Communication method, and device, core network device, network element, system and medium

By employing data request and privacy parameter interaction between the first and second network elements in the communication network, the problem of privacy leakage in data services is solved, and secure and efficient data transmission is achieved.

WO2025251236A1PCT designated stage Publication Date: 2025-12-11BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/097633
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-06-05
Publication Date
2025-12-11

AI Technical Summary

Technical Problem

In communication networks, there is a problem of data service privacy leakage on the data plane, especially in the process of data transmission between multiple data providers and consumers, where it is difficult to guarantee the privacy and security of data.

Method used

Through the communication method between the first network element and the second network element, requests and information, including data and privacy parameters, are received and sent. Based on the privacy parameters, it is determined whether the device meets the privacy conditions, and data is sent when the conditions are met, thus ensuring the security of data transmission.

Benefits of technology

It enables secure data services that meet privacy requirements during data transmission, improving the security and efficiency of data service processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024097633_11122025_PF_FP_ABST
    Figure CN2024097633_11122025_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure relates to a communication method, and a device, a core network device, a network element, a system and a medium. The method comprises: receiving a first request sent by a first device, wherein the first request is used for requesting a data service; on the basis of the first request, sending a second request to a second network element, wherein the second request is used for requesting first information, and the first information comprises at least one of the following: first data and a privacy parameter; receiving the first information, which is sent by the second network element; and on the basis of the privacy parameter, determining that the first device meets a privacy condition, and on the basis of the first data, sending second data to the first device. Therefore, a secure data service process is provided, and it is ensured that data transmission on a data plane meets privacy requirements.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method, device, core network device, network element, system and medium TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of communication, and in particular to a communication method, device, core network device, network element, system and medium. BACKGROUND

[0002] In a communication network, most of the data stored or transmitted in the network comes from network communication operations and subscriptions. As new generation communication functions and services expand from communication to fields such as sensing, computing and artificial intelligence, the range and types of data in the network will increase. As a function that provides a bridge between data providers and data consumers, data services can separate data consumers and data providers. When there are multiple data providers or multiple data consumers, data services help maintain data integrity and improve communication efficiency through reusability.

[0003] SUMMARY

[0004] To overcome the technical problem of data service privacy leakage on the data plane in the related art, the present disclosure provides a communication method, device, core network device, network element, system and medium.

[0005] According to a first aspect of an embodiment of the present disclosure, a communication method is provided, executed by a first network element, and the method comprises:

[0006] receiving a first request sent by a first device, the first request being used to request a data service;

[0007] sending a second request to a second network element according to the first request, the second request being used to request first information, the first information comprising at least one of the following: first data, a privacy parameter;

[0008] receiving the first information sent by the second network element;

[0009] determining that the first device satisfies a privacy condition according to the privacy parameter, and sending second data to the first device according to the first data.

[0010] According to a second aspect of an embodiment of the present disclosure, a communication method is provided, executed by a second network element, and the method comprises:

[0011] receiving a second request sent by a first network element, the second request being determined by the first network element according to a first request sent by a first device, the first request being used to request a data service, and the second request being used to request first information, the first information comprising at least one of the following: first data, a privacy parameter;

[0012] sending the first information to the first network element.

[0013] According to a third aspect of the embodiments of the present disclosure, a communication method is provided, performed by a first device, the method comprising:

[0014] sending, to a first network element, a first request, the first request being used to request a data service;

[0015] receiving second data sent by the first network element.

[0016] According to a fourth aspect of the embodiments of the present disclosure, a first network element is provided, comprising:

[0017] a transceiver, configured to receive a first request sent by a first device, the first request being used to request a data service;

[0018] the transceiver is further configured to send, to a second network element, a second request according to the first request, the second request being used to request first information, the first information comprising at least one of the following: first data and a privacy parameter;

[0019] the transceiver is further configured to receive the first information sent by the second network element.

[0020] the transceiver is further configured to determine, according to the privacy parameter, that the first device satisfies a privacy condition, and send second data to the first device according to the first data.

[0021] According to a fifth aspect of the embodiments of the present disclosure, a second network element is provided, comprising:

[0022] a transceiver, configured to receive a second request sent by a first network element, the second request being determined by the first network element according to a first request sent by a first device, the first request being used to request a data service, the second request being used to request first information, the first information comprising at least one of the following: first data and a privacy parameter;

[0023] the transceiver is further configured to send the first information to the first network element.

[0024] According to a sixth aspect of the embodiments of the present disclosure, a first device is provided, comprising:

[0025] a transceiver, configured to send, to a first network element, a first request, the first request being used to request a data service;

[0026] the transceiver is further configured to receive second data sent by the first network element.

[0027] According to a seventh aspect of the embodiments of the present disclosure, a first network element is provided, comprising:

[0028] one or more processors;

[0029] The first network element is configured to perform the communication method of any one of the first aspect of the present disclosure.

[0030] According to an eighth aspect of the embodiments of the present disclosure, a second network element is provided, comprising:

[0031] one or more processors;

[0032] The second network element is configured to perform the communication method of any one of the second aspect of the present disclosure.

[0033] According to a ninth aspect of the embodiments of the present disclosure, a core network device is provided, comprising the first network element and the second network element, wherein the first network element is configured to implement the communication method of any one of the first aspect of the present disclosure, and the second network element is configured to implement the communication method of any one of the second aspect of the present disclosure.

[0034] According to a tenth aspect of the embodiments of the present disclosure, a first device is provided, comprising:

[0035] one or more processors;

[0036] The first device is configured to perform the communication method of any one of the third aspect of the present disclosure.

[0037] According to an eleventh aspect of the embodiments of the present disclosure, a communication system is provided, comprising the first device and the core network device, wherein the core network device comprises the first network element and the second network element, the first network element is configured to implement the communication method of any one of the first aspect of the present disclosure, the second network element is configured to implement the communication method of any one of the second aspect of the present disclosure, and the first device is configured to implement the communication method of any one of the third aspect of the present disclosure.

[0038] According to a twelfth aspect of the embodiments of the present disclosure, a storage medium is provided, which stores instructions, when the instructions run on a communication device, the communication device performs the communication method of any one of the first aspect of the present disclosure, the second aspect of the present disclosure, or the third aspect of the present disclosure.

[0039] In the above manner, the first request sent by the first device is received, the first request is used to request a data service, the second request is sent to the second network element according to the first request, the second request is used to request the first information, the first information comprises at least one of the following: the first data and the privacy parameter, the first information sent by the second network element is received, the first device satisfies the privacy condition according to the privacy parameter, and the second data is sent to the first device according to the first data. Thus, a safe data service process is provided, and it is ensured that the data transmission on the data plane satisfies the privacy requirement. BRIEF DESCRIPTION OF DRAWINGS

[0040] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure, the following describes the drawings required by the embodiments, and the following drawings are only some embodiments of the present disclosure, and do not specifically limit the protection scope of the present disclosure.

[0041] FIG. 1 is an architecture schematic diagram of a communication system according to an embodiment of the present disclosure.

[0042] FIG. 2 is an interaction schematic diagram of a communication method according to an embodiment of the present disclosure.

[0043] FIG. 3A is a flow schematic diagram of a communication method according to an embodiment of the present disclosure.

[0044] FIG. 3B is a flow schematic diagram of a communication method according to an embodiment of the present disclosure.

[0045] FIG. 3C is a flow schematic diagram of a communication method according to an embodiment of the present disclosure.

[0046] FIG. 4 is a flow schematic diagram of a communication method according to an embodiment of the present disclosure.

[0047] FIG. 5 is a flow schematic diagram of a communication method according to an embodiment of the present disclosure.

[0048] FIG. 6 is a flow schematic diagram of a communication method according to an embodiment of the present disclosure.

[0049] FIG. 7 is a structural schematic diagram of a first network element according to an embodiment of the present disclosure.

[0050] FIG. 8 is a structural schematic diagram of a second network element according to an embodiment of the present disclosure.

[0051] FIG. 9 is a structural schematic diagram of a first device according to an embodiment of the present disclosure.

[0052] FIG. 10A is a structural schematic diagram of a communication device 10100 according to an embodiment of the present disclosure.

[0053] FIG. 10B is a structural schematic diagram of a chip 10200 according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0054] The embodiments of the present disclosure provide a communication method, device, core network device, network element, system and medium.

[0055] In a first aspect, the embodiments of the present disclosure provide a communication method, performed by a first network element, comprising:

[0056] receiving a first request sent by a first device, the first request being used to request a data service;

[0057] sending a second request to a second network element according to the first request, the second request being used for requesting first information, the first information comprising at least one of the following: first data, a privacy parameter;

[0058] receiving the first information sent by the second network element;

[0059] determining that the first device satisfies a privacy condition according to the privacy parameter, and sending second data to the first device according to the first data.

[0060] In the above embodiments, the first network element performs data service management, ensures that data transmission meets relevant privacy requirements, and improves the security of a data service process.

[0061] In some embodiments of the first aspect, the first request comprises at least one of the following:

[0062] a first service identifier of the data service;

[0063] a first identifier, the first identifier comprising an identifier of the first device and / or an identifier of a group to which the first device belongs;

[0064] a second identifier, the second identifier comprising a public land mobile network (PLMN) identifier of the first device;

[0065] a first area, the first area comprising an area in which the first device is located;

[0066] first destination information corresponding to the first request.

[0067] In the above embodiments, the relevant identifier information in the first request is used to label the first request, which provides a basis for determining whether the first request is authorized by the first network element, so that the first network element performs data service management.

[0068] In some embodiments of the first aspect, the sending of the second request to the second network element according to the first request comprises:

[0069] determining whether the first device is authorized to use the data service according to the first request;

[0070] in response to determining that the first device is authorized to use the data service, sending the second request to the second network element.

[0071] In the above embodiments, the first network element determines the data service authority of the first device according to the first request, and sends a data request to the second network element when authorization is determined, so that the first network element provides a privacy checking process and determines the security of the data service.

[0072] In some embodiments of the first aspect, the determining whether the first device is authorized to use the data service according to the first request comprises:

[0073] According to the first request, the subscription data corresponding to the first device is acquired;

[0074] According to the subscription data, it is determined whether the first device is authorized to use the data service.

[0075] In the above embodiment, the first network element determines the subscription data corresponding to the first device according to the first request, and determines whether the first device is authorized to use the data service according to the subscription data when the first device is authorized to provide the data service. Thus, whether to provide the data service for the first device is determined based on the subscription data, and the authorization determination process of the data service is improved.

[0076] In some embodiments of the first aspect, the determining whether the first device is authorized to use the data service according to the first request comprises:

[0077] According to the first request, it is determined whether the first device is authorized to use the data service through a service-based architecture (SBA) security mechanism.

[0078] In the above embodiment, the first network element determines whether the first device is authorized to use the data service through the SBA security mechanism.

[0079] In some embodiments of the first aspect, the privacy parameter comprises at least one of:

[0080] Second purpose information related to the first data;

[0081] A third identifier, the third identifier comprising at least one of: an identifier of a second device, an identifier of a group to which the second device belongs, and a second service identifier related to the first data, the second device being a device allowed to use the first data;

[0082] First domain information related to the first data, the first domain information comprising at least one of: time domain information, geographical information, and PLMN information;

[0083] A first sharing policy related to the first data;

[0084] Notification information and / or verification information;

[0085] Timing parameters of a timing device related to the first data.

