Communication method and communication device

By introducing data plane network elements and blockchain technology, the issues of data trustworthiness and security in the sixth-generation communication system have been solved, enabling trusted data storage and secure transmission, preventing privacy leaks, and improving data trustworthiness and security.

WO2025251186A1PCT designated stage Publication Date: 2025-12-11GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/097192
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-06-04
Publication Date
2025-12-11

AI Technical Summary

Technical Problem

In sixth-generation communication systems, how can we improve the credibility and security of data, especially to avoid privacy leaks during data operations and ensure the reliable storage and security of data?

Method used

By introducing data plane network elements, data operation permissions are verified through blockchain technology and smart contracts to ensure the immutability and traceability of data during storage and transmission. Data plane network element 1 provides data operation functions, while network element 2 manages or controls data plane access, thereby realizing trusted data collection, storage, access, and sharing.

Benefits of technology

It enhances data security and credibility, prevents privacy leaks, ensures the traceability and immutability of data throughout its lifecycle, and strengthens the credibility of data services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024097192_11122025_PF_FP_ABST
    Figure CN2024097192_11122025_PF_FP_ABST
Patent Text Reader

Abstract

Provided are a communication method and a communication device. The communication method comprises: a first network element sending a first message to a second network element, wherein the first message is used for determining a permission to operate on first data, the first data comprises related data of the first network element, and the second network element is used for providing a data operation function of a data plane.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method and communication device TECHNICAL FIELD

[0001] The present application relates to the technical field of communication, and more particularly, to a communication method and a communication device. BACKGROUND

[0002] In some communication systems (such as a 6th generation (6G) system), users have higher requirements for the credibility and security of data. Then, how to improve the credibility and security of data in the process of operating data is a problem to be solved.

[0003] SUMMARY

[0004] The present application provides a communication method and a communication device. The various aspects involved in the present application are introduced below.

[0005] In a first aspect, a communication method is provided, comprising: a first network element sending a first message to a second network element, the first message being used to determine an operation permission for first data, the first data comprising relevant data of the first network element, and the second network element being used to provide a data plane data operation function.

[0006] In a second aspect, a communication method is provided, comprising: a second network element receiving a first message sent by a first network element, the first message being used to determine an operation permission for first data, the first data comprising relevant data of the first network element, and the second network element being used to provide a data plane data operation function.

[0007] In a third aspect, a communication method is provided, comprising: a third network element receiving a first message sent by a first network element; and the third network element sending the first message to a second network element, wherein the first message is used to determine an operation permission for first data, the first data comprising relevant data of the first network element, the second network element being used to provide a data plane data operation function, and the third network element being used to manage or control the first network element to access the data plane.

[0008] In a fourth aspect, a communication device is provided, the communication device being a first network element, and the communication device comprising: a sending module, configured to send a first message to a second network element, the first message being used to determine an operation permission for first data, the first data comprising relevant data of the first network element, and the second network element being used to provide a data plane data operation function.

[0009] In a fifth aspect, a communication device is provided, the communication device being a second network element, the communication device comprising: a receiving module configured to receive a first message sent by a first network element, the first message being used to determine an operation right of first data, the first data comprising relevant data of the first network element, and the second network element being configured to provide a data operation function of a data plane.

[0010] In a sixth aspect, a communication device is provided, the communication device being a third network element, the communication device comprising: a first receiving module configured to receive a first message sent by a first network element; and a first sending module configured to send the first message to a second network element, wherein the first message is used to determine an operation right of first data, the first data comprising relevant data of the first network element, the second network element being configured to provide a data operation function of a data plane, and the third network element being configured to manage or control the first network element to access the data plane.

[0011] In a seventh aspect, a communication device is provided, comprising a processor, a memory, and a communication interface, the memory being configured to store one or more computer programs, and the processor being configured to invoke the computer programs in the memory to cause the communication device to perform some or all of the steps in the method of any one of the first aspect to the third aspect.

[0012] In an eighth aspect, a communication system is provided, comprising the communication device described above. In another possible design, the system can further comprise other devices interacting with the communication device in the solutions provided by the embodiments of the present application.

[0013] In a ninth aspect, a computer readable storage medium is provided, which stores a computer program, and the computer program causes a computer to perform some or all of the steps in the methods of the various aspects described above.

[0014] In a tenth aspect, a computer program product is provided, which comprises a non-transitory computer readable storage medium storing a computer program, and the computer program is operable to cause a computer to perform some or all of the steps in the methods of the various aspects described above. In some implementations, the computer program product can be a software installation package.

[0015] In an eleventh aspect, a chip is provided, which comprises a memory and a processor, and the processor can invoke and run a computer program from the memory to implement some or all of the steps described in the methods of the various aspects described above.

[0016] In the embodiments of this application, when the first data related to the first network element is operated in the data plane, the second network element can determine the operation permission of the first data based on the message sent by the first network element. That is, the first network element can control the operation permission of the first data, thereby facilitating the avoidance of data privacy leakage and the improvement of data security. BRIEF DESCRIPTION OF DRAWINGS

[0017] FIG. 1 is an example diagram of a communication system architecture to which embodiments of this application are applicable.

[0018] FIG. 2 is an example diagram of a blockchain architecture to which embodiments of this application are applicable.

[0019] FIG. 3 is an example diagram of a communication system architecture including a data plane provided by an embodiment of this application.

[0020] FIG. 4 is an example diagram of a communication system architecture including a data plane provided by another embodiment of this application.

[0021] FIG. 5 is a schematic diagram of a data plane provided by an embodiment of this application.

[0022] FIG. 6 is a schematic diagram of operation logic of a smart contract provided by an embodiment of this application.

[0023] FIG. 7 is a flowchart of a process of storing data based on a data plane provided by an embodiment of this application.

[0024] FIG. 8 is a flowchart of a communication method provided by an embodiment of this application.

[0025] FIG. 9 is a flowchart of a communication method provided by another embodiment of this application.

[0026] FIG. 10 is a flowchart of a communication method provided by yet another embodiment of this application.

[0027] FIG. 11 is a flowchart of a communication method provided by yet another embodiment of this application.

[0028] FIG. 12 is a flowchart of a communication method provided by yet another embodiment of this application.

[0029] FIG. 13 is a schematic diagram of interaction between a first network element and a data plane provided by an embodiment of this application.

[0030] FIG. 14 is a structural schematic diagram of a communication device provided by an embodiment of this application.

[0031] FIG. 15 is a structural schematic diagram of a communication device provided by another embodiment of this application.

[0032] FIG. 16 is a structural schematic diagram of a communication device provided by yet another embodiment of this application.

[0033] FIG. 17 is a schematic structural diagram of a communication apparatus provided in an embodiment of the present application. DETAILED DESCRIPTION

[0034] The technical solutions in the present application will be described below with reference to the drawings. In order to facilitate understanding, the following first introduces a communication system architecture to which the embodiments of the present application can be applied with reference to FIG. 1.

[0035] FIG. 1 is an example diagram of a system architecture of a wireless communication system 100 to which the embodiments of the present application can be applied. The system architecture shown in FIG. 1 can include terminal devices, access network (AN) devices, and network elements in a core network.

[0036] It should be understood that the technical solutions of the embodiments of the present application can be applied to various communication systems, for example: a 5th generation (5G) system or new radio (NR), a long term evolution (LTE) system, an LTE frequency division duplex (FDD) system, an LTE time division duplex (TDD), etc. The technical solutions provided in the present application can also be applied to future communication systems, such as a 6th generation mobile communication system, a satellite communication system, etc.

[0037] The terminal device in the embodiments of the present application can also be referred to as a user equipment (UE), an access terminal, a user unit, a user station, a mobile station, a mobile station (MS), an MT, a remote station, a remote terminal, a mobile device, a user terminal, a terminal, a wireless terminal, a user agent or a user apparatus. The terminal device in the embodiments of the present application can refer to a device providing voice and / or data connectivity for a user, and can be used to connect people, things and machines, such as handheld devices with wireless connection function, vehicle-mounted devices, etc. The terminal device in the embodiments of the present application can be a mobile phone, a tablet computer (Pad), a notebook computer, a palm computer, a mobile internet device (MID), a wearable device, a virtual reality (VR) device, an augmented reality (AR) device, a wireless terminal in industrial control, a wireless terminal in self driving, a wireless terminal in remote medical surgery, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, etc. Optionally, the terminal device can be used to act as a base station. For example, the terminal device can act as a scheduling entity, which provides sidelink signals between terminal devices in vehicle-to-everything (V2X) or device to device (D2D), etc. For example, a cellular phone and a car communicate with each other using sidelink signals. The cellular phone and the smart home device communicate with each other without relaying the communication signals through the base station.

[0038] The access network device can be an access device through which a terminal device accesses the network architecture wirelessly, and is mainly responsible for radio resource management, quality of service (QoS) management, data compression and encryption, etc. on the air interface side. The access network device can also be referred to as a radio access network (RAN) device, for example, the access network device can be a base station. The base station can broadly cover various names in the following or replace the following names, such as: NodeB, evolved NodeB (eNB), next generation NodeB (gNB), relay station, transmitting and receiving point (TRP), transmitting point (TP), master eNB (MeNB), secondary eNB (SeNB), multi-standard radio (MSR) node, home base station, network controller, access node, wireless node, access point (AP), transmission node, transceiver node, baseband unit (BBU), remote radio unit (RRU), active antenna unit (AAU), remote radio head (RRH), central unit (CU), distributed unit (DU), positioning node, etc. The base station can be a macro base station, a micro base station, a relay node, a donor node, or the like, or a combination thereof. The base station can also refer to a communication module, modem, or chip used in the aforementioned device or apparatus. The base station can also be a mobile switching center and a device that performs the function of a base station in D2D, V2X, machine-to-machine (M2M) communication, a network side device in a 6G network, a device that performs the function of a base station in a future communication system, etc. The base station can support networks of the same or different access technologies. Embodiments of the present application do not limit the specific technology and specific device form adopted by the access network device.

[0039] The base station can be fixed or mobile. For example, a helicopter or a drone can be configured to act as a mobile base station, and one or more cells can move according to the location of the mobile base station. In other examples, the helicopter or the drone can be configured to act as a device that communicates with another base station.

[0040] In some deployments, the access network device in the embodiments of the present application can refer to a CU or a DU, or the access network device includes a CU and a DU. The gNB can also include an AAU.

[0041] The type of network element in the core network can include a user plane function (UPF) network element, an access and mobility management function (AMF) network element, a session management function (SMF) network element, a policy control function (PCF) network element, a data network (DN), a network slice selection function (NSSF), an authentication server function (AUSF), a unified data management (UDM), a network exposure function (NEF), a network repository function (NRF), and a network slice-specific authentication and authorization function (NSSAAF). Among them, the UPF network element is mainly responsible for the transmission of user data, and other network elements can be referred to as control plane function network elements, which are mainly responsible for authentication, authorization, registration management, session management, mobility management, and policy control, etc. to ensure reliable and stable transmission of user data.

[0042] The UPF network element can be used to forward and receive data of the terminal device. For example, the UPF network element can receive service data from a data network and transmit it to the terminal device through the access network device; the UPF network element can also receive user data from the terminal device through the access network device and forward it to the data network. Among them, the transmission resources allocated and scheduled by the UPF network element for the terminal device are managed and controlled by the SMF network element. The bearer between the terminal device and the UPF network element can include a user plane connection between the UPF network element and the access network device, and a channel established between the access network device and the terminal device. Among them, the user plane connection is a QoS flow that can be established between the UPF network element and the access network device to transmit data.

[0043] The AMF network element can be used to manage the access of the terminal device to the core network, for example, location update of the terminal device, registration network, access control, mobility management of the terminal device, attachment and detachment of the terminal device, and the like. The AMF network element can also provide storage resources for the control plane of the session for the terminal device in the case of providing services for the session, to store the session identifier, the SMF network element identifier associated with the session identifier, and the like.

[0044] The SMF network element can be used to select a user plane network element for the terminal device, redirect a user plane network element for the terminal device, allocate an internet protocol (IP) address for the terminal device, establish a bearer (also referred to as a session) between the terminal device and the UPF network element, modify, release, and QoS control of the session.

[0045] The PCF network element is used to provide policies such as QoS policies, slice selection policies, and the like to the AMF network element and the SMF network element.

[0046] The DN can provide data services for users, such as IP multi-media service (IMS) networks, the Internet, and the like. There can be various application servers (ASs) in the DN to provide different application services, such as operator services, Internet access, or third-party services, and the like, and the ASs can implement the functions of application functions (AFs). Among them, the AF network element is used to interact with the network elements in the 3GPP core network to support application influence data routing, access network exposure functions, and interact with the PCF network element for policy control, and the like.

[0047] The NSSF is used for network slice selection, and the supported functions include: selecting a set of network slice implementations to serve the terminal device; determining the allowed network slice selection assistance information (NSSAI), and determining the mapping to the single-network slice selection assistance information (S-NSSAI) of the subscription when needed; determining the configured NSSAI, and determining the mapping to the S-NSSAI of the subscription when needed; determining a set of AMFs that can be queried for the terminal device, or determining a list of candidate AMFs based on configuration.

[0048] The AUSF is used to receive a request for authentication of the terminal device from the AMF, request a key from the UDM, and then forward the issued key to the AMF for authentication processing.

[0049] The UDM includes functions such as generation and storage of user subscription data, management of authentication data, and supports interaction with external third-party servers.

[0050] The NEF is used for capability exposure, that is, based on the NEF, the capabilities of the network can be output to external networks. An external untrusted application can access internal data of the core network through the NEF to ensure the security of the network. The NEF can provide functions such as external application QoS capability exposure, event subscription, AF request distribution, and the like.

[0051] The NRF is used for registration, management, and state detection of network elements in the core network, so as to realize automatic management of network elements in the core network. When a network element in the core network starts, it must be registered with the NRF to provide services. The registration information may include, for example, the type, address, and service list of the network element.

[0052] In addition, some networks (for example, a 5G network) also add a network data analysis function (network data analytics function, NWDAF) in the core network. Based on the NWDAF, data can be collected from various network elements, network management systems, and the like in the core network, and big data statistics, analysis, or intelligent data analysis can be performed, so as to obtain analysis or prediction data on the network side, and then assist various network elements to more effectively control terminal device access according to the data analysis results.

[0053] In some communication systems (for example, a 5G system, a 6G system, and the like), the network elements in the core network can also be referred to as network functions (network function, NF).

[0054] In the system architecture shown in FIG. 1, an important feature is that these system architectures include a service-oriented architecture, that is, a service provider (such as a network element in the core network) can provide specific services, and other network elements (consumers) can call through a defined API interface.

[0055] It should be noted that each network element in FIG. 1 can be a network element in a hardware device, a software function running on a dedicated hardware, or a virtualized function instantiated on a platform (for example, a cloud platform). It should be noted that in the network architecture shown in FIG. 1, only network elements included in the entire network architecture are exemplarily illustrated. In the embodiments of the present application, the network elements included in the entire network architecture are not limited.

[0056] Those skilled in the art can understand that the network architecture shown in FIG. 1 does not constitute a limitation on the network architecture, and the network architecture can include more or fewer network elements than shown, or some network elements can be combined, and the like. It should be understood that the AN or RAN is represented in the form of (R)AN in FIG. 1.

[0057] In some scenarios, the network device and the terminal device can be deployed on land, including indoor or outdoor, handheld or vehicle-mounted; can also be deployed on water surface; can also be deployed on aircraft, balloon and satellite in the air. The scenarios in which the network device and the terminal device are located are not limited in the embodiments of the present application.

[0058] By way of example and without limitation, in the embodiments of the present application, the network device can have a mobile characteristic, for example, the network device can be a mobile device. In some embodiments of the present application, the network device can be a satellite, a balloon station. For example, the satellite can be a low earth orbit (LEO) satellite, a medium earth orbit (MEO) satellite, a geostationary earth orbit (GEO) satellite, a high elliptical orbit (HEO) satellite, etc. In some embodiments of the present application, the network device can also be a base station arranged at a position on land, water, etc.

[0059] In the embodiments of the present application, the network device can serve a cell, and the terminal device communicates with the network device through a transmission resource (for example, a frequency domain resource, or a spectrum resource) used by the cell. The cell can be a cell corresponding to the network device (for example, a base station), and the cell can belong to a macro base station or a base station corresponding to a small cell. The small cell can include a metro cell, a micro cell, a pico cell, a femto cell, etc., and these small cells have the characteristics of small coverage and low transmit power, and are suitable for providing high-speed data transmission services.

[0060] For ease of understanding, some related technical knowledge involved in the embodiments of the present application is introduced first. The following related technologies can be combined with the technical solutions of the embodiments of the present application in any manner as optional schemes, and all belong to the protection scope of the embodiments of the present application. The embodiments of the present application include at least part of the following contents.

[0061] Blockchain

[0062] Referring to FIG. 2, the blockchain 200 is a typical distributed collaborative system. The system includes a plurality of blockchain nodes 210. The plurality of blockchain nodes 210 can jointly maintain a growing distributed data record. The data of the record can be protected in terms of content and timing by cryptographic techniques, making it difficult for any party to tamper with, deny, or fake. The blockchain node 210 can be a device with computing capability, such as a server, a server group, a blockchain chip, etc., where the server group can be centralized or distributed. In some other implementations, the server can also be a server providing services for a cloud platform.

[0063] In some implementations, a blockchain can include three basic elements: transaction, block, and chain. In a blockchain, data (e.g., transaction information, transaction execution result (also referred to as "state result"), etc.) can be encapsulated in the form of blocks. Blocks can be linked to each other by forward reference to form a "chain", also known as a blockchain.

[0064] In some implementations, a transaction can be understood as an operation, and executing a transaction can trigger a change in the state of the ledger in the blockchain.

