Communication method and communication apparatus
By verifying and managing access requests for sensing results in the communication system, and utilizing shared keys, short message service authorization codes, and token mechanisms, the problem of secure access to sensing results is solved, and the secure opening and protection against misuse of sensing information are achieved.
Patent Information
- Application Number
- PCT/CN2025/098675
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-06-21
- Filing Date
- 2025-05-30
- Publication Date
- 2025-12-26
AI Technical Summary
In existing communication systems, there is no effective solution for how to securely access sensing results and prevent the misuse of sensing information.
By verifying access requests for the sensing results, it is ensured that only authorized devices can access the relevant sensing results. Shared keys, SMS service authorization codes, and token mechanisms are used to verify the identity and permissions of devices, and the access permission list is dynamically adjusted to adapt to different scenario requirements.
It enables the opening of perception results based on device information and permissions, improves the security of perception information, and avoids the abuse and invalid access of perception information.
Smart Images

Figure CN2025098675_26122025_PF_FP_ABST
Abstract
Description
Communication methods and communication devices
[0001] This application claims priority to Chinese Patent Application No. 202410817568.6, filed on June 21, 2024, entitled "Communication Method and Communication Apparatus", the entire contents of which are incorporated herein by reference. Technical Field
[0002] This application relates to the field of communications, specifically to a communication method and a communication device. Background Technology
[0003] With technological advancements, communication systems are considering incorporating sensing technology, a technology that integrates communication and perception. For example, communication devices based on sensing technology can perform sensing operations and acquire sensing results. The applications of these sensing results can be diverse, such as forming control strategies to achieve functions like intruder detection, water level monitoring, and traffic risk warnings. However, in this scenario, there is currently no corresponding solution for how to access the sensing results. Summary of the Invention
[0004] This application provides a communication method and a communication device to enable secure access to sensing results.
[0005] In a first aspect, a communication method is provided, the method comprising: receiving a first message from a first device, the first message being used to request access to a perception result associated with a first perception parameter; performing a first verification on the first perception parameter; and if the first verification passes, sending the first perception result associated with the first perception parameter to the first device.
[0006] For example, the communication method can be implemented by a second network element, or by modules, units, processors, circuits, chips, or chip systems included in the second network element. Optionally, the second network element can be a network exposure function (NEF) network element.
[0007] For example, performing a first verification on the first sensing parameter can be replaced by performing a first verification on the first message, or performing a first verification to determine whether to send the first sensing result associated with the first sensing parameter to the first device.
[0008] It should be understood that the above-mentioned first perception result can be the result obtained by performing perception based on the first perception parameters.
[0009] In this embodiment of the application, by verifying the access request (i.e. the first message) of the sensing result, the first sensing result is returned when the verification passes, and the first sensing result is not returned when the verification fails. This helps to open the sensing result based on different access permissions, thereby helping to avoid the abuse of sensing information.
[0010] In some embodiments, performing a first verification on the first sensing parameter includes: verifying whether the first sensing parameter corresponds to the information of the first device; if the first verification passes, sending a first sensing result associated with the first sensing parameter to the first device includes: if the first sensing parameter corresponds to the information of the first device, sending the first sensing result to the first device.
[0011] It should be understood that the correspondence between the first sensing parameter and the information of the first device can be replaced with the correspondence between the first sensing parameter and the first device.
[0012] This application embodiment verifies whether the information of the first sensing parameter corresponds to that of the first device to determine whether to send the first sensing result associated with the first sensing parameter to the first device. This helps to realize the opening of sensing results at the granularity of requesting the correspondence between the sensing result and the sensing parameter.
[0013] In some embodiments, the correspondence between the first sensing parameter and the information of the first device indicates that the first device is a device that is allowed to access the sensing results associated with the first sensing parameter.
[0014] For example, the correspondence between a first sensing parameter and a first device can be verified based on the sensing parameters and the information of the devices corresponding to those sensing parameters. For instance, the correspondence between a first sensing parameter and a first device can be verified based on a first list, or in other words, the first device can be verified based on the first list to determine whether it is a device authorized to access the sensing results associated with the first sensing parameter. The first list may include one or more sensing parameters, and each of the one or more sensing parameters corresponds to one or more devices (or information about one or more devices).
[0015] If one or more of the above sensing parameters include the first sensing parameter, and the information of one or more devices corresponding to the first sensing parameter includes the information of the first device, then the first sensing parameter corresponds to the information of the first device.
[0016] If one or more of the above sensing parameters do not include the first sensing parameter, then the first sensing parameter does not correspond to the information of the first device.
[0017] If one or more of the above sensing parameters include the first sensing parameter, and the information of one or more devices corresponding to the first sensing parameter does not include the information of the first device, then the first sensing parameter does not correspond to the information of the first device.
[0018] For example, the first list can be dynamically indicated, which helps to flexibly adapt to different use cases or user needs. For example, the first list can be pre-configured for ease of implementation. As an example, the first list can be pre-configured; changes, deletions, or additions to the content of the first list can be implemented through dynamic indication.
[0019] For example, the first list may include sensing parameters and information about the devices corresponding to the sensing parameters.
[0020] For example, the first list may include sensing parameters, information about the devices corresponding to the sensing parameters, and information about the requesting devices for the sensing parameters. The requesting device for the sensing parameters mentioned here can be understood as the device that requests to perform sensing based on the sensing parameters. The information of the requesting device for the sensing parameters can be used, if the first verification passes, to determine the sensing result associated with the first sensing parameter that the first device is allowed to access, i.e., the first sensing result.
[0021] In some embodiments, the correspondence between the first sensing parameter and the information of the first device indicates that the first device is a device that requests to perform sensing based on the first sensing parameter.
[0022] For example, the correspondence between a first sensing parameter and the information of a first device can be verified based on the sensing parameters and the information of the device corresponding to the sensing parameters. Here, the device corresponding to the sensing parameter can be the device that requests to perform sensing based on the sensing parameter. For instance, the correspondence between the first sensing parameter and the first device can be verified based on a second list. The second list may include one or more sensing parameters, and each of the one or more sensing parameters corresponds to one or more devices (or information about one or more devices).
[0023] If one or more of the above sensing parameters include the first sensing parameter, and the information of one or more devices corresponding to the first sensing parameter includes the information of the first device, then the first sensing parameter corresponds to the information of the first device.
[0024] If one or more of the above sensing parameters do not include the first sensing parameter, then the first sensing parameter does not correspond to the information of the first device.
[0025] If one or more of the above sensing parameters include the first sensing parameter, and the information of one or more devices corresponding to the first sensing parameter does not include the information of the first device, then the first sensing parameter does not correspond to the information of the first device.
[0026] In this embodiment of the application, apart from the device that requests to perform sensing based on the first sensing parameter, other devices cannot access the sensing results associated with the first sensing parameter, thereby helping to improve the security of the sensing results and avoid the abuse of the sensing results.
[0027] In some embodiments, before receiving the first message from the first device, the method further includes: receiving a second message from the first device, the second message being used to request to perform sensing based on the first sensing parameters; and recording, based on the second message, the correspondence between the first sensing parameters and the first device.
[0028] For example, in response to the second message, the correspondence between the first sensing parameter and the first device can be recorded. For instance, in response to the second message, the aforementioned second list can be generated or updated.
[0029] In some embodiments, recording the correspondence between the first sensing parameters and the first device according to the second message includes: sending a third message to a first network element according to the second message, the third message being used to request the execution of sensing according to the first sensing parameters; receiving a response from the first network element to the third message; and if the response indicates that the sensing performed according to the first sensing parameters was successful, recording the correspondence between the first sensing parameters and the first device.
[0030] In response to the third message, if the perception of the first perception parameter is successful, the first perception parameter is recorded as corresponding to the first device. This ensures that after the first verification is passed, the first device can obtain the perception result associated with the first perception parameter, thereby helping to avoid invalid access to the perception result.
[0031] In some embodiments, recording the correspondence between the first sensing parameter and the first device according to the second message includes: decrypting the second message using a shared key between the terminal device and the terminal device; if the decryption result includes information about the first device, then recording the correspondence between the first sensing parameter and the first device.
[0032] For example, if the identifier in the decryption result of the second message indicates the first device, that is, the identifier in the decryption result of the second message is the same as the identifier of the first device, then the first sensing parameter is recorded as corresponding to the first device.
[0033] The aforementioned terminal device is the device that initiates the perception request. For example, the terminal device may be separate from the first device, with the terminal device sending the second message through the first device; or, the terminal device may be integrated with the first device, meaning the first device is deployed on the terminal device.
[0034] For example, the shared key mentioned above can be a shared key between the core network and the terminal device. As another example, the shared key can be a shared key between the second network element and the terminal device. As yet another example, the shared key can be a shared key between any network element in the core network and the terminal device (which can be understood as a public shared key between multiple network elements in the core network and the terminal device). This public shared key can be stored in a server or in a network element, and the second network element can obtain the public shared key from the server or a network element before decrypting the second message.
[0035] For example, the shared key can be a derived key obtained through the terminal device's main authentication process. Alternatively, the shared key can be pre-configured.
[0036] Since a malicious first device cannot obtain the shared key between the core network and the terminal device, the above method can prevent a malicious first device from obtaining the sensing results, thus helping to improve the security of the sensing results.
[0037] In some embodiments, the second message may include the Short Message Service (SMS) authorization code of the terminal device. For example, if the SMS authorization code verification passes, the first sensing parameter is recorded as corresponding to the first device. For instance, when the second network element receives the second message, it can compare whether the SMS authorization code generated for the terminal device in the server matches the SMS authorization code of the terminal device carried in the second message. The terminal device mentioned here is the device that initiated the sensing request. For example, the terminal device may be separate from the first device, with the terminal device sending the second message through the first device; or the terminal device may be integrated with the first device, i.e., the first device may be deployed on the terminal device.
[0038] If the two SMS service authorization codes are the same, the verification passes, and the first sensing parameter and its correspondence with the first device can be recorded. If the two SMS service authorization codes are different, the verification fails, and the first sensing parameter and its correspondence with the first device are not recorded.
[0039] Since a malicious first device, or a first device without authorization from the terminal device, cannot obtain the SMS service authorization code of the terminal device, recording the first perception parameters corresponding to the first device when the SMS service authorization code verification is successful can ensure the reliability of the recording results and prevent malicious devices from forging information in the second list, thereby helping to improve the security of the perception results.
[0040] In some embodiments, the first message includes the first sensing parameter and information about the first device.
[0041] In some embodiments, if the first message does not include the first sensing parameter or information about the first device, a failure response message is sent to the first device. Optionally, the failure response message may include a reason for the request failure, such as not carrying the sensing parameter and / or not carrying information about the first device.
[0042] The first verification may include verifying whether the first sensing parameters and the information of the first device correspond. Therefore, the first sensing parameters and the information of the first device included in the first message can support the implementation of the above first verification.
[0043] In some embodiments, the first message includes the first sensing parameter and information about the first device, including: the first message includes a first token, and the first token includes the first sensing parameter and information about the first device.
[0044] Since the first token can be signed by the second network element, the first token includes the first sensing parameters and the information of the first device, which can prevent the first sensing parameters and the information of the first device from being tampered with, thereby preventing other devices from stealing access rights.
[0045] In some embodiments, before receiving the first message from the first device, the method further includes: receiving a fourth message from the first device, the fourth message being used to request a token for accessing a perception result associated with the first perception parameter; performing a second verification on the first perception parameter; and if the second verification passes, sending the first token to the first device.
[0046] Using tokens for access authorization (verification) is compatible with the authorization mechanisms of existing communication systems and has strong versatility.
[0047] In some embodiments, performing a second verification on the first sensing parameter includes: verifying whether the first sensing parameter corresponds to the information of the first device; and sending the first token to the first device if the second verification passes includes: sending the first token to the first device if the first sensing parameter corresponds to the information of the first device.
[0048] For example, the second network element may send a response to the first device indicating that the token request is rejected, or the second network element may send a response to the first device indicating that the token request has failed. Optionally, the response may include a reason for the token request failure. The reason for the token request failure may include, for example, one or more of the following: not carrying sensing parameters, not carrying information about the requesting device, or the second network element refusing the first device access to the sensing results associated with the first sensing parameters.
[0049] In some embodiments, the correspondence between the first sensing parameter and the information of the first device indicates that the first device is a device that is allowed to access the sensing results associated with the first sensing parameter.
[0050] For example, the correspondence between the first sensing parameters and the first device can be verified using the first list mentioned above. The method for verifying the correspondence between the first sensing parameters and the first device using the first list is described above and will not be repeated here for brevity.
[0051] In some embodiments, the correspondence between the first sensing parameter and the information of the first device indicates that the first device is a device that requests to perform sensing based on the first sensing parameter.
[0052] For example, the first sensing parameter can be verified against the first device using the second list mentioned above. The method for verifying the correspondence between the first sensing parameter and the first device using the second list is described above and will not be repeated here for brevity.
[0053] In some embodiments, before sending the first sensing result associated with the first sensing parameter to the first device, the method further includes: sending a sensing result request to a first network element, the sensing result request being used to request the sensing result associated with the first sensing parameter; and receiving the first sensing result associated with the first sensing parameter from the first network element. Exemplarily, the first network element is a sensing function (SF) network element.
[0054] Secondly, a communication method is provided, the method comprising: sending a first message to a second network element, the first message being used to request access to a sensing result associated with a first sensing parameter; and receiving the first sensing result associated with the first sensing parameter from the second network element.
[0055] For example, the communication method can be implemented by the first device, or by modules, units, processors, circuits, chips, or chip systems included in the first device. Optionally, the first device can be an application function (AF) network element.
[0056] It should be understood that the above-mentioned first perception result can be the result obtained by performing perception based on the first perception parameters.
[0057] In this embodiment of the application, by verifying the access request (i.e. the first message) of the sensing result, the first sensing result is returned when the verification passes, and the first sensing result is not returned when the verification fails. This helps to open the sensing result based on different access permissions, thereby helping to avoid the abuse of sensing information.
[0058] In some embodiments, before sending the first message to the second network element, the method further includes: sending a second message to the second network element, the second message being used to request the execution of sensing based on the first sensing parameters.
[0059] In some embodiments, the first message includes the first sensing parameter and information about the first device.
[0060] In some embodiments, if the first message does not include the first sensing parameter or information about the first device, a failure response message is sent to the first device. Optionally, the failure response message may include a reason for the request failure, such as not carrying the sensing parameter and / or not carrying information about the first device.
[0061] In this embodiment of the application, the first message includes a first sensing parameter and information about the first device, which can support access permission verification.
[0062] In some embodiments, the first message includes a first token, which includes the first sensing parameter and information about the first device.
[0063] Since the first token can be signed by the second network element, the first token includes the first sensing parameters and the information of the first device, which can prevent the first sensing parameters and the information of the first device from being tampered with, thereby preventing other devices from stealing access rights.
[0064] In some embodiments, before sending the first message to the second network element, the method further includes: sending a fourth message to the second network element, the fourth message being used to request a token for accessing the sensing result associated with the first sensing parameter; and receiving the first token from the second network element.
[0065] In this embodiment, a token mechanism is used to access the perception results, which is compatible with the existing authorization mechanism of the communication system and has strong versatility.
[0066] Thirdly, a communication method is provided, the method comprising: receiving a first message from a second network element, the first message being used to request access to a sensing result associated with a first sensing parameter; and sending the first sensing result associated with the first sensing parameter to the second network element.
[0067] For example, the communication method can be implemented by a first network element, or by modules, units, processors, circuits, chips, or chip systems included in the first network element. Optionally, the first network element can be an SF network element.
[0068] Fourthly, a communication method is provided, the method comprising: sending a fifth message to a first network element, the fifth message being used to request access to a sensing result associated with a first sensing parameter, the fifth message including a first token, the first token including the first sensing parameter and information of a third network element; and receiving the first sensing result associated with the first sensing parameter from the first network element.
[0069] For example, this communication method can be implemented by a third network element, or by modules, units, processors, circuits, chips, or chip systems included in the third network element. Optionally, the third network element can be a network function consumer (NFc) network element.
[0070] For example, if the fifth message does not include the first token mentioned above, then the first network element will not send the first sensing result associated with the first sensing parameter to the third network element.
[0071] Since the first token is signed by the network element that issued the token, such as the fourth network element, the first token includes the first sensing parameters and the information of the third network element, which can prevent the first sensing parameters and the information of the third network element from being tampered with, thereby preventing other devices from stealing access rights.