[0086] In the above embodiment, whether the first request satisfies the privacy condition is determined through the above privacy parameter, thereby ensuring the security and privacy requirements of data in the data service process.

[0087] In some embodiments of the first aspect, the privacy condition comprises at least one of:

[0088] The second purpose information related to the first data matches the first purpose information corresponding to the first request;

[0089] The identity of the group to which the second device belongs and the second service identity related to the first data match the first service identity;

[0090] The identity information of the second device matches the identity information of the first device;

[0091] The first domain information related to the first data matches the second domain information corresponding to the first device;

[0092] The first sharing policy related to the first data matches the first request;

[0093] The notification and / or verification between the first network element and a third device is successful, and the third device is a device for collecting the first data;

[0094] According to the timing parameter of the timing device related to the first data, it is determined that the first data is valid.

[0095] In the above embodiments, the privacy condition based on the privacy parameter in the first network element is determined, so that the privacy security of the first request of the first device is determined according to the privacy condition, and the privacy security of the data service is ensured.

[0096] In some embodiments of the first aspect, the privacy parameter comprises the first sharing policy, and the sending of the second data to the first device according to the first data comprises:

[0097] According to the first sharing policy, the first data is securely processed to generate the second data;

[0098] The second data is sent to the first device.

[0099] In the above embodiments, the first network element securely processes the first data corresponding to the data service according to the sharing policy, thereby improving the security of the data corresponding to the data service in the transmission process.

[0100] In the above embodiments, the first device can be a terminal or an NF network element, and both the terminal and the NF network element can initiate the data service, thereby improving the richness of the data request end.

[0101] In a second aspect, the embodiments of the present disclosure provide a communication method, executed by a second network element, comprising:

[0102] receive a second request sent by the first network element, the second request being determined by the first network element according to a first request sent by the first device, the first request being used to request a data service, and the second request being used to request first information, the first information including at least one of the following: first data and a privacy parameter;

[0103] send the first information to the first network element.

[0104] In the above embodiment, the second network element sends the first information to the first network element according to the second request, so that the first network element performs privacy verification on the first request according to the privacy parameter of the first information, and provides the data service to the first device when the first request meets the privacy condition. The second network element provides the basis for privacy determination to ensure the privacy and security in the data service process.

[0105] In combination with some embodiments of the second aspect, the first request includes at least one of the following:

[0106] a first service identifier of the data service;

[0107] a first identifier, the first identifier including an identifier of the first device or an identifier of a group to which the first device belongs;

[0108] a second identifier, the second identifier including a PLMN identifier of the first device;

[0109] a first area, the first area including an area in which the first device is located;

[0110] first destination information corresponding to the first request.

[0111] In the above embodiment, the first request is labeled by the relevant identifier information in the first request, which provides a basis for whether the first network element authorizes the first request, so as to manage the data service by the first network element.

[0112] In combination with some embodiments of the second aspect, the privacy parameter includes at least one of the following:

[0113] second destination information related to the first data;

[0114] a third identifier, the third identifier including at least one of the following: an identifier of a second device, an identifier of a group to which the second device belongs, and a second service identifier related to the first data, the second device being a device allowed to use the first data;

[0115] first domain information related to the first data, the first domain information including at least one of the following: time domain information, regional information, and PLMN information;

[0116] a first sharing policy related to the first data;

[0117] notification information and / or verification information;

[0118] a timing parameter of a timing device related to the first data.

[0119] In the above embodiment, whether the first request meets the privacy condition is determined by the privacy parameter, thereby ensuring the security and privacy requirements of data in the data service process.

[0120] In a third aspect, the embodiments of the present disclosure provide a communication method, executed by a first device, the method comprising:

[0121] sending a first request to a first network element, the first request being used to request a data service;

[0122] receiving second data sent by the first network element.

[0123] In the above embodiment, the first device initiates a data service request and obtains corresponding second data, thereby providing a data sharing service for the first device and improving data service efficiency and data consumption experience.

[0124] In combination with some embodiments of the third aspect, the first request comprises at least one of:

[0125] a first service identifier of the data service;

[0126] a first identifier, the first identifier comprising an identifier of the first device or an identifier of a group to which the first device belongs;

[0127] a second identifier, the second identifier comprising a PLMN identifier of the first device;

[0128] a first area, the first area comprising an area in which the first device is located;

[0129] first destination information corresponding to the first request.

[0130] In the above embodiment, the first request is labeled by the relevant identifier information in the first request, which provides a basis for whether the first request is authorized by the first network element, so as to manage the data service by the first network element.

[0131] In the above embodiment, the first device can be a terminal or an NF network element, and both the terminal and the NF network element can initiate a data service, thereby improving the richness of the data request end.

[0132] In a fourth aspect, the embodiments of the present disclosure provide a first network element, comprising:

[0133] a transceiver module configured to receive a first request sent by a first device, the first request being used to request a data service;

[0134] The transceiver module is further configured to send a second request to a second network element according to the first request, the second request being used to request first information, the first information including at least one of the following: first data, a privacy parameter;

[0135] The transceiver module is further configured to receive the first information sent by the second network element.

[0136] The transceiver module is further configured to determine, according to the privacy parameter, that the first device satisfies a privacy condition, and send second data to the first device according to the first data.

[0137] In a fifth aspect, an embodiment of the present disclosure provides a second network element, comprising:

[0138] The transceiver module is configured to receive a second request sent by a first network element, the second request being determined by the first network element according to a first request sent by a first device, the first request being used to request a data service, and the second request being used to request first information, the first information including at least one of the following: first data, a privacy parameter;

[0139] The transceiver module is further configured to send the first information to the first network element.

[0140] In a sixth aspect, an embodiment of the present disclosure provides a first device, comprising:

[0141] The transceiver module is configured to send a first request to a first network element, the first request being used to request a data service.

[0142] The transceiver module is further configured to receive second data sent by the first network element.

[0143] In a seventh aspect, an embodiment of the present disclosure provides a first network element, comprising:

[0144] One or more processors;

[0145] The first network element is configured to perform the communication method in any one of the first aspects of the present disclosure.

[0146] In an eighth aspect, an embodiment of the present disclosure provides a second network element, comprising:

[0147] One or more processors;

[0148] The second network element is configured to perform the communication method in any one of the second aspects of the present disclosure.

[0149] In a ninth aspect, an embodiment of the present disclosure provides a core network device, comprising a first network element and a second network element, wherein the first network element is configured to implement the communication method according to any one of the first aspect of the present disclosure; and the second network element is configured to implement the communication method according to any one of the second aspect of the present disclosure.

[0150] In a tenth aspect, an embodiment of the present disclosure provides a first device, comprising:

[0151] one or more processors;

[0152] The first device is configured to implement the communication method according to any one of the third aspect of the present disclosure.

[0153] In an eleventh aspect, an embodiment of the present disclosure provides a communication system, comprising a first device and a core network device, wherein the core network device comprises a first network element and a second network element, the first network element is configured to implement the communication method according to any one of the first aspect of the present disclosure, the second network element is configured to implement the communication method according to any one of the second aspect of the present disclosure, and the first device is configured to implement the communication method according to any one of the third aspect of the present disclosure.

[0154] In a twelfth aspect, an embodiment of the present disclosure provides a storage medium, which stores instructions, when the instructions are executed on a communication device, the communication device is caused to perform the communication method according to any one of the first aspect of the present disclosure, the second aspect of the present disclosure or the third aspect of the present disclosure.

[0155] It can be understood that the first device, the first network element, the second network element, the core network device, the communication system or the storage medium are all configured to perform the method according to the embodiments of the present disclosure. Therefore, the beneficial effects achieved by them can refer to the beneficial effects in the corresponding method, which will not be described here.

[0156] The embodiments of the present disclosure provide a communication method, device, core network device, network element, system and medium. In some embodiments, the terms of communication method and information processing method can be replaced with each other, the terms of communication device and information processing device can be replaced with each other, and the terms of information processing system and communication system can be replaced with each other.

[0157] The embodiments of the present disclosure are not exhaustive, but only illustrate some embodiments, and are not specific limitations on the protection scope of the present disclosure. In the case of no contradiction, each step in an embodiment can be implemented as an independent embodiment, and the steps can be combined arbitrarily, for example, the scheme after removing part of the steps in an embodiment can also be implemented as an independent embodiment, and the order of the steps in an embodiment can be exchanged arbitrarily, in addition, the optional implementation manners in an embodiment can be combined arbitrarily; in addition, the embodiments can be combined arbitrarily, for example, part or all steps of different embodiments can be combined arbitrarily, an embodiment can be combined with optional implementation manners of other embodiments arbitrarily.

[0158] In each embodiment of the present disclosure, the terms and / or descriptions between the embodiments are consistent if there is no special description and logical conflict, and can be referred to each other, and the technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.

[0159] The terms used in the embodiments of the present disclosure are only for the purpose of describing the specific embodiments, and not as a limitation on the present disclosure.

[0160] In the embodiments of the present disclosure, unless otherwise specified, the elements expressed in singular form, such as "one", "a", "the", "above", "said", "preceding", "this" and the like, can represent "one and only one", and can also represent "one or more", "at least one" and the like. For example, in the case of using articles such as "a", "an", "the" and the like in English, the noun after the article can be understood as singular expression, and can also be understood as plural expression.

[0161] In the embodiments of the present disclosure, "plurality" means two or more.

[0162] In some embodiments, the terms "at least one of", "one or more", "a plurality of", "multiple" and the like can be replaced with each other.

[0163] In some embodiments, "at least one of A, B", "A and / or B", "in one case A, in another case B", "responsive to case A, responsive to case B" and the like, can be interpreted to include both cases, A and B, in some embodiments, A (A is performed regardless of B), in some embodiments, B (B is performed regardless of A), in some embodiments, selected from the group consisting of A and B (the selection between A and B is an option), in some embodiments, A and B (both A and B are performed).

[0164] In some embodiments, "A or B" and the like, can be interpreted to include both cases, A and B, in some embodiments, A (A is performed regardless of B), in some embodiments, B (B is performed regardless of A), in some embodiments, selected from the group consisting of A and B (the selection between A and B is an option).

[0165] In some embodiments, the prefix words "first", "second" and the like in the disclosure do not limit the position, order, priority, number or content of the described objects, and the description of the described objects should be understood in the context of the claims or embodiments, and should not be construed as redundant limitations. For example, the described object is "field", and the ordinal words before "field" in "first field" and "second field" do not limit the position or order between "fields", and "first" and "second" do not limit whether the "fields" modified by them are in the same message or not, nor do they limit the order of "first field" and "second field". For another example, the described object is "level", and the ordinal words before "level" in "first level" and "second level" do not limit the priority between "levels". For another example, the number of described objects is not limited by ordinal words, and can be one or more. For example, "first device", where the number of "devices" can be one or more. In addition, the objects modified by different prefix words can be the same or different, for example, the described object is "device", and "first device" and "second device" can be the same device or different devices, and their types can be the same or different; for another example, the described object is "information", and "first information" and "second information" can be the same information or different information, and their contents can be the same or different.

[0166] In some embodiments, "including A", "containing A", "for indicating A", "carrying A" can be interpreted as directly carrying A, or indirectly indicating A.

[0167] In some embodiments, the terms "in response to", "in response to determining", "in the case of", "when", "when", "if", "if" and the like can be replaced with each other.