[0065] In some implementations, the block is used to record transactions and state results that occur within a period of time. The node responsible for bookkeeping in the blockchain can reach a consensus on the current state of the ledger based on the block, where the consensus mechanism can be described later.

[0066] In some implementations, the blockchain can record a log of the entire state change. That is, each block in the blockchain holds data records (i.e., transactions, also referred to as “data transactions”) within a specified period of time, and forms a secure and reliable chain through cryptography, forming a tamper-proof, all-common distributed ledger (also referred to as a data ledger). In simple terms, the blockchain is an account book that records all historical transactions, and each node holds a copy. The nodes ensure that everyone’s account book eventually converges through a consensus algorithm. Each block in the blockchain is like a page of the account book, recording a batch of transaction entries. In this way, all transaction details are recorded in a public ledger that can be viewed by any node. If you want to modify a recorded transaction, you need to modify all the nodes that hold the ledger at the same time. At the same time, since each page in the blockchain ledger records the summary information of the previous page, if you modify the account book of a page (i.e., tamper with a block), the summary will not match the summary recorded on the next page. At this time, the next page content needs to be modified, which further causes the next page summary to not match the next page record. In this way, the modification of a transaction will cause the modification of all subsequent block summaries. Considering that all people need to recognize these changes, it will be a huge and almost impossible task. For this reason, the blockchain has the feature of being tamper-proof.

[0067] Generally, a block can include a block header and a block body. The block header can contain basic information of the current block to ensure that the current block can correctly enter the blockchain. For example, the block header can record the block hash value of the previous block of the current block. For another example, the block header can also record the block height of the current block. The block height, referred to as “block height” for short, is used to identify the position of the block in the blockchain. In some implementations, the block height of the genesis block is 0. The block body can be used to record transaction information. The transaction information can include, for example, transaction quantity and transaction data.

[0068] The blockchain is generally divided into three types: public blockchain, private blockchain, and consortium blockchain. In addition, there can be combinations of the above types, such as private blockchain + consortium blockchain, consortium blockchain + public blockchain, etc. The embodiments provided in the present application can be implemented in a suitable type of blockchain.

[0069] Consensus mechanism

[0070] The consensus mechanism can be understood as how the nodes responsible for recording in the blockchain (or recording nodes) reach a consensus to determine the validity of a record.

[0071] The consensus mechanism of the blockchain has the characteristics of "minority obeying majority" and "everyone is equal". The "minority obeying majority" does not refer to the number of nodes, but also can be the computing power, the number of shares or other characteristics that can be compared by computers. "Everyone is equal" means that when the node meets the condition, all nodes have the right to propose a consensus result, are directly recognized by other nodes, and finally have the possibility to become the final consensus result. For example, Bitcoin uses proof of work. Only when more than 51% of the accounting nodes in the entire network are controlled, it is possible to forge a non-existent record. When the number of nodes joining the blockchain is large enough, it is basically impossible, thereby eliminating the possibility of fraud.

[0072] The self-trust of the blockchain mainly reflects that the users distributed in the blockchain do not need to trust the other party of the transaction or a centralized institution, but only need to trust the software system under the blockchain protocol to realize the transaction. The premise of this self-trust is the consensus mechanism of the blockchain, that is, in a market where each node does not trust each other, the sufficient and necessary condition for the nodes to reach an agreement is that each node will voluntarily and honestly comply with the rules set in the protocol to judge the authenticity of each record, and finally record the record judged to be true in the blockchain. In other words, if each node has its own independent interests and competes with each other, it is almost impossible for these nodes to collude and cheat you, and this is particularly evident when the nodes have public credit in the network. The blockchain technology uses a set of consensus-based mathematical algorithms to establish a "trust" network between machines, thereby creating new credit through technical endorsement rather than a centralized credit institution.

[0073] The consensus mechanism of the blockchain can be one of the following consensus mechanisms: proof of work (PoW), proof of stake, proof of share, verification pool and practical byzantine fault tolerance (PBFT).

[0074] Smart contract

[0075] The smart contract is a set of promises defined in digital form, including the agreement on which the contract participants can execute the promises. Alternatively, the smart contract can be understood as a program deployed on a computer system, which can be automatically executed when the trigger condition of the smart contract is met.

[0076] The emergence of blockchain provides technical support for the implementation of smart contracts. The smart contract is written in a digital form into the blockchain, and the characteristics of the blockchain technology guarantee the transparency and traceability of the storage, reading and execution of the smart contract. On the other hand, a state machine system can be built by the consensus algorithm of the blockchain, so that the smart contract can be efficiently run. For a transaction, if the conditions of the smart contract are met, the transaction is considered valid, and the transaction information of the transaction can be recorded by the blockchain and the ledger is updated accordingly.

[0077] In some implementations, a user can invoke a smart contract by submitting a transaction to a blockchain system, set data recorded in the smart contract, and store the set smart contract in the blockchain. Accordingly, when a specific condition of the smart contract is triggered, the blockchain node can execute the smart contract and record the execution result and the execution status of the smart contract.

[0078] In some implementations, the smart contract can include a code function (function) and can interact with other contracts, make decisions, store data, etc.

[0079] Currently, various industries and even some fields in an industry (for example, finance, public welfare, insurance, cross-border payment, etc.) can build different types of blockchains according to their own industrial structure, and record valuable information and assets in the industry or industry on the blockchain.

[0080] Data plane (DP)

[0081] In some scenarios (for example, practical experience of intelligent 5G network), it is very difficult to obtain data, and the quality of the data is difficult to guarantee. On the one hand, the data collection based on network management also has the problems of less data types, long collection period (15 minutes), non-uniform data format, naming and calculation method of different manufacturers, which leads to the difficulty of opening network management data. On the other hand, it is more difficult to collect data from terminal devices, because collecting data from terminal devices may lead to leakage of private data and reduction of data security. Therefore, how to ensure that the data collected from the terminal device can be processed by a trusted node so as to not leak the privacy of the user, or how to track the collected data throughout the life cycle and ensure that the use of any data by any data consumer will be recorded, are currently unsolvable problems.

[0082] To solve the above problems, in some network architectures (for example, 6G network architecture), a scheme of adding a "data plane" is proposed. In some implementations, the data elements in the data plane will cover internal and external data of the network, including business data, user data, network data, perception data, external data, etc.

[0083] In some implementations, the basic data service includes data collection, data preprocessing, data storage, data access, data sharing and collaboration, etc. Among them, the basic data service can have the following characteristics: supporting trusted authentication, authorization and access, efficient data storage and management, on-demand data collection and data preprocessing, external data opening, etc. That is, the data plane can include one or more network elements that provide basic data services for the above data elements, or in other words, the data plane includes one or more functions (or network elements) to support one or more of the following data services: trusted, flexible data collection, data opening, data preprocessing, data storage, data tracking between data sources and data consumers. Among them, the data source and / or data consumer can be any node, for example, the data source can be any node with data storage requirements, and the data consumer can be any node with data calling requirements.

[0084] In some networks (for example, in a 6G network), "trust" will become an important requirement for users of data services, where data services are mainly reflected in data collection, data storage, data access, data sharing, etc. How to provide trusted storage and traceable characteristics of data in the process of providing data services has become a key problem that the data plane needs to solve.

[0085] Therefore, in view of the above problems, the embodiments of the present application introduce a data plane. The following describes a schematic diagram of a communication system architecture including a data plane according to the embodiments of the present application with reference to FIG. 3 and FIG. 4.

[0086] In some implementations, the data plane can be used to support one or more of the following functions: trusted data collection, trusted data storage, trusted data access, and trusted data sharing. It should be understood that in the embodiments of the present application, the name of the data plane is not limited, for example, the data plane can also be referred to as "data plane" or "data network element set", etc. In future communication architectures, this name can be replaced by the name corresponding to the network element with the same or similar function in the future communication architecture. In order to facilitate description, the embodiments of the present application take the data plane as an example for description.

[0087] Referring to FIG. 3 and FIG. 4, the data plane can include network element 1 and / or network element 2. In some implementations, network element 1 is used to provide data operation functions of the data plane, or in other words, network element 1 is used to operate data in the data plane. The embodiments of the present application do not make specific limitations on the data operation functions of the data plane provided by network element 1. For example, network element 1 can provide one or more of the following operations: data storage function of the data plane, data retrieval (calling) function of the data plane, data sharing function of the data plane, data collection function of the data plane, data processing function of the data plane, data opening function of the data plane, data verification function of the data plane, etc.

[0088] The name of the network element 1 is not limited in the embodiments of the present application. For example, the name of the network element 1 can include one or more of the following: a data plane operation network element, a data plane repository (DPR) network element, a data plane operation infrastructure, a data plane repository infrastructure, and the like. Of course, the network element 1 can also be other names, such as the names of network elements with the same or similar functions in future communication systems.

[0089] In some implementations, the network element 1 can be a blockchain node (for example, the blockchain node 210) located in a blockchain, which helps to implement functions such as trusted data storage in the communication system architecture by means of the characteristics of the blockchain introduced above.

[0090] It should be noted that the network element 1 can correspond to one or more entity devices (for example, servers). If the network element 1 corresponds to multiple entity devices, it can be understood that the network element is distributed. Among them, part or all of the entity devices in the multiple entity devices can be located in the blockchain. For example, the multiple entity devices can correspond to multiple blockchain nodes in the blockchain.

[0091] In some implementations, if the network element 1 is distributed and the multiple entity devices corresponding to the network element 1 belong to the same blockchain node, the multiple entity devices will store the same data, thereby ensuring the non-tamperability of the data.

[0092] In some implementations, the network element 1 can be used for one or more of the following: processing transaction requests, cooperating with other peer nodes, adding successfully verified transaction information to a newly created block, updating and maintaining the ledger corresponding to each blockchain node, and opening an application programming interface (API).

[0093] In some implementations, the above processing of transaction requests may, for example, include storing data based on transaction requests and / or retrieving data based on transaction requests.

[0094] In some implementations, the above cooperation with other peer nodes (also known as peer DPRF) may, for example, include verifying the consistency of transaction data and / or providing distributed storage for data together with other peer nodes. Among them, the peer node can refer to a blockchain node that saves a copy of the ledger and / or a copy of the smart contract in the blockchain.

[0095] In some implementations, the adding of the successfully verified transaction information into the newly created block can include adding the successfully verified transaction information into the newly created block and linking the block to the blockchain after the verification by the smart contract and the consensus algorithm.

[0096] In some implementations, the network element 1 can update and maintain the ledger corresponding to each blockchain node, which helps to provide the transaction information of each transaction.

[0097] In some implementations, the network element 1 can open an API interface, so that other network elements (for example, the network element 2 described below) can call the interface to perform the blockchain-based data service with the network element 1.

[0098] In some implementations, the network element 1 can include one or more logical functions, which will be exemplarily described below in combination with FIG. 5.

[0099] As shown in FIG. 5, the network element 1 can include one or more of the following logical functions: logical function 1, logical function 2, and logical function 3.

[0100] In some implementations, the logical function 1 is configured to provide a data operation function of a data plane. For example, the logical function 1 can be configured to provide a storage function of the data plane, or in other words, the logical function 1 is configured to provide a storage space for data to be stored to the data plane. Therefore, the logical function 1 can also be referred to as a data plane repository function (DPRF).

[0101] In some implementations, the logical function 2 is configured to provide a smart contract of the data plane, which can be understood as a smart protocol. The smart contract is configured to verify whether a transaction request is valid, or the smart contract is configured to verify whether data associated with the transaction request is valid, or the smart contract is configured to verify whether a transaction associated with the transaction request is valid. Therefore, the logical function 2 can also be referred to as a data plane smart contract (DPSC).

[0102] In some implementations, the logical function 2 can include a plurality of conditions. Generally, if a transaction satisfies all the conditions recorded in the logical function 2, the transaction can be considered valid, and accordingly, the transaction can be executed (for example, the data requested to be stored by the transaction can be stored to the logical function 1). Conversely, if the transaction does not satisfy some or all of the conditions recorded in the logical function 2, the transaction can be considered invalid, and accordingly, the transaction is not executed.

[0103] In some implementations, the logical function 3 is configured to record a ledger of the data plane, where the ledger is configured to record transaction information that occurred, which can include one or more of the following: the data itself, the data source, the data consumer, a timestamp, subsequent usage of the data, and data description information of the data.

[0104] In some implementations, the same ledger is stored for each logical function 1 (i.e., DPRF) of the same blockchain, which helps to improve traceability and non-tamperability of the data.

[0105] As described above, the logical function 3 is configured to record a ledger of the data plane, and thus, the logical function 3 can also be referred to as a data plane data ledger (DPDL).

[0106] The above describes a network element 1 in the data plane according to embodiments of the present disclosure, and the following describes a network element 2 in the data plane according to embodiments of the present disclosure.

[0107] In some implementations, the network element 2 is configured to manage or control data plane access, or in other words, the network element 2 can serve as an interface between data in the communication system and data operation network elements (e.g., network element 1) in the data plane. Thus, the network element 2 can also be referred to as a data plane access controller (DPAC). Of course, the network element 2 can also be referred to as one or more of the following in embodiments of the present disclosure: a data plane management network element, a data plane interface, a data plane control network element, and the present disclosure does not limit the network element 2 to these.

[0108] In some implementations, the network element 2 can be located in the core network, i.e., the network element 2 can be a network element in the core network.

[0109] In some implementations, the above management or control of data plane access can include one or more of the following: collecting data to be stored in the data plane; performing security verification on the data to be stored in the data plane; managing or verifying identification information of the data source of the data to be stored in the data plane; managing or verifying identification information of the data consumer of the data to be stored in the data plane; managing access rights to the data stored in the data plane; processing the data in the data plane; format conversion; performing data tracking on the data stored in the data plane; and interacting with data operation network elements (network element 1).

[0110] In some implementations, the above collection of data to be stored in the data plane can include data in the communication system (e.g., the communication system shown in FIG. 1) to be stored in the data plane.

[0111] In some implementations, the security verification of the data to be stored in the data plane can include, for example, security verification of the data to be stored by using a smart contract and / or a consensus mechanism.

[0112] In some implementations, the identification information of the data source of the data can be understood as identification information of the data source corresponding to the stored data. For example, if the terminal device 1 stores data in the data plane, the identification information of the data source of the data can include identification information of the terminal device 1, and correspondingly, the network element 2 is configured to store the identification information of the terminal device 1 corresponding to the data. For another example, if the AF 1 stores data in the data plane, the identification information of the data source of the data can include identification information of the AF 1, and correspondingly, the network element 2 is configured to store the identification information of the AF 1 corresponding to the data.

[0113] In some implementations, the identification information of the data consumer can be understood as identification information of the consumer who purchases or subscribes to the data. For example, if the AF 2 subscribes to data in the data plane, the data consumer corresponding to the data is the AF 2, and correspondingly, the network element 2 is configured to store the identification information of the AF 2 corresponding to the data.

[0114] In some implementations, the access permission can be used to indicate which user or device can access the data, or in other words, the access permission can be used to indicate which data a certain user or device can access.

[0115] In some scenarios, the format of the data received by the network element 2 can be different from the format supported by the data operation network element in the data plane, and correspondingly, the format conversion can include conversion of the format of the received data by the network element 2 to the format supported by the data operation network element in the data plane. Of course, in the embodiments of the present application, the format conversion can also include conversion of the format of the data stored in the data operation network element in the data plane to the format of the data supported by the data request end (for example, the data consumer). The data operation network element in the data plane can be, for example, the network element 1 introduced above.

[0116] In some implementations, the data tracking of the data stored in the data plane can include tracking of the operation process corresponding to the data. Of course, in the embodiments of the present application, the data tracking can include tracking of the data source corresponding to the data, and / or tracking of the data consumer that invokes the data.

[0117] In some implementations, interacting with the data operation network element in the data plane can be understood as network element 2 interacting with network element 1 in the data plane. For example, network element 2 can store data into network element 1, i.e., network element 2 can send a transaction request to network element 1 to request storing the data to be stored into network element 2, where the data to be stored can be sent by a data source to network element 1. For another example, network element 2 can obtain data to be accessed (or said to be invoked) from network element 1, i.e., network element 2 can send a transaction request to network element 1 to request obtaining the data to be accessed, where the data to be accessed can be requested to be accessed by a data consumer to network element 2.

[0118] It should be noted that in the embodiments of the present application, the function corresponding to network element 2 can be implemented by enhancing the data collection coordination function (DCCF). That is, network element 2 can be a network element with DCCF. Of course, in the embodiments of the present application, network element 2 can be a network element in a separate core network.

[0119] For ease of understanding, the network element 1 and the network element 2 in the embodiments of the present application are introduced below by taking the data plane collecting data for a terminal device as an example. It is assumed that the terminal device is a data source, the network element 1 is a DPR, and the network element 2 is a DPAC. In the process of the terminal device transacting with the data plane, the terminal device can send a transaction request to the DPAC, and the transaction request carries one or more of the following: data source ID (i.e., terminal device ID), data itself, and data description information. Correspondingly, the DPAC verifies the data source ID according to the transaction request sent by the terminal device. If the verification is passed, the DPAC can send the data source ID, the data itself, and the data description information to the DPR for storage. The data description information is used to describe the function of the data, or said to be used to describe the attribute or content of the data. For example, for the sensing data of the terminal device, the data description information of the data can be used to indicate that the data is the sensing data of the terminal device. For another example, for the location data of the terminal device, the data description information of the data can be used to indicate that the data is the location data of the terminal device. For another example, for the QoS data or session data of the terminal device, the data description information of the data can be used to indicate that the data is the QoS data or session data of the terminal device, and so on.

[0120] Referring back to FIG. 3 or FIG. 4, the network element 2 in the data plane can communicate with the control plane (CP) through a service interface. Taking the network element 2 as a DPAC as an example, the service interface can be denoted as Ndpac.