[0072] The embodiments of this application use a first token to determine whether to open the perception results, which helps to open the perception results according to the access permissions corresponding to different tokens, thereby avoiding the abuse of perception results.
[0073] In some embodiments, before sending the fifth message to the first network element, the method further includes: sending a sixth message to a fourth network element, the sixth message being used to request a token for accessing the sensing result associated with the first sensing parameter; and receiving the first token from the fourth network element.
[0074] The fourth network element can be, for example, a network repository function (NRF) network element. In this embodiment, the NRF network element can be used to implement the function of an authorization server.
[0075] Fifthly, a communication method is provided, the method comprising: receiving a sixth message from a third network element, the sixth message being used to request a token for accessing a sensing result associated with a first sensing parameter; performing a third verification according to the sixth message; and if the third verification passes, sending a first token to the third network element, the first token including the first sensing parameter and information of the third network element.
[0076] For example, the communication method can be implemented by a fourth network element, or by modules, units, processors, circuits, chips, or chip systems included in the fourth network element. Optionally, the fourth network element can be an NRF network element.
[0077] For example, if the third verification fails, the first token is not sent to the third network element. Alternatively, if the third verification fails, a response to the sixth message is sent to the third network element, indicating that the token request or verification failed. Optionally, if the first sensing parameters do not correspond to the information of the third network element, the fourth network element may send the reason for the verification failure to the third network element, such as the first sensing parameters not corresponding to the information of the third network element, or unauthorized access.
[0078] The embodiments of this application use a first token to determine whether to open the perception results, which helps to open the perception results according to the access permissions corresponding to different tokens, thereby avoiding the abuse of perception results.
[0079] In some embodiments, the sixth message includes the first sensing parameter, and the third verification according to the sixth message includes: verifying whether the first sensing parameter corresponds to the information of the third network element; if the third verification passes, sending the first token to the third network element includes: if the first sensing parameter corresponds to the information of the third network element, sending the first token to the third network element.
[0080] In some embodiments, the correspondence between the first sensing parameter and the information of the third network element indicates that the third network element is a device that is allowed to access the sensing results associated with the first sensing parameter.
[0081] As an example, based on the information of the sensing parameters and the corresponding devices, such as the third list, it is possible to verify whether the first sensing parameter corresponds to the third network element. That is, the third list can determine whether the third network element is allowed to access the sensing results associated with the first sensing parameter.
[0082] The third list may include one or more sensing parameters, each of which corresponds to one or more devices (or information about one or more devices).
[0083] If one or more of the above sensing parameters do not include the first sensing parameter, then the first sensing parameter does not correspond to the information of the third network element.
[0084] If one or more of the above sensing parameters include the first sensing parameter, and the information of one or more devices corresponding to the first sensing parameter includes the information of the third network element, then the first sensing parameter corresponds to the information of the third network element.
[0085] If one or more of the above sensing parameters include the first sensing parameter, and the information of one or more devices corresponding to the first sensing parameter does not include the information of the third network element, then the first sensing parameter does not correspond to the information of the third network element.
[0086] There are several ways to obtain the third list. In some embodiments, the third list can be dynamically indicated, which helps to flexibly adapt to different use cases or user needs. In some embodiments, the third list can be pre-configured for ease of implementation. For example, the third list can be pre-configured; changes, deletions, and additions to the content of the third list can be implemented through dynamic indication.
[0087] In some embodiments, the third verification includes verifying whether the third network element is allowed to access the first network element, wherein the first network element includes the first sensing parameter associated with the first sensing result; wherein, if the third network element is allowed to access the first network element, the third verification passes.
[0088] In some embodiments, if a first condition is met, the third network element is allowed to access the first network element, wherein the first condition includes one or more of the following conditions: the identifier of the public land mobile network (PLMN) to which the network element allowed to access the first network element belongs includes the identifier of the public land mobile network to which the third network element belongs; the identifier of the stand-alone non-public network (SNPN) to which the network element allowed to access the first network element belongs includes the identifier of the stand-alone non-public network to which the third network element belongs; the type of the network element allowed to access the first network element includes the type of the third network element; the network functional domain to which the network element allowed to access the first network element belongs includes the network functional domain to which the third network element belongs; or the network slice to which the network element allowed to access the first network element belongs includes the network slice to which the third network element belongs.
[0089] For example, the content of the first condition can be determined based on the allowed parameter set of the first network element. For instance, the first condition may include the conditions associated with the parameters in the allowed parameter set of the first network element.
[0090] For example, the allowed parameter set of the first network element includes an allowed PLMN set, which contains the identifiers of one or more PLMNs. If the identifier of the PLMN to which the network element belongs belongs to this allowed PLMN set, then the network element can access the first network element. In this implementation, the first condition includes: the identifiers of the PLMNs to which the network element is allowed to access the first network element include the identifiers of the PLMNs to which the third network element belongs.
[0091] For example, the allowed parameter set of the first network element includes an allowed network slice set, which contains identifiers of one or more network slices. If the identifier of the network slice to which the network element belongs belongs to the allowed network slice set, then the network element can access the first network element. In this implementation, the first condition includes: the network slice to which the network element allowed to access the first network element belongs includes the network slice to which the third network element belongs.
[0092] Similarly, the allowed parameter set of the first network element may also include one or more of the following: allowedSNPN set, allowed network functional domain set, or allowed network element type set. For specific implementation, please refer to the description of allowed PLMN set and allowed network slice set above, which will not be repeated here.
[0093] In some embodiments, the rule set of the first network element includes one or more rules. If the third network element satisfies at least one of the one or more rules, then the third network element is allowed to access the first network element.
[0094] For example, the one or more rules are associated with one or more first parameters. The first parameters may include one or more of the following: PLMN identifier, SNPN identifier, network element type, network functional domain indication information, or network slice indication information.
[0095] The one or more rules can indicate, through the aforementioned first parameter, the conditions that network elements must meet to be allowed to access the first network element. For example, the rule set may include rule 1 and rule 2, where rule 1 includes a set of allowed PLMNs; rule 2 includes a set of allowed network element types and a set of allowed network slices. Rule 1 indicates that the condition that a network element must meet to be allowed to access the first network element is that the identifier of the PLMN to which the network element belongs belongs to the allowed PLMN set. Rule 2 indicates that the conditions that a network element must meet to be allowed to access the first network element are: the network element type of the network element belongs to the allowed network element type set; and the network slice to which the network element belongs belongs to the allowed network slice set.
[0096] In some embodiments, the sixth message may include the first sensing parameters and information about the third network element (such as the identifier of the third network element), or the sixth message may include other parameters belonging to the third network element to support the execution of the third verification. These other parameters may include one or more of the following: PLMN identifier, SNPN identifier, network function type, network function domain, or network slice information.
[0097] A sixth aspect provides a communication method, the method comprising: receiving a fifth message from a third network element, the fifth message being used to request access to a sensing result associated with a first sensing parameter, the fifth message including a first token, the first token including the first sensing parameter and information of the third network element; and sending the first sensing result associated with the first sensing parameter to the third network element.
[0098] For example, the communication method can be implemented by a first network element, or by modules, units, processors, circuits, chips, or chip systems included in the first network element. Optionally, the first network element can be an SF network element.
[0099] In a seventh aspect, a communication device is provided, comprising: a unit for performing each step in any possible implementation of any of the first to sixth aspects.
[0100] Eighthly, a communication device is provided, the communication device including at least one processor coupled to a memory for storing a program or instructions, which, when executed by the processor, perform a method in any possible implementation of any of the first to sixth aspects above.
[0101] A ninth aspect provides a communication device comprising at least one processor and a memory coupled together, the memory storing program instructions which, when executed by the processor, perform a method of any possible implementation of any of the first to sixth aspects.
[0102] In a tenth aspect, a communication device is provided, the communication device including at least one processor and an interface circuit for transmitting and / or receiving signals, such that the processor performs the method in any of the possible implementations of the first to sixth aspects above.
[0103] Eleventhly, a computer program product is provided, comprising a computer program that, when executed by a processor, performs a method in any possible implementation of any of the first to sixth aspects.
[0104] In a twelfth aspect, a computer-readable storage medium is provided, which stores a computer program that, when executed, performs the method in any possible implementation of any of the first to sixth aspects above.
[0105] In a thirteenth aspect, a chip is provided, comprising: a processor for calling and running a computer program from a memory, causing a communication device having the chip installed to perform the methods in any of the possible implementations of the first to sixth aspects above. Attached Figure Description
[0106] Figure 1 is a schematic diagram of a communication system architecture applicable to an embodiment of this application.
[0107] Figure 2 is a flowchart illustrating a communication method provided in an embodiment of this application.
[0108] Figure 3 is a flowchart illustrating another communication method provided in an embodiment of this application.
[0109] Figure 4 is a schematic diagram of the architecture of a general application programming interface (API) framework.
[0110] Figure 5 is a schematic diagram of the northbound application interface call flow based on the architecture in Figure 4.
[0111] Figure 6 is a flowchart illustrating another communication method provided in an embodiment of this application.
[0112] Figure 7 is a schematic flowchart of a method for accessing perception results provided in an embodiment of this application.
[0113] Figure 8 is a schematic flowchart of another method for accessing perception results provided in an embodiment of this application.
[0114] Figure 9 is a schematic flowchart of a method for requesting perception provided in an embodiment of this application.
[0115] Figure 10 is a schematic flowchart of another method for sensing requests provided in an embodiment of this application.
[0116] Figure 11 is a flowchart illustrating a method for requesting a perception result according to an embodiment of this application.
[0117] Figure 12 is a flowchart illustrating another method for requesting authorization based on perception results provided in an embodiment of this application.
[0118] Figure 13 is a flowchart illustrating another method for requesting perception results provided in an embodiment of this application.
[0119] Figure 14 is a flowchart illustrating another method for requesting a perception result provided in an embodiment of this application.
[0120] Figure 15 is a schematic block diagram of a communication device provided in an embodiment of this application.
[0121] Figure 16 is a schematic block diagram of another communication device provided in an embodiment of this application. Detailed Implementation
[0122] The technical solutions in the embodiments of this application will now be described with reference to the accompanying drawings.
[0123] In the description of the embodiments of this application, unless otherwise stated, " / " indicates that the objects before and after are in an "or" relationship. For example, A / B can represent A or B. "And / or" in the embodiments of this application is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, and B alone, where A and B can be singular or plural. Furthermore, in the description of the embodiments of this application, unless otherwise stated, "multiple" refers to two or more. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or multiple. Additionally, to facilitate a clear description of the technical solutions of the embodiments of this application, the terms "first" and "second" are used in the embodiments of this application to distinguish identical or similar items with essentially the same function and effect. Those skilled in the art will understand that the words "first" and "second" do not limit the quantity or the order of execution, and that the words "first" and "second" do not necessarily imply that they are different.
[0124] In the various method embodiments of this application, the order of the sequence numbers does not imply the order of execution. The execution order should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0125] It is understood that in the embodiments of this application, descriptions such as "under the circumstances," "if," "when," and "if..." can be used interchangeably. Furthermore, these descriptions all refer to the corresponding processing that will be carried out under certain objective circumstances, and are not limited to a specific time, nor do they require any judgment action during implementation, nor do they imply any other limitations.
[0126] It is understood that some optional features in the embodiments of this application can be implemented independently in certain scenarios without relying on other features, such as the current solution on which they are based, to solve the corresponding technical problems and achieve the corresponding effects. Alternatively, they can be combined with other features as needed in certain scenarios. Correspondingly, the apparatus given in the embodiments of this application can also implement these features or functions, which will not be elaborated here.
[0127] In the embodiments of this application, unless otherwise specified, the same or similar parts between the various embodiments can be referred to each other. In the various embodiments of this application, and in the various implementation methods / methods / implementations within each embodiment, unless otherwise specified or logically conflicting, the terminology and / or descriptions between different embodiments and between the various implementation methods / methods / implementations within each embodiment are consistent and can be mutually referenced. The technical features in different embodiments and the various implementation methods / methods / implementations within each embodiment can be combined according to their inherent logical relationships to form new embodiments, implementation methods, methods, or implementation approaches. The embodiments of this application described below do not constitute a limitation on the scope of protection of this application.
[0128] With technological advancements, communication systems are considering incorporating sensing technology, which integrates communication and sensing. The 3rd Generation Partnership Project (3GPP) has initiated a project on integrated sensing and communication (ISAC) within its services and systems aspects (SA) 1. The communication system plans to add SF network elements to support the implementation of sensing technology. A possible communication system architecture is shown in Figure 1. The network architecture shown in Figure 1 may include terminal equipment, radio access network ((R)AN) equipment, and core network elements.
[0129] The terminal device in this application embodiment can also be referred to as user equipment (UE), access terminal, user unit, user station, mobile station, mobile station (MS), mobile terminal (MT), remote station, remote terminal, mobile device, user terminal, terminal, wireless core network element, user agent, user device, or terminal device. The terminal device in this application embodiment can be a device that provides voice and / or data connectivity to a user, and can be used to connect people, objects, and machines, such as handheld devices with wireless connectivity, vehicle-mounted devices, etc. The terminal devices in the embodiments of this application can be mobile phones, tablets, laptops, PDAs, mobile internet devices (MIDs), wearable devices, virtual reality (VR) devices, augmented reality (AR) devices, wireless terminals in industrial control, wireless terminals in self-driving, wireless terminals in remote medical surgery, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, wireless terminals in smart homes, etc. Optionally, the terminal device can be used to act as a base station. For example, the terminal device can act as a dispatching entity, providing sidelink signals between terminal devices in vehicle-to-everything (V2X) or device-to-device (D2D) communications. For example, cellular phones and cars communicate with each other using sidelink signals. Cellular phones and smart home devices communicate without relaying communication signals through base stations.
[0130] Access network equipment refers to devices that terminals access wirelessly within this network architecture. They are primarily responsible for air interface-side radio resource management, Quality of Service (QoS) management, data compression, and encryption. Access network equipment can also be called radio access network (RAN) equipment, such as base stations. A base station can broadly encompass, or be replaced by, various names including: NodeB, evolved NodeB (eNB), next-generation NodeB (gNB), relay station, access point, transmitting and receiving point (TRP), transmitting point (TP), master eNB (MeNB), secondary eNB (SeNB), multi-standard radio (MSR) node, home base station, network controller, access node, wireless node, access point (AP), transmission node, transceiver node, baseband unit (BBU), remote radio unit (RRU), active antenna unit (AAU), remote radio head (RRH), central unit (CU), distributed unit (DU), positioning node, etc. A base station can be a macro base station, micro base station, relay node, donor node, or similar entities, or combinations thereof. A base station can also refer to a communication module, modem, or chip installed within the aforementioned equipment or apparatus. A base station can also be a mobile switching center, a device that performs base station functions in D2D, V2X, and machine-to-machine (M2M) communications, or a device that performs base station functions in future communication systems. Base stations can support networks using the same or different access technologies. The embodiments of this application do not limit the specific technologies or device forms used in the access network equipment.
[0131] Base stations can be fixed or mobile. For example, a helicopter or drone can be configured to act as a mobile base station, and one or more cells can move depending on the location of the mobile base station. In other examples, a helicopter or drone can be configured as a device to communicate with another base station.
[0132] In some deployments, the access network device in this application embodiment may refer to a CU or a DU, or the access network device may include both a CU and a DU. The gNB may also include an AAU.
[0133] Core network elements may include user plane function (UPF) elements, access and mobility management function (AMF) elements, session management function (SMF) elements, policy control function (PCF) elements, network slice selection function (NSSF) elements, authentication server function (AUSF) elements, unified data management (UDM) elements, NEF elements, NRF elements, network slice-specific authentication and authorization function (NSSAAF) elements, network slice admission control function (NSACF) elements, edge application server discovery function (EASDF) elements, service communication proxy (SCP) elements, charging function (CHF) elements, and location management function (LMF) elements. Among them, the UPF network element is mainly responsible for the transmission of user data, while other network elements can be called control plane function network elements, which are mainly responsible for authentication, authorization, registration management, session management, mobility management and policy control, so as to ensure reliable and stable transmission of user data.