[0168] In some embodiments, the terms "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not lower than", "above", and the like can be replaced with each other, and the terms "less than", "less than or equal to", "not greater than", "fewer than", "fewer than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", "below", and the like can be replaced with each other.

[0169] In some embodiments, the apparatuses and devices can be interpreted as physical or virtual, and their names are not limited to the names described in the embodiments, and in some cases can also be understood as "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", "subject", and the like.

[0170] In some embodiments, "network" can be interpreted as an apparatus included in the network, such as an access network device, a core network device, and the like.

[0171] In some embodiments, an “access network device (AN device)” can also be referred to as a “radio access network device (RAN device),” a “base station (BS),” a “radio base station,” a “fixed station,” and in some embodiments can also be understood as a “node,” an “access point,” a “transmission point (TP),” a “reception point (RP),” a “transmission / reception point (TRP),” a “panel,” an “antenna panel,” an “antenna array,” a “cell,” a “macro cell,” a “small cell,” a “femto cell,” a “pico cell,” a “sector,” a “cell group,” a “serving cell,” a “carrier,” a “component carrier,” a “bandwidth part (BWP),” and the like.

[0172] In some embodiments, a "terminal" or "terminal device" can be referred to as a "user equipment" (UE), a "user terminal," a "mobile station" (MS), a "mobile terminal" (MT), a subscriber station, a mobile unit, a subscriber unit, a wireless unit, a remote unit, a mobile device, a wireless device, a wireless communication device, a remote device, a mobile subscriber station, an access terminal, a mobile terminal, a wireless terminal, a remote terminal, a handset, a user agent, a mobile client, a client, and / or the like.

[0173] In some embodiments, data, information and / or the like can be obtained in compliance with laws and regulations of a country where the data, information and / or the like is obtained.

[0174] In some embodiments, data, information and / or the like can be obtained after obtaining consent of a user.

[0175] In addition, each element, each row, or each column in a table of embodiments of the present disclosure can be implemented as an independent embodiment, and a combination of any element, any row, or any column can also be implemented as an independent embodiment.

[0176] FIG. 1 is an architecture diagram of a communication system according to an embodiment of the present disclosure. As shown in FIG. 1, the communication system 100 includes a first terminal 101 and a core network device 102.

[0177] In some embodiments, the first device 101 can be a terminal, such as at least one of a mobile phone, a wearable device, an Internet of Things device, a communication-capable car, a smart car, a tablet (Pad), a wireless transceiver-equipped computer, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in a smart grid, a wireless terminal device in transportation safety, a wireless terminal device in a smart city, a wireless terminal device in a smart home, but is not limited thereto.

[0178] In some embodiments, the first device 101 can be an NF (Network Functions) network element in a core network, which is a virtualized functional component or node in a network that can implement network functions in software form in a software-defined network and network function virtualization architecture. Among them, the NF network element functions can include: routing function, the NF network element can provide routing function through routing protocol (such as OSPF (Open Shortest Path First), BGP (Border Gateway Protocol), etc.), and forward and select the best path for data packets; firewall function, the NF network element can provide network security protection, identify and filter malicious traffic, and protect the network from attacks; encryption and decryption function, the NF network element can provide data encryption and decryption function to ensure the security and confidentiality of data during transmission; load balancing function, the NF network element can balance and distribute network traffic, so that different servers can efficiently handle requests, and improve network performance and availability; proxy function, the NF network element can act as a proxy server, intermediate processing between network requests, and increase the flexibility of management and control; cache function, the NF network element can cache commonly used data or content, speed up data transmission, and reduce network delay; service chain configuration, the NF network element can combine multiple NFs with different functions to form a service chain, thereby implementing complex network services; QoS (Quality of Service) management, the NF network element can implement network quality management, classify, schedule and control traffic, and guarantee the priority transmission of critical applications.

[0179] In some embodiments, the first device 101 can be an AS (Application Server), which is a server in a mobile communication network for managing and coordinating the running of one or more application programs. The AS communicates with (UE) and various network nodes in the mobile communication network, ensuring the security and trustworthiness of users in the network.

[0180] In some embodiments, the technical solutions of the present disclosure can be applicable to Open RAN architecture, at which time the interfaces between or within the access network devices involved in the embodiments of the present disclosure can become internal interfaces of Open RAN, and the processes and information interactions between these internal interfaces can be realized through software or programs.

[0181] In some embodiments, the core network device 102 can be one device including the first network element 1021, the second network element 1022, etc., or a plurality of devices or device groups including all or part of the first network element 1021, the second network element 1022, etc. The network element can be virtual or physical. The core network includes at least one of the Evolved Packet Core (EPC), the 5G Core Network (5GCN), the 6G Core Network (6GCN), and the Next Generation Core (NGC).

[0182] In some embodiments, the first network element 1021 can be a network element with network data analysis function or data management function, for example, a NWDAF (Network Data Analytics Function) network element or a DPMF (Data Plane Management function) network element, which is used to manage shared data, including data collection, data exposure, etc., and to ensure that the exposure of shared data complies with the data privacy requirements of relevant devices through the first network element 1021.

[0183] In some embodiments, the second network element 1022 can be a network element with data storage function, for example, an ADRF (Analytic Data Repository Function) network element or a DPSF (Data Plane Storage function) network element, which is used to store shared data associated with privacy parameters and to provide shared data to the first network element 1021 after receiving the data request sent by the first network element 1021.

[0184] In some embodiments, the first network element 1021 is configured to manage the shared data, and the name of the first network element 1021 is not limited to, for example, a data management network element, a privacy management network element, and the like, and the embodiments are not limited in this regard.

[0185] In some embodiments, the second network element 1022 is configured to store the shared data and / or the privacy parameters associated therewith, and the name of the second network element 1022 is not limited to, for example, a storage function network element, a data plane storage function network element, and the like, and the embodiments are not limited in this regard.

[0186] It can be understood that the communication system described in the embodiments of the present disclosure is for more clearly illustrating the technical solutions of the embodiments of the present disclosure, and does not constitute a limitation on the technical solutions proposed by the embodiments of the present disclosure. It can be known by those skilled in the art that, as the system architecture evolves and new business scenarios appear, the technical solutions proposed by the embodiments of the present disclosure are also applicable to similar technical problems.

[0187] The following embodiments of the present disclosure can be applied to the communication system 100 shown in FIG. 1, or part of the subjects, but are not limited thereto. The subjects shown in FIG. 1 are exemplary, and the communication system can include all or part of the subjects in FIG. 1, or other subjects other than FIG. 1. The number and form of each subject is arbitrary, each subject can be real or virtual, the connection relationship between each subject is exemplary, each subject can not be connected or can be connected, the connection can be in any way, can be direct connection or indirect connection, can be wired connection or wireless connection.

[0188] Embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), 6th generation mobile communication system (6G), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (Bluetooth (registered trademark)), Public Land Mobile Network (PLMN) network, Device-to-Device (D2D) system, Machine to Machine (M2M) system, Internet of Things (IoT) system, Vehicle-to-Everything (V2X), system using other communication methods, next-generation system expanded based thereon, and the like. Further, a plurality of systems can be applied in combination (for example, combination of LTE or LTE-A and 5G, and the like).

[0189] In some embodiments, the data service provides data to the data requester as a service product by using a data distribution / publishing framework to meet the real-time cross-system data requirements of the client, while achieving reuse and compliance with enterprise / industry regulations. The data sharing and security trade-off is achieved through the data service. The data service provides functions such as data collection, transmission, storage, and sharing.

[0190] In some embodiments, in order to provide internal or external network functions and data services in a convenient, efficient and secure manner, and to improve data service efficiency and data consumption experience, a communication method is proposed to ensure that shared data on the data plane meets privacy requirements and securely exposes shared data to data requesters.

[0191] In some embodiments, unlike related communication architectures, the communication architecture proposed in this embodiment can include three independent planes that handle different types of traffic, including a control plane, a user plane, and a data plane. The control plane carries the signaling traffic of each UE (User Equipment), and handles tasks such as authentication, authorization, and mobility management through the control plane. The control plane is also responsible for providing shared data to the data plane. The user plane carries the actual data traffic of each UE, and if the privacy requirements of the UE are met, the transmitted data traffic can be provided to the data plane. The data plane is responsible for collecting and managing shared data, and the data in the data plane can be associated with a group of UEs or a network / service task, rather than being associated with a UE.

[0192] In some embodiments, the ADRF network element or the DPSF network element is used to store shared data associated with privacy restriction parameters. When receiving a data request from the NWDAF network element or the DPMF network element, the ADRF network element or the DPSF network element provides shared data to the NWDAF network element or the DPMF network element. The NWDAF network element or the DPMF network element is used to manage shared data, including data collection, data exposure, data transmission, etc., to ensure that the exposure of shared data complies with the privacy requirements of the relevant UE.

[0193] FIG. 2 is an interaction diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 2, the embodiment of the present disclosure relates to a communication method, and the method includes:

[0194] Step S2101, the first device 101 sends a first request to the first network element 1021.

[0195] For example, the first device 101 is a request initiator, and sends a first request to the first network element 1021 to request a data sharing service. The first device 101 can be a terminal UE, and the data sharing service is initiated by the terminal UE. The first device 101 can also be a NF network element in the core network device 102, and the NF network element needs to initiate the data sharing service to the first network element 1021 to request sharing data for realizing corresponding functions. The first device 101 can also be an AS, and the AS needs to initiate the data sharing service to the first network element 1021 to request sharing data for realizing corresponding functions. The UE, the NF network element or the AS initiates the data sharing service to request sharing data, and the sharing data is used for realizing artificial intelligence, sensing, positioning, perception and the like in the UE, the NF network element or the AS. The first network element 1021 is deployed in the core network device 102, and is used for managing sharing data, including collecting the sharing data, exposing the sharing data and transmitting the sharing data. The sharing data can be pre-stored in other storage network elements of the core network device 102, and can also be collected from other devices or other network elements based on the first request to obtain the sharing data after the first network element 1021 receives the first request.

[0196] In some embodiments, the first device 101 is configured to initiate a data service request, and the first device 101 is a data consumer device.

[0197] In some embodiments, the first device 101 includes a terminal or a NF network element.

[0198] In some embodiments, the first network element 1021 receives the first request.

[0199] For example, after the first network element 1021 receives the first request, the first network element 1021 obtains sharing data according to the first request and sends the sharing data to the first device 101. The first network element 1021 can also determine whether to authorize the first device to obtain the data sharing service based on the first request. For example, the first request includes device ID information of the first device 101, and the first network element 1021 obtains subscription data of the device or obtains authorization information of the device based on the device ID information. If the subscription data or the authorization information of the first device 101 indicates that the device is not authorized to use the data service, the first network element 1021 feeds back authorization failure information to the first device 101.

[0200] In some embodiments, the first network element 1021 is configured to manage first data.

[0201] For example, the first network element 1021 manages the first data, including managing collection of the first data, data exposure of the first data and the like.

[0202] In some embodiments, the first network element 1021 includes a NWDAF network element or a DPMF network element.

[0203] In some embodiments, the name of the first network element is not limited.

[0204] In some embodiments, the first request is used to request a data service.

[0205] In some embodiments, the name of the first request is not limited, for example, "service request information", "shared data request", "data sharing request", etc.

