Communication method and apparatus

By establishing trust agreements between network elements and determining trusted status permissions, the security issues of embedded systems and IoT devices are resolved, and communication security and resource utilization efficiency are improved.

WO2026001734A1PCT designated stage Publication Date: 2026-01-02HUAWEI TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/101132
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-06-25
Filing Date
2025-06-16
Publication Date
2026-01-02

AI Technical Summary

Technical Problem

Embedded systems and IoT devices are vulnerable to attack due to cost, size, and power limitations, making it difficult to effectively prevent attackers from compromising the trusted state of the devices.

Method used

By establishing trust relationships between network elements, the trusted status permissions of network elements are determined, ensuring that only authorized network elements can query the trusted status of target network elements, thereby reducing the risk of information leakage.

Benefits of technology

It improves the security of communication between network elements, reduces the chance of information leakage, and saves signaling overhead and resource consumption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025101132_02012026_PF_FP_ABST
    Figure CN2025101132_02012026_PF_FP_ABST
Patent Text Reader

Abstract

The embodiments of the present application relate to the technical field of communications. Provided are a communication method and apparatus, which can determine the security of a network element used for implementing communication between a relying party and a verifier. The method comprises: a first network element receiving first request information; determining a trust certificate on the basis of the first request information; and sending second request information, wherein the first request information is used for requesting the measurement of a trusted status of a target network element, the trust certificate is used for indicating that the first network element has the permission to query the trusted status of the target network element, the second request information is used for requesting the trusted status of the target network element, and the second request information is further used for indicating the trust certificate.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method and apparatus

[0001] The present application claims priority from the Chinese patent application No. 202410836343.5 filed on June 25, 2024, and entitled "Communication method and apparatus", the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD

[0002] The present application relates to the field of communication technology, in particular to a communication method and apparatus. BACKGROUND

[0003] Embedded systems, Internet of Things devices, virtualized devices, and the like have entered many scenarios of daily life: home, office, factory, etc. The number of these devices has entered a boom.

[0004] However, due to cost, size, and power limitations, security is usually not a priority for device manufacturers. Therefore, these devices have a large attack surface that can be exploited by attackers, thereby affecting the security of the device and even the entire system.

[0005] Since it is difficult to prevent attackers from attacking devices, it is necessary to try to check whether the device has been attacked. One possible implementation is to use remote attestation (RA) technology. When a relying party (RP) exists verification requirement, the trusted state of the target network element needs to be requested from the verifier. Therefore, the verifier can send a request to the attester to determine the evidence and send it to the verifier for verifying the trusted state of the device. Further, the verifier can inform the RP of the trusted state.

[0006] Specifically, the RP can obtain the attestation result from the verifier through a specific network element. That is, the RP obtains the attestation result depends on the network element. Therefore, how to ensure the security of the network element is a problem to be solved urgently. SUMMARY

[0007] The communication method and apparatus provided by the embodiments of the present application can determine the security of the network element used to realize the communication between the relying party RP and the verifier.

[0008] In a first aspect, a communication method is provided, which can be performed by a first network element. The first network element can refer to the first network element itself, a component (e.g., a communication module, a processor, a circuit, a chip, or a chip system) in the first network element, or a logic module or software capable of implementing all or part of the functions of the first network element. The method includes: receiving first request information, the first request information being used to request a trust status of a target network element; determining a letter of trust according to the first request information, the letter of trust being used to indicate that the first network element has the permission to query the trust status of the target network element; and sending second request information, the second request information being used to request the trust status of the target network element, and the second request information being further used to indicate the letter of trust.

[0009] Based on the scheme, when the first network element receives a request for measurement (e.g., the first request information), the first network element can obtain the permission to query the trust status of the target network element (i.e., the letter of trust), and then obtain the trust status of the target network element (e.g., the first measurement result). That is, the first network element can query the trust status of the target network element only when the first network element has the permission. This can avoid the first network element querying the trust status of a network element without authorization. It can be understood that the first network element that can obtain authorization is usually trusted, and thus, obtaining the permission for the first network element to query the trust status of the target network element can be regarded as determining the security of the first network element. That is, when the first network element obtains the permission, it means that the first network element is trusted. Therefore, the probability of the information of the target network element being leaked can be reduced.