[0134] UPF network elements can be used to forward and receive data from terminals. For example, a UPF network element can receive service data from the data network and transmit it to the terminal through access network equipment; a UPF network element can also receive user data from the terminal through access network equipment and forward it to the data network. The transmission resources allocated and scheduled by the UPF network element for the terminal are managed and controlled by the SMF network element. The bearer between the terminal and the UPF network element can include: the user plane connection between the UPF network element and the access network equipment, and the establishment of a channel between the access network equipment and the terminal. The user plane connection is where a QoS flow (transmission flow) for data transmission can be established between the UPF network element and the access network equipment.
[0135] AMF network elements can be used to manage terminal access to the core network, such as terminal location updates, network registration, access control, terminal mobility management, and terminal attachment and detachment. When providing services for a terminal's session, AMF network elements can also provide control plane storage resources for that session to store session identifiers and the associated SMF network element identifiers.
[0136] SMF network elements can be used to select user plane network elements for terminals, redirect user plane network elements for terminals, assign Internet Protocol (IP) addresses to terminals, establish bearers (also known as sessions) between terminals and UPF network elements, modify and release sessions, and perform QoS control.
[0137] PCF network elements are used to provide policies to AMF and SMF network elements, such as QoS policies and slice selection policies.
[0138] The NSSF network element is used for network slice selection and supports the following functions: selecting the set of network slice instance examples to serve the terminal device; determining the allowed network slice selection assistance information (NSSAI), and, when necessary, determining the mapping to the subscribed single-network slice selection assistance information (S-NSSAI); determining the configured NSSAI, and, when necessary, determining the mapping to the subscribed S-NSSAI; determining the AMF set that may be used to query the terminal device, or determining a list of candidate AMF network elements based on the configuration.
[0139] The AUSF network element is used to receive requests from the AMF network element to authenticate the terminal. It requests a key from the UDM network element and then forwards the issued key to the AMF network element for authentication processing.
[0140] UDM network elements include functions such as generating and storing user subscription data and managing authentication data, and support interaction with external third-party servers.
[0141] NEF network elements are used for capability exposure, meaning that network capabilities can be exported to external networks based on NEF network elements. External untrusted applications can access core network data through NEF network elements to ensure network security. NEF network elements can provide functions such as QoS capability exposure for external applications, event subscription, and AF network element request distribution.
[0142] NRF network elements are used for core network element registration, management, and status detection, thereby achieving automated management of core network elements. When a core network element starts up, it must register with the NRF network element before it can provide services. Registration information may include, for example, the core network element's type, address, and service list.
[0143] CHF network elements can be used to generate call detail records (CDRs) and provide the quotas needed for online billing to SMF network elements.
[0144] LMF network elements can include the following functions: supporting the location determination of terminal devices; obtaining downlink location measurement or location estimation from terminal devices; obtaining uplink location measurement; and obtaining auxiliary data related to non-terminal devices.
[0145] The network architecture shown in Figure 1 can also include AF network elements and data network (DN) network elements.
[0146] AF network elements can be used to interact with 3GPP core network elements to support the routing of application-affected data, access network exposure functions, and interact with PCF network elements for policy control, etc.
[0147] DN network elements can provide data services to users for networks such as IP Multimedia Service (IMS) networks and the Internet. A DN network element can contain various application servers (AS) that provide different application services, such as carrier services, Internet access, or third-party services. The AS can implement the functions of the AF network element.
[0148] As mentioned earlier, to support the implementation of sensing technology, the network architecture shown in Figure 1 may also include SF network elements. SF network elements can be responsible for collecting sensing data reported by terminal devices and / or network devices, and further analyzing it to form sensing results that can be understood by third parties.
[0149] In some embodiments, an SF network element can be decomposed into SF-C network elements and SF-U network elements, or in other words, an SF network element includes SF-C network elements and SF-U network elements. The SF-C network element is responsible for receiving external sensing requests from the NEF network element and forwarding these requests to the terminal device / access network device. The SF-U network element is responsible for receiving reported sensing data from the terminal device / access network device, analyzing it, forming and storing the sensing results, and reporting them to the NEF network element, thus enabling the external sharing of the sensing results. For example, an SF network element may also include an SF-D network element. The SF-D network element is generally understood as a network data analytics function (NWDAF) network element. The SF-D network element can use artificial intelligence (AI) capabilities to process the sensing results sent by the SF-U network element to form further sensing results.
[0150] An SF network element can be a single network element, or it can be broken down into SF-C and SF-U network elements, or into SF-C, SF-U, and SF-D network elements. Optionally, an SF network element can also be integrated with other network elements (such as an AMF network element). It should be understood that when an SF network element is broken down into SF-C, SF-U, and SF-D network elements, the SF-C and SF-U network elements can be integrated with one network element, and the SF-D network element can be integrated with another network element.
[0151] It should be noted that the embodiments of this application can be applied to any of the above scenarios. The following will take the SF network element as a single network element as an example to introduce the solution provided by the embodiments of this application.
[0152] In the system architecture shown in Figure 1, various parts or functional entities can communicate with each other through interfaces. For example, terminal devices can connect to the AN via the Uu interface for access stratum (AS) communication, exchanging AS messages and wireless data transmission; terminal devices can connect to the AMF network element via the N1 interface for non-access stratum (NAS) communication, exchanging NAS messages; the AN can connect to the AMF via the N2 interface to transmit radio bearer control information from the core network side to the AN; the UPF can transmit data with the AN via the N3 interface and with the DN via the N6 interface, etc. The interfaces connecting other parts or functional entities are shown in Figure 1 and will not be elaborated here.
[0153] It should be understood that the above-mentioned network elements in the core network can also be referred to as functional entities, and this application does not limit this. For example, a UPF network element can also be referred to as a UPF entity, and an AMF network element can also be referred to as an AMF entity, etc.
[0154] It should also be understood that in some embodiments, the functional entity or network element can be simply referred to as xx. For example, a UPF entity (or UPF network element) can be simply referred to as UPF, and an AMF entity (or AMF network element) can be simply referred to as AMF. For ease of description, the xx (such as UPF, AMF, etc.) mentioned in the embodiments of this application can refer to the xx entity or xx network element, which will not be repeated hereafter.
[0155] The network elements in Figure 1 can be network components in hardware devices, software functions running on dedicated hardware, or virtualized functions implemented on a platform (e.g., a cloud platform). It should be noted that the embodiments of this application are not limited to the system architecture described above and can be applied to other future communication system architectures. Furthermore, the names of the various network elements used in the embodiments of this application may remain functionally the same in future communication systems, but their names may change.
[0156] One possible use case for ISAC could be: network devices and / or terminal devices sensing nearby targets; the core network SF element processing the sensing data to generate sensing results, and the AF (Action Center) formulating control policies based on the sensing results, thereby achieving functions such as intruder detection, water level monitoring, and traffic risk warning. Specifically, the SF can be responsible for collecting sensing data reported by terminal devices and / or network devices, further analyzing it to form sensing results understandable to third parties.
[0157] It can be seen that the applications of perception results are very wide. Therefore, the mechanism for accessing perception results is very important, but there is currently no corresponding solution on how to achieve access to perception results.
[0158] To address the aforementioned issues, embodiments of this application provide a communication method that facilitates access to sensing results by opening up sensing results at the granularity of sensing parameters.
[0159] Figure 2 is a flowchart illustrating a communication method provided in an embodiment of this application. The method shown in Figure 2 involves the interaction between network element A and network element B. It should be understood that network element A and network element B can be physical or logical entities capable of implementing the method shown in Figure 2. Network element A and network element B can be chips, chip systems, or processors that support the implementation of the method shown in Figure 2, and can also be logical nodes, logical modules, or software capable of implementing all or part of the network element functions.
[0160] The communication method provided in this application embodiment will now be described from the perspective of the interaction between network element A and network element B.
[0161] The method shown in Figure 2 may include steps S210 and S220.
[0162] In step S210, network element B sends a first message to network element A. Correspondingly, network element A receives the first message from network element B. The first message can be used to request a sensing result.
[0163] In some embodiments, the first message may include a first sensing parameter, that is, the first message may be used to request access to the sensing result associated with the first sensing parameter. For example, the first sensing parameter may include a sensing service type and / or a sensing area, etc. The sensing service type may include, for example, low-altitude service, marine service, border and coastal defense service, and vehicle-to-everything (V2X) service, etc. The sensing area may be a sensing range indicated by one or more parameters, such as a geographical area or a specific cell.
[0164] In step S220, network element B receives the first sensing result from network element A. Correspondingly, network element A sends the first sensing result to network element B.
[0165] The aforementioned first perception result is associated with the first perception parameter. Here, "first perception parameter associated with first perception result" means that the first perception result is obtained by performing perception based on the first perception parameter. It should be understood that "first perception result associated with first perception parameter" has the same meaning as "first perception parameter associated with first perception result".
[0166] In some embodiments, the device receiving the sensing result access request (such as network element A) is a sensing function network element. In this case, network element A can send the stored first sensing result to network element B. For example, when accessing the sensing result within a mobile network, network element B can communicate directly with the sensing function network element. Exemplarily, network element A can be an SF network element, and network element B can be a network function consumer (NFc) network element.
[0167] In some embodiments, the device receiving the sensing result access request (such as network element A) is a non-sensing function network element. In this case, network element A can first obtain the first sensing result from the sensing function network element, and then forward the first sensing result to network element B. For example, when accessing the sensing result outside the mobile network, network element B can obtain the sensing result from the SF network element through network element A. Exemplarily, network element A can be a NEF network element, and network element B can be the AF network element mentioned above, that is, the AF network element can obtain the sensing result from the SF network element through the NEF network element. Optionally, the terminal device or enterprise user can initiate an access request for the sensing result through the AF network element.
[0168] In this embodiment, the perception result requested by the first message can be determined based on the perception parameters carried in the first message; in other words, the perception result opened to the requesting party can be determined based on the perception parameters carried in the first message. By carrying perception parameters in the perception request, it is helpful to achieve access to perception results at the granularity of perception parameters.
[0169] In some embodiments, the first message may include an identifier of a sensing function network element. This sensing function network element may be a network element that performs sensing and / or stores sensing results. In this case, the first message may be used to request access to the sensing results stored by the sensing function network element, and / or, the first message may be used to request access to the sensing results obtained by the sensing function network element performing sensing.
[0170] For example, different sensing network elements may have different functions. For instance, different sensing network elements can be used to perform sensing for different areas. Also, different sensing network elements can be used to perform sensing for different service types. Taking sensing network element C as an example of performing sensing for sensing area 1, if the first message carries the identifier of sensing network element C, then the first message can be used to request access to the sensing results obtained by sensing network element C performing sensing, that is, it can be used to request access to the sensing results obtained by sensing network element C performing sensing based on sensing area 1.
[0171] For example, different sensing function network elements may correspond to different levels of precision. Taking sensing function network element D with precision N as an example, if the first message includes the identifier of sensing function network element D, then the first message can be used to request access to the sensing result obtained by sensing function network element D performing sensing, that is, the first message can be used to request access to the sensing result with precision N.
[0172] In some embodiments, the first message may include a first sensing parameter and an identifier of the sensing function network element D. For example, if the first message includes the first sensing parameter and the identifier of the sensing function network element D, then the first message can be used to request access to the sensing result associated with the first sensing parameter stored in the sensing function network element D, that is, the first message can be used to request access to the sensing result associated with the first sensing parameter with a precision of N.
[0173] In some embodiments, the first message may include a first sensing parameter and a performance parameter. The performance parameter may also be referred to as a performance metric, sensing performance parameter, or sensing performance indicator. For example, the first sensing parameter may be associated with multiple sensing results, and the first message is used to request the sensing result among these multiple sensing results that meets the aforementioned performance indicator requirements. Providing sensing results at the granularity of sensing parameters and performance parameters helps to provide sensing results according to the requester's needs, thereby avoiding data redundancy.
[0174] The performance parameters mentioned above may include one or more of the following: position accuracy, speed accuracy, confidence level, detection resolution, false alarm probability, maximum perceived service latency, or refresh rate. These performance parameters are described below.
[0175] Position accuracy can be used to characterize the degree of closeness between the position of a perceived target in the perception result and the actual position of the perceived target; in other words, it is the error or error level between the position of the perceived target in the perception result and the actual position of the perceived target. For example, a position accuracy of 1 meter means that the difference between the position of the perceived target in the perception result and the actual position of the perceived target does not exceed 1 meter.
[0176] Velocity accuracy can be used to characterize how close the velocity of a perceived target in the perception result is to the actual velocity of the perceived target. For example, velocity accuracy can include horizontal velocity accuracy and vertical velocity accuracy.
[0177] Confidence level refers to the percentage of true perceived results among all perceived results, taking accuracy into account. Generally, the confidence level is lower when the equipment is operating well than when it is operating poorly. This is because when the equipment is operating well, the reliability of the perceived results is higher, allowing for a lower confidence level; while when the equipment is operating poorly, a higher confidence level is needed to improve the reliability of the perceived results.
[0178] Detection resolution refers to the minimum quantitative change that a sensing device can reliably distinguish, identify, or detect. For example, detection resolution can include velocity resolution, angular resolution, and distance resolution. For instance, a sensing device can only detect a change in the velocity of a target if the velocity of the target exceeds the velocity resolution.
[0179] The probability of a missed detection can refer to the probability that a sensed target is not detected when it is present.
[0180] False alarm probability can refer to the probability of falsely detecting a target when the target does not exist.
[0181] Maximum sensing service latency can refer to the time elapsed from the event that triggers the determination of the sensing result to the availability of the sensing result by the sensing function network element.
[0182] Refresh rate can refer to the frequency at which sensing network elements generate sensing results.
[0183] It should be understood that the above-mentioned sensing parameters and performance parameters are given as examples only, and the sensing parameters and performance parameters may include more or fewer contents, which is not limited in this application.
[0184] This application embodiment enables the opening of perception results at different granularities by carrying different information in the first message, which helps to improve the flexibility of accessing perception results and can adapt to different usage scenarios.
[0185] In some embodiments, the method shown in FIG2 may further include step S230 (not shown in the figure).
[0186] In step S230, network element B sends a first sensing request to network element A. Correspondingly, network element A receives the first sensing request from network element B.
[0187] The aforementioned first perception request can be used to request the execution of perception.
[0188] For example, the first perception request may include first perception parameters, and the first perception request may be used to request the execution of perception based on the first perception parameters.
[0189] For example, a first sensing request may include first sensing parameters and performance parameters. The first sensing request can be used to request the execution of sensing based on the first sensing parameters, and the sensing results associated with the first sensing parameters must meet the requirements of the performance parameters. Exemplarily, the performance parameters in the first sensing request can be used to filter devices that perform sensing, such as determining devices that perform sensing based on the first sensing parameters.
[0190] For example, the first perception request may include the first perception parameters and the identifier of the perception function network element. The first perception request can be used to request the perception function network element to perform perception according to the first perception parameters.
[0191] For example, the first sensing request may include information about the initiator of the sensing request, such as information about network element B. The information about the initiator of the sensing request can be used to distinguish sensing requests initiated by different devices, or to distinguish the sensing results obtained from sensing requests initiated by different devices.
[0192] In some embodiments, in response to a first sensing request, a sensing function network element can perform sensing and store the sensing results. The storage methods for the sensing results can include various approaches.
[0193] For example, sensing results and sensing parameters can be stored together, such as storing a first sensing parameter together with a first sensing result. This would provide support for providing granular open sensing results based on sensing parameters.
[0194] For example, the sensing results, sensing parameters, and information about the requesting device can be stored together, such as storing the first sensing parameters, the first sensing result, and network element B together. This would provide support for the granular release of sensing results based on the sensing request initiator.
[0195] Regardless of the access mechanism for the perceived results, if the perceived results can be accessed arbitrarily, it may lead to the abuse of perceived information.
[0196] To address this issue, this application provides another communication method. By verifying the access request (i.e., the first message) for the sensing result, the first sensing result is returned when the verification passes, and not returned when the verification fails. This helps to open the sensing result based on different access permissions, thereby helping to avoid the misuse of sensing information.
[0197] Figure 3 is a flowchart illustrating another communication method provided in an embodiment of this application. The method shown in Figure 3 may, for example, involve interaction between a first device and a second network element.
[0198] It should be understood that the second network element can be, for example, a NEF network element, or a chip, processor or chip system that implements the NEF network element function, or a logical node, logical module or software that can implement all or part of the NEF network element function.