[0206] In some embodiments, the first request includes at least one of the following:

[0207] a first service identifier of the data service;

[0208] a first identifier, the first identifier including an identifier of the first device or an identifier of a group to which the first device belongs;

[0209] a second identifier, the second identifier including a public land mobile network (PLMN) identifier of the first device;

[0210] a first area, the first area including an area in which the first device is located;

[0211] first destination information corresponding to the first request.

[0212] For example, the first network element 1021 manages a plurality of different types of data services, such as AI data services, positioning data services, etc. The first request can include a first service identifier of the data service, which is used by the first network element 1021 to identify the type of data service requested by the first device, so as to facilitate the first network element 1021 to obtain the corresponding shared data.

[0213] Optionally, in some embodiments, the first service identifier can also be a task identifier under a certain type of data service, the task identifier being used to directly identify a sub-task under the data service, and the first network element 1021 obtains shared data corresponding to the sub-task under the type of data service based on the first service identifier.

[0214] The first identifier includes an identifier of the first device or an identifier of a group to which the first device belongs, and the first identifier is used by the first network element 1021 to determine whether the first device 101 is authorized to obtain a data service. For example, the first network element 1021 obtains subscription data of the device based on the device ID information, or obtains authorization information of the device, to determine whether the first device is authorized to use the data service.

[0215] A second identifier, the second identifier being a PLMN identifier of the first device, the second identifier being used for determining whether the first device 101 is authorized to obtain the data service in the first network element 1021. The PLMN identifier is a network identifier of a cellular mobile communication network of an operator, and is used to indicate a cellular mobile communication network currently operated by the first device. In an example, the first network element 1021 determines whether the first device 101 is authorized to use the data service according to the obtained privacy parameter associated with the shared data and the second identifier.

[0216] A first region, the first region including region information currently located by the first device 101, the first network element 1021 having a regional restriction on devices authorized to use the data service, the restriction being that the data service is provided to devices in certain specific regions. According to the first region, it is determined whether the device is located in the authorized specific region, and whether the first device 101 is authorized to obtain the data service is determined.

[0217] First request first purpose information, the data service provided by the first network element 1021 has a purpose, for example, the shared data provided by the first network element 1021 based on the data service is mainly used for positioning awareness. If the first device 101 requests the first network element 1021 to expose the shared data based on the first request, and the shared data is used for AI prediction in the first device 101, the first purpose corresponding to the first request does not match the purpose of the shared data provided by the data service in the first network element 1021. Therefore, the first network element 1021 can refuse to provide the data service to the first device 101 based on the first purpose information.

[0218] Step S2102, the first network element 1021 determines whether the first device 101 is authorized to use the data service according to the first request.

[0219] In an example, the first network element 1021 determines whether the first device 101 is authorized to use the data service according to the first request, and the first network element 1021 can determine whether the first device 101 is authorized to use the data service corresponding to the first request by using a set determination mechanism according to the device identifier of the first device 101 in the first request.

[0220] In some embodiments, the above step S2102 includes:

[0221] The first network element 1021 obtains the subscription data corresponding to the first device according to the first request;

[0222] The first network element 1021 determines whether the first device is authorized to use the data service according to the subscription data.

[0223] In an example, the first device 101 is a UE, and the first network element determines that the first device 101 is a UE based on the first request. The first network element obtains the subscription data corresponding to the first device according to the first request, and determines whether the first device 101 is authorized to use the data service according to the subscription data.

[0224] In some embodiments, the step S2103 includes:

[0225] The first network element 1021 determines whether the first device is authorized to use the data service according to the SBA security mechanism based on the first request.

[0226] In an example, the first device 101 is a core network device NF network element, and the first network element 1021 determines that the first device 101 is an NF network element based on the first request. The first network element 1021 determines whether the first device is authorized to use the data service according to the SBA security mechanism. The SBA security mechanism refers to security measures and mechanisms used in the service-based architecture, which aims to protect the security, integrity and reliability of services, communications and data. In the service-based architecture, various services communicate and interact through the network. In order to prevent potential security threats and attacks, a series of security mechanisms need to be taken to ensure the security of the system. In this embodiment, the SBA security mechanism verifies whether the first device is authorized to use the data service.

[0227] In step S2103, the first network element 1021 sends a second request to the second network element 1022 in response to determining that the first device 101 is authorized to use the data service.

[0228] In an example, the first network element 1021 is configured to manage shared data related to the data service, including shared data scheduling, shared data exposure, etc. When it is determined that the first device 101 is authorized to use the data service, the first network element 1021 sends a second request to the second network element 1022, and requests the shared data from the second network element 1022 through the second request.

[0229] In some embodiments, the second network element 1022 receives the second request.

[0230] In some embodiments, the second network element 1022 is configured to store first data, which is shared data corresponding to the data service.

[0231] In some embodiments, the second network element 1022 comprises: an ADRF network element or a DPSF network element.

[0232] In some embodiments, the name of the second network element is not limited, which is, for example, “data storage network element”, “data plane storage function network element”, etc.

[0233] In some embodiments, the second request is used to request the first information.

[0234] In some embodiments, in order to enable the second network element 1022 to determine the corresponding first information based on the second request, the second request can include part or all of the parameters in the first request. For example, the second request can include the first service identifier of the data service, which can be the identification information of the service type corresponding to the data service, and can also be the task identifier information of the subtask corresponding to the data service.

[0235] In some embodiments, the name of the second request is not limited, which is, for example, “data request”, “shared data request”, etc.

[0236] In step S2104, the second network element 1022 sends the first information to the first network element 1021 according to the second request, and the first information includes at least one of the following: first data and privacy parameters.

[0237] For example, the first data in the first information is the shared data related to the data service, the first information includes the first data and the privacy parameters, and the first network element 1021 determines whether to expose the first data to the first device 101 according to the privacy parameters in the first information. For example, the first network element 1021 can also generate second data by performing security processing on the first data according to the privacy parameters in the case of determining to expose the first data to the first device 101 based on the privacy parameters, and feed back the second data to the first device 101.

[0238] In some embodiments, the first device 101 can issue multiple data service requests of different types based on the same first data. The first network element 1021 can request the first information from the second network element 1022 based on the initial data request sent by the first device 101, and at this time the first information can include the first data and the privacy parameters. If the first device 101 fails to obtain authorization to use the data service based on the first data request or the initial data request, and initiates a subsequent data service request to the first network element 1021, the first network element 1021 can request the first information from the second network element 1022, which includes the first data. The first network element 1021 can obtain the privacy parameters related to the first data based on the first data request or the initial data request of the first device 101 before, and determine whether to expose the first data to the first device 101 according to the privacy parameters.

[0239] In some embodiments, the first device 101 can send multiple different types of data service requests, respectively requesting the same or different data services, after the first device sends the first request for the first time, the first network element 1021 can request the first information from the second network element 1022 based on the first data request sent by the first device 101, at this time the first information can include the first data and the privacy parameter. When the first device sends the first request for the second time or after, the first network element 1021 can request the first information from the second network element 1022, and the second network element 1022 can send the first information to the first network element 1021, at this time it can be considered that the first network element has all or part of the corresponding privacy parameter, and the first information includes the first data, or includes the remaining part of the privacy parameter that the first network element does not have. The first network element 1021 can determine whether to expose the first data to the first device 101 based on all the privacy parameters already available, or the first network element 1021 can determine whether to expose the first data to the first device 101 based on the part of the privacy parameters already available and the remaining part of the privacy parameters included in the first information. In some embodiments, all or part of the privacy parameters can be pre-configured, pre-defined, or pre-indicated by other information; the first network element 1021 can determine whether to expose the first data to the first device 101 based on all the privacy parameters pre-configured, pre-defined, or pre-indicated by other information, or the first network element 1021 can determine whether to expose the first data to the first device 101 based on the part of the privacy parameters pre-configured, pre-defined, or pre-indicated by other information and the remaining part of the privacy parameters included in the first information.

[0240] In some embodiments, the privacy parameter includes at least one of:

[0241] Second purpose information related to the first data;

[0242] Third identification, the third identification includes at least one of: identification of the second device, identification of the group to which the second device belongs, and second service identification related to the first data, the second device is a device allowed to use the first data;

[0243] First domain information related to the first data, the first domain information includes at least one of: time domain information, regional information, and PLMN information;

[0244] First sharing strategy related to the first data;

[0245] Notification information and / or verification information;

[0246] Timing parameter of a timing device related to the first data.

[0247] For example, the privacy parameter can include second purpose information related to the first data, the second purpose information being a purpose of use of the first data, for example, the second purpose information indicating that the first data is used for AI prediction, perception positioning, etc. The first network element 1021 compares the second purpose information of the privacy parameter with first purpose information corresponding to the first request, and determines to provide the shared data to the first device 101 when the first purpose information and the second purpose information match.

[0248] The privacy parameter includes a third identifier, the third identifier including an identifier of the second device, an identifier of a group to which the second device belongs, and a second service identifier related to the first data, where the second device is an identifier of a device authorized to use a data service. The first network element 1021 determines whether the device ID, the device group ID, and the service identifier in the privacy parameter detection match the device ID, the device group ID, and the service identifier in the first request, so as to determine whether to provide the shared data to the first device 101.

[0249] The privacy parameter includes first domain information associated with the first data, the first domain information including at least one of time domain information, geographical information, and PLMN information. For example, the first domain information includes time domain information, the time domain information being used to indicate an allowed exposure time of the first data, for example, the time domain information indicating a time domain range of 10:00-12:00, and the first network element 1021 receiving the first request at 10:12, the first request of the first device 101 being within the time domain range specified in the privacy parameter, and the first network element 1021 determining to provide the shared data to the first device 101. The first domain information includes geographical information, the geographical information being used to indicate an allowed exposure area range of the first data. The first domain information includes PLMN information, the PLMN information being used to indicate a type of cellular network of the second device.

[0250] In step S2105, the first network element 1021 determines whether the first device satisfies a privacy condition according to the privacy parameter.

[0251] For example, in this embodiment, the first network element 1021 determines whether a data service request initiated by the first device satisfies a privacy condition according to the privacy parameter. It should be noted that the first network element 1021 can be configured with multiple privacy conditions, and the privacy condition used for determination is determined based on the type of the privacy parameter.

[0252] In some embodiments, the privacy condition includes at least one of:

[0253] The second purpose information related to the first data matches first purpose information corresponding to the first request;

[0254] The identifier of the group to which the second device belongs and the second service identifier related to the first data match the first service identifier;

[0255] The identification information of the second device matches the identification information of the first device;

[0256] The first domain information related to the first data matches the second domain information corresponding to the first device;

[0257] The first sharing policy related to the first data matches the first request;

[0258] The notification and / or verification between the first network element and the third device is successful, and the third device is a device for collecting the first data;

[0259] According to the timing parameter of the timing device related to the first data, it is determined that the first data is valid.

[0260] For example, the first network element 1021 determines whether the first device satisfies the privacy condition according to the privacy parameter fed back by the second network element 1022.

[0261] (1) If the second purpose information of the first data matches the first purpose information of the first request, it is determined that the first device satisfies the privacy condition; the second purpose information can be used to indicate the allowed exposure purpose of the first data, for example, the first data is only allowed to be used for AI prediction, or for perception positioning, etc., and the purpose of the requested data service is included in the first request. When the first purpose information and the second purpose information match, the first device satisfies the privacy condition.