[0121] In some embodiments, the access network device can communicate with the network element in the core network directly based on a service-based interface of the access network device. In other words, the access network device can provide services to other network elements (e.g., network elements in the core network) directly and / or can invoke services provided by other network elements directly. Referring to FIG. 4, in Option 1 shown in FIG. 4, the access network device can communicate with the network element in the core network directly based on a service-based interface of the access network device.

[0122] In some embodiments, the access network device communicating with the network element in the core network directly based on a service-based interface of the access network device can also be referred to or replaced by at least one of the following: the access network device communicating with the network element in the core network directly based on a service-based N2 interface, the access network device communicating with the network element in the core network directly based on a distributed NAS-based interface.

[0123] In some embodiments, the terminal device can communicate with the network element in the core network directly based on a service-based interface of the terminal device. In other words, the terminal device can provide services to other network elements (e.g., network elements in the core network) directly and / or can invoke services provided by other network elements directly. Referring to FIG. 4, in Option 2 shown in FIG. 4, the terminal device can communicate with the network element in the core network directly based on a service-based interface of the terminal device.

[0124] In some embodiments, the service-based interface mentioned in the embodiments of the present application can also be referred to or replaced by a service-based architecture (SBA) interface.

[0125] In some scenarios, the data plane is a distributed architecture, which helps to support flexible and efficient data management. That is, the distributed data plane can include multiple network elements 1, and correspondingly, different network elements 1 can be associated with different or same network elements 2. At this time, the data source can access through selecting a data plane (or network element 2) that is closer, thereby reducing the transmission delay of data.

[0126] For ease of understanding, the operation logic of the smart contract in the embodiments of the present application is introduced below in combination with FIG. 6. Referring to FIG. 6, it is assumed that the network element 1 is DPR and the network element 2 is DPAC. If the DPAC sends a transaction request to the DPR, the DPR will send a parameter 1 associated with the transaction request to the DPSC, so that the DPSC determines whether the transaction request is valid. Correspondingly, the DPSC can determine whether the transaction request is valid based on a preconfigured condition, and outputs a parameter 2 to the DPR.

[0127] In some embodiments, the parameter 1 can include one or more of the following: identification information of the smart contract; information indicating that the transaction is requested based on the blockchain; the transaction request; the ledger state information; identification information associated with the transaction.

[0128] In some embodiments, the identification information of the smart contract can be, for example, an ID of the smart contract. In the embodiments of the present application, the manner of determining the identification information of the smart contract is not limited. For example, the DPR can determine the identification information of the smart contract based on the type of the transaction request.

[0129] In some embodiments, the parameter 1 includes information indicating that the transaction is requested based on the blockchain, that is, the parameter 1 can be used to indicate that the transaction corresponds to a data transaction based on the blockchain, where the data transaction can include, for example, data storage and / or data retrieval.

[0130] In some embodiments, the transaction request can include data description information of the data associated with the transaction request. The data associated with the transaction request can include, for example, data requested to be called by the transaction request and / or data requested to be stored by the transaction request.

[0131] In some embodiments, the DPR can provide the DPR with the ledger state information of the currently stored ledger, so that the DPSC can verify the validity of the data and achieve traceability of the data.

[0132] In some embodiments, the identification information associated with the transaction is used to indicate the data service associated with the transaction request, that is, the identification information can represent whether the transaction request sent by the DPR each time is for the same data service. In some scenarios, due to the request message capacity, the performance of the blockchain, and the like, the data associated with a data service can need to be executed in multiple transactions, and multiple transactions are associated with multiple transaction requests. At this time, the above-mentioned identification information can be used to indicate that the multiple transaction requests are for data of the same data service.

[0133] In some embodiments, the parameter 2 can include one or more of the following information: information indicating that the transaction is accepted or rejected; information indicating whether the transaction is valid; information indicating the reason why the transaction is invalid; updated ledger state.

[0134] In some embodiments, if the DPSC determines that the transaction is valid according to the internal logic, the parameter 2 includes information indicating that the transaction is accepted. Conversely, if the DPSC determines that the transaction is invalid according to the internal logic, the parameter 2 includes information indicating that the transaction is rejected.

[0135] In some implementations, if the DPSC determines that the transaction is valid according to the internal logic (e.g., the preconfigured condition described above), the parameter 2 includes information indicating that the transaction is valid. Conversely, if the DPSC determines that the transaction is invalid according to the internal logic, the parameter 2 includes information indicating that the transaction is invalid.

[0136] It should be noted that the information indicating acceptance or rejection of the transaction and the information indicating whether the transaction is valid can be indicated by the same information to reduce transmission overhead. Of course, in the embodiments of the present application, the information indicating acceptance or rejection of the transaction and the information indicating whether the transaction is valid can be independent information.

[0137] In some implementations, the parameter 2 can include information indicating the reason for invalidating the transaction, so that the user can confirm the reason for invalidating the transaction, thereby improving the user experience.

[0138] In some implementations, if the transaction is valid, the parameter 2 can include the updated ledger state, so that the DPR stores the updated ledger state.

[0139] For example, the transaction request in the parameter 1 carries data description information of the data 1, and the data description information indicates that the data 1 is a perception result of the terminal device. Accordingly, after receiving the parameter 1, the DPSC can know that the data 1 is a perception result of the terminal device based on the data description information. Then, the DPSC can determine whether the data 1 is valid within the valid time based on the preconfigured valid time of the perception result, i.e., whether the data 1 is valid. If the generation time of the data 1 exceeds the valid time, the DPSC determines that the data 1 is invalid. If the generation time of the data 1 does not exceed the valid time, the DPSC determines that the data 1 is valid.

[0140] For ease of understanding, the process of storing data based on the smart contract on the blockchain is described below in conjunction with FIG. 7. In the example of FIG. 7, the data source is a terminal device, and the terminal device requests to store data on the data plane. The method of FIG. 7 includes steps S701 to S715.

[0141] In step S701, the terminal device sends a data transaction request to the network element 2 (i.e., the DPAC).

[0142] In some embodiments, the data transaction request is used to store the data 1 of the terminal device on the data plane.

[0143] In some embodiments, the data transaction request can include one or more of the following: data 1 that needs to be stored, an identifier of the terminal device, a transaction type, and data description information of the data 1. The data 1 can include one or more of the following: application layer data of the terminal device, measurement result data of the terminal device based on configuration, location information of the terminal device, movement trajectory information of the terminal device, artificial intelligence (AI) data of the terminal device, perception data of the terminal device, and the like. The identifier of the terminal device can include, for example, a generic public subscription identifier (GPSI). The transaction type can indicate, for example, that the transaction is data storage.

[0144] At step S702, the network element 2 determines whether to authorize the transaction request of the terminal device according to the subscription information of the terminal device.

[0145] In some embodiments, the network element 2 can query the subscription information of the terminal device according to the identifier of the terminal device and the transaction type, to determine whether the terminal device has the permission to perform the transaction corresponding to the transaction type. If the terminal device has the permission, the network element 2 authorizes the transaction request of the terminal device and performs step S703. Conversely, if the terminal device does not have the permission, the network element 2 rejects the transaction request of the terminal device.

[0146] At step S703, the network element 2 sends a blockchain transaction request to the master DPRF (or master logical function 1). The blockchain transaction request corresponds to the data transaction request in step S701.

[0147] In some embodiments, the blockchain transaction request includes one or more of the following: an identifier of the data source (i.e., the identifier of the terminal device); an identifier associated with the transaction, data description information of the data 1, and the data 1.

[0148] In some embodiments, the master DPRF is a node that can directly communicate with the network element 2. The network element 2 can determine the master DPRF based on configuration, for example, the network element 2 can determine the DPRF directly connected to the network element 2 as the master DPRF based on configuration.

[0149] At step S704, the master DPRF determines a DPSC (or logical function 2) that matches the blockchain transaction request according to the blockchain transaction request.

[0150] At step S705, the master DPRF sends a call request to the DPSC to request to call the DPSC.

[0151] In some implementations, the invocation request can include the parameter 1 introduced above, and accordingly, the DPSC can determine whether the transaction of the data 1 is valid based on the parameter 1. For example, the DPSC determines that the data 1 is a sensing result of the terminal device according to the data description information in the parameter 1. Then, the DPSC can determine whether the data 1 is valid based on the valid time of the configured sensing result and the generation time of the data 1. If the data 1 is out of the valid time, the DPSC determines that the data 1 is invalid, and thus rejects to store the data 1. Then, the DPSC returns the indication information that the transaction is invalid to the main DPRF. Conversely, if the data 1 is within the valid time, the DPSC determines that the data 1 is valid, and executes step S706.

[0152] In step S706, the DPSC returns the transaction verification result and the ledger update status to the main DPRF.

[0153] In step S707, the main DPRF sends a request for verifying the consistency of the data 1 to the peer DPRF according to the consensus mechanism.

[0154] In some embodiments, step S707 is executed in the case that the DPSC returns that the transaction is valid.

[0155] In some embodiments, the main DPRF and the peer DPRF belong to the same blockchain, and the peer DPRF can be a DPRF other than the main DPRF in the blockchain.

[0156] In step S708, the peer DPRF invokes the DPSC to perform the consistency check on the data 1.

[0157] In step S709, the peer DPRF sends the consistency verification result to the main DPRF.

[0158] In step S710, the main DPRF confirms whether to perform the transaction of the data 1 according to the consistency verification result.

[0159] In some embodiments, if the consistency check on the data 1 passes, the main DPRF confirms the transaction of the data 1. For example, the main DPRF updates the ledger state associated with the data 1, and creates a new block to store the data 1 and the transaction information associated with the data 1.

[0160] In step S711, the main DPRF broadcasts the ledger state associated with the data 1 to the peer DPRF.

[0161] In step S712, the peer DPRF updates the locally stored ledger state based on the ledger state associated with the data 1 broadcast by the main DPRF.

[0162] In step S713, the peer DPRF returns response information to the main DPRF to indicate whether the update of the ledger state associated with the data 1 is successful.

[0163] At step S714, the master DPRF sends response information for the blockchain transaction request to the network element 2, and the response information is used to indicate that the transaction is completed.

[0164] At step S715, the network element 2 sends response information for the transaction request to the terminal device, and the response information is used to indicate that the transaction is completed.

[0165] As can be seen from the foregoing description, when the data operation (or data service) based on the data plane is performed through the network element 2 at present, there are still some problems. For example, the device (such as the terminal device) related to the generation of the data 1 has no control over the operation of the data 1 on the data plane, which may cause security problems (such as privacy leakage) when other data sources (such as network elements and AFs in the core network) operate the data 1 on the data plane. For another example, the data operation on the data plane is currently based on the DPSC to determine whether the data transaction is valid, but the protocol does not specify what data processing principles should be included in the DPSC and how to configure these principles. For another example, there is no relevant provision for how the terminal device interacts with the network element 2.

[0166] To solve the above problems, the present application provides embodiment 1 and embodiment 2. Among them, embodiment 1 aims to ensure that the device related to the generation of the data can control the operation of the data on the data plane, and which principles can be configured in the DPSC to determine whether the transaction is valid. Embodiment 2 aims to introduce how the terminal device accesses the data plane.

[0167] It should be noted that the embodiment 1 and embodiment 2 introduced below can be used alone or in combination. For example, the first network element can use the structure of embodiment 2 to interact with the network element of the data plane, and the specific interaction mode can be referred to embodiment 1.

[0168] The embodiment 1 and embodiment 2 will be introduced respectively as follows.

[0169] Embodiment 1:

[0170] In embodiment 1, when the first data related to the first network element is operated on the data plane, the second network element can determine the operation authority of the first data based on the message (i.e., the first message below) sent by the first network element. In this way, the first network element can control the operation authority of the first data, thereby facilitating to avoid data privacy leakage and improving the security of the data.

[0171] Embodiment 1 will be introduced below in combination with FIG. 8. FIG. 8 is a flow diagram of a communication method according to an embodiment of the present application. The method shown in FIG. 8 includes step S810.

[0172] At step S810, the first network element sends a first message to the second network element. The first message is used to determine the operation permission of the first data.

[0173] In embodiments of the present application, the first data comprises relevant data of the first network element. For example, the first data is generated in relation to the first network element. As an example, the first data comprises data generated by the first network element, or in other words, the first network element is the generator of the first data.

[0174] Embodiments of the present application do not make specific limitations on the first network element. Illustratively, the first network element can comprise one of the following: a terminal device, an access network device, a network element in a core network, an application device, etc.

[0175] Embodiments of the present application do not make specific limitations on the application device. Illustratively, the application device can comprise one or more of the following: an application server, an AF, a third-party application, a third-party server, etc.

[0176] In embodiments of the present application, the second network element can be used to provide data operation functions (or data service functions) in the data plane. In some embodiments, the second network element can be the network element 1 (e.g., DPR) mentioned above. For the introduction of the network element 1, please refer to the above.

[0177] In some embodiments, the second network element used to provide data operation functions in the data plane can mean that the second network element is used to operate data in the data plane. Embodiments of the present application do not make specific limitations on the data operation functions provided by the second network element. Illustratively, the data operation functions provided by the second network element can comprise one or more of the following: data storage, data retrieval, data sharing, data collection, data processing (such as preprocessing), data opening, data verification, etc.

[0178] In some embodiments, the second network element can be located in a blockchain. Or in other words, the second network element is a node in the blockchain.

[0179] In embodiments of the present application, the operation permission of the first data can comprise a plurality of types, for example, there is a corresponding operation permission for any operation performed on the first data. Illustratively, the operation permission of the first data can comprise one or more of the following: storage permission of the first data, retrieval permission of the first data, sharing permission of the first data, collection permission of the first data, processing (such as preprocessing) permission of the first data, opening permission of the first data, verification permission of the first data, etc.

[0180] In some embodiments, the operation permission of the first data can be determined based on the first data. For example, the first data comprises sensing data (or sensing metadata, sensing raw data) of the first network element, and the operation permission of the first data can be determined based on the sensing data.

[0181] In some embodiments, the operation permission of the first data can be determined based on the data description information of the first data. For example, the first data comprises the data description information of the perception data, and the operation permission of the first data can be determined based on the data description information of the perception data.

[0182] In some embodiments, the operation permission of the first data can be determined based on the first data and the data description information of the first data.

[0183] In the embodiments of the present application, the second network element can determine the operation permission of the first data according to the first message, for example, determine the operation permission of the first data by the data source.

[0184] In some embodiments, the first message can be used to indicate one or more of the following: whether the first data can be operated, operations that can be performed on the first data, operations that cannot be performed on the first data, allowed data sources, disallowed data sources, allowed data consumers, disallowed data consumers, operations that can be performed on the first data after the data consumer retrieves the first data, operations that cannot be performed on the first data after the data consumer retrieves the first data, time limit for operating the first data, whether the first data needs to be preprocessed before operating the first data, and whether the first network element needs to be notified of the operation performed on the first data.

[0185] Taking the first data comprising the location information of the first network element as an example, whether the first data can be operated can refer to whether the location information of the first network element can be operated, such as whether the location information of the first network element can be stored, whether the location information of the first network element can be retrieved, and the like.

[0186] The operations that can be performed on the first data can be used to indicate which operations can be performed on the first data, or in other words, which types of data can be operated. Taking the first data comprising the perception information (the perception information can comprise perception data and / or perception result) of the first network element as an example, the operations that can be performed on the first data can indicate that the perception data of the first network element can be operated, or the perception result of the first network element can be operated, and the like.

[0187] The operations that cannot be performed on the first data can be used to indicate which operations cannot be performed on the first data, or in other words, which types of data cannot be operated. Still taking the first data comprising the perception information of the first network element as an example, the operations that cannot be performed on the first data can indicate that the perception data of the first network element cannot be operated, or the perception result of the first network element cannot be operated, and the like.

[0188] In some embodiments, the first message can indicate operations that can be performed on the first data and operations that cannot be performed on the first data at the same time. Taking the example that the first data includes perception information of the first network element, the first message can indicate that the perception result of the first network element can be operated, but the perception data of the first network element cannot be operated, in other words, the first message can indicate that the first network element only agrees to operate the perception result in the data plane.

[0189] The allowed data source can be used to indicate which data source can operate on the first data. Taking the example of storing the first data, the allowed data source can be used to indicate which data source can store the first data.

[0190] The disallowed data source can be used to indicate which data source cannot operate on the first data. Taking the example of storing the first data, the disallowed data source can be used to indicate which data source cannot store the first data.

[0191] The allowed data consumer can be used to indicate which data consumer can operate on the first data. Taking the example of calling the first data, the allowed data consumer can be used to indicate which data consumer can call the first data.

[0192] The disallowed data consumer can be used to indicate which data consumer cannot operate on the first data. Taking the example of calling the first data, the disallowed data consumer can be used to indicate which data consumer cannot call the first data.

[0193] The operation that the data consumer can perform on the first data after calling the first data can be used to indicate the operation that the data consumer can perform on the first data after calling the first data. For example, the data consumer can use the first data to perform AI model training, generate perception results, etc. after calling the first data.

[0194] The operation that the data consumer cannot perform on the first data after calling the first data can be used to indicate the operation that the data consumer cannot perform on the first data after calling the first data. For example, the data consumer cannot use the first data to perform AI model training, generate perception results, etc. after calling the first data.

[0195] The time limit for operating on the first data means that the first data can be operated within the time limit, otherwise the first data cannot be operated. This is because, considering that some data (such as information of an AI model on the side of the first network element, location information of the first network element, etc.) is not updated for a period of time, it can be considered that the data is invalid and cannot be authenticated. Taking the example of data storage, the data source can provide a timestamp of collecting the first data when storing the first data, so as to determine whether the data source stores the first data within the storage time limit of the first data according to the timestamp.

[0196] In some embodiments, the purpose of the preprocessing of the first data can comprise at least one of the following: reducing signaling overhead, improving security of data transmission. The preprocessing of the first data by the embodiments of the present application is not specifically limited, and exemplary preprocessing can comprise one or more of the following: compression processing, normalization processing, anonymization processing, and the like.