[0199] It should be understood that the first device may be, for example, an AF network element, or a chip, processor or chip system that implements the AF network element function, or a logical node, logical module or software that can implement all or part of the AF network element function.
[0200] The method provided in this application embodiment will now be described from the perspective of the interaction between the second network element and the first device. The method shown in Figure 3 may include steps S310 to S330.
[0201] In step S310, the second network element receives a first message from the first device, and correspondingly, the first device sends a first message to the second network element. The first message is used to request access to the sensing results associated with the first sensing parameters.
[0202] In some embodiments, the first message may include a first perception parameter. The first perception parameter can be used to indicate the perception result requested by the first message. That is, the first message includes the first perception parameter to indicate that the first message is used to request the perception result associated with the first perception parameter.
[0203] The perception result associated with the first perception parameter mentioned here can refer to the perception result obtained by performing perception based on the first perception parameter. For example, perception data is obtained by performing perception based on the first perception parameter, and a perception result can be further formed based on this perception data. This perception result is the perception result associated with the first perception parameter.
[0204] In some embodiments, the first message may include information about the first device. The first device is the device requesting the sensing result. The information about the first device includes information that can identify the first device, such as the identifier of the first device.
[0205] In some embodiments, the first message may include an identifier of the sensing function network element. The meaning of the sensing function network element identifier in the first message can be referred to the above description, and will not be repeated here for the sake of brevity.
[0206] In step S320, the second network element performs a first verification on the first sensing parameter.
[0207] If the first verification passes, proceed to step S330.
[0208] If the first verification fails, the first sensing result associated with the first sensing parameter will not be sent to the first device. For example, if the first verification fails, a verification failure indication message can be sent to the first device.
[0209] In step S330, the second network element sends the first sensing result associated with the first sensing parameter to the first device.
[0210] The first verification can be performed in various ways. In some embodiments, it can be verified whether the first sensing parameter corresponds to the information of the first device. If the first sensing parameter corresponds to the information of the first device, the first verification passes, and the first sensing result is sent to the first device; if the first sensing parameter does not correspond to the information of the first device, the first verification fails, and the first sensing result is not sent to the first device.
[0211] It should be understood that the above-mentioned first perception result can be the result obtained by performing perception based on the first perception parameters.
[0212] In this embodiment of the application, by verifying the access request (i.e. the first message) of the sensing result, the first sensing result is returned when the verification passes, and the first sensing result is not returned when the verification fails. This helps to open the sensing result based on different access permissions, thereby helping to avoid the abuse of sensing information.
[0213] It should be understood that the correspondence between the first sensing parameter and the information of the first device can be replaced with the statement that the first sensing parameter corresponds to the first device. The following will explain the meaning of this correspondence with specific examples.
[0214] The first sensing parameter corresponds to the information of the first device (first meaning).
[0215] In some embodiments, the correspondence between the first sensing parameter and the information of the first device can mean that the first device is a device that is allowed to access the sensing results associated with the first sensing parameter.
[0216] In some embodiments, the correspondence between a first sensing parameter and a first device can be verified based on the sensing parameter and the information of the device corresponding to the sensing parameter. For example, the correspondence between the first sensing parameter and the first device can be verified based on a first list, or in other words, the first device can be verified based on the first list to determine whether it is a device authorized to access the sensing results associated with the first sensing parameter. The first list may include one or more sensing parameters, each of which corresponds to one or more devices (or information about one or more devices).
[0217] If one or more of the above sensing parameters do not include the first sensing parameter, then the first sensing parameter does not correspond to the information of the first device.
[0218] If one or more of the above sensing parameters include the first sensing parameter, and the information of one or more devices corresponding to the first sensing parameter includes the information of the first device, then the first sensing parameter corresponds to the information of the first device.
[0219] If one or more of the above sensing parameters include the first sensing parameter, and the information of one or more devices corresponding to the first sensing parameter does not include the information of the first device, then the first sensing parameter does not correspond to the information of the first device.
[0220] There are several ways to obtain the first list. In some embodiments, the first list can be dynamically indicated, which helps to flexibly adapt to different use cases or user needs. In some embodiments, the first list can be pre-configured for ease of implementation. For example, the first list can be pre-configured; changes, deletions, or additions to the content of the first list can be implemented through dynamic indication.
[0221] Optionally, the first list can be pre-configured by the carrier.
[0222] Optionally, a first list may be pre-configured for the second network element during the registration process or when the second network element is successfully registered.
[0223] Optionally, the first list can be stored in the second network element.
[0224] The following describes the method for verifying whether the first sensing parameter corresponds to the first device (first verification) provided in the embodiments of this application, taking the first list as an example.
[0225] In some embodiments, the first list may include a first type of perception parameters. The perception results associated with the first type of perception parameters are perception results that can be accessed by any device, or in other words, the devices corresponding to the first type of perception parameters are all devices. Generally, the perception results associated with the first type of perception parameters can be perception results that do not involve information security and can be opened to all visitors. In this case, if the first type of perception parameters includes the first perception parameter, the first verification passes; if the first type of perception parameters does not include the first perception parameter, the first verification fails.
[0226] In some embodiments, the first list may include information about a second type of sensing parameter and the device corresponding to the second type of sensing parameter. The sensing results associated with the second type of sensing parameter are only accessible to the device corresponding to the second type of sensing parameter. In this case, if the first sensing parameter (denoted as sensing parameter 1) corresponds to the first device, that is, the second type of sensing parameter includes the first sensing parameter, and the device corresponding to the first sensing parameter includes the first device, then the first verification passes.
[0227] For example, if the second type of sensing parameter includes sensing parameter 1, and the device corresponding to sensing parameter 1 includes the first device, that is, sensing parameter 1 corresponds to the first device (as shown in Table 1), then the first verification passes.
[0228] An example of the first list in Table 1
[0229] For example, if the second type of sensing parameter includes sensing parameter 1, but the device corresponding to sensing parameter 1 does not include the first device, that is, sensing parameter 1 does not correspond to the first device (as shown in Table 2), then the first verification fails.
[0230] Another example of the first list in Table 2
[0231] For example, if the second type of perception parameters does not include perception parameter 1 (as shown in Table 3), then the first verification will fail.
[0232] Another example of the first list in Table 3
[0233] In some embodiments, the first list may include a third type of sensing parameter, information about the device corresponding to the third type of sensing parameter, and information about the requesting device for the third type of sensing parameter. The requesting device for the third type of sensing parameter mentioned here can be understood as the device requesting to perform sensing based on the third type of sensing parameter. In this case, if the first sensing parameter (denoted as sensing parameter 1) corresponds to the first device, that is, the third type of sensing parameter includes the first sensing parameter, and the device corresponding to the first sensing parameter includes the first device, then the first verification passes.
[0234] For example, referring to Table 4, the requesting devices for sensing parameter 1 include the first device and the second device. The device corresponding to sensing parameter 1 requested by the first device includes the first device, while the device corresponding to sensing parameter 1 requested by the second device does not include the first device. It can be seen that the sensing parameters include sensing parameter 1, and the device corresponding to sensing parameter 1 includes the first device, that is, the first verification passes.
[0235] Another example of the first list in Table 4
[0236] For example, referring to Table 5, the requesting devices for sensing parameter 1 include the first device and the second device. The device corresponding to sensing parameter 1 requested by the first device includes the first device, and the device corresponding to sensing parameter 1 requested by the second device includes the first device. It can be seen that the sensing parameters include sensing parameter 1, and the device corresponding to sensing parameter 1 includes the first device, that is, the first verification is successful.
[0237] Another example of the first list in Table 5
[0238] The information of the requesting device for the third type of sensing parameter can be used to determine the sensing result associated with the first sensing parameter that the first device is allowed to access, i.e., the first sensing result, if the first verification passes.
[0239] Referring to Table 4, the perception result associated with perception parameter 1 can include the perception result obtained by the first device requesting to perform perception based on perception parameter 1 and the perception result obtained by the second device requesting to perform perception based on perception parameter 1. Since the device corresponding to perception parameter 1 requested by the first device includes the first device, the first perception result can be the perception result obtained by the first device requesting to perform perception based on perception parameter 1.
[0240] Referring to Table 5, the perception result associated with perception parameter 1 may include the perception result obtained by the first device requesting to perform perception based on perception parameter 1 and the perception result obtained by the second device requesting to perform perception based on perception parameter 1. Since the device corresponding to perception parameter 1 requested by the first device includes the first device, and the device corresponding to perception parameter 1 requested by the second device includes the first device, the first perception result may include the perception result obtained by the first device requesting to perform perception based on perception parameter 1 and the perception result obtained by the second device requesting to perform perception based on perception parameter 1.
[0241] To support the above verification method, the sensing parameters, the sensing results associated with the sensing parameters, and the requesting device for the sensing parameters can be stored together.
[0242] It should be noted that the first list may include one or more of the above-mentioned types of perception parameters.
[0243] The requesting device for the aforementioned sensing parameters can be the same as or different from the device corresponding to the sensing parameters. Below are some examples where the requesting device for the sensing parameters is different from the device corresponding to the sensing parameters.
[0244] For example, the requesting device for a sensing parameter and the device corresponding to the sensing parameter can be different devices belonging to the same organization. That is, the sensing result obtained by a device within that organization is accessible to any device within that organization, but not to any device within other organizations. In other words, sensing results can be shared within an organization, but cannot be accessed across organizations. As an example, one or more devices in company A can access the sensing result obtained by a device in company A requesting sensing, but one or more devices in company A cannot access the sensing result obtained by a device in company B requesting sensing.
[0245] For example, the requesting device for sensing parameters and the device corresponding to the sensing parameters can be different devices located in the same area. That is, sensing results obtained by a device within that area are allowed to be accessed by any device within that area, but not by any device in other areas. In other words, sensing results can be shared within the same area, but cannot be accessed across areas. As an example, one or more devices in cell A can access sensing results obtained by a device in cell A requesting sensing, but one or more devices in cell A cannot access sensing results obtained by a device in cell B requesting sensing.
[0246] For example, the device corresponding to the perception parameter can be a user with specific functions, and the device requesting the perception parameter can be a device of a certain type associated with that specific function. As an example, the device corresponding to the perception parameter can be a user related to traffic management, and the device requesting the perception parameter can be one or more intelligent vehicles. That is, the user related to traffic management can access the perception results obtained from multiple intelligent vehicles requesting and executing perception. Optionally, the user related to traffic management can access the perception results related to road traffic conditions from the perception results obtained from multiple intelligent vehicles requesting and executing perception.
[0247] Considering the possibility that the requesting device for the aforementioned sensing parameters may differ from the device corresponding to the sensing parameters, another example of the first list is shown in Table 6.
[0248] Another example of the first list in Table 6
[0249] Referring to Table 6, the first, second, and third devices can be devices belonging to the same organization or the same region mentioned above; the fourth and fifth devices can be devices belonging to the same organization or the same region mentioned above; users related to traffic management departments can access all perception results obtained by the intelligent vehicle requesting perception, such as the perception results associated with perception parameter 2 and the perception results associated with perception parameter 3.
[0250] It should be noted that the first list above is only provided as an example, and the sensing parameters and the information of the devices corresponding to the sensing parameters can also be represented in other forms, such as software code, etc., which are not limited in this application.
[0251] In this embodiment, based on the sensing parameters and the information of the devices corresponding to the sensing parameters, it can be determined whether the first device is a device authorized to access the sensing results associated with the first sensing parameters. This helps to enable the opening of sensing results based on access permissions, thereby helping to avoid the abuse of sensing results. Furthermore, verification based on different types of sensing parameters and the information of the devices corresponding to different types of sensing parameters helps to enable the opening of sensing results at different granularities.
[0252] The first sensing parameter corresponds to the information of the first device (second meaning).
[0253] In some embodiments, the correspondence between the first sensing parameter and the information of the first device can mean that the first device is a device that requests to perform sensing based on the first sensing parameter. That is, if the device requesting the sensing result associated with the first sensing parameter (i.e., the first device) is also a device requesting to perform sensing based on the first sensing parameter, then the information of the first sensing parameter corresponds to that of the first device. Alternatively, if the device requesting the sensing result associated with the first sensing parameter is also a device requesting to perform sensing based on the first sensing parameter, then that device is allowed to access the sensing result associated with the first sensing parameter.
[0254] In some embodiments, the correspondence between a first sensing parameter and the information of a first device can be verified based on the sensing parameter and the information of the device corresponding to the sensing parameter. Here, the device corresponding to the sensing parameter can be the device that requests to perform sensing based on the sensing parameter. For example, the correspondence between the first sensing parameter and the first device can be verified based on a second list. The second list may include one or more sensing parameters, each of which corresponds to one or more devices (or information of one or more devices).
[0255] If one or more of the above sensing parameters do not include the first sensing parameter, then the first sensing parameter does not correspond to the information of the first device.
[0256] If one or more of the above sensing parameters include the first sensing parameter, and the information of one or more devices corresponding to the first sensing parameter includes the information of the first device, then the first sensing parameter corresponds to the information of the first device.
[0257] If one or more of the above sensing parameters include the first sensing parameter, and the information of one or more devices corresponding to the first sensing parameter does not include the information of the first device, then the first sensing parameter does not correspond to the information of the first device.
[0258] Table 7 is an example of the second list. Referring to Table 7, the device corresponding to the sensing parameter is the device in the same row as the sensing parameter in the second list. That is, there is a correspondence between the sensing parameter and the device information in the same row of Table 7.
[0259] An example of the second list in Table 7
[0260] It should be noted that the second list above is only provided as an example, and the sensing parameters and the information of the devices corresponding to the sensing parameters can also be represented in other forms, such as software code, etc., which are not limited in this application.
[0261] In this embodiment of the application, apart from the device that requests to perform sensing based on the first sensing parameter, other devices cannot access the sensing results associated with the first sensing parameter, thereby helping to improve the security of the sensing results and avoid the abuse of the sensing results.
[0262] In some embodiments, before receiving the first message from the first device, the method shown in FIG3 may further include steps S340 and S350 (both not shown in the figure).
[0263] In step S340, the second network element receives a second message from the first device, and correspondingly, the first device sends a second message to the second network element. The second message can be used to request the execution of sensing based on the first sensing parameters.
[0264] For example, the second message may include the first sensing parameters, or it may include the first sensing parameters and information about the first device. Alternatively, the second message may include the first sensing parameters, information about the first device, and information about the sensing network element.
[0265] In step S350, according to the second message, the second network element records the correspondence between the first sensing parameter and the first device.
[0266] In some embodiments, the second network element may record the correspondence between the first sensing parameters and the first device, or the correspondence between the first sensing parameters and the first device may be stored in the second network element.
[0267] In some embodiments, in response to a second message, the correspondence between the first sensing parameter and the first device can be recorded. For example, in response to a second message, the aforementioned second list is generated or updated. If the second list is not stored in the system when the second message is received, the second list is generated. If the second list is already stored in the system when the second message is received, the second list is updated.
[0268] In some embodiments, the second network element may send a third message to the first network element based on the second message. The third message may be used to request the execution of sensing based on the first sensing parameters. Exemplarily, the third message may carry the same information as the second message.
[0269] Correspondingly, the second network element can receive a response from the first network element to the third message. If the response (i.e., the response to the third message) indicates that the sensing performed according to the first sensing parameters was successful, the first sensing parameters are recorded as corresponding to the first device. For example, if the response indicates that the sensing performed according to the first sensing parameters was successful, the aforementioned second list is generated or updated. Similarly, if the response indicates that the sensing performed according to the first sensing parameters was successful, and the second list is not stored in the system, then the second list is generated; if the second list is already stored in the system, then the second list is updated.
[0270] In some embodiments, the second network element may use a shared key with the terminal device to decrypt the second message. The terminal device mentioned here is the device that initiated the sensing request. For example, the terminal device may be separate from the first device, sending the second message through the first device; or the terminal device may be integrated with the first device, i.e., the first device may be deployed on the terminal device.
[0271] For example, the shared key mentioned above can be a shared key between the core network and the terminal device. As another example, the shared key can be a shared key between the second network element and the terminal device. As yet another example, the shared key can be a shared key between any network element in the core network and the terminal device (which can be understood as a public shared key between multiple network elements in the core network and the terminal device). This public shared key can be stored in a server or in a network element, and the second network element can obtain the public shared key from the server or a network element before decrypting the second message.