[0262] (2) If the second service identifier matches the first service identifier of the data service requested by the first device, it is determined that the first device satisfies the privacy condition, the first service identifier is used to identify the identifier of the service type corresponding to the data service requested by the first device, and the second service identifier related to the first data is included in the privacy parameter, which is used to indicate the identifier of the service allowed to use the first data. When the requested data service identifier matches the service identifier of the first data, the data service is authorized to be provided to the first device.

[0263] (3) If the identification information of the second device matches the identification information of the first device, it is determined that the first device satisfies the privacy condition. For example, the second device associated with the first data can be a UE-ID, a UE group-ID, a service identifier, etc., wherein the second device is a device allowed to use the first data. When the identification information corresponding to the first device is any identification information in the identification information corresponding to the second device, the first device can be authorized to use the data service.

[0264] (4) If the first domain information matches the second domain information of the first device at present, including time domain information matching, regional information matching or PLMN identifier matching, it is determined that the first device meets the privacy condition. For example, the domain information can include multiple types, such as time domain information, regional information and PLMN identifier information, etc. When the first device initiates the first request, the domain information corresponding to the first device at present can be carried in the first request. When the domain information matches the domain information corresponding to the first data, the first device is authorized to use the data service, wherein the domain information corresponding to the first data can be the domain range information allowed to use the first data.

[0265] It should be noted that the matching relationship between the above parameters can be an equal relationship, that is, the second purpose information is the same as the first purpose information, the second service identifier is the same as the first service identifier, the identifier information of the second device is the same as the identifier information of the first device, or the first domain information is the same as the second domain information. In some embodiments, the matching relationship between the above parameters can also be a containing relationship, that is, the privacy parameters corresponding to the privacy condition include multiple parameters, and the parameter corresponding to the first request is the same as one of the privacy parameters, then it is determined that the first request initiated by the first device meets the privacy condition. For example, the second purpose information associated with the first data includes AI prediction purpose, positioning service purpose and perception service purpose, the first purpose information corresponding to the first request is AI prediction purpose, it is determined that the purpose of the first request matches the purpose of the first data, and the first device meets the privacy condition; the second service identifier includes multiple service identifiers of multiple service types, and the first service identifier is any identifier in the multiple service identifiers, it is determined that the second service identifier matches the first service identifier, and the first device meets the privacy condition; the first domain information associated with the first data includes time domain information and regional information of shared data exposure, and when the time domain and region corresponding to the first request meet the time domain and region requirements of the first domain information, it is determined that the first device meets the privacy condition.

[0266] (5) The first sharing policy is used to indicate whether the first data needs to be further encrypted or decrypted before use. For example, the first sharing policy is also used to indicate the encryption state of the first data in the collection process. According to the first sharing policy, it can be determined whether the first network element 1021 has encrypted the first data in the data collection process, or whether the first data needs to be processed to meet the sharing policy.

[0267] (6) If the notification information and / or the verification information are included in the privacy parameter, the first network element 1021 performs notification and verification with the second network element 1022 based on the notification information and / or the verification information, and determines that the first request initiated by the first device satisfies the privacy condition in a case where the notification and / or the verification process is successful. For example, the second network element 1022 returns the first data and the terminal ID information of the terminal providing the first data in the privacy parameter, the first network element 1021 interacts with the terminal based on the terminal ID information, sends notification and / or verification information to the terminal to complete the notification and / or verification process, and determines that the first device satisfies the privacy condition in a case where the communication and / or verification process is successful.

[0268] (7) If the timing parameter of the timing device corresponding to the first data is included in the privacy parameter, the timing parameter is used to indicate the validity period of the first data, and the current privacy condition is determined in a case where the current first data is valid according to the timing parameter.

[0269] In some embodiments, the privacy parameter can include multiple privacy parameters, which correspond to a plurality of privacy conditions that need to be determined whether the first device satisfies simultaneously, and the first device is determined to satisfy the privacy condition in a case where the first device satisfies the plurality of privacy conditions simultaneously, and the first device is determined to not satisfy the privacy condition in a case where the first device does not satisfy any of the plurality of privacy conditions.

[0270] In step S2106, the first network element 1021 determines that the first device satisfies the privacy condition, and sends the second data to the first device according to the first data.

[0271] For example, the first network element 1021 sends the second data to the first device according to the first data in a case where the first network element 1021 determines that the first request initiated by the first device satisfies the privacy condition. The second data is shared data corresponding to a data service, the first network element 1021 generates the second data by performing security and privacy processing on the first data, and sends the second data to the first device.

[0272] In some embodiments, the second data includes shared data corresponding to a data service.

[0273] In some embodiments, the name of the second data is not limited, which is, for example, “shared data”, “privacy data”, “exposure data”, etc.

[0274] In some embodiments, the privacy parameter includes a first sharing policy, and the step S2106 includes:

[0275] The first network element 1021 performs security processing on the first data according to the first sharing policy to generate the second data.

[0276] The first network element 1021 sends the second data to the first device 101.

[0277] In an example, the privacy parameter includes a first sharing policy related to the first data, where the first sharing policy is used to indicate a sharing manner of the first data. The first network element 1021 performs security processing on the first data according to the first sharing policy, generates second data, and sends the second data to the first device. For example, the first network element 1021 can perform encryption protection or desensitization processing on the first data according to the first sharing policy, and generate the second data after security protection processing and send the second data to the first device 101.

[0278] In the above manner, the first request sent by the first device is received, the first request is used to request a data service, a second request is sent to the second network element according to the first request, the second request is used to request first information, the first information includes at least one of the following: the first data, the privacy parameter, the first information sent by the second network element is received, the first device satisfies the privacy condition is determined according to the privacy parameter, and the second data is sent to the first device according to the first data. Thus, a secure data service process is provided, and it is ensured that data transmission on a data plane meets privacy requirements.

[0279] In some embodiments, the names of information and the like are not limited to the names described in the embodiments, and terms such as “information”, “message”, “signal”, “signaling”, “report”, “configuration”, “indication”, “instruction”, “command”, “channel”, “parameter”, “domain”, “field”, “symbol”, “symbol”, “codebook”, “codeword”, “code point”, “bit”, “data”, “program”, “chip”, and the like can be replaced with each other.

[0280] In some embodiments, the terms “codebook”, “codeword”, and “precoding matrix” can be replaced with each other. For example, a codebook can be a collection of one or more codewords / precoding matrices.

[0281] In some embodiments, the terms “uplink”, “physical uplink”, and the like can be replaced with each other, the terms “downlink”, “physical downlink”, and the like can be replaced with each other, and the terms “side”, “sidelink”, “sidelink communication”, “sidelink communication”, “direct connection”, “direct connection link”, “direct connection communication”, “direct connection link communication”, and the like can be replaced with each other.

[0282] In some embodiments, the terms “downlink control information (DCI),” “downlink (DL) assignment,” “DL DCI,” “uplink (UL) grant,” “UL DCI,” and the like can be replaced with each other.

[0283] In some embodiments, the terms “physical downlink shared channel (PDSCH),” “DL data,” and the like can be replaced with each other, and the terms “physical uplink shared channel (PUSCH),” “UL data,” and the like can be replaced with each other.

[0284] In some embodiments, the terms “radio,” “wireless,” “radio access network (RAN),” “access network (AN),” “RAN-based,” and the like can be replaced with each other.

[0285] In some embodiments, the terms “search space,” “search space set,” “search space configuration,” “search space set configuration,” “control resource set (CORESET),” “CORESET configuration,” and the like can be replaced with each other.

[0286] In some embodiments, the terms “synchronization signal (SS),” “synchronization signal block (SSB),” “reference signal (RS),” “pilot,” “pilot signal,” and the like can be replaced with each other.

[0287] In some embodiments, the terms “time instant,” “time point,” “time,” “time location,” and the like can be replaced with each other, and the terms “time duration,” “time period,” “time window,” “window,” “time,” and the like can be replaced with each other.

[0288] In some embodiments, the terms “component carrier (CC),” “cell,” “frequency carrier,” “carrier frequency,” and the like can be replaced with each other.

[0289] In some embodiments, the terms “resource block (RB),” “physical resource block (PRB),” “sub-carrier group (SCG),” “resource element group (REG),” “PRB pair,” “RB pair,” “resource element (RE),” “sub-carrier,” and the like can be replaced with each other.

[0290] In some embodiments, the terms “wireless access scheme,” “waveform,” and the like can be replaced with each other.

[0291] In some embodiments, the terms “precoding,” “precoder,” “weight,” “precoding weight,” “quasi-co-location (QCL),” “transmission configuration indication (TCI) state,” “spatial relation,” “spatial domain filter,” “transmission power,” “phase rotation,” “antenna port,” “antenna port group,” “layer,” “the number of layers,” “rank,” “resource,” “resource set,” “resource group,” “beam,” “beam width,” “beam angular degree,” “antenna,” “antenna element,” “panel,” and the like can be replaced with each other.

[0292] In some embodiments, the terms “frame”, “radio frame”, “subframe”, “slot”, “sub-slot”, “mini-slot”, “symbol”, “symbol”, “transmission time interval (TTI)”, and the like can be replaced with each other.

[0293] In some embodiments, the terms “acquire”, “obtain”, “get”, “receive”, “transmit”, “bidirectional transmission”, “send and / or receive”, and the like can be replaced with each other, which can be interpreted as receiving from other subjects, acquiring from protocols, obtaining from higher layers, processing by itself, implementing autonomously, and the like.

[0294] In some embodiments, the terms “send”, “transmit”, “report”, “issue”, “transmit”, “bidirectional transmission”, “send and / or receive”, and the like can be replaced with each other.

[0295] In some embodiments, the terms “certain”, “preset”, “pre-set”, “set”, “indicated”, “certain”, “arbitrary”, “first”, and the like can be replaced with each other, and “certain A”, “preset A”, “pre-set A”, “set A”, “indicated A”, “certain A”, “arbitrary A”, “first A” can be interpreted as A specified in advance in protocols and the like, A obtained by setting, configuration, or indication, and the like, A specified, certain, arbitrary, or first, and the like, but are not limited thereto.

[0296] In some embodiments, determination or judgment can be made by a value represented by 1 bit (0 or 1), by a true or false value (Boolean value) represented by true or false, or by comparison of numerical values (for example, comparison with a predetermined value), but is not limited thereto.

[0297] In some embodiments, “not expecting to receive” can be interpreted as not receiving in time domain resources and / or frequency domain resources, or can be interpreted as not performing subsequent processing on the data and the like after receiving the data and the like; “not expecting to send” can be interpreted as not sending, or can be interpreted as sending but not expecting the receiving party to respond to the content of the sending.

[0298] The communication method related to the embodiments of the present disclosure can include at least one of steps S2101-S2106. For example, steps S2101-S2103 can be implemented as an independent embodiment, steps 2104-S2106 can be implemented as an independent embodiment, steps S2101+steps S2106 can be implemented as an independent embodiment, steps S2101+steps S2102+steps S2103 can be implemented as an independent embodiment, steps S2103+steps S2104 can be implemented as an independent embodiment, steps S2105+steps S2106 can be implemented as an independent embodiment, but the present disclosure is not limited thereto.

[0299] In some embodiments, steps S2101, S2103, S2104 and S2106 can be exchanged in order or executed simultaneously.

[0300] In some embodiments, steps S2102-S2103 are optional, and one or more of the steps can be omitted or replaced in different embodiments.

[0301] In some embodiments, other optional implementations can be described before or after the description of Figure 2.