[0197] In some embodiments, whether the operation performed on the first data needs to be notified to the first network element means whether the first network element needs to be notified when any processing is performed on the first data. For example, whether the first network element needs to be notified when the first data is stored (e.g., the first data is stored is notified). Or, whether the first network element needs to be notified when the first data is invoked (e.g., the first data is invoked is notified).

[0198] Taking the operation permission of the first data as an example, the first message can be used to indicate one or more of the following: whether the first data can be stored, the first data that can be stored (or the type of the first data that can be stored), the first data that cannot be stored (or the type of the first data that cannot be stored), which data sources are allowed to store the first data, which data sources are not allowed to store the first data, the time limit for the data sources to store the first data, whether the first data needs to be preprocessed before the data sources store the first data, whether the first network element needs to be notified when the data sources store the first data.

[0199] Taking the operation permission of the first data as an example, the first message can be used to indicate one or more of the following: whether the first data can be stored, the first data that can be stored (or the type of the first data that can be stored), the first data that cannot be stored (or the type of the first data that cannot be stored), which data sources are allowed to store the first data, which data sources are not allowed to store the first data, the time limit for the data sources to store the first data, whether the first data needs to be preprocessed before the data sources store the first data, whether the first network element needs to be notified when the data sources store the first data.

[0200] The first message is described in detail below.

[0201] In some embodiments, the first message used to determine the operation permission of the first data can mean that the first message is used to configure the operation permission of the first data. In some embodiments, the first message used to determine the operation permission of the first data can mean that the first message is used to indicate the operation permission of the first data. This is described in detail below in combination with Embodiment 1.1 and Embodiment 1.2.

[0202] Embodiment 1.1: The first message is used to configure the operation permission of the first data

[0203] In some embodiments, embodiment 1.1 can be understood as a way for the first network element to indirectly participate in the operation control of the first data.

[0204] In some embodiments, the first network element can send the data operation policy (or data control policy, data processing policy, etc.) to the second network element through the first message in a manner of policy configuration. In this way, when other data sources (i.e., network elements requesting to operate the first data) request to operate the first data, the second network element can determine the operation permission of the other data sources on the first data according to the configured data operation policy.

[0205] In some embodiments, the first message can include first configuration information, which is used to configure the operation permission on the first data.

[0206] In some embodiments, the first configuration information can be understood or replaced by the data operation policy, or the first configuration information can be used to configure the data operation policy. That is, in some embodiments, the first message can carry the data operation policy of the data plane, and the first network element can configure the data operation policy of the data plane to the second network element through the first message.

[0207] In some embodiments, the first message can be used to configure the data operation policy corresponding to one or more data sources. That is, one or more data sources can share the data operation policy of the data plane, for example, a first network element (such as the first network element A) can configure a data operation policy to the second network element, and when other operation requesters need to operate the data of the first network element A, the second network element can determine the operation permission on the data by using the data operation policy of the first network element A. Of course, the embodiments of the present application are not limited thereto, and one first network element can configure multiple data operation policies to the second network element, and the second network element can determine the operation permission on the data by using part or all of the multiple data operation policies.

[0208] In some embodiments, the first configuration information can be associated with one or more of the following: the type of data to be operated, the data source, the data consumer, the operation time limit of the data, and the operation notification of the data. In other words, the first configuration information can be used to configure one or more of the above, or the first configuration information is determined according to one or more of the above.

[0209] The embodiments of the present application do not limit the type of data to be operated, for example, the type of data to be operated can include one or more of the following: the location information of the first network element, the perception information of the first network element, the QoS information of the first network element, the session information of the first network element, etc. In some embodiments, the type of data to be operated can also have a finer granularity of division, such as the type of data to be operated can include the perception data of the first network element, the perception result of the first network element, etc.

[0210] The operation time limit of data can be used to indicate a time limit for operating the first data. Within the operation time limit of data, the data source can operate the first data. If the operation time limit of data is exceeded, the data source cannot operate the first data.

[0211] The operation notification of data can be used to indicate whether notification of the first network element is required when operating the first data.

[0212] In some embodiments, the first configuration information can be used to indicate one or more of the following: operations that can be performed on the first data, operations that cannot be performed on the first data, allowed data sources, disallowed data sources, allowed data consumers, disallowed data consumers, operations that can be performed on the first data after the data consumer retrieves the first data, a time limit for operating the first data, whether preprocessing of the first data is required before operating the first data, and whether notification of the first network element is required for the operation of the first data.

[0213] Embodiments of the present application do not limit the configuration granularity of the first configuration information. For example, the first configuration information can be configured for different data types. That is, the first network element can send multiple first configuration information to the second network element, and different first configuration information is used to configure different data types. For example, one first configuration information is used to configure the location information of the first network element, another first configuration information is used to configure the sensing information of the first network element, and another first configuration information is used to configure the QoS information of the first network element. However, embodiments of the present application are not limited thereto, for example, different data types can share one first configuration information. Alternatively, all data of the first network element share one first configuration information, and the like.

[0214] In some embodiments, after the second network element receives the first configuration information, the second network element can record the first configuration information in the DPSC of the second network element. In some embodiments, if the first configuration information is recorded in the DPSC of the second network element, it can be considered that the data operation strategy corresponding to the first configuration information has been configured in the second network element.

[0215] For ease of understanding, an example of the first configuration information is given below in conjunction with Table 1.

[0216] Table 1

[0217] In the example of Table 1, the first configuration information is configured for different data description information, wherein different data description information can be used to indicate different data types. For one data description information, one or more of the data operation strategies shown in Table 1 can be configured.

[0218] Embodiment 1.2: The first message is used to indicate the operation permission of the first data

[0219] In some embodiments, embodiment 1.2 can be understood as a way that the first network element directly participates in the operation control of the first data.

[0220] In some embodiments, when any one of the data sources requests to operate the first data, the second network element can request the first network element to indicate the operation permission of the data source to the first data. In this case, the first network element can indicate the operation permission of the data source to the first data through the first message.

[0221] In some embodiments, the second network element requests the first network element to indicate the operation permission of the data source to the first data is determined according to one or more of the following: the DPSC in the second network element, the identifier of the first network element, the data description information of the first data, and the first data.

[0222] In some embodiments, the first message can include first indication information, and the first indication information is used to indicate the operation permission of the first data.

[0223] In some embodiments, the first indication information can be used to indicate one or more of the following: whether the first data can be operated, the operations that can be performed on the first data, and the operations that cannot be performed on the first data.

[0224] As an example, the data source requests to store the location information of the first network element in the data plane, and the first network element does not want to store the location information in the data plane. In this case, the first network element can indicate that the first data cannot be stored through the first indication information.

[0225] As another example, the data source requests to store the perception information of the first network element in the data plane. The first network element can determine whether the stored data is perception data or only perception result. If the perception data needs to be stored, the first network element can indicate that the perception data cannot be stored. If the perception result needs to be stored, the first network element can indicate that the perception result can be stored. Alternatively, when the data source requests to store the perception information of the first network element in the data plane, the first network element can indicate through the first indication information that only the perception result can be stored.

[0226] In some embodiments, in addition to the first configuration information and / or the first indication information described above, the first message can also include other information. For example, the first message can also include one or more of the following: the identifier of the first network element, the data description information of the first data, the first data, and the identifier of the data source of the first data.

[0227] As an example, the first message may include: first configuration information, the identifier of the first network element, the data description information of the first data, and the identifier of the data source of the first data.

[0228] As another example, the first message may include: first configuration information, the identifier of the first network element, first data, and the identifier of the data source of the first data.

[0229] As another example, the first message may include: first instruction information, the identifier of the first network element, the data description information of the first data, and the identifier of the data source of the first data.

[0230] As another example, the first message may include: first instruction information, the identifier of the first network element, first data, and the identifier of the data source of the first data.

[0231] As another example, the first message may include: first instruction information, the identifier of the first network element, the data description information of the first data, the first data, and the identifier of the data source of the first data.

[0232] Of course, the information contained in the first message can be combined in other ways, but for the sake of brevity, we will not go into detail here.

[0233] The interaction process of the embodiments of this application is described below.

[0234] Referring again to Figure 8, in some embodiments, the method shown in Figure 8 may further include step S805. In step S805, the second network element sends a second message to the first network element. The second message is used to request the first network element to determine its operation permission for the first data.

[0235] For example, in Embodiment 1.2, when the data source requests to operate on the first data, the second network element can send a second message to the first network element. As another example, in Embodiment 1.1, the second network element can send a second message to the first network element to request the first network element to configure operation permissions for the first data. However, the embodiments of this application are not limited to these. For example, in Embodiment 1.1, if no request is received from the second network element, the first network element can proactively configure operation permissions for the first data.

[0236] In some embodiments, the second message may include one or more of the following: the identifier of the first network element (i.e., the identifier of the first network element), data description information of the first data, the first data, the identifier of the data source of the first data, and second indication information. The second indication information is used to request the first network element to determine its operation permissions for the first data.

[0237] As an example, the second message can not contain (not carry) the first data. This is because the first data itself is relatively large, and occupies relatively large air interface resources and core network resources. In some embodiments, in the case that the second message does not contain the first data, the first network element can determine the operation permission of the first data according to the data description information of the first data.

[0238] As an example, the second message can contain the first data. In this case, the first network element can perform more accurate operation permission control according to the first data. Taking the case that the first data includes location information of the first network element as an example, the first network element can determine whether the location information in the first data is inaccurate or too accurate according to the location information in the first data and the current location information of the first network element, and then determine the operation permission of the first data according to the determination result. For example, the first network element can indicate that the data source cannot operate the first data in the first message because the location information is inaccurate or too accurate.

[0239] As an example, the second message can include the identifier of the first network element, the data description information of the first data, the identifier of the data source of the first data, and the second indication information.

[0240] As an example, the second message can include the identifier of the first network element, the first data, the identifier of the data source of the first data, and the second indication information.

[0241] As an example, the second message can include the identifier of the first network element, the data description information of the first data, the first data, the identifier of the data source of the first data, and the second indication information.

[0242] As an example, the second message can include the data description information of the first data, the identifier of the data source of the first data, and the second indication information.

[0243] As an example, the second message can include the first data, the identifier of the data source of the first data, and the second indication information.

[0244] In some embodiments, the message between the first network element and the second network element is sent and / or received through a third network element. In other words, the message between the first network element and the second network element is forwarded through the third network element. For example, the first message is sent and / or received through the third network element. For another example, the second message is sent and / or received through the third network element.

[0245] In some embodiments, the third network element is used to manage or control the first network element to access the data plane. For example, the third network element can be the network element 2 mentioned above. For the related description of the network element 2, please refer to the above.

[0246] In some embodiments, the message between the first network element and the third network element can be sent and / or received in different ways. For example, the message between the first network element and the third network element can be sent and / or received in different ways, or in other words, the first network element and the third network element can communicate in different connection modes, when the communication system architecture is different. Several ways are exemplarily introduced below.

[0247] In some embodiments, the message sent by the first network element to the third network element is sent by the first network element calling the service of the third network element.

[0248] In some embodiments, the message sent by the third network element to the first network element is sent by the third network element calling the service of the first network element.

[0249] Taking the first network element as a terminal device for example, the terminal device can directly call the service of the third network element to send a message to the third network element, and the third network element can directly call the service of the terminal device to send a message to the terminal device. In other words, the terminal device can communicate with the third network element based on the service interface of the terminal device, or the terminal device can provide services through the service interface. For example, in the communication system (such as a 6G system) shown in FIG. 4, if the connection mode of option 2 is adopted, the terminal device can directly call the service of the third network element to send a message to the third network element, and the third network element can directly call the service of the terminal device to send a message to the terminal device.

[0250] As an implementation manner, the terminal device can have the first module mentioned in Embodiment 2 below to provide related services of the control plane through the first module.

[0251] Taking the first network element as an access network device for example, the access network device can directly call the service of the third network element to send a message to the third network element, and the third network element can directly call the service of the access network device to send a message to the access network device. For example, in the communication system shown in FIG. 4, if the connection mode of option 1 or option 2 is adopted, the access network device can directly call the service of the third network element to send a message to the third network element, and the third network element can directly call the service of the access network device to send a message to the access network device.

[0252] Taking the first network element as a network element in a core network for example, the network element in the core network can directly call the service of the third network element to send a message to the third network element, and the third network element can directly call the service of the network element in the core network to send a message to the network element in the core network. For example, in the communication systems shown in FIG. 3 and FIG. 4, the network element in the core network can directly call the service of the third network element to send a message to the third network element, and the third network element can directly call the service of the network element in the core network to send a message to the network element in the core network.

[0253] Taking the first network element as an application device (such as an AF) for example, the application device can directly invoke or invoke the service of the third network element through the NEF to send a message to the third network element, and the third network element can directly invoke or invoke the service of the application device through the NEF to send a message to the application device. For example, in the communication system shown in FIG. 3 and FIG. 4, the application device can directly invoke the service of the third network element to send a message to the third network element, and the third network element can directly invoke the service of the application device to send a message to the application device.

[0254] In some embodiments, the message sent by the first network element to the third network element is sent by the first network element to the access network device through an access layer message (such as an RRC message), and then the access network device invokes the service of the third network element to send to the third network element.

[0255] In some embodiments, the message sent by the third network element to the first network element is sent by the third network element to the access network device, and then the access network device sends it to the first network element through an access layer message.

[0256] Taking the first network element as a terminal device for example, the terminal device can send a message to the access network device through an access layer message, and then the access network device sends the message to the third network element by directly invoking the service of the third network element; and / or, the third network element can directly invoke the service of the access network device to send a message to the access network device, and then the access network device sends the message to the terminal device through an access layer message.

[0257] That is, in some embodiments, the terminal device can communicate with the third network element based on a distributed NAS interface. For example, in the communication system shown in FIG. 4, if the connection mode of option 1 is adopted, the access network device can provide services in the form of a service interface. In this scenario, the terminal device can send a message to the access network device through an access layer message, and then the access network device sends the message to the third network element by directly invoking the service of the third network element; and / or, the third network element can directly invoke the service of the access network device to send a message to the access network device, and then the access network device sends the message to the terminal device through an access layer message.

[0258] As an implementation, the terminal device can support different NAS types, and different types of messages sent by the terminal device to the access network device can be carried in different NAS containers. Then, the access network device can call the service interface provided by the corresponding network element according to the type of the NAS container carrying the message to send the message. Taking the terminal device sending a message to the third network element as an example, the terminal device can carry the message in the first NAS container of the access layer message, that is, the message is sent to the data plane. Then, the access network device can call the service interface of the third network element according to the first NAS container to send the message of the terminal device. Similarly, when the third network element wants to send a message to the terminal device, it can call the service provided by the access network device to send the message to the access network device, and then the access network device carries the message in the first NAS container of the access layer message and sends it to the terminal device.

[0259] That is, in some embodiments, the messages transmitted (received and / or sent) between the first network element and the third network element are carried in the first NAS container of the access layer message. The first NAS container is used to carry the NAS message sent to the data plane. For example, the first network element can send a message to the access network device through the first NAS container in the access layer message, and then the access network device sends the message to the third network element by calling the service of the third network element. For another example, the third network element can send a message to the access network device by calling the service of the access network device, and then the access network device carries the message in the first NAS container of the access layer and sends it to the first network element.

[0260] In some embodiments, different NAS containers can be included in the access layer message. For example, the access layer message can include the first NAS container described above, and other NAS containers in addition to the first NAS container.

[0261] In some embodiments, different NAS containers included in the access layer message are used to carry different types of NAS messages. Alternatively, different NAS containers included in the access layer message are used to carry NAS messages sent to different objects (such as different network elements). As an example, messages sent to AMF, SMF, PCF, and the third network element are carried in different NAS containers.

[0262] In some embodiments, the messages between the first network element and the third network element are received and / or sent through the control plane.

[0263] In some embodiments, the message sent by the first network element to the third network element is sent by the AMF to the third network element by calling the service of the third network element after the first network element sends the NAS message to the AMF.

[0264] In some embodiments, the message sent by the third network element to the first network element is the message sent by the third network element to the AMF after the third network element invokes a service of the AMF, and sent by the AMF to the first network element through a NAS message.

[0265] Taking the first network element as a terminal device for example, the terminal device can send a message to the AMF through a NAS message (or in other words, through an N1 interface), and then the AMF sends the message to the third network element by directly invoking a service of the third network element; and / or, the third network element can send a message to the AMF by invoking a service of the AMF, and then the AMF sends the message to the terminal device through a NAS message. That is, in some embodiments, the terminal device can communicate with the third network element based on the service-oriented architecture of 5G. For example, in the communication system shown in FIG. 1, FIG. 3, the terminal device can send a message to the AMF through a NAS message, and then the AMF sends the message to the third network element by directly invoking a service of the third network element; and / or, the third network element can send a message to the AMF by invoking a service of the AMF, and then the AMF sends the message to the terminal device through a NAS message.

[0266] Taking the first network element as an access network device for example, the access network device can send a message to the AMF through a next generation application protocol (NGAP) message, and then the AMF sends the message to the third network element by directly invoking a service of the third network element; and / or, the third network element can send a message to the AMF by invoking a service of the AMF, and then the AMF sends the message to the access network device through an NGAP message. For example, in the communication system shown in FIG. 1, FIG. 3, the access network device can send a message to the AMF through an NGAP message, and then the AMF sends the message to the third network element by directly invoking a service of the third network element; and / or, the third network element can send a message to the AMF by invoking a service of the AMF, and then the AMF sends the message to the access network device through an NGAP message. In some embodiments, the access network device sending a message to the AMF through an NGAP message can also be understood or replaced as the access network device sending a message to the AMF through an N2 interface.

[0267] In some embodiments, the message between the first network element and the third network element is received and / or sent through a user plane.

[0268] In some embodiments, the message sent by the first network element to the third network element is the message sent by the first network element to the UPF, and sent by the UPF to the third network element according to the address of the third network element.