[0272] For example, the shared key can be a derived key obtained through the terminal device's main authentication process. Alternatively, the shared key can be pre-configured.
[0273] For example, the terminal device may encrypt the second message using the shared key before decrypting it.
[0274] If the decryption result includes information about the first device, then the first sensing parameter is recorded as corresponding to the first device. For example, if the identifier in the decryption result of the second message indicates the first device, that is, the identifier in the decryption result of the second message is the same as the identifier of the first device, then the first sensing parameter is recorded as corresponding to the first device. Since malicious AF network elements cannot obtain the shared key between the core network and the terminal device, the above method can prevent malicious AF network elements from obtaining the sensing result, which helps to improve the security of the sensing result.
[0275] In some embodiments, the second message may include the Short Message Service (SMS) authorization code of the terminal device. For example, if the SMS authorization code verification passes, the first sensing parameter is recorded as corresponding to the first device. For instance, when the second network element receives the second message, it can compare whether the SMS authorization code generated for the terminal device in the server matches the SMS authorization code of the terminal device carried in the second message. The terminal device mentioned here is the device that initiated the sensing request. For example, the terminal device may be separate from the first device, with the terminal device sending the second message through the first device; or the terminal device may be integrated with the first device, i.e., the first device may be deployed on the terminal device.
[0276] If the two SMS service authorization codes match, the verification passes, and the first sensing parameter corresponding to the first device can be recorded. If the two SMS service authorization codes do not match, the verification fails, and the first sensing parameter corresponding to the first device is not recorded. Since malicious AF network elements, or AF network elements without authorization from the terminal device, cannot obtain the terminal device's SMS service authorization code, recording the first sensing parameter corresponding to the first device when the SMS service authorization code verification passes ensures the reliability of the recording results and prevents malicious devices from forging information in the second list, thereby improving the security of the sensing results.
[0277] In some embodiments, the first device is associated with an enterprise user. In this case, the identity of the enterprise user can be verified based on the registration certificate of the first device. That is, if the registration certificate of the first device is genuine, the first device is considered non-malicious; if the first device does not have a registration certificate or the registration certificate is fake, the first device is considered malicious. Denying the device's access to the sensing results in the case of a malicious device helps improve the security of the sensing results. Simultaneously, in the case of a malicious device, when a second message is received from the first device, the correspondence between the first sensing parameters and the first device is not recorded, thereby preventing malicious devices from forging sensing records.
[0278] In some embodiments, the response to the third message may indicate a failure of perception based on the first sensing parameter. The reason for the perception failure may include, for example, a malfunction of the sensing device. In this case, if the response to the second message records the correspondence between the first sensing parameter and the first device, the first device will not be able to obtain the sensing result associated with the first sensing parameter after the first verification passes. Therefore, recording the correspondence between the first sensing parameter and the first device when the response indicates successful perception based on the first sensing parameter ensures that the first device can obtain the sensing result associated with the first sensing parameter after the first verification passes, thereby helping to avoid invalid access to the sensing result.
[0279] In some embodiments, the first message may include a first sensing parameter and information about the first device to support the implementation of the first verification described above. For example, when using the first verification method mentioned above, if the first message does not include the first sensing parameter or information about the first device, a failure response message is sent to the first device. Optionally, the failure response message may include a reason for request failure, such as not carrying the sensing parameter and / or not carrying information about the first device.
[0280] In some embodiments, the second network element may obtain information about the first device through other means, such as determining the information about the first device through information such as the resource location communicated with the first device. In this case, the first message may not include information about the first device.
[0281] It should be understood that the embodiments in this application are merely illustrative examples of two meanings corresponding to the first sensing parameter and the first device, and this application does not limit them.
[0282] In some embodiments, verification and authorization of access to the perceived result can be performed based on the token to be compatible with the authorization mechanism of existing communication systems, thus having strong versatility.
[0283] The following section introduces the existing technology of using tokens for access authorization.
[0284] This research project, undertaken by the 3GPP SA3 project group, focuses on the Common API Framework (CAPIF) for authentication and authorization between the 3GPP northbound interface and the mobile network. Based on the CAPIF framework, authorization operations can be implemented when services are invoked from outside the mobile network to resources within the network, thereby protecting data and information within the network.
[0285] Figure 4 is a schematic diagram of the architecture of a general application programming interface (API) framework. The architecture shown in Figure 4 includes an API invoker 401, a CAPIF core function 402, an API exposing function 403, an API publishing function 404, and an API management function 405.
[0286] API caller 401 can invoke entities of CAPIF or service APIs. These are typically provided by third-party application providers with service agreements with PLMN operators. API callers can reside within the same trust domain as the PLMN operator's network. API caller 401 can be an application on a server or an application on a terminal device.
[0287] The CAPIF core function 402 is responsible for the authentication and authorization operations of each entity in the CAPIF framework.
[0288] The API Openness feature 403 is responsible for opening up service APIs to API callers.
[0289] The API publishing function 404 is responsible for publishing service APIs to the outside world so that they can be discovered by API callers.
[0290] API management feature 405 enables API providers to manage their service APIs. This management can include monitoring events reported by the CAPIF core functionality and monitoring the status of the service APIs.
[0291] Figure 5 is a schematic diagram of the northbound application programming interface (API) call flow based on the architecture in Figure 4. The flow shown in Figure 5 involves the interaction between the API caller, the CAPIF core functionality, and the API open functionality. Specifically, the flow shown in Figure 5 may include steps 1 to 8.
[0292] Step 1: Implement authentication and establish a secure connection between the API caller and the CAPIF core functionality.
[0293] Step 2: The API caller sends an access token request to the CAPIF core functionality.
[0294] Step 3: CAPIF core functionality verifies the access token request. If the access token request is successfully verified, proceed to Step 4.
[0295] Step 4: The CAPIF core function issues an access token to the API caller.
[0296] Step 5: Implement identity authentication and establish a secure connection between the API caller and the API open function.
[0297] Step 6: The API caller carries the access token and requests resources from the API to open its functions.
[0298] Step 7: The API Open Functionality verifies the access token. This includes verifying the access token, the authorization statement within the access token, and the API Open Functionality's request to execute a northbound API. Typically, after successful verification, step 8 is executed.
[0299] Step 8: The API Open Function sends a response to the resource request to the API caller.
[0300] The following describes the token-based access authorization method used in the embodiments of this application.
[0301] In some embodiments, the first message includes first sensing parameters and information about the first device, and may include: the first message includes a first token, and the first token includes the first sensing parameters and information about the first device. Since the first token can be signed by a second network element, the inclusion of the first sensing parameters and information about the first device in the first token can prevent the first sensing parameters and information about the first device from being tampered with, thereby preventing other devices from stealing access rights.
[0302] In some embodiments, before receiving a first message from the first device, the second network element may receive a fourth message from the first device. The fourth message requests a token for accessing a sensing result associated with the first sensing parameter. The fourth message may, for example, include the first sensing parameter and information about the first device.
[0303] Before issuing an access token, it is typically necessary to verify the first device's permission to access the first sensing parameter in order to enable access to sensing results based on permissions. For example, the second network element can perform a second verification on the first sensing parameter. If the second verification passes, the second network element can send a first token to the first device. The first token is a token used to access the sensing results associated with the first sensing parameter. If the second verification fails, the second network element can send a response to the first device indicating that the token request is rejected.
[0304] Optionally, the response (indicating rejection of the token request) may include a reason for the token request failure. The reason for the token request failure may include, for example, one or more of the following: not carrying sensing parameters, not carrying information about the requesting device, or the second network element denying the first device access to the sensing result associated with the first sensing parameters.
[0305] For example, the first token can be carried in the response to the fourth message. The response to the fourth message may include, for example, an indication of whether the token request was successful. As an example, this indication can be a 1-bit value, with different values indicating whether the token request was successful; for example, a bit value of 1 indicates a successful request, and a bit value of 0 indicates a failed request. As another example, the indication can be 200 OK, used to indicate that the token request was successful. It should be noted that the number of bits and the meaning of their values are merely illustrative and are not limited in this application.
[0306] In some embodiments, performing a second verification on the first sensing parameter may include verifying whether the first sensing parameter corresponds to information of the first device. If the first sensing parameter corresponds to information of the first device, a first token is sent to the first device. If the first sensing parameter does not correspond to the first device, a token for accessing the sensing result associated with the first sensing parameter is not sent to the first device.
[0307] For example, the correspondence between the first sensing parameter and the information of the first device can mean that the first device is a device that is allowed to access the sensing results associated with the first sensing parameter. For example, the correspondence between the first sensing parameter and the first device can be verified according to the first list mentioned above. The first list may include one or more sensing parameters, and each of the one or more sensing parameters corresponds to one or more devices (or information of the first or more devices).
[0308] If one or more of the above sensing parameters do not include the first sensing parameter, then the first sensing parameter does not correspond to the information of the first device.
[0309] If one or more of the above sensing parameters include the first sensing parameter, and the information of one or more devices corresponding to the first sensing parameter includes the information of the first device, then the first sensing parameter corresponds to the information of the first device.
[0310] If one or more of the above sensing parameters include the first sensing parameter, and the information of one or more devices corresponding to the first sensing parameter does not include the information of the first device, then the first sensing parameter does not correspond to the information of the first device.
[0311] For example, the correspondence between the first sensing parameter and the information of the first device can mean that the first device is a device that requests to perform sensing based on the first sensing parameter. For instance, the correspondence between the first sensing parameter and the first device can be verified according to the second list described above. The second list may include one or more sensing parameters, each of which corresponds to one or more devices (or information of the first or more devices).
[0312] If one or more of the above sensing parameters do not include the first sensing parameter, then the first sensing parameter does not correspond to the information of the first device.
[0313] If one or more of the above sensing parameters include the first sensing parameter, and the information of one or more devices corresponding to the first sensing parameter includes the information of the first device, then the first sensing parameter corresponds to the information of the first device.
[0314] If one or more of the above sensing parameters include the first sensing parameter, and the information of one or more devices corresponding to the first sensing parameter does not include the information of the first device, then the first sensing parameter does not correspond to the information of the first device.
[0315] The second verification method can be similar to the first verification method mentioned above. Details not described in detail can be found in the previous introduction; for the sake of brevity, they will not be repeated here.
[0316] As mentioned earlier, the first message may include a first token, which may include first sensing parameters and information about the first device. In this case, performing the first verification on the first sensing parameters may include verifying information such as the format of the first token to prevent the first message from carrying a maliciously forged token.
[0317] Alternatively, performing a first verification on the first sensing parameter may include verifying whether the first sensing parameter in the first token corresponds to the information of the first device. If the first sensing parameter corresponds to the information of the first device, then a first sensing result is sent to the first device. This is because the device that performs the verification on the first sensing parameter in the fourth message and the device that performs the verification on the first sensing parameter in the first message may be different devices or different modules within the same device. Therefore, when the first message includes a first token, performing a second verification on the first sensing parameter in the first token can improve the reliability of the verification result and help to further improve the security of the sensing result.
[0318] To verify whether the first sensing parameter in the first token corresponds to the information of the first device, please refer to the previous introduction on verifying whether the first sensing parameter corresponds to the information of the first device. For the sake of brevity, it will not be repeated here.
[0319] In some embodiments, if the second network element does not store the first sensing result (e.g., the first sensing result is stored in the first network element), and the first verification passes, the second network element can obtain the first sensing result from the first network element before sending it to the first device. For example, before sending the first sensing result associated with the first sensing parameter to the first device, the second network element can send a sensing result request to the first network element. This sensing result request can be used to request the sensing result associated with the first sensing parameter; the second network element receives the first sensing result associated with the first sensing parameter from the first network element. It should be understood that this sensing result request and the first message mentioned above can be the same or different.
[0320] If the first message from the first device includes the identifier of the sensing device, the second network element sends the first message to the sensing device corresponding to the identifier, i.e., the identifier indicates the first network element. When the sensing results associated with the first sensing parameter include sensing result 1 and sensing result 2, if the first device is allowed to access sensing result 1, the second network element requests sensing result 1 from the first network element (as in the example in Table 4 above).
[0321] For example, the first network element is a sensing function network element. It should be understood that the first network element can be a SF (Sensing Function), or it can be a chip, processor, or chip system that implements the SF network element function, or it can be a logical node, logical module, or software that can implement all or part of the SF network element function.
[0322] It can be seen that the token-based access authorization mechanism provided in this application embodiment is compatible with the CAPIF framework.
[0323] The previously described method for accessing sensing results applies to scenarios where sensing results are accessed externally to the mobile network. In this scenario, external devices cannot directly request sensing results from the sensing network element; they need to request the sensing results from the first network element (sensing network element) through a second network element (non-sensing network element). The following section introduces a method applicable to scenarios where sensing results are accessed internally within the mobile network.
[0324] Figure 6 is a flowchart illustrating another communication method provided in an embodiment of this application. The method shown in Figure 6 may, for example, involve the interaction between a first network element, a third network element, and a fourth network element.
[0325] It should be understood that the first network element can be an SF network element, or a chip, processor or chip system that implements the functions of an SF network element, or a logical node, logical module or software that can implement all or part of the functions of an SF network element.
[0326] It should be understood that the third network element can be any NF (which can be called NFc) that needs to access SF network element services, or it can be a chip, processor or chip system that implements the above-mentioned NF functions, or it can be a logical node, logical module or software that can implement all or part of the NF functions.
[0327] It should be understood that the fourth network element can be, for example, an NRF network element, or a chip, processor, or chip system that implements the functions of an NRF network element, or a logical node, logical module, or software that can implement all or part of the functions of an NRF network element.
[0328] The method provided in this application embodiment will now be described from the perspective of the interaction between the first network element, the third network element, and the fourth network element. The method shown in Figure 6 may include steps S610 and S620.
[0329] In step S610, the third network element sends a fifth message to the first network element, and correspondingly, the first network element receives the fifth message from the third network element. The fifth message is used to request access to the sensing results associated with the first sensing parameter.
[0330] For example, the fifth message may include a first token, wherein the first token is a token for accessing the perception result associated with the first perception parameter.
[0331] Optionally, the first token may include first sensing parameters and information about the third network element. Since the first token is signed by the network element that issued the token, such as the fourth network element, including the first sensing parameters and information about the third network element in the first token can prevent the first sensing parameters and information about the third network element from being tampered with, thereby preventing other devices from stealing access rights.
[0332] In step S620, the third network element receives the first sensing result associated with the first sensing parameter from the first network element, and correspondingly, the first network element sends the first sensing result associated with the first sensing parameter to the third network element.
[0333] If the fifth message includes the first token mentioned above, then step S620 is executed; if the fifth message does not include the first token mentioned above, then step S620 is not executed, that is, the first network element does not send the first sensing result associated with the first sensing parameter to the third network element.
[0334] In some embodiments, the first token can be verified before the first network element sends the first sensing result to the third network element. For example, the format and other information of the first token can be verified, or the first sensing parameters carried in the first token can be verified, which helps to prevent the first token from being tampered with, thereby further improving reliability. The method for verifying the first sensing parameters can refer to the description of the first verification above, and will not be repeated here for the sake of brevity.
[0335] The embodiments of this application use a first token to determine whether to open the perception results, which helps to open the perception results according to the access permissions corresponding to different tokens, thereby avoiding the abuse of perception results.
[0336] In some embodiments, before the third network element sends the fifth message to the first network element, the third network element may request the first token, such as requesting the first token from the fourth network element. The fourth network element mentioned here may be the NRF network element mentioned above, and in this embodiment, the NRF network element can be used to implement the function of an authorization server.
[0337] For example, before the third network element sends the fifth message to the first network element, the method shown in Figure 6 may further include step S630 (not shown in the figure). In step S630, the third network element may send a sixth message to the fourth network element, wherein the sixth message may be used to request a token for accessing the sensing result associated with the first sensing parameter. As an example, the sixth message may include the first sensing parameter and information about the third network element.
[0338] In some embodiments, the method shown in FIG6 may further include steps S640 and S650 (both not shown in the figure).
[0339] In step S640, the fourth network element can perform a third verification based on the sixth message. Further, the fourth network element can determine whether to issue a first token to the third network element based on the result of the third verification. For example, if the third verification passes, step S650 is executed; if the third verification fails, step S650 is not executed. In step S650, the fourth network element sends the first token to the third network element.