[0302] Figure 3A is a flow diagram of a communication method according to an embodiment of the present disclosure. As shown in Figure 3A, the embodiments of the present disclosure relate to a communication method performed by a first network element, and the method comprises:

[0303] Step S3101, receiving a first request sent by a first device.

[0304] In some embodiments, the first request is used to request a data service.

[0305] Optional implementations of step S3101 can be found in the optional implementations of step S2101 of Figure 2 and other related parts of the embodiments related to Figure 2, which will not be described here.

[0306] Step S3102, sending a second request to a second network element according to the first request.

[0307] In some embodiments, the second request is used to request first information.

[0308] In some embodiments, the first information includes at least one of the following: first data, privacy parameters.

[0309] The optional implementation of step S3102 can refer to the optional implementation of step S2103 in FIG. 2 and other associated parts in the embodiments related to FIG. 2, which will not be repeated here.

[0310] Step S3103 receives the first information sent by the second network element.

[0311] The optional implementation of step S3103 can refer to the optional implementation of step S2104 in FIG. 2 and other associated parts in the embodiments related to FIG. 2, which will not be repeated here.

[0312] Step S3104 determines, according to the privacy parameter, that the first device meets the privacy condition, and sends the second data to the first device according to the first data.

[0313] The optional implementation of step S3104 can refer to the optional implementation of step S2106 in FIG. 2 and other associated parts in the embodiments related to FIG. 2, which will not be repeated here.

[0314] The communication method related to the embodiments of the present disclosure can include at least one of steps S3101-S3104. For example, step S3101 can be implemented as an independent embodiment, step S3102 can be implemented as an independent embodiment, step S3103 can be implemented as an independent embodiment, and step S3104 can be implemented as an independent embodiment, but is not limited thereto.

[0315] In some embodiments, steps S3101, S3102, S3103, and S3104 can be exchanged in order or executed simultaneously.

[0316] In some embodiments, step S3101 is optional, which can be omitted or replaced in different embodiments.

[0317] In some embodiments, step S3202 is optional, which can be omitted or replaced in different embodiments.

[0318] FIG. 3B is a flow diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 3B, the embodiments of the present disclosure relate to a communication method, which is executed by a first network element, and the above method includes:

[0319] Step S3201 receives a first request sent by a first device.

[0320] In some embodiments, the first request is used to request a data service.

[0321] The optional implementation of step S3201 can refer to the optional implementation of step S2101 in FIG. 2 and other associated parts in the embodiments related to FIG. 2, which will not be repeated here.

[0322] Step S3202, judging whether the first device is authorized to use the data service according to the first request.

[0323] The optional implementation of step S3202 can refer to the optional implementation of step S2102 in FIG. 2 and other associated parts in the embodiments related to FIG. 2, which will not be repeated here.

[0324] Step S3203, in response to determining that the first device is authorized to use the data service, sending a second request to a second network element.

[0325] The optional implementation of step S3203 can refer to the optional implementation of step S2103 in FIG. 2 and other associated parts in the embodiments related to FIG. 2, which will not be repeated here.

[0326] Step S3204, determining that the first device satisfies the privacy condition according to the first information, and sending second data to the first device according to the first data.

[0327] The optional implementation of step S3204 can refer to the optional implementation of step S2106 in FIG. 2 and other associated parts in the embodiments related to FIG. 2, which will not be repeated here.

[0328] The optional implementation of step S3204 can refer to the optional implementation of step S2106 in FIG. 2 and other associated parts in the embodiments related to FIG. 2, which will not be repeated here.

[0329] The communication method related to the embodiments of the present disclosure can include at least one of steps S3201-S3204. For example, step S3201 can be implemented as an independent embodiment, step S3202 can be implemented as an independent embodiment, step S3203 can be implemented as an independent embodiment, and step S3204 can be implemented as an independent embodiment, but is not limited thereto.

[0330] In some embodiments, steps S3201, S3202, S3203, and S3204 can be exchanged in order or executed simultaneously.

[0331] In some embodiments, step S3201 is optional, which can be omitted or replaced in different embodiments.

[0332] In some embodiments, step S3202 is optional, which can be omitted or replaced in different embodiments.

[0333] FIG. 3C is a flow diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 3C, the embodiments of the present disclosure relate to a communication method, which is performed by a first network element, and the above method comprises:

[0334] Step S3301, receiving the first request sent by the first device.

[0335] The optional implementation of step S3301 can refer to the optional implementation of step S2101 in FIG. 2 and other associated parts in the embodiments involved in FIG. 2, which will not be repeated here.

[0336] Step S3302, sending the second request to the second network element according to the first request.

[0337] The optional implementation of step S3302 can refer to the optional implementation of step S2103 in FIG. 2 and other associated parts in the embodiments involved in FIG. 2, which will not be repeated here.

[0338] Step S3303, receiving the first information sent by the second network element, the first information including at least one of the following: the first data, the privacy parameter.

[0339] The optional implementation of step S3303 can refer to the optional implementation of step S2104 in FIG. 2 and other associated parts in the embodiments involved in FIG. 2, which will not be repeated here.

[0340] Step S3304, determining whether the first device meets the privacy condition according to the privacy parameter.

[0341] The optional implementation of step S3304 can refer to the optional implementation of step S2105 in FIG. 2 and other associated parts in the embodiments involved in FIG. 2, which will not be repeated here.

[0342] Step S3305, determining that the first device meets the privacy condition, and sending the second data to the first device according to the first data.

[0343] The optional implementation of step S3305 can refer to the optional implementation of step S2106 in FIG. 2 and other associated parts in the embodiments involved in FIG. 2, which will not be repeated here.

[0344] The communication method involved in the embodiments of the present disclosure can include at least one of steps S3301-S3305. For example, step S3301 can be implemented as an independent embodiment, step S3302 can be implemented as an independent embodiment, step S3303 can be implemented as an independent embodiment, step S3304 can be implemented as an independent embodiment, and step S3304 can be implemented as an independent embodiment, but is not limited thereto.

[0345] In some embodiments, steps S3301, S3302, S3303, S3304, and S3305 can be exchanged in order or executed simultaneously.

[0346] In some embodiments, step S3301 is optional, which can be omitted or replaced in different embodiments.

[0347] In some embodiments, step S3302 is optional, which can be omitted or replaced in different embodiments.

[0348] FIG. 4 is a flow diagram of a communication method according to some embodiments of the present disclosure. As shown in FIG. 4, some embodiments of the present disclosure relate to a communication method, which is performed by a second network element, and the above method comprises:

[0349] In step S4101, a second request sent by a first network element is received.

[0350] Optional implementation of step S4101 can refer to optional implementation of step S2103 in FIG. 2 and other associated parts in embodiments related to FIG. 2, which will not be described here.

[0351] In step S4102, first information is sent to the first network element according to the second request.

[0352] Optional implementation of step S4101 can refer to optional implementation of step S2104 in FIG. 2 and other associated parts in embodiments related to FIG. 2, which will not be described here.

[0353] The communication method related to some embodiments of the present disclosure can comprise at least one of steps S4101-S4102. For example, step S4101 can be implemented as an independent embodiment, and step S4102 can be implemented as an independent embodiment, but is not limited thereto.

[0354] In some embodiments, the order of steps S4101 and S4102 can be exchanged or executed simultaneously.

[0355] In some embodiments, step S4101 is optional, which can be omitted or replaced in different embodiments.

[0356] In some embodiments, step S4102 is optional, which can be omitted or replaced in different embodiments.

[0357] FIG. 5 is a flow diagram of a communication method according to some embodiments of the present disclosure. As shown in FIG. 5, some embodiments of the present disclosure relate to a communication method, which is performed by a first device, and the above method comprises:

[0358] In step S5101, a first request is sent to a first network element.

[0359] Optional implementation of step S5101 can refer to optional implementation of step S2101 in FIG. 2 and other associated parts in embodiments related to FIG. 2, which will not be described here.

[0360] Step S5102, receiving the second data sent by the first network element.

[0361] The optional implementation of step S5102 can refer to the optional implementation of step S2106 in FIG. 2 and other associated parts in the embodiments involved in FIG. 2, which will not be repeated here.

[0362] The communication method involved in the embodiments of the present disclosure can include at least one of steps S5101-S5102. For example, step S5101 can be implemented as an independent embodiment, and step S5102 can be implemented as an independent embodiment, but is not limited thereto.

[0363] In some embodiments, the order of steps S5101 and S5102 can be exchanged or executed simultaneously.

[0364] In some embodiments, step S5101 is optional, and can be omitted or replaced in different embodiments.

[0365] In some embodiments, step S5102 is optional, and can be omitted or replaced in different embodiments.

[0366] FIG. 6 is a flow diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 6, the embodiments of the present disclosure involve a communication method, and the above method includes:

[0367] Step S6101, the UE or the NF network element or the AS as a data consumer, sends a data service request to request a data sharing service.

[0368] In some embodiments, the data service request can be a service request dedicated to the data sharing service. The data service request can also be a service request for other functions (for example: artificial intelligence, sensing, perception, etc.), in which the shared data can be used as the input of the service.

[0369] Step S6102, after receiving the data service request sent by the data consumer, the NWDAF network element or the DPMF network element determines whether the data consumer is authorized to use the data sharing service.

[0370] In some embodiments, the data consumer is a UE, and the authorization mechanism of the UE is a NWDAF network element or a DPMF network element that determines whether the UE is authorized to obtain the right to use the data sharing service based on the subscription data of the UE. Alternatively, the data consumer can also be an NF network element, and the authorization mechanism of the NF network element consumer can reuse the SBA (Service Based Architecture) security mechanism defined in TS 33.501 protocol to determine whether the NF network element is authorized to obtain the right to use the data sharing service.

[0371] Step S6103: When it is determined that the UE or the NF network element consumer is authorized to use the data sharing service, the NWDAF network element or the DPMF network element sends a data request to the ADRF network element or the DPSF network element.

[0372] For example, the NWDAF network element or the DPMF network element authorizes the data service request of the UE or the NF network element consumer, and when it is determined that the UE or the NF network element consumer is authorized to use the data sharing service, the NWDAF network element or the DPMF network element sends a data request to the ADRF network element or the DPSF network element.

[0373] Step S6104: The ADRF network element or the DPSF network element sends the shared data and the related privacy condition parameter to the NWDAF network element or the DPMF network element.

[0374] For example, the privacy condition parameter is used to determine whether the data service request of the UE or the NF network element consumer meets the privacy condition, and in a case where it is determined that the UE or the NF network element consumer meets the privacy condition based on the privacy condition parameter, the shared data is sent to the UE or the NF network element consumer. Alternatively, in a case where it is determined that the UE or the NF network element consumer meets the privacy condition, the shared data is transformed (for example, encrypted, desensitized, etc.) according to the privacy condition parameter, and the transformed shared data is sent to the UE or the NF network element consumer.

[0375] Step S6105: The NWDAF network element or the DPMF network element determines whether the shared data can be exposed to the UE or the NF network element consumer.

[0376] For example, the NWDAF network element or the DPMF network element can determine whether to provide the data sharing service to the UE or the NF network element consumer in the following manner:

[0377] (1) The purpose is provided in the privacy condition parameter, and the NWDAF network element or the DPMF network element checks whether the purpose corresponding to the service request matches the purpose related to the shared data. If the purpose related to the shared data is the same as the purpose corresponding to the service request, the shared data is authorized to be provided to the UE or the NF network element consumer. For example, the purpose includes perception, sharing, positioning, etc.

