypting at least one of the following based on the fourth key: a fourth checksum for verifying the first terminal, the identifier of the first terminal, and the first access network. The device identifier, the identifier of the first resource of the first network requested for use, and the fourth verification code are calculated based on the second key and at least one of the following: the identifier of the first terminal, the identifier of the first access network device, and the identifier of the first resource.
51. A first core network device, comprising: The first communication unit is used to upload the billing-related information of the first terminal to the blockchain. The billing-related information of the first terminal is used to determine the first communication billing value recognized by the first terminal and the first core network device. The first core network device belongs to the first network, and the first terminal belongs to the second network.
52. A first terminal, comprising: The second communication unit is configured to send a first signature for determining that the first terminal recognizes the first communication billing value, wherein the first terminal belongs to the second network.
53. A first access network device, comprising: The third communication unit is configured to receive a first signature from a first terminal for determining that the first terminal recognizes a first communication billing value, wherein the first terminal belongs to a second network and the first access network device belongs to the first network; and to send the first signature to a first core network device, wherein the first core network device belongs to the first network.
Citation Information
Patent Citations
Non-repudiation charging method for heterogeneous wireless network
CN104507065A
Method and apparatus for providing roaming service
CN110622530A
Roaming charging processing method, device and system
CN112449316A
Method system and device for transferring accounting information
CN1628449A
Sterilization, deodorization and Cleansing effect excellent Therawater Alkali ionized water composition and manufacturing method
KR1020210153494A