[0340] The sixth message may include the first sensing parameter. A third verification is performed based on the sixth message, for example, verifying whether the first sensing parameter corresponds to the information of the third network element. If the first sensing parameter corresponds to the information of the third network element, a first token is sent to the third network element, indicating successful verification. If the first sensing parameter does not correspond to the information of the third network element, no first token is sent to the third network element, indicating verification failure. Optionally, if the first sensing parameter does not correspond to the information of the third network element, the fourth network element may send a reason for the verification failure to the third network element, such as the mismatch between the first sensing parameter and the information of the third network element.
[0341] For example, the correspondence between the first sensing parameter and the information of the third network element can indicate that the third network element is a device that is allowed to access the sensing result associated with the first sensing parameter. As an example, based on the information of the sensing parameter and the device corresponding to the sensing parameter, such as a third list, it is possible to verify whether the first sensing parameter corresponds to the third network element, that is, the third list can determine whether the third network element is allowed to access the sensing result associated with the first sensing parameter.
[0342] The third list may include one or more sensing parameters, each of which corresponds to one or more devices (or information about one or more devices).
[0343] If one or more of the above sensing parameters do not include the first sensing parameter, then the first sensing parameter does not correspond to the information of the third network element.
[0344] If one or more of the above sensing parameters include the first sensing parameter, and the information of one or more devices corresponding to the first sensing parameter includes the information of the third network element, then the first sensing parameter corresponds to the information of the third network element.
[0345] If one or more of the above sensing parameters include the first sensing parameter, and the information of one or more devices corresponding to the first sensing parameter does not include the information of the third network element, then the first sensing parameter does not correspond to the information of the third network element.
[0346] There are several ways to obtain the third list. In some embodiments, the third list can be dynamically indicated, which helps to flexibly adapt to different use cases or user needs. In some embodiments, the third list can be pre-configured for ease of implementation. For example, the third list can be pre-configured; changes, deletions, or additions to the content of the third list can be implemented through dynamic indication.
[0347] Optionally, the third list can be pre-configured by the operator.
[0348] Optionally, a third list can be pre-configured for the fourth network element during the registration process or when the fourth network element is successfully registered.
[0349] Optionally, the third list can be stored in the fourth network element.
[0350] The following uses a third list as an example to describe the method for verifying whether a first sensing parameter corresponds to a third network element (third verification) provided in this application embodiment. It should be understood that the third list is only given as an example, and the sensing parameters and the information of the devices corresponding to the sensing parameters can also be represented in other forms, such as software code, etc., which are not limited in this application.
[0351] In some embodiments, the third list may include the first type of perception parameters. The perception results associated with the first type of perception parameters are those accessible to any device; in other words, the devices corresponding to the first type of perception parameters are all devices. Generally, the perception results associated with the first type of perception parameters can be perception results that do not involve information security and can be opened to all visitors. In this case, if the first type of perception parameters includes the first perception parameter, the third verification passes; if the first type of perception parameters does not include the first perception parameter, the third verification fails.
[0352] In some embodiments, the third list may include information about the second type of sensing parameters and the devices corresponding to the second type of sensing parameters. The sensing results associated with the second type of sensing parameters are only accessible to the devices corresponding to the second type of sensing parameters. In this case, if the first sensing parameter (denoted as sensing parameter 1) corresponds to the third network element, that is, the second type of sensing parameters includes the first sensing parameter, and the device corresponding to the first sensing parameter includes the third network element, then the third verification passes.
[0353] For example, if the second type of sensing parameter includes sensing parameter 1, and the device corresponding to sensing parameter 1 includes the third network element, that is, sensing parameter 1 corresponds to the third network element (as shown in Table 8), then the third verification passes.
[0354] An example of the third list in Table 8
[0355] For example, if the second type of sensing parameter includes sensing parameter 1, and the device corresponding to sensing parameter 1 does not include the third network element, that is, sensing parameter 1 does not correspond to the third network element (as shown in Table 9), then the third verification will fail.
[0356] Another example of the third list in Table 9
[0357] For example, if the second type of perception parameters does not include perception parameter 1 (as shown in Table 10), then the third verification will fail.
[0358] Another example of the third list in Table 10
[0359] It should be noted that the third list may include one or more of the above-mentioned types of perception parameters.
[0360] To support the above verification method, the sensing parameters and sensing results can be stored together.
[0361] In this embodiment, based on the sensing parameters and the information of the devices corresponding to the sensing parameters, it can be determined whether the third network element is a device that is allowed to access the sensing results associated with the first sensing parameter. This helps to enable the opening of sensing results according to access permissions, thereby helping to avoid the abuse of sensing results. Furthermore, verification based on different types of sensing parameters and the information of the devices corresponding to different types of sensing parameters helps to enable the opening of sensing results at different granularities.
[0362] It should be understood that the correspondence between the first sensing parameter and the information of the third network element can be replaced with the correspondence between the first sensing parameter and the third network element.
[0363] Optionally, the first token can be carried in the response to the sixth message. As an example, the response to the sixth message may also include an indication of whether the token request was successful. It should be understood that the configuration method and meaning of this indication can be found in the previous description of the response to the fourth message, and will not be repeated here for the sake of brevity.
[0364] It should be noted that if the sixth message does not include the first sensing parameter or information about the third network element, the token request will fail. Optionally, the response to the sixth message may include the reason for the request failure, such as the absence of the first sensing parameter and / or the absence of information about the requesting device.
[0365] In some embodiments, the third verification may include verifying whether a third network element is allowed to access the first network element. If the third network element is allowed to access the first network element, the third verification passes; if the third network element is not allowed to access the first network element, the third verification fails. The first network element includes a first sensing parameter associated with a first sensing result.
[0366] For example, if the first condition is met, then the third network element is allowed to access the first network element, wherein the first condition includes one or more of the following conditions: the identifier of the PLMN to which the network element allowed to access the first network element belongs includes the identifier of the PLMN to which the third network element belongs; the identifier of the SNPN to which the network element allowed to access the first network element belongs includes the identifier of the SNPN to which the third network element belongs; the type of the network element allowed to access the first network element includes the type of the third network element; the network functional domain to which the network element allowed to access the first network element belongs includes the network functional domain to which the third network element belongs; or the network slice to which the network element allowed to access the first network element belongs includes the network slice to which the third network element belongs.
[0367] Optionally, the content of the first condition can be determined based on the allowed parameter set of the first network element. For example, the first condition may include the conditions associated with the parameters in the allowed parameter set of the first network element.
[0368] For example, the allowed parameter set of the first network element includes an allowed PLMN set, which contains the identifiers of one or more PLMNs. If the identifier of the PLMN to which the network element belongs belongs to this allowed PLMN set, then the network element can access the first network element. In this implementation, the first condition includes: the identifier of the PLMN to which the network element allowed to access the first network element belongs includes the identifier of the PLMN to which the third network element belongs. As an example, if the allowed PLMN set of the first network element includes PLMN#1 and PLMN#2, then if the third network element belongs to PLMN#1 or PLMN#2, the first condition is satisfied.
[0369] For example, the allowed parameter set of the first network element includes an allowed network slice set, which contains identifiers of one or more network slices. If the identifier of the network slice to which the network element belongs belongs to this allowed network slice set, then the network element can access the first network element. In this implementation, the first condition includes: the network slice to which the network element allowed to access the first network element belongs includes the network slice to which the third network element belongs. As an example, if the allowed network slice set of the first network element includes network slice 1 and network slice 2, then if the third network element belongs to either network slice 1 or network slice 2, the first condition is satisfied.
[0370] Similarly, the allowed parameter set of the first network element may also include one or more of the following: allowedSNPN set, allowed network functional domain set, or allowed network element type set. For specific implementation, please refer to the description of allowed PLMN set and allowed network slice set above, which will not be repeated here.
[0371] It should be understood that if the first condition includes multiple conditions, then the first condition is satisfied if all of the multiple conditions are met.
[0372] Optionally, the allowed parameter set of the first network element is usually stored in the network element profile (NF profile) of the first network element.
[0373] For example, the rule set of the first network element includes one or more rules. If the third network element satisfies at least one of the one or more rules, then the third network element is allowed to access the first network element.
[0374] For example, the one or more rules are associated with one or more first parameters. The first parameter may include one or more of the following: PLMN identifier, SNPN identifier, network element type, network functional domain indication information, or network slice indication information. Optionally, the network functional domain indication information may be the name or identifier of the network functional domain; the network slice indication information may be the identifier of the network slice.
[0375] The one or more rules can indicate, through the aforementioned first parameter, the conditions that network elements must meet to be allowed to access the first network element. For example, the rule set may include rule 1 and rule 2, where rule 1 includes a set of allowed PLMNs; rule 2 includes a set of allowed network element types and a set of allowed network slices. Rule 1 indicates that the condition that a network element must meet to be allowed to access the first network element is that the identifier of the PLMN to which the network element belongs belongs to the allowed PLMN set. Rule 2 indicates that the conditions that a network element must meet to be allowed to access the first network element are: the network element type of the network element belongs to the allowed network element type set; and the network slice to which the network element belongs belongs to the allowed network slice set.
[0376] It should be noted that the rule set of the first network element may also include other information, which is not limited in this application.
[0377] In some embodiments, the sixth message may include the first sensing parameters and information about the third network element (such as the identifier of the third network element), or the sixth message may include other parameters belonging to the third network element to support the execution of the third verification. These other parameters may include one or more of the following: PLMN identifier, SNPN identifier, network function type, network function domain, or network slice information.
[0378] As can be seen, the first token involved in the internal access sensing result scenario (the method shown in Figure 6) and the first token involved in the external access sensing result scenario (the method shown in Figure 3) are both tokens that can be used to request access sensing results. However, it should be understood that the format of the first token can be the same or different in different use cases. For example, the format of the first token involved in the internal access sensing result scenario and the format of the first token involved in the external access scenario can be different.
[0379] It should be understood that "verification passed" mentioned in the embodiments of this application can also be called "verification successful", and "verification failed" can also be called "verification unsuccessful" or "verification failed".
[0380] It should be noted that the sensing results in this application embodiment may include sensing data generated during the execution of sensing operations, or sensing results formed based on sensing data. Optionally, in scenarios where sensing results are accessed outside the mobile network, the sensing results formed based on sensing data may be made available to the first device, while the sensing data generated during the execution of sensing operations may not be made available to the first device, thereby improving the security of the sensing data. Optionally, in scenarios where sensing results are accessed within the mobile network, both the sensing results formed based on sensing data and the sensing data generated during the execution of sensing operations may be made available to the third network element.
[0381] To facilitate understanding, the methods provided in the embodiments of this application will be described below with specific examples. It should be noted that in the examples below, SF network element will be abbreviated as SF, NEF network element as NEF, AF network element as AF, NFc network element as NFc, and NRF network element as NRF.
[0382] Perception Results Access (External)
[0383] Figure 7 is a schematic flowchart of a method for accessing perception results provided in an embodiment of this application. The method shown in Figure 7 may involve the interaction between SF, NEF, and AF. The method shown in Figure 7 may include steps 1 to 4.
[0384] In step 1, AF sends a sensing request to SF via NEF.
[0385] For example, the NEF can receive a perception request from the AF; the NEF then sends the perception request from the AF to the SF. The perception request may include perception parameters (referred to as the first perception parameter for ease of description), and the perception request is used to request the SF to perform perception based on the first perception parameter.
[0386] In step 2, the SF performs sensing based on the first sensing parameters. Optionally, the SF can associate and store the sensing result obtained by performing sensing based on the first sensing parameters (denoted as the first sensing result) with the first sensing parameters.
[0387] In step 3, AF requests NEF authorization. The authorization mentioned here refers to granting permission to access the perceived results.
[0388] Optionally, NEF can validate the content of the request. If the validation passes, it authorizes the AF to access the sensing results; if the validation fails, it does not authorize the AF to access the sensing results. The request may include, for example, the first sensing parameter and the AF's identifier.
[0389] If AF is authorized, step 4 can be performed.
[0390] In step 4, AF obtains the first perception result from SF through NEF.
[0391] For example, the NEF receives a perception result request from the AF and sends the perception result request to the SF; the NEF receives the perception result sent by the SF and sends the perception result to the AF.
[0392] Perception result access (internal)
[0393] Figure 8 is a schematic flowchart of another method for accessing perception results provided in an embodiment of this application. The method shown in Figure 8 may involve the interaction between SF, NRF, and NFc. The method shown in Figure 8 may include steps 1 to 3.
[0394] In step 1, SF stores the sensing results. For example, SF can store sensing parameters and the sensing results obtained by performing sensing based on those parameters in a related manner.
[0395] In step 2, NFc requests a token from NRF. This token is used to access the sensing results.
[0396] For example, when an NFc requests a token from an NRF, it can carry awareness parameters and the NFc's identifier. Alternatively, when an NFc requests a token from an NRF, it can carry other parameters belonging to the NFc, such as one or more of the following: PLMN identifier, SNPN identifier, network function type, network function domain, or network slice information, to verify whether the NFc is allowed to access the SF (see the previous description).
[0397] In step 3, NFc obtains the perception result from SF based on the token.
[0398] For example, NFc can send a sensing result request to SF, wherein the sensing result request carries a token; and receive the sensing result sent by SF.
[0399] As mentioned earlier, the correspondence between the first sensing parameter and the information of the first device can be interpreted as follows: the first device is the device that requests to perform sensing based on the first sensing parameter. In other words, if the device requesting the sensing result associated with the first sensing parameter (i.e., the first device) is the device that requests to perform sensing based on the first sensing parameter, then the information of the first sensing parameter corresponds to that of the first device.
[0400] In this case, there are multiple methods for recording the information of the first sensing parameter and the first device. The following section describes the methods for recording the information of the first sensing parameter and the first device in conjunction with sensing request process 1 and sensing request process 2.
[0401] Perception Request Process 1
[0402] Figure 9 is a schematic flowchart of a perception request method provided in an embodiment of this application. The method shown in Figure 9 may involve the interaction between SF, NEF, AF, and UE, wherein AF is deployed on UE.
[0403] The method shown in Figure 9 may include steps 1 through 5.
[0404] In step 1, the UE sends a perception request to the AF. The perception request includes the AF ID (denoted as AF1 ID) and perception parameters (denoted as the first perception parameter).
[0405] In step 2, the AF sends a perception request to the NEF. The perception request includes the AF ID (denoted as AF1 ID) and the first perception parameter.
[0406] In step 3, NEF confirms that the AF was a perception request triggered under UE authorization.
[0407] For example, the perception request in steps 1 and 2 carries a Short Message Service (SMS) authorization code. The NEF verifies whether this authorization code matches the SMS service authorization code generated in the network. If they match, the perception request (AF) is triggered under UE authorization. If they do not match, the AF is not triggered under UE authorization.
[0408] For example, the perception request can be encrypted using a shared key. When the NEF receives the encrypted perception request, it decrypts it using the shared key with the terminal device. If the decryption result includes the AF1 ID (i.e., the ID of the AF that initiated the perception request in step 2), then the AF was a perception request triggered under UE authorization. Optionally, the shared key can be a derived key obtained in the terminal device's main authentication process.
[0409] If the AF is a perception request triggered under UE authorization, then proceed to step 4; otherwise, the process terminates.
[0410] In step 4, the NEF records the first sensing parameter carried in the sensing request received in step 2, which corresponds to the AF1 ID.
[0411] In step 5, sensing is performed via SF.
[0412] For example, the NEF can send the perception request from step 2 to the SF; the SF performs perception based on the first perception parameter in the perception request. After obtaining the perception result, the SF stores the first perception parameter in association with the perception result.
[0413] Perception Request Process 2
[0414] Figure 10 is a schematic flowchart of another perception request method provided in an embodiment of this application. The method shown in Figure 10 may involve the interaction between SF, NEF, AF1, and AF2. Among them, AF is associated with enterprise users, or in other words, AF does not depend on UE.
[0415] The method shown in Figure 10 may include steps 1 through 4'.
[0416] In step 1, AF1 sends a perception request to SF via NEF. The perception request initiated by AF1 includes the first perception parameter and the AF1 ID.
[0417] In step 2, the SF performs sensing based on the first sensing parameters to obtain the sensing result. Optionally, the SF can associate and store the first sensing parameters with the sensing result.
[0418] In step 3, the SF sends a sensing response to the NEF.
[0419] The perception response is used to indicate that the perception was successfully performed according to the first perception parameter. The perception response may include indication information of successful perception, the AF1 ID, and the first perception parameter.