[0378] (2) If the identity of the data consumer is provided in the privacy condition parameter, the NWDAF network element or the DPMF network element checks whether the UE-ID, NF network element consumer-ID or service / task request ID information matches the UE-ID, UE group ID, NF network element consumer ID or service / task associated with the shared data contained in the data consumer parameter.

[0379] (3) If the sharing domain is provided in the privacy condition parameter, the NWDAF network element or the DPMF network element checks whether the PLMN (Public Land Mobile Network) ID or geographic location information is contained in the sharing domain parameter related to the shared data.

[0380] (4) If the sharing policy is provided in the privacy condition parameter, the NWDAF network element or the DPMF network element checks whether the sharing policy of the service request matches the sharing policy related to the shared data. For example, if the sharing policy indicates that encryption protection or desensitization is required, the NWDAF network element or the DPMF network element needs to perform the encryption protection or desensitization mechanism to encrypt or desensitize the shared data before sending the shared data to the UE or the NF network element consumer.

[0381] (5) If the use notification and verification is provided in the privacy condition parameter, the NWDAF network element or the DPMF network element needs to interact with the UE providing the shared data for notification and verification. If the use notification and verification fails, the privacy check fails, and the NWDAF network element or the DPMF network element does not provide the shared data to the UE or the NF network element consumer.

[0382] (6) If the timer is provided in the privacy condition parameter, the NWDAF network element or the DPMF network element checks whether the shared data is still valid according to the timer upon receiving the service request.

[0383] Step S6106, if the above privacy check passes, the NWDAF network element or the DPMF network element provides the shared data to the UE or the NF network element consumer.

[0384] In the above manner, it is ensured that the shared data service on the data plane meets the privacy requirements of data security, and a data service process of safely and publicly sharing data to the UE or the NF network element consumer is provided. Thus, under the premise of ensuring data privacy and data security, the difficulty of data acquisition is reduced, and the data service efficiency and data consumption experience are improved.

[0385] The embodiments of the present disclosure further provide a device for implementing any of the above methods, for example, a device comprising units or modules for implementing the steps performed by the terminal in any of the above methods. For another example, another device is further provided, comprising units or modules for implementing the steps performed by the network equipment (such as an access network device, a core network function node, a core network device, etc.) in any of the above methods.

[0386] It should be understood that the division of each unit or module in the above device is only a logical function division, and all or part of the units or modules can be integrated into one physical entity or physically separated in actual implementation. In addition, the units or modules in the device can be implemented in the form of processor invoking software: for example, the device comprises a processor connected with a memory, the memory stores instructions, and the processor invokes the instructions stored in the memory to implement any of the above methods or to implement the functions of each unit or module of the device, wherein the processor is a general processor such as a central processing unit (CPU) or a microprocessor, and the memory is a memory in the device or a memory outside the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuit, and the functions of part or all of the units or modules can be implemented by the design of the hardware circuit, and the hardware circuit can be understood as one or more processors; for example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC), and the functions of part or all of the units or modules are implemented by the design of the logical relationship between the elements in the circuit; for another example, in another implementation, the hardware circuit is a programmable logic device (PLD), and taking a field programmable gate array (FPGA) as an example, it can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by a configuration file, so as to implement the functions of part or all of the units or modules. All units or modules of the above device can be implemented in the form of processor invoking software, or all units or modules can be implemented in the form of hardware circuit, or part of the units or modules are implemented in the form of processor invoking software, and the remaining part is implemented in the form of hardware circuit.

[0387] In the embodiments of the present disclosure, the processor is a circuit with signal processing capability. In one implementation, the processor can be a circuit with instruction reading and running capability, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), a digital signal processor (DSP), or the like. In another implementation, the processor can implement certain functions through a logical relationship of a hardware circuit, and the logical relationship of the hardware circuit is fixed or can be reconfigured. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In the reconfigurable hardware circuit, the processor loads a configuration document to implement the hardware circuit configuration. It can be understood that the processor loads instructions to implement the functions of the above part or all units or modules. In addition, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), and the like.

[0388] FIG. 7 is a structural schematic diagram of the first network element according to the embodiments of the present disclosure. As shown in FIG. 7, the first network element 1021 can include at least one of a transceiver module 7101, a transceiver module 7102, a transceiver module 7103, and a transceiver module 7104. In some embodiments, the transceiver module 7101 is configured to receive a first request sent by a first device, the first request being used to request a data service, the transceiver module 7102 is configured to send a second request to a second network element according to the first request, the second request being used to request first information, the first information including at least one of the following: first data, a privacy parameter; the transceiver module 7103 is configured to receive the first information sent by the second network element; and the transceiver module 7104 is configured to determine that the first device satisfies a privacy condition according to the privacy parameter, and send second data to the first device according to the first data. Optionally, the transceiver module 7101, the transceiver module 7102, the transceiver module 7103, and the transceiver module 7104 are used to perform at least one of the communication steps (for example, steps S2102, S2103, S2105, and S2106, but not limited to this) of sending and / or receiving performed by the first network element 1021 in any one of the above methods, and details are not described herein.

[0389] In some embodiments, the transceiver module can include a sending module and / or a receiving module, which can be separate or integrated together. Optionally, the transceiver module can be mutually replaced with a transceiver.

[0390] Optionally, the first request includes at least one of the following:

[0391] a first service identifier of the data service;

[0392] a first identifier, the first identifier including an identifier of the first device and / or an identifier of a group to which the first device belongs;

[0393] a second identifier, the second identifier including a public land mobile network (PLMN) identifier of the first device;

[0394] a first area, the first area including an area in which the first device is located;

[0395] first destination information corresponding to the first request.

[0396] Optionally, the transceiver module 7102 includes:

[0397] a determination sub-module configured to determine whether the first device is authorized to use the data service according to the first request;

[0398] a determination sub-module configured to send the second request to the second network element in response to determining that the first device is authorized to use the data service.

[0399] Optionally, the determining sub-module is configured to:

[0400] According to the first request, obtain subscription data corresponding to the first device;

[0401] According to the subscription data, determine whether the first device is authorized to use the data service.

[0402] Optionally, the determining sub-module is configured to:

[0403] According to the first request, determine whether the first device is authorized to use the data service through a service-based architecture (SBA) security mechanism.

[0404] Optionally, the privacy parameter includes at least one of:

[0405] Second purpose information related to the first data;

[0406] A third identifier, the third identifier including at least one of: an identifier of the second device, an identifier of a group to which the second device belongs, and a second service identifier related to the first data, the second device being a device allowed to use the first data;

[0407] First domain information related to the first data, the first domain information including at least one of: time domain information, geographical information, and PLMN information;

[0408] A first sharing policy related to the first data;

[0409] Notification information and / or verification information;

[0410] Timing parameters of a timing device related to the first data.

[0411] Optionally, the privacy condition includes at least one of:

[0412] The second purpose information matches first purpose information corresponding to the first request;

[0413] The second service identifier matches a first service identifier;

[0414] The identifier information of the second device matches the identifier information of the first device;

[0415] The first domain information matches second domain information corresponding to the first device;

[0416] The first request matches the first sharing policy;

[0417] Notification and / or verification between the first network element and a third device are successful, the third device being a device that collects the first data;

[0418] According to the timing parameters, determine that the first data is valid.

[0419] Optionally, the privacy parameter comprises a first sharing policy, and the transceiver 7104 is further configured to:

[0420] perform security processing on the first data according to the first sharing policy to generate second data;

[0421] send the second data to the first device.

[0422] Optionally, the first device comprises a terminal or a network function (NF) network element.

[0423] FIG. 8 is a structural schematic diagram of a second network element according to an embodiment of the present disclosure. As shown in FIG. 8, the second network element 1022 can comprise at least one of a transceiver 8101 and a transceiver 8102.

[0424] In some embodiments, the transceiver 8101 is configured to receive a second request sent by the first network element, the second request being determined by the first network element according to a first request sent by the first device, the first request being used to request a data service, and the second request being used to request first information, the first information comprising at least one of the following: the first data and the privacy parameter, and the transceiver 8102 is configured to send the first information to the first network element. Optionally, the transceiver 8101 and the transceiver 8102 are used to perform at least one of the communication steps (for example, step S2104, but not limited thereto) of sending and / or receiving performed by the second network element 1022 in any of the above methods, and details are not described herein again.

[0425] In some embodiments, the transceiver can comprise a sending module and / or a receiving module, and the sending module and the receiving module can be separate or integrated together. Optionally, the transceiver can be replaced by a transceiver.

[0426] Optionally, the first request comprises at least one of the following:

[0427] a first service identifier of the data service;

[0428] a first identifier, the first identifier comprising an identifier of the first device and / or an identifier of a group to which the first device belongs;

[0429] a second identifier, the second identifier comprising a PLMN identifier of the first device;

[0430] a first area, the first area comprising an area in which the first device is located;

[0431] first destination information corresponding to the first request.

[0432] Optionally, the privacy parameter comprises at least one of the following:

[0433] second destination information related to the first data;

[0434] a third identifier, the third identifier comprising at least one of an identifier of the second device, an identifier of a group to which the second device belongs, and a second service identifier related to the first data, the second device being a device allowed to use the first data;

[0435] a first domain information related to the first data, the first domain information comprising at least one of time domain information, geographical information, and PLMN information;

[0436] a first sharing policy related to the first data;

[0437] notification information and / or verification information;

[0438] a timing parameter of a timing device related to the first data.

[0439] Optionally, the first device comprises a terminal or a NF network element.

[0440] FIG. 9 is a structural schematic diagram of a first device according to an embodiment of the present disclosure. As shown in FIG. 9, the first device 101 can comprise at least one of a transceiver module 9101 and a transceiver module 9102.

[0441] In some embodiments, the transceiver module 9101 is configured to send a first request to a first network element, the first request being used to request a data service, and the transceiver module 9102 is configured to receive second data sent by the first network element. Optionally, the transceiver module 9101 and the transceiver module 9102 are used to perform at least one of the communication steps (for example, step S2101, but not limited thereto) of sending and / or receiving performed by the first device 101 in any of the above methods, and details are not described herein again.

[0442] In some embodiments, the transceiver module can comprise a sending module and / or a receiving module, and the sending module and the receiving module can be separate or integrated together. Optionally, the transceiver module can be replaced by a transceiver.

[0443] Optionally, the first request comprises at least one of:

[0444] a first service identifier of the data service;

[0445] a first identifier, the first identifier comprising an identifier of the first device and / or an identifier of a group to which the first device belongs;

[0446] a second identifier, the second identifier comprising a PLMN identifier of the first device;

[0447] a first area, the first area comprising an area in which the first device is located;

[0448] first destination information corresponding to the first request.

[0449] Optionally, the first device comprises a terminal or a NF network element.

[0450] FIG. 10A is a structural schematic diagram of a communication device 10100 according to an embodiment of the present disclosure. The communication device 10100 can be a network device (for example, an access network device, a core network device, etc.), a terminal (for example, a user equipment, etc.), a chip, a chip system, or a processor supporting the network device to implement any of the above methods, or a chip, a chip system, or a processor supporting the terminal to implement any of the above methods. The communication device 10100 can be used to implement the methods described in the above method embodiments, and details can be referred to the descriptions in the above method embodiments.