[0269] In some embodiments, the message sent by the third network element to the first network element is the message sent by the third network element to the UPF, and sent by the UPF to the first network element according to the address of the first network element.

[0270] Taking the first network element as a terminal device for example, the terminal device can send a message to the UPF, and then the UPF sends the message to the third network element according to the address of the third network element; and / or, the third network element can send a message to the UPF, and then the UPF sends the message to the terminal device according to the address of the terminal device.

[0271] Taking the first network element as an access network device for example, the access network device can send a message to the UPF, and then the UPF sends the message to the third network element according to the address of the third network element; and / or, the third network element can send a message to the UPF, and then the UPF sends the message to the access network device according to the address of the access network device.

[0272] The implementation of the address is not limited in the embodiments of the present application. For example, the address mentioned in the embodiments of the present application can be an IP address, or can be a fully qualified domain name (FQDN).

[0273] In some embodiments, the address of the first network element can be sent by the core network to the third network element. In some embodiments, the address of the third network element can be sent by the core network to the first network element.

[0274] In some embodiments, when the first network element or the third network element sends a message to the UPF, the receiving address of the message can be carried. For example, when the first network element sends a message to the UPF, the address of the third network element can be carried. For example, when the third network element sends a message to the UPF, the address of the first network element can be carried.

[0275] In some embodiments, the third network element knows the data sources and / or devices related to data generation that can access the data plane, that is, the third network element knows which data sources and / or devices related to data generation can access the data plane. As an implementation, the data sources and / or devices related to data generation can register with the third network element, and the data sources and / or devices related to data generation that complete the registration can access the data plane.

[0276] In some embodiments, when the third network element forwards the data source or the message of the first network element to the second network element, it can verify whether the data source or the first network element can access the data plane. In the case that the data source or the first network element can access the data plane, the third network element forwards the data source or the message of the first network element to the second network element.

[0277] As an implementation, the third network element can verify whether the data source (or the first network element) can access the data plane according to the identifier of the data source (or the first network element).

[0278] In some embodiments, the operation on the first data is requested by the fourth network element, that is, the data source mentioned above is the fourth network element.

[0279] The fourth network element is not specifically limited in the present application. For example, the fourth network element can include one of the following: a terminal device, an access network device, a network element in a core network, an application device, and a network management device. In some embodiments, the network management device can include an operations, administration, and maintenance (OAM) device, for example.

[0280] In some embodiments, the fourth network element can carry one or more types of information when requesting an operation on the first data. The present application does not limit the information carried by the fourth network element when requesting an operation on the first data. For example, the fourth network element can carry one or more of the following information: an identifier of the fourth network element, the first data, data description information of the first data, an identifier of the first network element, and a first parameter.

[0281] The first parameter can be used to indicate the operation requested by the fourth network element. For example, the first parameter can be used to indicate that the fourth network element requests one or more of the following: data storage, data retrieval, data sharing, data collection, data processing (such as preprocessing), data opening, data verification, and the like.

[0282] In some embodiments, the request sent by the fourth network element can not contain the first data. In the case where the request sent by the fourth network element does not contain the first data, the first network element and the second network element can determine the operation authority on the first data according to the data description information of the first data.

[0283] In some embodiments, in the case where the request sent by the fourth network element does not contain the first data, if the first network element or the second network element determines that the fourth network element has the operation authority on the first data, the fourth network element can request an operation on the first data again, and this time the request contains the first data. For example, the fourth network element can not carry the first data when sending a storage request to the second network element for the first time, and then the fourth network element can send a storage request to the second network element again after determining that it has the storage authority, and this time the storage request carries the first data. The advantage of this approach is that if the first data requested by the fourth network element to operate has existed on the data plane before, or if the first network element (or the second network element) determines that the fourth network element cannot operate the first data, the request sent by the fourth network element does not carry the first data, which is beneficial to avoid wasting air interface resources and core network resources.

[0284] In some embodiments, the request sent by the fourth network element can contain the first data. In this case, the first network element and the second network element can perform more accurate operation authority control according to the first data.

[0285] For ease of understanding, the following takes the fourth network element (data source) requesting to store the data of the first network element as an example to give several examples of embodiment 1. It should be noted that the following examples take the first network element as a terminal device and the fourth network element as an NF as an example for introduction.

[0286] Example 1: The first network element indicates the operation permission of the first data based on the distributed NAS interface

[0287] In example 1, the first network element directly participates in the data operation of the data plane through the distributed NAS interface, which is beneficial to the direct control of the first network element on the related processing of the first network element. In the scheme of example 1, when the first network element interacts with the access network device, a new NAS message type (i.e. the message type carried by the first NAS container mentioned above) needs to be added.

[0288] In example 1, when the fourth network element wants to store the first data to the data plane, the first network element indicates the operation permission of the first data. Only when the fourth network element has the related storage permission of the first data, the first data can be stored correspondingly.

[0289] The following introduces the flow of example 1 in combination with FIG. 9.

[0290] FIG. 9 is a flowchart of a communication method provided by another embodiment of the present application. The method shown in FIG. 9 includes steps S901 to S912.

[0291] In step S901, the fourth network element sends a request to the third network element to request to store the first data of the first network element to the data plane. For example, the fourth network element can send a request (such as Ndpac_MetaTrans_create / update request) to the third network element to request to store the first data to the data plane.

[0292] In some embodiments, the request includes one or more of the following: the identifier of the fourth network element, the first data, the data description information of the first data, and the identifier of the first network element.

[0293] In step S902, the third network element sends a request to the second network element to request to store the first data to the data plane. For example, the third network element can send a request (such as Ndpr_DataStorage_request) to the second network element to request to store the first data to the data plane after the third network element verifies.

[0294] In some embodiments, the request sent by the third network element to the second network element can carry the information carried in the request of step S901.

[0295] In step S903, the second network element sends an Ndpac_DataConsensus_request message to the third network element. The message is used to request the first network element to determine the operation authority of the fourth network element on the first data.

[0296] In some embodiments, the second network element determines that the operation authority of the fourth network element on the first data needs to be determined by the first network element according to one or more of the data description information of the first data, the identity of the first network element, and the DPSC in the second network element. In this case, the second network element can send the Ndpac_DataConsensus_request message to the third network element.

[0297] In some embodiments, the Ndpac_DataConsensus_request message can include one or more of the following information: the identity of the first network element, the data description information of the first data, the first data, the identity of the data source of the first data (i.e. the identity of the fourth network element), and the second indication information.

[0298] In step S904, the third network element invokes the service of the access network device, and sends an Nran_DataConsensus_request message to the access network device to request the first network element to determine the operation authority of the fourth network element on the first data.

[0299] In some embodiments, the Nran_DataConsensus_request message carries the information carried in the Ndpac_DataConsensus_request message in step S903.

[0300] In step S905, the access network device requests the first network element to determine the operation authority of the fourth network element on the first data through an access layer message.

[0301] In some embodiments, the access layer message includes a first NAS container, and the first NAS container carries the message sent by the data plane to the first network element. For example, the first NAS container carries the information carried in the Ndpac_DataConsensus_request message in step S903.

[0302] In step S906, the first network element determines the operation authority of the fourth network element on the first data.

[0303] In some embodiments, the first network element can determine the operation authority of the fourth network element on the first data according to the first data. In some embodiments, the first network element can determine the operation authority of the fourth network element on the first data according to the data description information of the first data.

[0304] For example, according to the received information, the first network element learns that the fourth network element wants to store the location information of the first network element to the data plane, and the first network element does not want to store its own location information to the data plane, and then the first network element can determine that the fourth network element does not have the storage right for the first data.

[0305] For another example, according to the received information, the first network element learns that the fourth network element wants to store the perception information of the first network element to the data plane. In this case, the first network element judges whether the first data to be stored is perception data (perception element data) or only perception result. If it is perception data, the first network element can determine that the fourth network element does not have the storage right for the first data; if it is only perception result, the first network element can determine that the fourth network element has the storage right for the first data. In some embodiments, in the case that the first network element cannot judge whether the first data to be stored is perception data or only perception result (for example, the second network element does not send the first data to the first network element), the first network element can return to the second network element an indication that only agrees to store the perception result to the data plane.

[0306] In step S907, the first network element sends an access layer message to the access network device, and the access layer message includes the first indication information.

[0307] In some embodiments, the access layer message includes a first NAS container, and the first NAS container carries the message sent to the data plane.

[0308] In some embodiments, the access layer message includes one or more of the following: the identifier of the first network element, the data description information of the first data, the first data, the identifier of the data source (i.e. the fourth network element) of the first data, and the first indication information.

[0309] In step S908, the access network device sends an Nran_DataConsensus_response message to the third network element to send the first indication information to the third network element.

[0310] In step S909, the third network element sends an Ndpac_DataConsensus_response message to the second network element to send the first indication information to the second network element.

[0311] In some embodiments, if the first indication information indicates that the fourth network element does not have the storage right, the second network element returns a data storage failure to the fourth network element. Otherwise, the second network element performs steps S910 to S912.

[0312] In step S910, the second network element initiates a consensus authentication.

[0313] For example, the second network element can initiate a consensus authentication based on the second network element, or in other words, initiate a consensus authentication based on the blockchain. In the case where it is ensured that all storage nodes in the second network element are valid according to the DPSC authentication data, the DPDL in the second network element is updated.

[0314] At step S911, the second network element sends an Ndpr_DataStorage_response to the third network element, indicating that the first data is successfully stored.

[0315] At step S912, the third network element sends an Ndpac_MetaTrans_create / update_response to the fourth network element, indicating that the first data is successfully stored.

[0316] Example 2: The first network element indicates the operation permission of the first data based on the service interface of the first network element

[0317] In example 2, the first network element directly participates in the data operation of the data plane through the service interface of the first network element, which is beneficial to the direct control of the first network element on the related processing of the first network element. In the scheme of example 2, the first network element needs to have the capability of the service interface, which may have a larger change to the first network element itself, but the first network element directly calls the service interface of the third network element, which is more direct and simple in logic.

[0318] In example 2, when the fourth network element wants to store the first data to the data plane, the first network element indicates the operation permission of the fourth network element on the first data. Only when the fourth network element has the related storage permission on the first data, the first data can be stored correspondingly.

[0319] The flow of example 2 will be introduced below in combination with FIG. 10.

[0320] FIG. 10 is a flow diagram of a communication method according to another embodiment of the present application. The method shown in FIG. 10 includes steps S1001 to S1010.

[0321] At step S1001, the fourth network element sends a request to the third network element, requesting to store the first data of the first network element to the data plane. For example, the fourth network element can send a request (such as Ndpac_MetaTrans_create / update request) to the third network element to request to store the first data to the data plane.

[0322] In some embodiments, the request includes one or more of the following: an identifier of the fourth network element, the first data, data description information of the first data, and an identifier of the first network element.

[0323] At step S1002, the third network element sends a request to the second network element, requesting to store the first data to the data plane. For example, the third network element can send a request (e.g., Ndpr_DataStorage_request) to the second network element after the third network element verifies, to request to store the first data to the data plane.

[0324] In some embodiments, the request sent by the third network element to the second network element can carry the information carried in the request of step S1001.

[0325] At step S1003, the second network element sends an Ndpac_DataConsensus_request message to the third network element. The message is used to request the first network element to determine the operation authority of the fourth network element on the first data.

[0326] In some embodiments, the second network element determines that the operation authority of the fourth network element on the first data needs to be determined by the first network element according to one or more of the data description information of the first data, the identifier of the first network element, and the DPSC in the second network element. In this case, the second network element can send the Ndpac_DataConsensus_request message to the third network element.

[0327] In some embodiments, the Ndpac_DataConsensus_request message can include one or more of the following information: the identifier of the first network element, the data description information of the first data, the first data, the identifier of the data source of the first data (i.e., the identifier of the fourth network element), and the second indication information.

[0328] At step S1004, the third network element invokes the service of the first network element to request the first network element to determine the operation authority of the fourth network element on the first data.

[0329] In some embodiments, when the first network element has the structure shown in embodiment 2, the third network element can directly invoke the service of the first network element.

[0330] In some embodiments, the third network element can send an Nue_dpac_DataConsensus_request message to the first network element, which carries the information carried in the Ndpac_DataConsensus_request message in step S1003.

[0331] At step S1005, the first network element determines the operation authority of the fourth network element on the first data.

[0332] In some embodiments, the first network element can determine the operation permission of the fourth network element on the first data according to the first data. In some embodiments, the first network element can determine the operation permission of the fourth network element on the first data according to the data description information of the first data.

[0333] For example, according to the received information, the first network element knows that the fourth network element wants to store the location information of the first network element to the data plane. The first network element can determine that the fourth network element has no storage permission on the first data according to the current location information and the location information in the first data, and the first network element does not want to store its own location information to the data plane.

[0334] For another example, according to the received information, the first network element knows that the fourth network element wants to store the perception information of the first network element to the data plane. In this case, the first network element determines whether the first data to be stored is perception data (perception element data) or only perception result. If it is perception data, the first network element can determine that the fourth network element has no storage permission on the first data. If it is only perception result, the first network element can determine that the fourth network element has storage permission on the first data. In some embodiments, in the case that the first network element cannot determine whether the first data to be stored is perception data or only perception result (for example, the second network element does not send the first data to the first network element), the first network element can return the related indication to the second network element that only agrees to store the perception result to the data plane.

[0335] In step S1006, the first network element sends the Nue_dpac_DataConsensus_response message to the third network element to send the first indication information to the third network element.

[0336] In some embodiments, the Nue_dpac_DataConsensus_response message includes one or more of the following: the identifier of the first network element, the data description information of the first data, the first data, the identifier of the data source (i.e. the fourth network element) of the first data, and the first indication information.

[0337] In step S1007, the third network element sends the Ndpac_DataConsensus_response message to the second network element to send the first indication information to the second network element.

[0338] In some embodiments, if the first indication information indicates that the fourth network element has no storage permission, the second network element returns data storage failure to the fourth network element. Otherwise, the second network element performs steps S1008 to S1010.

[0339] In step S1008, the second network element initiates consensus authentication.

[0340] For example, the second network element can initiate a consensus authentication based on the second network element, or in other words, initiate a consensus authentication based on the blockchain. In the case where it is ensured that all storage nodes in the second network element are valid according to the DPSC authentication data, the DPDL in the second network element is updated.

[0341] At step S1009, the second network element sends an Ndpr_DataStorage_response to the third network element, indicating that the first data is successfully stored.

[0342] At step S1010, the third network element sends an Ndpac_MetaTrans_create / update_response to the fourth network element, indicating that the first data is successfully stored.

[0343] Example 3: The first network element operates a policy based on distributed NAS interface configuration data

[0344] In example 3, the first network element operates a policy based on distributed NAS interface configuration data, and the first network element configures the data operation policy in the data plane in advance, so that the first network element can indirectly control the related processing of the first network element. The scheme of example 3 is beneficial to avoid the need to interact with the first network element every time data is operated, thereby saving signaling overhead, reducing the use of air interface resources, and reducing communication pressure.

[0345] In example 3, the first network element sends the first configuration information (data operation policy) to the second network element through policy configuration. In this way, when the second network element receives an operation request of the fourth network element on the first data, the operation authority of the fourth network element on the first data can be determined according to the data operation policy configured by the first network element.

[0346] Next, in conjunction with FIG. 11, the flow of example 3 is introduced.

[0347] FIG. 11 is a flow diagram of a communication method according to another embodiment of the present application. The method shown in FIG. 11 includes steps S1101 to S1111.

[0348] At step S1101, the first network element sends an access layer message to an access network device, and the access layer message includes first configuration information.

[0349] In some embodiments, the first configuration information is carried in a first NAS container of the access layer message. The first NAS container is used to carry a NAS message sent to the data plane.

[0350] In some embodiments, the access layer message can include one or more of the following: the first configuration information, an identifier of the first network element, and data description information corresponding to the first configuration information.

[0351] In some embodiments, the data description information corresponding to the first configuration information can be understood as which data description information is configured by the first configuration information.

[0352] In step S1102, the access network device sends an Ndpac_DMPolicyControl_create / update request message to the third network element to send the first configuration information to the third network element.

[0353] In some embodiments, the Ndpac_DMPolicyControl_create / update request message includes the information carried by the access layer message in step S1101.

[0354] In step S1103, the third network element sends an Ndpr_DMPolicyControl_create / update_request message to the second network element to send the first configuration information to the second network element.

[0355] In some embodiments, the Ndpr_DMPolicyControl_create / update_request message includes the information carried by the access layer message in step S1101.

[0356] In step S1104, the second network element records the first configuration information and sends an Ndpr_DMPolicyControl_create / update_response message to the third network element to indicate that the data operation policy configuration is successful.

[0357] In some embodiments, the first configuration information is recorded in the DPSC of the second network element.

[0358] In step S1105, the third network element sends an Ndpac_DMPolicyControl_create / update response to the access network device to indicate that the data operation policy configuration is successful.

[0359] In some embodiments, the Ndpac_DMPolicyControl_create / update response message can carry one or more of the following information: the identifier of the first network element, the data description information corresponding to the first configuration information, and information indicating that the data operation policy configuration is successful.

[0360] In step S1106, the access network device sends an access layer message to the first network element to indicate that the data operation policy configuration is successful.

[0361] In some embodiments, the access layer message includes a first NAS container, in which information indicating that the data operation policy configuration is successful is carried.

[0362] In some embodiments, the first NAS container includes one or more of the following information: an identifier of the first network element, data description information corresponding to the first configuration information, and information indicating that the data operation policy configuration is successful.

[0363] At step S1107, the fourth network element sends a request to the third network element to store the first data of the first network element to the data plane. For example, the fourth network element can send a request (such as Ndpac_MetaTrans_create / update request) to the third network element to request to store the first data to the data plane.