[0420] In step 4, NEF records the first sensing parameter corresponding to the AF1 ID.
[0421] In step 1', AF2 sends a perception request to SF via NEF. The perception request initiated by AF2 includes the second perception parameter and the AF2 ID.
[0422] In step 2', SF sensing failed. Due to sensing malfunction or other reasons, SF's sensing failed this time.
[0423] In step 3', the SF sends a sensing response to the NEF.
[0424] The perception response is used to indicate a perception failure performed according to the second perception parameter. The perception response may include indication information indicating the perception failure.
[0425] In step 4', NEF does not record the correspondence between the second sensing parameter and AF2 ID.
[0426] As mentioned earlier, the authorization methods for the second network element (such as NEF) to the first device (such as AF) can include token-based methods and non-token-based methods. The following will introduce the two authorization methods in detail.
[0427] Authorization method 1 for perception result request (non-token method)
[0428] Figure 11 is a flowchart illustrating a method for requesting a perception result according to an embodiment of this application. The method shown in Figure 11 may involve interactions between SF, NEF, and AF. Specifically, the method shown in Figure 11 uses authorization method 1, i.e., a non-token method, when requesting a perception result.
[0429] The method shown in Figure 11 may include steps 0 through 4.
[0430] In step 0, the correspondence between AF and sensing parameters is pre-configured. Alternatively, the sensing parameters and their corresponding devices are pre-configured. The device corresponding to a sensing parameter is a device that is allowed to access the sensing results associated with that sensing parameter.
[0431] In step 1, the AF sends a perception result request to the NEF. The perception result request may include the first perception parameter and the AF ID (such as AF1 ID).
[0432] In step 2, NEF verifies whether the AF1 ID corresponds to the first sensing parameter based on the pre-configuration information in step 0.
[0433] If the verification passes, proceed to step 3.
[0434] In step 2', NEF verifies whether AF1 ID is information about the device requesting to perform sensing based on the first sensing parameters. For example, NEF can verify whether AF1 ID is information about the device requesting to perform sensing based on the first sensing parameters based on the sensing parameters recorded in the aforementioned sensing request process 1 or sensing request process 2 and the corresponding device information.
[0435] If the verification passes, proceed to step 3.
[0436] In step 3, NEF sends a sensing result request to SF, and NEF receives a sensing result response from SF.
[0437] In step 4, NEF sends a sensing result response to AF.
[0438] It should be noted that this embodiment is not compatible with the CAPIF framework.
[0439] Authorization method 2 for perception result requests (token-based method)
[0440] Figure 12 is a flowchart illustrating another method for requesting authorization based on a perception result provided in an embodiment of this application. The method shown in Figure 12 may involve the interaction between NEF and AF.
[0441] The method shown in Figure 12 may include steps 0 through 5.
[0442] In step 1, AF sends a token request to NEF. This token can be used to subsequently send a sensing result request to NEF to obtain the sensing result. At this point, it is assumed that the token request does not carry sensing parameters.
[0443] In step 2, NEF sends a token response to AF.
[0444] The token response indicates that the token request failed, along with the reason for the failure (or error indication), such as "no perception parameter carried".
[0445] In step 3, AF sends a token request to NEF again.
[0446] Based on the error indication received in step 2, AF sends a token request to NEF again. The token request carries the AF ID (such as AF1 ID) and the first perception parameter.
[0447] In step 4, NEF verifies whether the AF1 ID corresponds to the first sensing parameter. Optionally, NEF verifies whether the AF1 ID is information about the device requesting sensing based on the first sensing parameter. For example, NEF can verify whether the AF1 ID is information about the device requesting sensing based on the first sensing parameter by using the sensing parameters recorded in the aforementioned sensing request process 1 or sensing request process 2 and the corresponding device information.
[0448] In step 5, NEF sends a token response to AF based on the verification result.
[0449] If the verification in step 4 passes, the token response indicates that the token request was successful, and the token response includes the token. For example, the token may include the first perception parameter and the AF1 ID. Since the token is signed by NEF, the AF cannot be tampered with, thus ensuring the authenticity of the first perception parameter and the AF1 ID.
[0450] If the verification in step 4 fails, the token response indicates that the token request failed and the reason for the failure (or error indication), such as unauthorized, or AF1 is not allowed to access the sensing result associated with the first sensing parameter, or AF1 is not the device that requested to perform sensing based on the first sensing parameter.
[0451] It should be noted that step 4 can also be replaced by: verifying whether the AF1 ID corresponds to the first sensing parameter based on the pre-configured correspondence between the AF and the sensing parameters, or in other words, based on the pre-configured sensing parameters and the information of the devices corresponding to the sensing parameters.
[0452] As can be seen, this embodiment is compatible with the CAPIF framework.
[0453] After obtaining the token, AF can use the token to request the perception result from NEF. The method of requesting the perception result from NEF using the token is described below with reference to Figure 13.
[0454] Figure 13 is a flowchart illustrating another method for requesting a perception result according to an embodiment of this application. The method shown in Figure 13 may involve the interaction between SF, NEF, and AF.
[0455] The method shown in Figure 13 may include steps 1 through 4.
[0456] In step 1, the AF requests the perception result from the NEF, carrying a token. The token includes the first perception parameter and the AF ID (such as AF1ID).
[0457] In step 2, NEF verifies whether the AF1 ID carried in the token corresponds to the first sensing parameter. Optionally, NEF verifies whether the AF1 ID is information about the device requesting to perform sensing based on the first sensing parameter. For example, NEF can verify whether the AF1 ID is information about the device requesting to perform sensing based on the first sensing parameter based on the sensing parameters recorded in the aforementioned sensing request process 1 or sensing request process 2 and the corresponding device information.
[0458] If the verification passes, proceed to steps 3 and 4; if the verification fails, proceed to step 3'.
[0459] In step 3, NEF sends a sensing result request to SF and receives a sensing result response from SF.
[0460] The perception result request includes a first perception parameter. The SF can select the perception result associated with the first perception parameter based on the first perception parameter and send it to the NEF.
[0461] In step 4, NEF sends a sensing result response to AF. This sensing result response includes the first sensing result associated with the first sensing parameter.
[0462] In step 3', NEF sends a sensing result response to AF. This sensing result response indicates that the sensing result request failed, and includes the reason for the failure (or error indication): unauthorized, or AF1 is not allowed to access the sensing result associated with the first sensing parameter, or AF1 is not the device that requested to perform sensing based on the first sensing parameter.
[0463] It should be noted that step 2 can also be replaced by: verifying whether the AF1 ID corresponds to the first sensing parameter based on the pre-configured correspondence between the AF and the sensing parameters, or in other words, based on the pre-configured sensing parameters and the information of the devices corresponding to the sensing parameters.
[0464] The above section introduced the method for obtaining the perception results of external access to mobile network elements. The following section, in conjunction with Figure 14, introduces the method for obtaining the perception results of internal access to mobile networks.
[0465] Figure 14 is a flowchart illustrating another method for requesting a perception result according to an embodiment of this application. The method shown in Figure 14 may involve interactions between SF, NRF, and NFc.
[0466] The method shown in Figure 14 may include steps 0 through 6.
[0467] In step 0, after acquiring the sensing results, SF associates and stores the sensing results and sensing parameters.
[0468] In step 0', the NRF pre-configures the correspondence between the NFC and the sensing parameters. In other words, it pre-configures the sensing parameters and the corresponding devices. The device corresponding to the sensing parameter is the device that is allowed to access the sensing results associated with that sensing parameter.
[0469] For example, the correspondence between NFC and sensing parameters can be represented as a third list, which can be pre-configured by the operator or stored in the NRF by the SF in the form of an NF Profile during registration.
[0470] In step 1, NFc sends a token request to NRF.
[0471] The token request may include a first perception parameter and an NFcID (such as an NFc1 ID), which can request a token for accessing the perception result associated with the first perception parameter.
[0472] The NRF does not include the sensing parameters and the information of the devices corresponding to the sensing parameters. If the NRF does not include a third list, the token request may also include other parameters of the NFC, such as one or more of the following: PLMN identifier, SNPN identifier, network function type, network function domain, or network slice information, to verify whether the NFC is allowed to access the SF (see the introduction above).
[0473] In step 2, the NFc1 ID is verified to correspond to the first perception parameter based on the third list.
[0474] In step 2', based on the other parameters to which NFc belongs and the first condition check, it is determined whether NFc1 is allowed to access SF.
[0475] Generally, if the NRF includes a third list, the NRF can perform verification as described in step 2. If the NRF does not include the sensing parameters and the information of the devices corresponding to the sensing parameters, such as if the NRF does not include a third list, the NRF can perform verification as described in step 2'.
[0476] Alternatively, if both steps 2 and 2' pass the verification, the NRF is considered to have successfully verified the token request.
[0477] If the above verification passes, step 3 can be executed.
[0478] In step 3, the NRF sends a token response to the NFc. This token response indicates that the token request was successful and may include the issued token.
[0479] Optionally, the token may include an NFc1 ID and a first-sensory parameter. Since the token is signed with an NRF, the NFc cannot be tampered with, thus ensuring the authenticity of the first-sensory parameter and the NFc1 ID.
[0480] In step 4, NFc sends a perception result request to SF. The perception result request includes a token.
[0481] In step 5, the SF selects the perception result associated with the first perception parameter. The SF can select the first perception result associated with the first perception parameter based on the first perception parameter carried in the token. Optionally, before selecting the first perception result based on the first perception parameter, the SF can first verify the token, such as verifying the token's format and other information. After the verification is successful, the SF can select the first perception result.
[0482] In step 6, SF sends a sensing result response to NFc. This sensing result response includes the first sensing result.
[0483] The method embodiments provided in this application have been described above. The apparatus embodiments provided in this application will be described below. It should be understood that the description of the apparatus embodiments corresponds to the description of the method embodiments. Therefore, any content not described in detail can be referred to the method embodiments above. For the sake of brevity, it will not be repeated here.
[0484] Figure 15 is a schematic block diagram of a communication device provided in an embodiment of this application. As shown in Figure 15, the communication device 1500 may include a transceiver unit 1510 and / or a processing unit 1520. The transceiver unit 1510 can implement corresponding communication functions, and the processing unit 1520 is used for data processing. The transceiver unit 1510 may also be referred to as a communication interface or a communication unit. Optionally, the device 1500 may further include a storage unit, which can be used to store instructions and / or data. The processing unit 1520 can read the instructions and / or data in the storage unit to enable the device to implement the aforementioned method embodiment.
[0485] In one possible design, the device 1500 can be a second network element in the above method embodiments. For example, the device 1500 can be a NEF network element, or a chip, processor, or chip system that implements the NEF network element function. It can also be a logical node, logical module, or software that can implement all or part of the NEF network element function. The device 1500 can be used to execute the steps or processes performed by the second network element in any of the above method embodiments.
[0486] Specifically, the transceiver unit 1510 can be used to receive a first message from the first device, the first message being used to request access to the sensing result associated with the first sensing parameter. The processing unit 1520 can be used to perform a first verification on the first sensing parameter. If the first verification passes, the transceiver unit 1510 is further used to send the first sensing result associated with the first sensing parameter to the first device.
[0487] Optionally, performing a first verification on the first sensing parameter includes: verifying whether the first sensing parameter corresponds to the information of the first device; if the first verification passes, sending a first sensing result associated with the first sensing parameter to the first device includes: if the first sensing parameter corresponds to the information of the first device, sending the first sensing result to the first device.
[0488] Optionally, the correspondence between the first sensing parameter and the information of the first device indicates that the first device is a device that is allowed to access the sensing results associated with the first sensing parameter.
[0489] Optionally, the correspondence between the first sensing parameters and the information of the first device indicates that the first device is a device that requests to perform sensing based on the first sensing parameters.
[0490] Optionally, before receiving the first message from the first device, the transceiver unit 1510 is further configured to: receive a second message from the first device, the second message being used to request to perform sensing according to the first sensing parameters; the processing unit 1520 may be configured to record the correspondence between the first sensing parameters and the first device according to the second message.
[0491] Optionally, recording the correspondence between the first sensing parameters and the first device according to the second message includes: sending a third message to the first network element according to the second message, the third message being used to request the execution of sensing according to the first sensing parameters; receiving a response from the first network element to the third message; and if the response indicates that the sensing performed according to the first sensing parameters was successful, recording the correspondence between the first sensing parameters and the first device.
[0492] Optionally, recording the correspondence between the first sensing parameter and the first device according to the second message includes: decrypting the second message using a shared key between the terminal device and the terminal device; if the decryption result includes information about the first device, then recording the correspondence between the first sensing parameter and the first device.
[0493] Optionally, the first message includes the first sensing parameters and information about the first device.
[0494] Optionally, the first message includes the first sensing parameters and information about the first device, including: the first message includes a first token, and the first token includes the first sensing parameters and information about the first device.
[0495] Optionally, before receiving the first message from the first device, the transceiver unit 1510 is further configured to: receive a fourth message from the first device, the fourth message being used to request a token for accessing the perception result associated with the first perception parameter; the processing unit 1520 may be configured to perform a second verification on the first perception parameter; if the second verification passes, the transceiver unit 1510 is further configured to send the first token to the first device.
[0496] Optionally, performing a second verification on the first sensing parameter includes: verifying whether the first sensing parameter corresponds to the information of the first device; and sending the first token to the first device if the second verification passes includes: sending the first token to the first device if the first sensing parameter corresponds to the information of the first device.
[0497] Optionally, the correspondence between the first sensing parameter and the information of the first device indicates that the first device is a device that is allowed to access the sensing results associated with the first sensing parameter.
[0498] Optionally, the correspondence between the first sensing parameters and the information of the first device indicates that the first device is a device that requests to perform sensing based on the first sensing parameters.
[0499] Optionally, before sending the first sensing result associated with the first sensing parameter to the first device, the transceiver unit 1510 is further configured to: send a sensing result request to the first network element, the sensing result request being used to request the sensing result associated with the first sensing parameter; and receive the first sensing result associated with the first sensing parameter from the first network element; wherein the first network element is a sensing function network element.
[0500] In one possible design, the device 1500 can be the first device in the above method embodiments. For example, the device 1500 can be an AF network element, or a chip, processor, or chip system that implements the AF network element function. It can also be a logic node, logic module, or software that can implement all or part of the AF network element function. The device 1500 can be used to execute the steps or processes performed by the first device in any of the above method embodiments.
[0501] The transceiver unit 1510 is configured to send a first message to the second network element, the first message being a request to access the sensing result associated with the first sensing parameter. The transceiver unit 1510 is also configured to receive the first sensing result associated with the first sensing parameter from the second network element.
[0502] Optionally, before sending the first message to the second network element, the transceiver unit 1510 is further configured to: send a second message to the second network element, the second message being used to request the execution of sensing based on the first sensing parameters.
[0503] Optionally, the first message includes the first sensing parameters and information about the first device.
[0504] Optionally, the first message includes a first token, which includes the first sensing parameter and information about the first device.
[0505] Optionally, before sending the first message to the second network element, the transceiver unit 1510 is further configured to: send a fourth message to the second network element, the fourth message being used to request a token for accessing the sensing result associated with the first sensing parameter; and receive the first token from the second network element.
[0506] In one possible design, the device 1500 can be the first network element in the above method embodiments. For example, the device 1500 can be an SF network element, or it can be a chip, processor, or chip system that implements the functions of an SF network element. It can also be a logical node, logical module, or software that can implement all or part of the functions of an SF network element. The device 1500 can be used to execute the steps or processes performed by the first network element in any of the above method embodiments.
[0507] The transceiver unit 1510 is used to receive a first message from the second network element, the first message being a request to access the sensing result associated with the first sensing parameter. The transceiver unit 1510 then sends the first sensing result associated with the first sensing parameter to the second network element.
[0508] Optionally, the first network element is a sensing function network element.
[0509] In one possible design, the device 1500 can be a third network element in the above method embodiments. For example, the device 1500 can be an NFc network element, or it can be a chip, processor, or chip system that implements the functions of an NFc network element. It can also be a logical node, logical module, or software that can implement all or part of the functions of an NFc network element. The device 1500 can be used to execute the steps or processes performed by the third network element in any of the above method embodiments.