[0451] As shown in FIG. 10A, the communication device 10100 includes one or more processors 10101. The processor 10101 can be a general purpose processor or a special purpose processor, for example, a baseband processor or a central processing unit. The baseband processor can be used to process communication protocols and communication data, and the central processing unit can be used to control the communication device (for example, a base station, a baseband chip, a terminal device, a terminal device chip, a DU or a CU, etc.), execute programs, and process data of the programs. Optionally, the communication device 10100 is configured to execute any of the above methods. Optionally, the one or more processors 10101 are configured to invoke instructions to enable the communication device 10100 to execute any of the above methods.

[0452] In some embodiments, the communication device 10100 further includes one or more transceivers 10102. When the communication device 10100 includes the one or more transceivers 10102, the transceiver 10102 performs at least one of the communication steps (for example, step S201, but not limited to this) in the above methods, and the processor 10101 performs at least one of the other steps. In an optional embodiment, the transceiver can include a receiver and / or a transmitter, which can be separate or integrated together. Optionally, the terms of transceiver, transceiving unit, transceiver, transceiving circuit, interface circuit, interface, etc. can be replaced with each other, and the terms of transmitter, transmitting unit, transmitter, transmitting circuit, etc. can be replaced with each other, and the terms of receiver, receiving unit, receiver, receiving circuit, etc. can be replaced with each other.

[0453] In some embodiments, the communication device 10100 also includes one or more memories 10103 for storing data. Optionally, all or a portion of the memory 10103 can also reside in the communication device 10100. In some embodiments, the communication device 10100 can include one or more interface circuits 10104. Optionally, the interface circuit 10104 can be used to receive data from the memory 10103 or from another device or system, or to send data to the memory 10103 or to another device or system. For example, the interface circuit 10104 can receive data in packets, each packet having a header and a payload.

[0454] The communication device 10100 described in the above embodiments can be a network device or a terminal, but the scope of the communication device 10100 described in the present disclosure is not limited thereto, and the structure of the communication device 10100 can not be limited by FIG. 10A. The communication device can be a standalone device or can be part of a larger device. For example, the communication device can be: (1) a standalone integrated circuit (IC), or a chip, or a chip system or subsystem; (2) a set of one or more ICs, which can optionally also include a storage component for storing data, programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, a terminal device, a smart terminal device, a cellular phone, a wireless device, a handset, a mobile unit, a vehicle-mounted device, a network device, a cloud device, an artificial intelligence device, etc.; (6) other devices, etc.

[0455] FIG. 10B is a structural schematic diagram of a chip 10200 according to an embodiment of the present disclosure. For the case where the communication device 10100 is a chip or a chip system, the structural schematic diagram of the chip 10200 shown in FIG. 10B can be referred to, but is not limited thereto.

[0456] The chip 10200 includes one or more processors 10201. The chip 10200 is configured to perform any of the above methods.

[0457] In some embodiments, the chip 10200 further includes one or more interface circuits 10202. Optionally, the terms interface circuit, interface, transceiver pin, etc. can be replaced by each other. In some embodiments, the chip 10200 further includes one or more memories 10203 for storing data. Optionally, all or part of the memory 10203 can be outside the chip 10200. Optionally, the interface circuit 10202 is connected with the memory 10203, the interface circuit 10202 can be used to receive data from the memory 10203 or other devices, the interface circuit 10202 can be used to send data to the memory 10203 or other devices. For example, the interface circuit 10202 can read the data stored in the memory 10203 and send the data to the processor 10201.

[0458] In some embodiments, the interface circuit 10202 performs at least one of the communication steps (for example, step S201, but not limited to) such as sending and / or receiving in the above method. The interface circuit 10202 performing the communication steps such as sending and / or receiving in the above method means that the interface circuit 10202 performs data interaction between the processor 10201, the chip 10200, the memory 10203 or the transceiver device. In some embodiments, the processor 10201 performs at least one of the other steps.

[0459] The modules and / or devices described in each embodiment of the virtual device, the physical device, the chip, etc. can be combined or separated as appropriate. Optionally, part or all of the steps can also be performed by multiple modules and / or devices, which are not limited here.

[0460] The disclosure also proposes a storage medium, and the above storage medium stores instructions, when the above instructions run on the communication device 10100, the communication device 10100 executes any one of the above methods. Optionally, the above storage medium is an electronic storage medium. Optionally, the above storage medium is a computer readable storage medium, but is not limited to this, it can also be a storage medium readable by other devices. Optionally, the above storage medium can be a non-transitory storage medium, but is not limited to this, it can also be a transitory storage medium.

[0461] The disclosure also proposes a program product, and the above program product is executed by the communication device 10100, so that the communication device 10100 executes any one of the above methods. Optionally, the above program product is a computer program product.

[0462] The disclosure also proposes a computer program, when it runs on a computer, so that the computer executes any one of the above methods.

Claims

1. A communication method characterized by comprising: The method is executed by a first network element, and the method comprises: receiving a first request sent by a first device, the first request being used for requesting a data service; sending a second request to a second network element according to the first request, the second request being used for requesting first information, the first information comprising at least one of the following: first data, a privacy parameter; receiving the first information sent by the second network element; determining that the first device satisfies a privacy condition according to the privacy parameter, and sending second data to the first device according to the first data.

2. The method of claim 1, wherein, The first request comprises at least one of the following: a first service identifier of the data service; a first identifier, the first identifier comprising an identifier of the first device and / or an identifier of a group to which the first device belongs; a second identifier, the second identifier comprising a public land mobile network (PLMN) identifier of the first device; a first area, the first area comprising an area in which the first device is located; first destination information corresponding to the first request.

3. The method of claim 1, wherein, The sending of the second request to the second network element according to the first request comprises: determining whether the first device is authorized to use the data service according to the first request; in response to determining that the first device is authorized to use the data service, sending the second request to the second network element.

4. The method of claim 3, wherein, The determining of whether the first device is authorized to use the data service according to the first request comprises: obtaining subscription data corresponding to the first device according to the first request; determining whether the first device is authorized to use the data service according to the subscription data.

5. The method of claim 3, wherein, The determining of whether the first device is authorized to use the data service according to the first request comprises: determining whether the first device is authorized to use the data service by a service-based architecture (SBA) security mechanism according to the first request.

6. The method according to any one of claims 1-5, characterized in that, The privacy parameter comprises at least one of the following: second destination information related to the first data; a third identifier, the third identifier comprising at least one of the following: an identifier of a second device, an identifier of a group to which the second device belongs, and a second service identifier related to the first data, the second device being a device allowed to use the first data; first domain information related to the first data, the first domain information comprising at least one of the following: time domain information, regional information, and PLMN information; a first sharing policy related to the first data; notification information and / or verification information; a timing parameter of a timing device related to the first data.

7. The method according to any one of claims 1 to 6, characterized in that, The privacy condition comprises at least one of the following: the second destination information related to the first data matches first destination information corresponding to the first request; an identifier of a group to which the second device belongs and the second service identifier related to the first data match the first service identifier; identifier information of the second device matches identifier information of the first device; first domain information related to the first data matches second domain information corresponding to the first device; the first sharing policy related to the first data matches the first request; notification and / or verification between the first network element and a third device are successful, the third device being a device that collects the first data; The first data is determined to be valid according to a timing parameter of a timing device related to the first data.

8. The method according to any one of claims 1-6, characterized in that, The privacy parameter comprises the first sharing policy, and the sending of the second data to the first device according to the first data comprises: safely processing the first data according to the first sharing policy to generate the second data; sending the second data to the first device.

9. A communication method characterized by comprising: The method is performed by a second network element, and the method comprises: receiving a second request sent by a first network element, the second request being determined by the first network element according to a first request sent by a first device, the first request being used to request a data service, and the second request being used to request first information, the first information comprising at least one of the following: first data and a privacy parameter; sending the first information to the first network element.

10. The method of claim 9, wherein, The first request comprises at least one of the following: a first service identifier of the data service; a first identifier, the first identifier comprising an identifier of the first device and / or an identifier of a group to which the first device belongs; a second identifier, the second identifier comprising a PLMN identifier of the first device; a first area, the first area comprising an area in which the first device is located; first destination information corresponding to the first request.

11. The method according to any one of claims 9-10, characterized in that, The privacy parameter comprises at least one of the following: second destination information related to the first data; a third identifier, the third identifier comprising at least one of the following: an identifier of a second device, an identifier of a group to which the second device belongs, and a second service identifier related to the first data, the second device being a device allowed to use the first data; first domain information related to the first data, the first domain information comprising at least one of the following: time domain information, regional information, and PLMN information; a first sharing policy related to the first data; notification information and / or verification information; a timing parameter of a timing device related to the first data.

12. A communication method characterized by comprising: The method is performed by a first device, and the method comprises: sending a first request to a first network element, the first request being used to request a data service; receiving second data sent by the first network element.

13. The method of claim 12, wherein, The first request comprises at least one of the following: a first service identifier of the data service; a first identifier, the first identifier comprising an identifier of the first device, or an identifier of a group to which the first device belongs; a second identifier, the second identifier comprising a PLMN identifier of the first device; a first area, the first area comprising an area in which the first device is located; first destination information corresponding to the first request.

14. A first network element, characterized by, comprises: a transceiver module configured to receive a first request sent by a first device, the first request being used to request a data service; the transceiver module is further configured to send a second request to a second network element according to the first request, the second request being used to request first information, the first information comprising at least one of the following: first data and a privacy parameter; the transceiver module is further configured to receive the first information sent by the second network element; the transceiver module is further configured to determine that the first device satisfies a privacy condition according to the privacy parameter, and send second data to the first device according to the first data.

15. A second network element, characterized by comprises: The transceiver module is configured to receive a second request sent by the first network element, the second request being determined by the first network element according to a first request sent by the first device, the first request being used to request a data service, and the second request being used to request first information, the first information including at least one of the following: first data and a privacy parameter. The transceiver module is further configured to send the first information to the first network element.

16. A first device, comprising: The method comprises: The transceiver module is configured to send a first request to a first network element, the first request being used to request a data service. The transceiver module is further configured to receive second data sent by the first network element.

17. A first network element, characterized by The method comprises: One or more processors; The first network element is configured to perform the communication method of any one of claims 1-8.

18. A second network element, characterized by The method comprises: One or more processors; The second network element is configured to perform the communication method of any one of claims 9-11.

19. A core network device, comprising: The method comprises a first network element and a second network element, wherein the first network element is configured to implement the communication method of any one of claims 1-8, and the second network element is configured to implement the communication method of any one of claims 9-11.

20. A first device, comprising: The method comprises: One or more processors; The first device is configured to perform the communication method of any one of claims 12-13.

21. A communication system, characterized by The method comprises a first device and a core network device, the core network device comprising a first network element and a second network element, wherein the first network element is configured to implement the communication method of any one of claims 1-8, the second network element is configured to implement the communication method of any one of claims 9-11, and the first device is configured to implement the communication method of any one of claims 12-13.

22. A storage medium, the storage medium storing instructions, wherein, When the instructions run on the communication device, the communication device is caused to perform the communication method of any one of claims 1-8, the communication method of any one of claims 9-11, or the communication method of any one of claims 12-13.

Citation Information

Patent Citations

  • Positioning method, device and system and storage medium

    CN114786121A

  • Data analysis method and device, electronic equipment and storage medium

    CN114916007A

  • Communication method, device and system

    CN116210253A

  • Privacy protection method and device, terminal, node and storage medium

    CN117295063A

  • Shared service establishment method and related product

    WO2022227587A1