[0364] In some embodiments, the request includes one or more of the following: an identifier of the fourth network element, the first data, data description information of the first data, and an identifier of the first network element.

[0365] At step S1108, the third network element sends a request to the second network element to store the first data to the data plane. For example, the third network element can send a request (such as Ndpr_DataStorage_request) to the second network element to request to store the first data to the data plane after the third network element verifies.

[0366] In some embodiments, the request sent by the third network element to the second network element can carry the information carried in the request of step S1107.

[0367] At step S1109, the second network element determines the operation authority of the fourth network element on the first data according to the first configuration information.

[0368] At step S1110 and step S1111, if the second network element determines that the fourth network element has the storage authority on the first data, the second network element sends indication information of the first data storage success to the fourth network element through the third network element.

[0369] Example 4: The first network element configures the data operation policy based on the service interface of the first network element

[0370] In example 4, the first network element configures the data operation policy based on the service interface of the first network element, so that the first network element configures the data operation policy in advance in the data plane, and the first network element can indirectly control the related processing of the first network element. The scheme of example 4 is beneficial to avoid the need to interact with the first network element every time data operation, thereby saving signaling overhead, reducing the use of air interface resources, and reducing communication pressure.

[0371] In Example 4, the first network element sends the first configuration information (data operation policy) to the second network element in a manner of policy configuration. In this way, when the second network element receives the operation request of the fourth network element on the first data, the operation permission of the fourth network element on the first data can be determined according to the data operation policy configured by the first network element.

[0372] The flow of Example 4 is introduced below in combination with FIG. 12.

[0373] FIG. 12 is a flow diagram of a communication method according to another embodiment of the present application. The method shown in FIG. 12 includes steps S1201 to S1209.

[0374] In step S1201, the first network element invokes a service of the third network element, and sends the first configuration information to the third network element. For example, the first network element can send the first configuration information to the third network element through an Ndpac_DMPolicyControl_create / update_request message.

[0375] In some embodiments, the Ndpac_DMPolicyControl_create / update_request message can include one or more of the following information: the first configuration information, the identifier of the first network element, and data description information corresponding to the first configuration information.

[0376] In step S1202, the third network element sends the first configuration information to the second network element. For example, the third network element can send the first configuration information to the second network element through an Ndpr_DMPolicyControl_create / update_request message.

[0377] In some embodiments, the Ndpr_DMPolicyControl_create / update_request message can include one or more of the following information: the first configuration information, the identifier of the first network element, and data description information corresponding to the first configuration information.

[0378] In step S1203, the second network element records the first configuration information, and sends an Ndpr_DMPolicyControl_create / update_response message to the third network element to indicate that the data operation policy configuration is successful.

[0379] In some embodiments, the first configuration information is recorded in the DPSC of the second network element.

[0380] At step S1204, the third network element sends an Ndpac_DMPolicyControl_create / update_response message to the first network element to indicate that the data operation policy configuration is successful.

[0381] In some embodiments, the Ndpac_DMPolicyControl_create / update_response message can carry one or more of the following information: an identifier of the first network element, data description information corresponding to the first configuration information, and information indicating that the data operation policy configuration is successful.

[0382] At step S1205, the fourth network element sends a request to the third network element to request storing the first data of the first network element to the data plane. For example, the fourth network element can send a request (such as an Ndpac_MetaTrans_create / update request) to the third network element to request storing the first data to the data plane.

[0383] In some embodiments, the request includes one or more of the following: an identifier of the fourth network element, the first data, data description information of the first data, and an identifier of the first network element.

[0384] At step S1206, the third network element sends a request to the second network element to request storing the first data to the data plane. For example, the third network element can send a request (such as an Ndpr_DataStorage_request) to the second network element to request storing the first data to the data plane after the third network element verifies the request.

[0385] In some embodiments, the request sent by the third network element to the second network element can carry the information carried in the request of step S1205.

[0386] At step S1207, the second network element determines the operation authority of the fourth network element on the first data according to the first configuration information.

[0387] At steps S1208 and S1209, if the second network element determines that the fourth network element has the storage authority on the first data, the second network element sends indication information of the first data storage success to the fourth network element through the third network element.

[0388] Embodiment 2:

[0389] In some embodiments, the first network element (such as a terminal device) can have a functional entity equivalent to the data plane to ensure that the first network element can access the data plane. The following takes the first module as an example to introduce the first module.

[0390] FIG. 13 shows a schematic diagram of a first network element interacting with a data plane. The first network element comprises a first module configured to manage or control the first network element to access the data plane.

[0391] In some embodiments, the first module can be a functional entity equivalent to the data plane.

[0392] In some embodiments, if the data plane adopts a new protocol or a new connection mode, the first network element side can connect with the data plane through the first module.

[0393] The embodiments of the present application do not limit the name of the first module. For example, the first module can also be referred to as a DPAC functional entity, or the name of a network element in a future communication system that has the same or similar function as the first module.

[0394] The first module can comprise one or more functions, for example, the first module is configured to manage or control the first network element to access the data plane, or in other words, the first module is configured to interact with the data plane (such as DPAC). For another example, in addition to being able to manage or control the first network element to access the data plane, the first module can also be configured to one or more of the following: collect data generated by the first network element, determine the operation permission of the data related to the first network element, and preprocess the data generated by the first network element.

[0395] In some embodiments, the first module configured to interact with the data plane can comprise one or more of the following: sending the data of the first network element to the data plane (such as to the third network element or the second network element), and sending the data operation policy of the first network element (such as the first configuration information in embodiment 1) to the data plane (such as to the second network element).

[0396] In some embodiments, the first module configured to determine the operation permission of the data related to the first network element can comprise the first module configured to determine the operation permission of the related data (such as the data generated by the first network element) of the first network element in the data plane. For example, whether the related data of the first network element can be stored in the data plane, whether the related data of the first network element can be opened to other data consumers, and the like.

[0397] In some embodiments, the first module configured to preprocess the data generated by the first network element can be configured to remove the privacy information of the data generated by the first network element. For example, the first module can perform one or more of the following on the data generated by the first network element: anonymization processing, normalization processing, and the like.

[0398] The method embodiments of the present application are described in detail above in combination with FIGS. 1 to 13, and the device embodiments of the present application are described in detail below in combination with FIGS. 14 to 17. It should be understood that the description of the method embodiments corresponds to the description of the device embodiments, and therefore, the parts not described in detail can be referred to the foregoing method embodiments.

[0399] Figure 14 is a schematic diagram of a structure of a communication device according to an embodiment of the present application. The communication device 1400 shown in Figure 14 is a first network element. The communication device 1400 comprises a sending module 1410. The sending module 1410 can be configured to send a first message to a second network element, the first message being used to determine an operation permission for first data, the first data comprising relevant data of the first network element, the second network element being configured to provide a data operation function of a data plane.

[0400] Optionally, the first message comprises first configuration information, the first configuration information being used to configure the operation permission for the first data.

[0401] Optionally, the first configuration information is associated with one or more of the following: a data type to be operated, a data source, a data consumer, a time limit for operation of data, a notification for operation of data.

[0402] Optionally, the first configuration information is used to indicate one or more of the following: an operation that can be performed on the first data; an operation that cannot be performed on the first data; an allowed data source; a disallowed data source; an allowed data consumer; a disallowed data consumer; an operation that can be performed on the first data after the first data is invoked by a data consumer; a time limit for operation of the first data; whether pre-processing of the first data is required before operation of the first data; whether the first network element needs to be notified after operation of the first data.

[0403] Optionally, the first configuration information is configured for different data types.

[0404] Optionally, the first message comprises first indication information, the first indication information being used to indicate the operation permission for the first data.

[0405] Optionally, the first indication information is used to indicate one or more of the following: whether an operation can be performed on the first data, an operation that can be performed on the first data, an operation that cannot be performed on the first data.

[0406] Optionally, the first message comprises one or more of the following: an identifier of the first network element; data description information of the first data; the first data; an identifier of a data source of the first data.

[0407] Optionally, the communication device further comprises a receiving module 1420, configured to receive a second message sent by the second network element, the second message being used to request the first network element to determine the operation permission for the first data.

[0408] Optionally, the second message comprises one or more of the following information: an identifier of the first network element; data description information of the first data; the first data; an identifier of a data source of the first data; second indication information for requesting the first network element to determine an operation permission for the first data.

[0409] Optionally, the message between the first network element and the second network element is transmitted and / or received through a third network element, the third network element being configured to manage or control the first network element to access a data plane.

[0410] Optionally, the message transmitted by the first network element to the third network element is transmitted by the first network element by invoking a service of the third network element; and / or, the message transmitted by the third network element to the first network element is transmitted by the third network element by invoking a service of the first network element.

[0411] Optionally, the message transmitted by the first network element to the third network element is transmitted by the first network element to an access network device, and then transmitted by the access network device to the third network element by invoking a service of the third network element; and / or, the message transmitted by the third network element to the first network element is transmitted by the third network element to the access network device, and then transmitted by the access network device to the first network element by an access layer message.

[0412] Optionally, the message transmitted between the first network element and the third network element is carried in a first NAS container in the access layer message, the first NAS container being configured to carry a NAS message transmitted to a data plane.

[0413] Optionally, the message transmitted by the first network element to the third network element is transmitted by the first network element to an AMF, and then transmitted by the AMF to the third network element by invoking a service of the third network element; and / or, the message transmitted by the third network element to the first network element is transmitted by the third network element to the AMF, and then transmitted by the AMF to the first network element by a NAS message.

[0414] Optionally, the message transmitted by the first network element to the third network element is transmitted by the first network element to a UPF, and then transmitted by the UPF to the third network element according to an address of the third network element; and / or, the message transmitted by the third network element to the first network element is transmitted by the third network element to a UPF, and then transmitted by the UPF to the first network element according to an address of the first network element.

[0415] Optionally, the operation on the first data is requested by a fourth network element, and information carried by the fourth network element when requesting the operation on the first data comprises one or more of the following: an identifier of the fourth network element; the first data; data description information of the first data; an identifier of the first network element; and a first parameter indicating the operation requested by the fourth network element.

[0416] Optionally, the fourth network element comprises one of the following: a terminal device, an access network device, a network element in a core network, an application device, and a network management device.

[0417] Optionally, the first network element comprises a first module configured to manage or control the first network element to perform data plane access.

[0418] Optionally, the first module is further configured to perform one or more of the following: collect data generated by the first network element, determine an operation permission of data related to the first network element, pre-process data generated by the first network element, and the pre-processing is configured to remove privacy information of the data generated by the first network element.

[0419] Optionally, the second network element is located in a blockchain.

[0420] Optionally, the first network element comprises one of the following: a terminal device, an access network device, a network element in a core network, and an application device.

[0421] Optionally, the sending module 1410 can be a transceiver 1730. The communication device 1400 can further comprise a processor 1710 and a memory 1720, as shown in FIG. 17.

[0422] FIG. 15 is a structural schematic diagram of a communication device according to another embodiment of the present application. The communication device 1500 shown in FIG. 15 is a second network element. The communication device 1500 comprises a receiving module 1510. The receiving module 1510 can be configured to receive a first message sent by a first network element, the first message being used to determine an operation permission of first data, the first data comprising related data of the first network element, and the second network element being configured to provide a data operation function of a data plane.

[0423] Optionally, the first message comprises first configuration information, and the first configuration information is used to configure the operation permission of the first data.

[0424] Optionally, the first configuration information is associated with one or more of the following: the data type being operated on, the data source, the data consumer, and the data. Alternatively, the first configuration information is used to indicate one or more of the following: operations that can be performed on the first data; operations that cannot be performed on the first data; allowed data sources; disallowed data sources; allowed data consumers; disallowed data consumers; operations that the data consumer can perform on the first data after retrieving it; the timeliness of operations on the first data; whether preprocessing of the first data is required before operations are performed on it; and whether the first network element needs to be notified of the operations performed on the first data.

[0425] Optionally, the first configuration information is configured for different data types.

[0426] Optionally, the first message includes first indication information, which is used to indicate operation permissions for the first data.

[0427] Optionally, the first indication information is used to indicate one or more of the following: whether the first data can be operated on, the operation that can be performed on the first data, and the operation that cannot be performed on the first data.

[0428] Optionally, the first message includes one or more of the following: the identifier of the first network element; the data description information of the first data; the first data; and the identifier of the data source of the first data.

[0429] Optionally, the communication device further includes: a sending module 1520, configured to send a second message to the first network element, the second message being used to request the first network element to determine its operation permission for the first data.

[0430] Optionally, the second message includes one or more of the following: the identifier of the first network element; the data description information of the first data; the first data; the identifier of the data source of the first data; and second indication information, used to request the first network element to determine the operation permission for the first data.

[0431] Optionally, the messages between the first network element and the second network element are sent and / or received through a third network element, which is used to manage or control the first network element to access the data plane.

[0432] Optionally, the message sent by the first network element to the third network element is sent by the first network element invoking the service of the third network element; and / or, the message sent by the third network element to the first network element is sent by the third network element invoking the service of the first network element.

[0433] Optionally, the message sent by the first network element to the third network element is sent by the first network element to an access network device through an access layer message, and then sent by the access network device to the third network element by invoking a service of the third network element; and / or the message sent by the third network element to the first network element is sent by the third network element to an access network device, and then sent by the access network device to the first network element through an access layer message.

[0434] Optionally, the message transmitted between the first network element and the third network element is carried in a first NAS container in the access layer message, and the first NAS container is used to carry a NAS message sent to a data plane.

[0435] Optionally, the message sent by the first network element to the third network element is sent by the first network element to an access network device through an access layer message, and then sent by the access network device to the third network element by invoking a service of the third network element; and / or the message sent by the third network element to the first network element is sent by the third network element to an access network device, and then sent by the access network device to the first network element through an access layer message.

[0436] Optionally, the message sent by the first network element to the third network element is sent by the first network element to an access network device through an access layer message, and then sent by the access network device to the third network element by invoking a service of the third network element; and / or the message sent by the third network element to the first network element is sent by the third network element to an access network device, and then sent by the access network device to the first network element through an access layer message.

[0437] Optionally, the operation on the first data is requested by a fourth network element, and information carried by the fourth network element when requesting the operation on the first data includes one or more of the following: an identifier of the fourth network element; the first data; data description information of the first data; an identifier of the first network element; and a first parameter indicating the operation requested by the fourth network element.

[0438] Optionally, the fourth network element includes one of the following: a terminal device, an access network device, a network element in a core network, an application device, and a network management device.

[0439] Optionally, the first network element includes a first module for managing or controlling data plane access of the first network element.

[0440] Optionally, the first module is further configured to perform one or more of the following: collecting data generated by the first network element, determining an operation permission of data related to the first network element, pre-processing data generated by the first network element, and the preprocessing is used to remove privacy information of the data generated by the first network element.

[0441] Optionally, the second network element is located in a blockchain.

[0442] Optionally, the first network element comprises one of: a terminal device, an access network device, a network element in a core network, and an application device.

[0443] Optionally, the receiving module 1510 can be a transceiver 1730. The communication device 1500 can further include a processor 1710 and a memory 1720, as shown in FIG. 17.

[0444] FIG. 16 is a structural schematic diagram of a communication device according to another embodiment of the present application. The communication device 1600 shown in FIG. 16 is a third network element. The communication device 1600 includes a first receiving module 1610 and a first sending module 1620. The first receiving module 1610 is configured to receive a first message sent by a first network element. The first sending module 1620 is configured to send the first message to a second network element. The first message is used to determine an operation permission for first data, the first data includes related data of the first network element, the second network element is configured to provide a data operation function in a data plane, and the third network element is configured to manage or control the first network element to access the data plane.

[0445] Optionally, the first message includes first configuration information, and the first configuration information is used to configure the operation permission for the first data.

[0446] Optionally, the first configuration information is associated with one or more of: a data type to be operated, a data source, a data consumer, a time limit for operation of data, and a notification of operation of data.

[0447] Optionally, the first configuration information is used to indicate one or more of: an operation that can be performed on the first data, an operation that cannot be performed on the first data, an allowed data source, a disallowed data source, an allowed data consumer, a disallowed data consumer, an operation that can be performed on the first data after the first data is invoked by the data consumer, a time limit for operation of the first data, whether preprocessing of the first data is required before operation of the first data, and whether the first network element needs to be notified of the operation performed on the first data.

[0448] Optionally, the first configuration information is configured for different data types.

[0449] Optionally, the first message includes first indication information, and the first indication information is used to indicate the operation permission for the first data.

[0450] Optionally, the first indication information is used for indicating one or more of the following: whether the first data can be operated, operations that can be performed on the first data, operations that cannot be performed on the first data.

[0451] Optionally, the first message comprises one or more of the following: an identifier of the first network element; data description information of the first data; the first data; an identifier of a data source of the first data.

[0452] Optionally, the communication device further comprises: a second receiving module, configured to receive a second message sent by the second network element; and a second sending module, configured to send the second message to the first network element, the second message being used for requesting the first network element to determine the operation permission for the first data.

[0453] Optionally, the second message comprises one or more of the following: an identifier of the first network element; data description information of the first data; the first data; an identifier of a data source of the first data; and second indication information, used for requesting the first network element to determine the operation permission for the first data.

[0454] Optionally, the message sent by the first network element to the third network element is sent by the first network element by invoking a service of the third network element; and / or the message sent by the third network element to the first network element is sent by the third network element by invoking a service of the first network element.

[0455] Optionally, the message sent by the first network element to the third network element is sent by the first network element to an access network device through an access layer message, and then sent by the access network device to the third network element by invoking a service of the third network element; and / or the message sent by the third network element to the first network element is sent by the third network element to the access network device by invoking a service of the access network device, and then sent by the access network device to the first network element through an access layer message.

[0456] Optionally, the message transmitted between the first network element and the third network element is carried in a first NAS container in the access layer message, and the first NAS container is used for carrying a NAS message sent to a data plane.