[0510] The transceiver unit 1510 is configured to send a fifth message to the first network element, the fifth message being a request to access the sensing result associated with the first sensing parameter. The fifth message includes a first token, the first token including the first sensing parameter and information about the third network element. The transceiver unit 1510 is also configured to receive the first sensing result associated with the first sensing parameter from the first network element.
[0511] Optionally, before sending the fifth message to the first network element, the transceiver unit 1510 is further configured to: send a sixth message to the fourth network element, the sixth message being used to request a token for accessing the sensing result associated with the first sensing parameter; and receive the first token from the fourth network element.
[0512] In one possible design, the device 1500 can be the fourth network element in the above method embodiments. For example, the device 1500 can be an NRF network element, or it can be a chip, processor, or chip system that implements the NRF network element function. It can also be a logical node, logical module, or software that can implement all or part of the NRF network element function. The device 1500 can be used to execute the steps or processes performed by the fourth network element in any of the above method embodiments.
[0513] The transceiver unit 1510 is configured to receive a sixth message from a third network element, the sixth message being a request for a token for accessing the sensing result associated with the first sensing parameter. The processing unit 1520 is configured to perform a third verification based on the sixth message. If the third verification passes, the transceiver unit 1510 is further configured to send a first token to the third network element, the first token including the first sensing parameter and information of the third network element.
[0514] Optionally, the sixth message includes the first sensing parameter, and the third verification based on the sixth message includes: verifying whether the first sensing parameter corresponds to the information of the third network element; if the third verification passes, sending the first token to the third network element includes: if the first sensing parameter corresponds to the information of the third network element, sending the first token to the third network element.
[0515] Optionally, the correspondence between the first sensing parameter and the information of the third network element indicates that the third network element is a device that is allowed to access the sensing results associated with the first sensing parameter.
[0516] Optionally, the third verification includes verifying whether the third network element is allowed to access the first network element, wherein the first network element includes the first sensing parameter associated with the first sensing result; wherein, if the third network element is allowed to access the first network element, the third verification passes.
[0517] Optionally, if the first condition is met, the third network element is allowed to access the first network element, wherein the first condition includes one or more of the following conditions: the identifier of the public terrestrial mobile network to which the network element allowed to access the first network element belongs includes the identifier of the public terrestrial mobile network to which the third network element belongs; the identifier of the independent non-public network to which the network element allowed to access the first network element belongs includes the identifier of the independent non-public network to which the third network element belongs; the type of the network element allowed to access the first network element includes the type of the third network element; the network functional domain to which the network element allowed to access the first network element belongs includes the network functional domain to which the third network element belongs; or the network slice to which the network element allowed to access the first network element belongs includes the network slice to which the third network element belongs.
[0518] In one possible design, the device 1500 can be the first network element in the above method embodiments. For example, the device 1500 can be an SF network element, or it can be a chip, processor, or chip system that implements the functions of an SF network element. It can also be a logical node, logical module, or software that can implement all or part of the functions of an SF network element. The device 1500 can be used to execute the steps or processes performed by the first network element in any of the above method embodiments.
[0519] The transceiver unit 1510 is used to receive a fifth message from a third network element, the fifth message being used to request access to the sensing result associated with the first sensing parameter, the fifth message including a first token, the first token including the first sensing parameter and information of the third network element; and to send the first sensing result associated with the first sensing parameter to the third network element.
[0520] Optionally, the first network element is a sensing function network element.
[0521] It should be understood that the "unit" in device 1500 can be implemented in hardware, software, or by hardware executing corresponding software. For example, the "unit" can refer to an application-specific integrated circuit (ASIC), electronic circuitry, a processor (e.g., a shared processor, a proprietary processor, or a group processor, etc.) and memory for executing one or more software or firmware programs, combined logic circuitry, and / or other suitable components supporting the described functions. As another example, transceiver unit 1510 can be replaced by transceiver circuitry (e.g., it may include receiving and transmitting circuitry), and processing unit 1520 can be replaced by a processor or processing circuitry.
[0522] Figure 16 shows a schematic block diagram of another communication device provided in an embodiment of this application. The communication device 1600 may be a first network element, a second network element, a third network element, a fourth network element, or a first device; it may also be a chip, chip system, or processor, etc., within the first network element, second network element, third network element, fourth network element, or first device that implements the above-described method. This device can be used to implement the methods described in the above-described method embodiments, and specific details can be found in the descriptions of the above-described method embodiments.
[0523] The communication device 1600 may include one or more processors 1610, which may also be referred to as processing units, and can implement certain control functions. The processor 1610 may be a general-purpose processor or a dedicated processor, such as a baseband processor or a central processing unit. The baseband processor can be used to process communication protocols and communication data, while the central processing unit can be used to control the communication device, execute software programs, and process data from the software programs.
[0524] In an alternative design, the processor 1610 may also store instructions and / or data that can be executed by the processor 1610 to cause the communication device 1600 to perform the methods described in the above method embodiments.
[0525] In another alternative design, the communication device 1600 may include a communication interface 1620 for implementing receiving and transmitting functions. For example, the communication interface 1620 may be a transceiver circuit, interface, interface circuit, or transceiver. The transceiver circuit, interface, interface circuit, or transceiver for implementing receiving and transmitting functions may be separate or integrated. The aforementioned transceiver circuit, interface, interface circuit, or transceiver may be used for reading and writing code / data, or it may be used for transmitting or relaying signals.
[0526] Optionally, the communication device 1600 may include one or more memories 1630, which may store instructions that can be executed on the processor 1610, causing the communication device 1600 to perform the methods described in the above method embodiments. Optionally, the memories 1630 may also store data. Optionally, the processor 1610 may also store instructions and / or data. The processor 1610 and the memories 1630 may be provided separately or integrated together.
[0527] It should be understood that, in one possible design, the steps in the method embodiments provided in this application can be implemented by integrated logic circuits in the processor's hardware or by instructions in software form. The steps of the method disclosed in the embodiments of this application can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules in the processor. The software modules can reside in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method. To avoid repetition, detailed descriptions are not provided here.
[0528] It should be noted that the processor in the embodiments of this application can be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method embodiments can be completed by the integrated logic circuits in the processor's hardware or by instructions in software form. The processor can be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this application can be directly embodied in the execution of a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software modules can be located in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. This storage medium is located in memory, and the processor reads the information in the memory and, in conjunction with its hardware, completes the steps of the above method.
[0529] It is understood that the memory in the embodiments of this application can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM). It should be noted that the memory used in the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.
[0530] This application also provides a computer program product, which includes computer program code. When the computer program code is run on a computer, it causes the computer to execute the various steps or processes performed by the network element / device in any of the above method embodiments.
[0531] This application also provides a computer-readable storage medium storing program code that, when run on a computer, causes the computer to execute the various steps or processes performed by the network element / device in any of the above method embodiments.
[0532] This application also provides a communication device, including a processor and an interface, the interface being used to send and / or receive signals, causing the processor to execute the various steps or processes performed by the network element / device in any of the above method embodiments.
[0533] The above-described device and method embodiments are completely corresponding, with corresponding modules or units performing corresponding steps. For example, a communication unit or communication interface performs the receiving or sending steps in the method embodiment, while other steps besides sending and receiving can be performed by a processing unit or processor.
[0534] In the embodiments of this application, the terms and English abbreviations are exemplary examples given for ease of description and should not be construed as limiting the application in any way. The embodiments of this application do not preclude the possibility of defining other terms that can achieve the same or similar functions in existing or future agreements.
[0535] As used in this specification, the terms "component," "module," "system," etc., are used to refer to computer-related entities, hardware, firmware, combinations of hardware and software, software, or software in execution. For example, a component can be, but is not limited to, a process running on a processor, a processor, an object, an executable file, an execution thread, a program, and / or a computer. As illustrated, applications running on computing devices and computing devices can both be components. One or more components may reside in a process and / or an execution thread, and components may be located on a single computer and / or distributed among two or more computers. Furthermore, these components can be executed from various computer-readable storage media on which various data structures are stored. Components can communicate, for example, via local and / or remote processes based on signals having one or more data packets (e.g., data from two components interacting with another component between a local system, a distributed system, and / or a network, such as the Internet interacting with other systems via signals).
[0536] Those skilled in the art will recognize that the various illustrative logical blocks and steps described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this application.
[0537] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be based on the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0538] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0539] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0540] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0541] In the above embodiments, the functions of each functional unit can be implemented entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions (programs). When the computer program instructions (programs) are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available media may be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media (e.g., solid-state disks, SSDs), etc.
[0542] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solutions of the embodiments of this application, essentially or in other words, the parts that contribute to the prior art, or parts of the technical solutions, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0543] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A communication method characterized by comprising: The method comprises: receiving a first message from a first device, the first message being used to request access to a first perception parameter associated perception result; performing a first check on the first perception parameter; if the first check passes, sending a first perception result associated with the first perception parameter to the first device.
2. The method of claim 1, wherein, The performing a first check on the first perception parameter comprises checking whether the first perception parameter corresponds to information of the first device. The if the first check passes, sending a first perception result associated with the first perception parameter to the first device comprises: if the first perception parameter corresponds to the information of the first device, sending the first perception result to the first device.
3. The method of claim 2, wherein, The first perception parameter corresponding to the information of the first device means that the first device is a device allowed to access the first perception parameter associated perception result.
4. The method of claim 2, wherein, The first perception parameter corresponding to the information of the first device means that the first device is a device requesting to perform perception according to the first perception parameter.
5. The method of claim 4, wherein, Before the receiving a first message from a first device, the method further comprises: receiving a second message from the first device, the second message being used to request to perform perception according to the first perception parameter; according to the second message, recording that the first perception parameter corresponds to the first device.
6. The method of claim 5, wherein, The according to the second message, recording that the first perception parameter corresponds to the first device comprises: sending a third message to a first network element according to the second message, the third message being used to request to perform perception according to the first perception parameter; receiving a response to the third message from the first network element; if the response indicates that the perception performed according to the first perception parameter is successful, recording that the first perception parameter corresponds to the first device.
7. The method according to claim 5 or 6, characterized in that, The according to the second message, recording that the first perception parameter corresponds to the first device comprises: decrypting the second message using a shared key between a terminal device and the first device; if a result of the decryption comprises information of the first device, recording that the first perception parameter corresponds to the first device.
8. The method according to any one of claims 1-7, characterized in that, The first message comprises the first perception parameter and the information of the first device.
9. The method of claim 8, wherein, The first message comprises the first perception parameter and the information of the first device comprises: the first message comprises a first token, the first token comprising the first perception parameter and the information of the first device.
10. The method of claim 9, wherein, Before the receiving a first message from a first device, the method further comprises: receiving a fourth message from the first device, the fourth message being used to request a token for accessing the first perception parameter associated perception result; performing a second check on the first perception parameter; if the second check passes, sending the first token to the first device.
11. The method of claim 10, wherein: The performing a second check on the first perception parameter comprises checking whether the first perception parameter corresponds to information of the first device. The if the second check passes, sending the first token to the first device comprises: If the first awareness parameter corresponds to information of the first device, sending the first token to the first device.
12. The method of claim 11, wherein, The first awareness parameter corresponding to the information of the first device means that the first device is a device allowed to access awareness results associated with the first awareness parameter.
13. The method of claim 11, wherein, The first awareness parameter corresponding to the information of the first device means that the first device is a device requesting to perform awareness according to the first awareness parameter.
14. The method of any one of claims 1-13, wherein, Before the first awareness result associated with the first awareness parameter is sent to the first device, the method further comprises: sending an awareness result request to a first network element, the awareness result request being used to request awareness results associated with the first awareness parameter; receiving first awareness results associated with the first awareness parameter from the first network element; The first network element is an awareness function network element.
15. A method of communication, comprising: Comprising: sending a first message to a second network element, the first message being used to request access to awareness results associated with a first awareness parameter; receiving first awareness results associated with the first awareness parameter from the second network element.
16. The method of claim 15, wherein, Before the first message is sent to the second network element, the method further comprises: sending a second message to the second network element, the second message being used to request to perform awareness according to the first awareness parameter.
17. The method according to claim 15 or 16, characterized in that The first message is from a first device, and the first message includes the first awareness parameter and information of the first device.
18. The method of claim 17, wherein, The first message includes a first token, and the first token includes the first awareness parameter and information of the first device.
19. The method of claim 18, wherein, Before the first message is sent to the second network element, the method further comprises: sending a fourth message to the second network element, the fourth message being used to request a token for accessing awareness results associated with the first awareness parameter; receiving the first token from the second network element.
20. A method of communication, comprising: Comprising: sending a fifth message to a first network element, the fifth message being used to request access to awareness results associated with a first awareness parameter, the fifth message including a first token, the first token including the first awareness parameter and information of a third network element; receiving first awareness results associated with the first awareness parameter from the first network element.
21. The method of claim 20, wherein, Before the fifth message is sent to the first network element, the method further comprises: sending a sixth message to a fourth network element, the sixth message being used to request a token for accessing awareness results associated with the first awareness parameter; receiving the first token from the fourth network element.
22. A method of communication, comprising: Comprising: receiving a sixth message from a third network element, the sixth message being used to request a token for accessing awareness results associated with a first awareness parameter; performing a third check according to the sixth message; If the third check passes, sending a first token to the third network element, the first token including the first awareness parameter and information of the third network element.
23. The method of claim 22, wherein, The sixth message includes the first awareness parameter, and the third check according to the sixth message comprises: checking whether the first awareness parameter corresponds to the information of the third network element; The If the third check passes, sending the first token to the third network element comprises: If the first awareness parameter corresponds to information of the third network element, the first token is sent to the third network element.
24. The method of claim 23, wherein, The first awareness parameter corresponding to the information of the third network element means that the third network element is a device allowed to access awareness results associated with the first awareness parameter.
25. The method of claim 22, wherein, The third check includes checking whether the third network element is allowed to access a first network element including a first awareness result associated with the first awareness parameter. If the third network element is allowed to access the first network element, the third check is passed.
26. The method of claim 25, wherein, If the first condition is met, the third network element is allowed to access the first network element, wherein the first condition includes one or more of the following conditions: An identifier of a public land mobile network to which a network element allowed to access the first network element belongs includes an identifier of a public land mobile network to which the third network element belongs; An identifier of an independent non-public network to which a network element allowed to access the first network element belongs includes an identifier of an independent non-public network to which the third network element belongs; A type of a network element allowed to access the first network element includes a type of the third network element; A network function domain to which a network element allowed to access the first network element belongs includes a network function domain to which the third network element belongs; or A network slice to which a network element allowed to access the first network element belongs includes a network slice to which the third network element belongs.
27. A communications device, characterized by A unit for performing each step of the method of any one of claims 1-26.
28. A communications device, characterized by An apparatus comprising a processor coupled with a memory storing a program or instructions that, when executed by the processor, cause the apparatus to perform the method of any one of claims 1-26.
29. A readable storage medium, on which a computer program or instructions are stored, characterized in that, The computer program or instructions, when executed, cause the computer to perform the method of any one of claims 1-26.
30. A computer program product, characterised in that, The computer program instructions cause the computer to perform the method of any one of claims 1-26.
31. A method of communication, comprising: Comprising: The third network element sends a fifth message to the first network element, the fifth message being used to request access to awareness results associated with a first awareness parameter, the fifth message including a first token, the first token including the first awareness parameter and information of the third network element; The first network element receives the fifth message from the third network element, and sends a first awareness result associated with the first awareness parameter to the third network element; The third network element receives the first awareness result from the first network element.
32. A method of communication, comprising: Comprising: The third network element sends a sixth message to a fourth network element, the sixth message being used to request a token for accessing awareness results associated with a first awareness parameter; The fourth network element receives the sixth message from the third network element, and performs a third check according to the sixth message; The fourth network element, in a case where the third check is passed, sends a first token to the third network element, the first token including the first awareness parameter and information of the third network element; The third network element receives the first token from the fourth network element.
33. A communication system including a communication device for performing the method of claim 20 or 21 and a first network element for: receiving a fifth message from the communication device, sending a first sensing result associated with a first sensing parameter to the communication device.
34. A communication system including a communication device for performing the method of claim 20 or 21 and a communication device for performing the method of any one of claims 22-26.
Citation Information
Patent Citations
Perception authentication method, device and node
CN117956453A
Perception data collection method, device, equipment and system and storage medium
CN118056417A
Systems, methods, and computer readable media for sharing awareness information
US20120079018A1
Security implementation method and apparatus, terminal device, and network elements
WO2023159603A1