[0457] Optionally, the message sent by the first network element to the third network element is sent by the first network element to an access network device through an access layer message, and then sent by the access network device to the third network element by invoking a service of the third network element; and / or the message sent by the third network element to the first network element is sent by the third network element to the access network device by invoking a service of the access network device, and then sent by the access network device to the first network element through an access layer message.

[0458] Optionally, the message sent by the first network element to the third network element is sent by the first network element to a UPF, and then sent by the UPF to the third network element according to an address of the third network element; and / or the message sent by the third network element to the first network element is sent by the third network element to a UPF, and then sent by the UPF to the first network element according to an address of the first network element.

[0459] Optionally, the operation on the first data is requested by a fourth network element, and information carried by the fourth network element when requesting the operation on the first data includes one or more of the following: an identifier of the fourth network element; the first data; data description information of the first data; an identifier of the first network element; and a first parameter indicating the operation requested by the fourth network element.

[0460] Optionally, the fourth network element includes one of the following: a terminal device, an access network device, a network element in a core network, an application device, and a network management device.

[0461] Optionally, the first network element includes a first module for managing or controlling the first network element to perform data plane access.

[0462] Optionally, the first module is further configured to perform one or more of the following: collecting data generated by the first network element, determining an operation permission of data related to the first network element, pre-processing data generated by the first network element, and the preprocessing is used to remove privacy information of the data generated by the first network element.

[0463] Optionally, the second network element is located in a blockchain.

[0464] Optionally, the first network element includes one of the following: a terminal device, an access network device, a network element in a core network, and an application device.

[0465] Optionally, the first receiving module 1610 and the first sending module 1620 can be a transceiver 1730. The communication device 1600 can further include a processor 1710 and a memory 1720, as shown in FIG. 17.

[0466] FIG. 17 is a schematic structural diagram of a communication device according to an embodiment of the present application. The dashed line in FIG. 17 indicates that the unit or module is optional. The device 1700 can be used to implement the method described in the above method embodiments. The device 1700 can be a chip, a terminal device, or a network device.

[0467] The apparatus 1700 can include one or more processors 1710. The processor 1710 can support the apparatus 1700 to implement the methods described in the foregoing method embodiments. The processor 1710 can be a general processor or a special-purpose processor. For example, the processor can be a central processing unit (CPU). Alternatively, the processor can also be other general processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs) or other programmable logic devices, discrete gates or transistor logic, discrete hardware components, etc. The general processor can be a microprocessor or the processor can also be any conventional processor.

[0468] The apparatus 1700 can also include one or more memories 1720. The memory 1720 stores a program that can be executed by the processor 1710, so that the processor 1710 performs the methods described in the foregoing method embodiments. The memory 1720 can be independent of the processor 1710 or integrated in the processor 1710.

[0469] The apparatus 1700 can also include a transceiver 1730. The processor 1710 can communicate with other devices or chips through the transceiver 1730. For example, the processor 1710 can perform data transceiving with other devices or chips through the transceiver 1730.

[0470] The embodiments of the present application also provide a computer readable storage medium for storing a program. The computer readable storage medium can be applied to the terminal device or the network device provided by the embodiments of the present application, and the program causes the computer to execute the method performed by the terminal device or the network device in the various embodiments of the present application.

[0471] The embodiments of the present application also provide a computer program product. The computer program product includes a program. The computer program product can be applied to the terminal device or the network device provided by the embodiments of the present application, and the program causes the computer to execute the method performed by the terminal device or the network device in the various embodiments of the present application.

[0472] The embodiments of the present application also provide a computer program. The computer program can be applied to the terminal device or the network device provided by the embodiments of the present application, and the computer program causes the computer to execute the method performed by the terminal device or the network device in the various embodiments of the present application.

[0473] It should be understood that the terms "system" and "network" can be used interchangeably in this application. In addition, the terms used in this application are only used to explain the specific embodiments of this application, and are not intended to limit this application. The terms "first", "second", "third", and "fourth" and the like in the specification and claims of this application and the drawings are used to distinguish different objects, and are not used to describe a specific order. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion.

[0474] In embodiments of this application, the term "indicate" can be direct indication, or indirect indication, or can represent an associated relationship. For example, A indicates B, which can mean that B can be obtained through A; or A indirectly indicates B, for example, A indicates C, and B can be obtained through C; or A and B have an associated relationship.

[0475] In embodiments of this application, "B corresponding to A" means that B is associated with A, and B can be determined according to A. However, it should also be understood that determining B according to A does not mean that B is determined only according to A, but B can also be determined according to A and / or other information.

[0476] In embodiments of this application, the term "corresponding" can represent a direct or indirect corresponding relationship between the two, or can represent an associated relationship between the two, or can represent an indication and being indicated, configuration and being configured, etc.

[0477] In embodiments of this application, the term "include" can mean direct inclusion, or indirect inclusion. Alternatively, the term "include" mentioned in embodiments of this application can be replaced by "indicate" or "used to determine". For example, A includes B can be replaced by A indicates B, or A is used to determine B.

[0478] In embodiments of this application, "configuration" can include configuration through at least one of system message, radio resource control (RRC) signaling, and medium access control control element (MAC CE).

[0479] In embodiments of this application, "predefined" or "preconfigured" can be implemented by pre-saving corresponding codes, tables or other information that can be used to indicate related information in devices (such as terminal devices and network devices), and this application does not limit the specific implementation manner. For example, predefinition can mean definition in a protocol.

[0480] In the embodiments of the present application, the "protocol" can refer to a standard protocol in the communication field, for example, can include an LTE protocol, an NR protocol, and a related protocol applied in a future communication system, and the present application does not make any limitation thereto.

[0481] In the embodiments of the present application, the term "and / or" is only used to describe the association relationship of the associated objects, and can represent three relationships, for example, A and / or B can represent three cases of A alone, A and B together, and B alone. In addition, the character " / " in the present application generally represents an "or" relationship between the associated objects.

[0482] In various embodiments of the present application, the size of the sequence number of the above processes does not mean the order of execution, and the execution order of the processes should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0483] In several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be implemented in other ways. For example, the above-described device embodiments are only schematic, for example, the division of the units is only a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interface, device or unit, and can be electrical, mechanical or other forms.

[0484] The units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, that is, they can be located in one place, or can be distributed on a plurality of network units. According to actual needs, some or all of the units can be selected to achieve the purpose of the embodiments of the present application.

[0485] In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit.

[0486] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware or any combination thereof. When implemented by software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present application are generated. The computer can be a general purpose computer, a special purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer readable storage medium or transmitted from one computer readable storage medium to another computer readable storage medium, for example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center through wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.) mode. The computer readable storage medium can be any available medium that can be read by a computer or a data storage device such as a server, data center and the like integrated with one or more available media sets. The available media can be magnetic media (for example, floppy disk, hard disk, magnetic tape), optical media (for example, digital video disc (DVD)) or semiconductor media (for example, solid state disk (SSD)) and the like.

[0487] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical range disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A communication method characterized by comprising: The method comprises: a first network element sends a first message to a second network element, the first message being used to determine an operation permission for first data, the first data comprising relevant data of the first network element, and the second network element being used to provide a data plane data operation function.

2. The method of claim 1, wherein, The first message comprises first configuration information, the first configuration information being used to configure the operation permission for the first data.

3. The method of claim 2, wherein, The first configuration information is associated with one or more of the following: a data type to be operated, a data source, a data consumer, an operation time limit of the data, and an operation notification of the data.

4. The method according to claim 2 or 3, characterized in that, The first configuration information is used to indicate one or more of the following: an operation that can be performed on the first data; an operation that cannot be performed on the first data; an allowed data source; a disallowed data source; an allowed data consumer; a disallowed data consumer; an operation that can be performed on the first data after the first data is invoked by the data consumer; an operation time limit of the first data; whether preprocessing of the first data is required before the operation of the first data is performed; whether the first network element needs to be notified of the operation of the first data.

5. The method according to any one of claims 2-4, characterized in that, The first configuration information is configured for different data types.

6. The method of claim 1, wherein, The first message comprises first indication information, the first indication information being used to indicate the operation permission for the first data.

7. The method of claim 6, wherein, The first indication information is used to indicate one or more of the following: whether an operation can be performed on the first data, an operation that can be performed on the first data, and an operation that cannot be performed on the first data.

8. The method according to any one of claims 1-7, characterized in that, The first message comprises one or more of the following: an identifier of the first network element; data description information of the first data; the first data; an identifier of a data source of the first data.

9. The method according to any one of claims 1-8, characterized in that, The method further comprises: the first network element receives a second message sent by the second network element, the second message being used to request the first network element to determine the operation permission for the first data.

10. The method of claim 9, wherein, The second message comprises one or more of the following information: an identifier of the first network element; data description information of the first data; the first data; an identifier of a data source of the first data; second indication information, used to request the first network element to determine the operation permission for the first data.

11. The method according to any one of claims 1-10, characterized in that, Messages between the first network element and the second network element are sent and / or received through a third network element, the third network element being used to manage or control data plane access of the first network element.

12. The method of claim 11, wherein: the message sent by the first network element to the third network element is sent by the first network element by invoking a service of the third network element; and / or the message sent by the third network element to the first network element is sent by the third network element by invoking a service of the first network element.

13. The method of claim 11, wherein: the message sent by the first network element to the third network element is sent by the first network element to an access network device through an access layer message, and then sent by the access network device to the third network element by invoking a service of the third network element; and / or the message sent by the third network element to the first network element is sent by the third network element to an access network device through an access layer message, and then sent by the access network device to the first network element by invoking a service of the first network element. The message sent by the third network element to the first network element is sent by the access network device to the first network element through an access layer message after the third network element calls a service of the access network device and sends it to the access network device.

14. The method of claim 13, wherein, The message transmitted between the first network element and the third network element is carried in a first NAS container in the access layer message, and the first NAS container is used to carry a NAS message sent to a data plane.

15. The method of claim 11, wherein: The message sent by the first network element to the third network element is sent by the AMF to the third network element after the first network element sends it to the AMF through a NAS message; and / or The message sent by the third network element to the first network element is sent by the AMF to the first network element through a NAS message after the third network element calls a service of the AMF and sends it to the AMF.

16. The method of claim 11, wherein: The message sent by the first network element to the third network element is sent by the UPF to the third network element according to an address of the third network element after the first network element sends it to the UPF; and / or The message sent by the third network element to the first network element is sent by the UPF to the first network element according to an address of the first network element after the third network element sends it to the UPF. The operation on the first data is requested by a fourth network element, and information carried by the fourth network element when requesting the operation on the first data includes one or more of the following:

17. The method of any one of claims 1-16, wherein, An identifier of the fourth network element; The first data; Data description information of the first data; An identifier of the first network element; A first parameter for indicating the operation requested by the fourth network element. The fourth network element includes one of the following: a terminal device, an access network device, a network element in a core network, an application device, and a network management device.

18. The method of claim 17, wherein, The first network element includes a first module for managing or controlling the first network element to access a data plane.

19. The method of any one of claims 1-18, wherein, The first module is further configured to perform one or more of the following: collecting data generated by the first network element, determining an operation permission of data related to the first network element, pre-processing data generated by the first network element, and the preprocessing is used to remove privacy information of the data generated by the first network element.

20. The method of claim 19, wherein, The second network element is located in a blockchain.

21. The method of any one of claims 1-20, wherein, The first network element includes one of the following: a terminal device, an access network device, a network element in a core network, and an application device.

22. The method of any one of claims 1-21, wherein, Comprising:

23. A method of communication, comprising: The second network element receives a first message sent by the first network element, and the first message is used to determine an operation permission of first data, and the first data includes related data of the first network element, and the second network element is used to provide a data operation function of a data plane. The first message includes first configuration information, and the first configuration information is used to configure the operation permission of the first data.

24. The method of claim 23, wherein, The first configuration information is associated with one or more of the following: a data type to be operated, a data source, a data consumer, an operation time limit of data, and an operation notification of data.

25. The method of claim 24, wherein, The first configuration information is used to indicate one or more of the following:

26. The method of claim 24 or 25, wherein, ​ operations that can be performed on the first data; operations that cannot be performed on the first data; allowed data sources; unallowed data sources; allowed data consumers; unallowed data consumers; operations that can be performed on the first data after the first data is invoked by the data consumer; time limit for operations on the first data; whether pre-processing of the first data is required before operations on the first data are performed; whether the first network element needs to be notified of operations performed on the first data.

27. The method of any one of claims 24-26, wherein, The first configuration information is configured for different data types.

28. The method of claim 23, wherein, The first message includes first indication information, the first indication information being used to indicate operation permissions on the first data.

29. The method of claim 28, wherein, The first indication information is used to indicate one or more of the following: whether operations can be performed on the first data, operations that can be performed on the first data, and operations that cannot be performed on the first data.

30. The method of any one of claims 23-29, wherein, The first message includes one or more of the following: an identifier of the first network element; data description information of the first data; the first data; an identifier of a data source of the first data.

31. The method of any one of claims 23-30, wherein, The method further includes: The second network element sends a second message to the first network element, the second message being used to request the first network element to determine operation permissions on the first data.

32. The method of claim 31, wherein, The second message includes one or more of the following information: an identifier of the first network element; data description information of the first data; the first data; an identifier of a data source of the first data; second indication information, used to request the first network element to determine operation permissions on the first data.

33. The method of any one of claims 23-32, wherein, Messages between the first network element and the second network element are sent and / or received through a third network element, the third network element being used to manage or control data plane access of the first network element.

34. The method of claim 33, wherein: the message sent by the first network element to the third network element is sent by the first network element invoking a service of the third network element; and / or the message sent by the third network element to the first network element is sent by the third network element invoking a service of the first network element.

35. The method of claim 33, wherein: the message sent by the first network element to the third network element is sent by an access network device to the third network element after the first network element sends the message to the access network device through an access layer message, and the access network device invokes a service of the third network element to send the message to the third network element; and / or the message sent by the third network element to the first network element is sent by the access network device to the first network element after the third network element invokes a service of the access network device to send the message to the access network device, and the access network device sends the message to the first network element through an access layer message.

36. The method of claim 35, wherein, Messages transmitted between the first network element and the third network element are carried in a first NAS container in the access layer message, and the first NAS container is used to carry NAS messages sent to a data plane.

37. The method of claim 33, wherein: The message sent by the first network element to the third network element is sent by the first network element to the AMF through a NAS message, and then sent by the AMF to the third network element by calling a service of the third network element; and / or The message sent by the third network element to the first network element is sent by the third network element to the AMF, and then sent by the AMF to the first network element through a NAS message.

38. The method of claim 33, wherein: The message sent by the first network element to the third network element is sent by the first network element to the UPF, and then sent by the UPF to the third network element according to an address of the third network element; and / or The message sent by the third network element to the first network element is sent by the third network element to the UPF, and then sent by the UPF to the first network element according to an address of the first network element. The fourth network element requests operation on the first data, and information carried by the fourth network element when requesting operation on the first data includes one or more of the following:

39. The method of any one of claims 23-38, wherein, An identifier of the fourth network element; The first data; Data description information of the first data; An identifier of the first network element; A first parameter indicating the operation requested by the fourth network element. The fourth network element includes one of the following: a terminal device, an access network device, a network element in a core network, an application device, and a network management device.

40. The method of claim 39, wherein, The first network element includes a first module for managing or controlling the first network element to access a data plane.

41. The method of any one of claims 23-40, wherein, The first module is further configured to perform one or more of the following: collecting data generated by the first network element, determining an operation permission of data related to the first network element, pre-processing data generated by the first network element, and the preprocessing is used to remove privacy information of the data generated by the first network element.

42. The method of claim 41, wherein, The second network element is located in a blockchain.

43. The method of any one of claims 23-42, wherein, The first network element includes one of the following: a terminal device, an access network device, a network element in a core network, and an application device.

44. The method of any one of claims 23-43, wherein, It includes:

45. A method of communication, the method comprising: The third network element receives a first message sent by a first network element; The third network element sends the first message to a second network element; The first message is used to determine an operation permission of first data, the first data includes related data of the first network element, the second network element is used to provide a data operation function of a data plane, and the third network element is used to manage or control the first network element to access the data plane. The first message includes first configuration information, and the first configuration information is used to configure the operation permission of the first data.

46. The method of claim 45, wherein, The first configuration information is associated with one or more of the following: a data type to be operated, a data source, a data consumer, an operation time limit of the data, and an operation notification of the data.

47. The method of claim 46, wherein, The first configuration information is used to indicate one or more of the following:

48. The method of claim 46 or 47, wherein, Operations that can be performed on the first data; Operations that cannot be performed on the first data; Allowed data sources; Disallowed data sources; Allowed data consumers; Disallowed data consumers; Operations that can be performed on the first data after the data consumer retrieves the first data; An operation time limit of the first data; ​ whether the first data needs to be pre-processed before the operation on the first data is performed; whether the operation performed on the first data needs to be notified to the first network element.

49. The method of any one of claims 46-48, wherein, The first configuration information is configured for different data types.

50. The method of claim 45, wherein, The first message includes first indication information, and the first indication information is used to indicate the operation permission of the first data.

51. The method of claim 50, wherein, The first indication information is used to indicate one or more of the following: whether the first data can be operated, the operation that can be performed on the first data, and the operation that cannot be performed on the first data.

52. The method of any one of claims 45-51, wherein, The first message includes one or more of the following: an identifier of the first network element; data description information of the first data; the first data; an identifier of a data source of the first data.

53. The method of any one of claims 45-52, wherein, The method further includes: The third network element receives a second message sent by the second network element; The third network element sends the second message to the first network element, and the second message is used to request the first network element to determine the operation permission of the first data.

54. The method of claim 53, wherein, The second message includes one or more of the following information: an identifier of the first network element; data description information of the first data; the first data; an identifier of a data source of the first data; second indication information, used to request the first network element to determine the operation permission of the first data.

55. The method of any one of claims 45-54, wherein: the message sent by the first network element to the third network element is sent by the first network element invoking a service of the third network element; and / or the message sent by the third network element to the first network element is sent by the third network element invoking a service of the first network element.

56. The method of any one of claims 45-54, wherein: the message sent by the first network element to the third network element is sent by the first network element to an access network device through an access layer message, the access network device invokes a service of the third network element to send to the third network element; and / or the message sent by the third network element to the first network element is sent by the third network element to an access network device, and the access network device sends the first network element through an access layer message.

57. The method of claim 56, wherein, The message transmitted between the first network element and the third network element is carried in a first NAS container in the access layer message, and the first NAS container is used to carry a NAS message sent to a data plane.

58. The method of any one of claims 45-54, wherein: the message sent by the first network element to the third network element is sent by the first network element to an AMF through a NAS message, the AMF invokes a service of the third network element to send to the third network element; and / or the message sent by the third network element to the first network element is sent by the third network element to an AMF, and the AMF sends the first network element through a NAS message.

59. The method of any one of claims 45-54, wherein: The message sent by the first network element to the third network element is sent by the UPF to the third network element according to the address of the third network element after the first network element sends the message to the UPF. And / or The message sent by the third network element to the first network element is sent by the UPF to the first network element according to the address of the first network element after the third network element sends the message to the UPF.

60. The method of any one of claims 45-59, wherein, The operation on the first data is requested by a fourth network element, and information carried by the fourth network element when requesting the operation on the first data includes one or more of the following: An identifier of the fourth network element; The first data; Data description information of the first data; An identifier of the first network element; A first parameter for indicating the operation requested by the fourth network element.

61. The method of claim 60, wherein, The fourth network element includes one of the following: a terminal device, an access network device, a network element in a core network, an application device, and a network management device.

62. The method of any one of claims 45-61, wherein, The first network element includes a first module for managing or controlling the first network element to perform data plane access.

63. The method of claim 62, wherein, The first module is further configured to perform one or more of the following: collecting data generated by the first network element, determining an operation permission of data related to the first network element, and preprocessing data generated by the first network element, wherein the preprocessing is used to remove privacy information of the data generated by the first network element.

64. The method of any one of claims 45-63, wherein, The second network element is located in a blockchain.

65. The method of any one of claims 45-64, wherein, The first network element includes one of the following: a terminal device, an access network device, a network element in a core network, and an application device.

66. A communications device, characterized by The communication device is a first network element, and the communication device includes: A sending module configured to send a first message to a second network element, wherein the first message is used to determine an operation permission of first data, and the first data includes related data of the first network element, and the second network element is configured to provide a data operation function in a data plane.

67. The communication device of claim 66, wherein, The first message includes first configuration information, and the first configuration information is used to configure the operation permission of the first data.

68. The communication device of claim 67, wherein, The first configuration information is associated with one or more of the following: a data type to be operated, a data source, a data consumer, an operation time limit of data, and an operation notification of data.

69. The communication device of claim 67 or 68, wherein, The first configuration information is used to indicate one or more of the following: An operation that can be performed on the first data; An operation that cannot be performed on the first data; An allowed data source; A disallowed data source; An allowed data consumer; A disallowed data consumer; An operation that can be performed on the first data after the first data is retrieved by a data consumer; An operation time limit of the first data; Whether preprocessing of the first data is required before the operation on the first data is performed; Whether the first network element needs to be notified of the operation performed on the first data.

70. The communication device of any of claims 67-69, wherein, The first configuration information is configured for different data types.

71. The communications device of claim 66, wherein The first message includes first indication information, and the first indication information is used to indicate the operation permission of the first data.

72. The communication device of claim 71, wherein, The first indication information is used to indicate one or more of the following: whether an operation can be performed on the first data, an operation that can be performed on the first data, and an operation that cannot be performed on the first data.

73. The communication device of any of claims 66-72, wherein, The first message comprises one or more of the following: an identifier of the first network element; data description information of the first data; the first data; an identifier of a data source of the first data.

74. The communication device of any of claims 66-73, wherein, The communication device further comprises: a receiving module configured to receive a second message sent by the second network element, the second message being used to request the first network element to determine an operation permission on the first data.

75. The communication device of claim 74, wherein, The second message comprises one or more of the following: an identifier of the first network element; data description information of the first data; the first data; an identifier of a data source of the first data; second indication information used to request the first network element to determine the operation permission on the first data.

76. The communication device of any of claims 66-75, wherein, The messages between the first network element and the second network element are sent and / or received through a third network element, and the third network element is used to manage or control the first network element to access a data plane.

77. The communication device of claim 76, wherein: the message sent by the first network element to the third network element is sent by the first network element by invoking a service of the third network element; and / or the message sent by the third network element to the first network element is sent by the third network element by invoking a service of the first network element.

78. The communication device of claim 76, wherein: the message sent by the first network element to the third network element is sent by the first network element to an access network device through an access layer message, and then sent by the access network device to the third network element by invoking a service of the third network element; and / or the message sent by the third network element to the first network element is sent by the third network element to an access network device by invoking a service of the access network device, and then sent by the access network device to the first network element through an access layer message.

79. The communication device of claim 78, wherein, The messages transmitted between the first network element and the third network element are carried in a first NAS container in the access layer message, and the first NAS container is used to carry a NAS message sent to a data plane.

80. The communication device of claim 76, wherein: the message sent by the first network element to the third network element is sent by the first network element to an access and mobility function (AMF) through a NAS message, and then sent by the AMF to the third network element by invoking a service of the third network element; and / or the message sent by the third network element to the first network element is sent by the third network element to the AMF by invoking a service of the AMF, and then sent by the AMF to the first network element through a NAS message.

81. The communication device of claim 76, wherein: the message sent by the first network element to the third network element is sent by the first network element to a user plane function (UPF), and then sent by the UPF to the third network element according to an address of the third network element; and / or the message sent by the third network element to the first network element is sent by the third network element to the UPF, and then sent by the UPF to the first network element according to an address of the first network element. The operation on the first data is requested by a fourth network element, and information carried by the fourth network element when requesting the operation on the first data comprises one or more of the following:

82. The communication device of any of claims 66-81, wherein, ​ An identifier of the fourth network element; The first data; Data description information of the first data; An identifier of the first network element; A first parameter, used for indicating an operation requested by the fourth network element.

83. The communication device of claim 82, wherein, The fourth network element comprises one of the following: a terminal device, an access network device, a network element in a core network, an application device, and a network management device.

84. The communication device of any of claims 66-83, wherein, The first network element comprises a first module, which is used for managing or controlling the first network element to perform data plane access.

85. The communication device of claim 84, wherein, The first module is further used for one or more of the following: collecting data generated by the first network element, determining an operation permission of data related to the first network element, pre-processing the data generated by the first network element, and the preprocessing is used for removing privacy information of the data generated by the first network element.

86. The communication device of any of claims 66-85, wherein, The second network element is located in a blockchain.

87. The communication device of any of claims 66-86, wherein, The first network element comprises one of the following: a terminal device, an access network device, a network element in a core network, and an application device.

88. A communications device, comprising: The communication device is a second network element, and the communication device comprises: A receiving module, configured to receive a first message sent by a first network element, the first message being used for determining an operation permission of first data, the first data comprising related data of the first network element, and the second network element being used for providing a data operation function in a data plane.

89. The communication device of claim 88, wherein, The first message comprises first configuration information, and the first configuration information is used for configuring the operation permission of the first data.

90. The communication device of claim 89, wherein, The first configuration information is associated with one or more of the following: a data type to be operated, a data source, a data consumer, an operation time limit of data, and an operation notification of data.

91. The communication device of claim 89 or 90, wherein, The first configuration information is used for indicating one or more of the following: An operation that can be performed on the first data; An operation that cannot be performed on the first data; An allowed data source; A disallowed data source; An allowed data consumer; A disallowed data consumer; An operation that can be performed on the first data after the first data is invoked by a data consumer; An operation time limit of the first data; Whether preprocessing of the first data is required before the operation of the first data is performed; Whether the first network element needs to be notified of the operation of the first data.

92. The communication device of any of claims 89-91, wherein, The first configuration information is configured for different data types.

93. The communication device of claim 88, wherein, The first message comprises first indication information, and the first indication information is used for indicating the operation permission of the first data.

94. The communication device of claim 93, wherein, The first indication information is used for indicating one or more of the following: whether an operation can be performed on the first data, an operation that can be performed on the first data, and an operation that cannot be performed on the first data.

95. The communication device of any of claims 88-94, wherein, The first message comprises one or more of the following: An identifier of the first network element; Data description information of the first data; The first data; An identifier of a data source of the first data.

96. The communication device of any of claims 88-95, wherein, The communication device further comprises: A sending module, configured to send a second message to the first network element, the second message being used for requesting the first network element to determine the operation permission of the first data.

97. The communication device of claim 96, wherein, The second message comprises one or more of the following information: An identifier of the first network element; Data description information of the first data; The first data; An identifier of a data source of the first data. The second indication information is used for requesting the first network element to determine the operation permission of the first data.

98. The communication device of any of claims 88-97, wherein, The message between the first network element and the second network element is transmitted and / or received through a third network element, and the third network element is used for managing or controlling the first network element to access the data plane.

99. The communication device of claim 98, wherein: The message transmitted by the first network element to the third network element is transmitted by the first network element by invoking a service of the third network element; and / or The message transmitted by the third network element to the first network element is transmitted by the third network element by invoking a service of the first network element.

100. The communication device of claim 98, wherein: The message transmitted by the first network element to the third network element is transmitted by the first network element to an access network device through an access layer message, and the access network device transmits the message to the third network element by invoking a service of the third network element; and / or The message transmitted by the third network element to the first network element is transmitted by the third network element to an access network device by invoking a service of the access network device, and the access network device transmits the message to the first network element through an access layer message.

101. The communication device of claim 100, wherein, The message transmitted between the first network element and the third network element is carried in a first NAS container in the access layer message, and the first NAS container is used for carrying a NAS message transmitted to the data plane.

102. The communication device of claim 98, wherein: The message transmitted by the first network element to the third network element is transmitted by the first network element to an access network device through an access layer message, and the access network device transmits the message to the third network element by invoking a service of the third network element; and / or The message transmitted by the third network element to the first network element is transmitted by the third network element to an access network device by invoking a service of the access network device, and the access network device transmits the message to the first network element through an access layer message.

103. The communication device of claim 98, wherein: The message transmitted by the first network element to the third network element is transmitted by the first network element to an access network device through an access layer message, and the access network device transmits the message to the third network element by invoking a service of the third network element; and / or The message transmitted by the third network element to the first network element is transmitted by the third network element to an access network device through an access layer message, and the access network device transmits the message to the first network element by invoking a service of the third network element; and / or The operation on the first data is requested by a fourth network element, and information carried by the fourth network element when requesting the operation on the first data includes one or more of the following:

104. The communication device of any of claims 88-103, wherein, An identifier of the fourth network element; The first data; Data description information of the first data; An identifier of the first network element; A first parameter used for indicating the operation requested by the fourth network element. The fourth network element includes one of the following: a terminal device, an access network device, a network element in a core network, an application device, and a network management device.

105. The communication device of claim 104, wherein, The first network element includes a first module used for managing or controlling the first network element to access the data plane.

106. The communication device of any of claims 88-105, wherein, ​ 107. The communication device of claim 106, wherein, The first module is further configured to perform one or more of the following: collecting data generated by the first network element, determining an operation permission of data related to the first network element, pre-processing data generated by the first network element, and the pre-processing is configured to remove privacy information of the data generated by the first network element.

108. The communication device of any of claims 88-107, wherein, The second network element is located in a blockchain.

109. The communication device of any of claims 88-108, wherein, The first network element comprises one of the following: a terminal device, an access network device, a network element in a core network, and an application device.

110. A communications device, comprising: The communication device is a third network element, and the communication device comprises: a first receiving module configured to receive a first message sent by a first network element; a first sending module configured to send the first message to a second network element; The first message is used to determine an operation permission of first data, the first data comprises related data of the first network element, the second network element is configured to provide a data plane operation function, and the third network element is configured to manage or control the first network element to access the data plane.

111. The communication device of claim 110, wherein, The first message comprises first configuration information, and the first configuration information is used to configure the operation permission of the first data.

112. The communication device of claim 111, wherein, The first configuration information is associated with one or more of the following: a data type to be operated, a data source, a data consumer, an operation time limit of the data, and an operation notification of the data.

113. The communication device of claim 111 or 112, wherein, The first configuration information is used to indicate one or more of the following: an operation that can be performed on the first data; an operation that cannot be performed on the first data; an allowed data source; a disallowed data source; an allowed data consumer; a disallowed data consumer; an operation that can be performed on the first data after the first data is invoked by the data consumer; an operation time limit of the first data; whether pre-processing of the first data is required before the operation of the first data is performed; whether the first network element needs to be notified of the operation of the first data.

114. The communication device of any of claims 111-113, wherein, The first configuration information is configured for different data types.

115. The communication device of claim 110, wherein, The first message comprises first indication information, and the first indication information is used to indicate the operation permission of the first data.

116. The communication device of claim 115, wherein, The first indication information is used to indicate one or more of the following: whether an operation can be performed on the first data, an operation that can be performed on the first data, and an operation that cannot be performed on the first data.

117. The communication device of any of claims 110-116, wherein, The first message comprises one or more of the following: an identifier of the first network element; data description information of the first data; the first data; an identifier of a data source of the first data.

118. The communication device of any of claims 110-117, wherein, The communication device further comprises: a second receiving module configured to receive a second message sent by the second network element; a second sending module configured to send the second message to the first network element, and the second message is used to request the first network element to determine the operation permission of the first data.

119. The communication device of claim 118, wherein, The second message comprises one or more of the following information: an identifier of the first network element; data description information of the first data; the first data; an identifier of a data source of the first data; second indication information used to request the first network element to determine the operation permission of the first data. 120.The communication device of any of claims 110-119, wherein: the message sent by the first network element to the third network element is sent by the first network element invoking a service of the third network element; and / or, the message sent by the third network element to the first network element is sent by the third network element invoking a service of the first network element. 121.The communication device of any of claims 110-119, wherein: the message sent by the first network element to the third network element is sent by the first network element to an access network device through an access layer message, and is sent by the access network device to the third network element by invoking a service of the third network element; and / or, the message sent by the third network element to the first network element is sent by the third network element to the access network device by invoking a service of the access network device, and is sent by the access network device to the first network element through an access layer message. The message transmitted between the first network element and the third network element is carried in a first NAS container in the access layer message, and the first NAS container is used to carry a NAS message sent to a data plane. 123.The communication device of any of claims 110-119, wherein: the message sent by the first network element to the third network element is sent by the first network element to an access and mobility function (AMF) through a NAS message, and is sent by the AMF to the third network element by invoking a service of the third network element; and / or, the message sent by the third network element to the first network element is sent by the third network element to the AMF by invoking a service of the AMF, and is sent by the AMF to the first network element through a NAS message. 124.The communication device of any of claims 110-119, wherein: the message sent by the first network element to the third network element is sent by the first network element to a user plane function (UPF), and is sent by the UPF to the third network element according to an address of the third network element; and / or, the message sent by the third network element to the first network element is sent by the third network element to the UPF, and is sent by the UPF to the first network element according to an address of the first network element. The operation on the first data is requested by a fourth network element, and information carried by the fourth network element when requesting the operation on the first data comprises one or more of the following:

122. The communication device of claim 121, wherein, an identifier of the fourth network element; the first data; data description information of the first data; an identifier of the first network element; a first parameter indicating the operation requested by the fourth network element. The fourth network element comprises one of the following: a terminal device, an access network device, a network element in a core network, an application device, and a network management device. The first network element comprises a first module for managing or controlling the first network element to access a data plane. The first module is further configured to perform one or more of the following: collecting data generated by the first network element, determining an operation permission of data related to the first network element, and pre-processing data generated by the first network element, wherein the pre-processing is used to remove privacy information of the data generated by the first network element.

125. The communication device of any of claims 110-124, wherein, ​ ​ ​ ​ ​ ​ 126. The communication device of claim 125, wherein, ​ 127. The communication device of any of claims 110-126, wherein, ​ 128. The communication device of claim 127, wherein, ​ 129. The communication device of any of claims 110-128, wherein, The second network element is located in a blockchain.

130. The communication device of any of claims 110-129, wherein, The first network element comprises one of: a terminal device, an access network device, a network element in a core network, an application device.

131. A communications device, characterized by A communication device comprising a transceiver, a memory and a processor, the memory being configured to store a program, the processor being configured to invoke the program in the memory and control the transceiver to receive or send a signal, so that the communication device performs the method of any one of claims 1-22 or 23-44 or 45-65.

132. An apparatus, comprising: A device comprising a processor configured to invoke a program from a memory, so that the device performs the method of any one of claims 1-22 or 23-44 or 45-65.

133. A chip, characterized in that, A chip comprising a processor configured to invoke a program from a memory, so that the device installed with the chip performs the method of any one of claims 1-22 or 23-44 or 45-65.

134. A computer-readable storage medium, characterized in that, A computer program product having stored thereon a program, the program causing a computer to perform the method of any one of claims 1-22 or 23-44 or 45-65.

135. A computer program product, characterized in that, A computer program product having stored thereon a program, the program causing a computer to perform the method of any one of claims 1-22 or 23-44 or 45-65.

136. A computer program, characterized in that, A computer program product having stored thereon a program, the program causing a computer to perform the method of any one of claims 1-22 or 23-44 or 45-65.

Citation Information

Patent Citations

  • Processing method of data interaction, server and device

    CN106897866A

  • Secure interaction method and device

    CN111949956A

  • Control system and control method

    JP2017220114A

  • Data processing method, system, device, and storage medium

    WO2023179750A1

  • Communication method and communication apparatus

    WO2024032226A1