[0010] In a possible design, the first request information is further used to indicate first information of the target network element, and determining the letter of trust according to the first request information includes: determining the letter of trust according to the first information of the target network element, the first information of the target network element being information related to the target network element.

[0011] Based on the possible design, the first network element can determine the letter of trust based on the related information of the target network element (i.e., the first information of the target network element), so as to ensure that the letter of trust is the permission for the target network element (e.g., the letter of trust can be used to indicate that the first network element has the permission to query the trust status of the target network element). Then, after the first network element obtains the permission (i.e., the letter of trust), the first network element can be considered as trusted, so as to reduce the probability of the information of the target network element being leaked.

[0012] In a possible design, determining the letter of trust according to the first information of the target network element includes: determining authentication information corresponding to second information of the target network element according to the second information of the target network element and preconfigured information, the second information of the target network element being determined according to the first information of the target network element, the preconfigured information including a correspondence between second information of a plurality of network elements and a plurality of authentication information, and the letter of trust including the authentication information corresponding to the second information of the target network element.

[0013] In a possible design, the second information of the target network element includes a first identifier or a second identifier, the first identifier being an identifier of a vendor to which the target network element belongs, and the second identifier being an identifier of a network function type of the target network element.

[0014] Based on the above two possible designs, the first network element can query, in the preconfigured information thereof, whether there is authentication information of the target network element (that is, whether there is authentication information corresponding to the second information of the target network element); if there is, the aforementioned credential includes the authentication information. That is, the first network element does not need to rely on other network elements, and can determine the credential by the preconfigured information itself, thereby improving the efficiency of determining the credential and saving signaling overhead.

[0015] In a possible design, the second request information is further used to indicate the second information of the target network element.

[0016] Based on this possible design, the second request information can further indicate the second information of the target network element, so that the receiver of the second request information can verify the credential based on the second information of the target network element, thereby improving the accuracy of the verification result of the credential.

[0017] In a possible design, the credential is used to indicate that the first network element has the permission to query the trusted state of the target network element, including: the credential is used to grant the first network element the permission to obtain the trusted state of the target network element; further, determining the credential according to the first information of the target network element includes: sending third request information, the third request information being used to request the credential, and the third request information being further used to indicate the first information of the target network element; and receiving the credential.

[0018] Based on this possible design, the first network element can request other network elements to grant the credential to it (that is, send the third request information) to obtain the credential. That is, when the first network element has a demand (that is, needs the credential), the first network element can request the network element, and the first network element itself does not need to store the permission (such as one or more credentials) that it has, thereby saving the storage space of the first network element.

[0019] In a possible design, before sending the third request information, the communication method further includes: determining, according to the first information of the target network element, whether there is the credential; and sending the third request information includes: when there is no credential, sending the third request information.

[0020] In a possible design, sending the second request information includes: determining, according to the first information of the target network element, whether there is the credential; and when there is the credential, sending the second request information.

[0021] Based on the two possible designs above, the first network element can first query whether the credential exists, and if not, request the credential from other network elements; if the credential exists, there is no need to request from other network elements, and the first network element can directly request the third network element to acquire the trusted state of the target network element, thereby saving resources and improving the efficiency of the first network element in acquiring the trusted state of the target network element.

[0022] In a possible design, the third request information is used to indicate the identity of the first network element and / or the first information of the target network element, and the identity of the first network element and the first information of the target network element are used to determine the credential.

[0023] Based on the possible design, the identity of the first network element and / or the first information of the target network element can be carried in the third request information, so as to ensure that the credential is used for the authority of the target network element (for example, the credential can be used to indicate that the first network element has the authority to query the trusted state of the target network element), and then after the first network element acquires the authority (i.e., the credential), it can be considered that the first network element is trusted, thereby reducing the probability of information leakage of the target network element.

[0024] In a possible design, the communication method further includes: acquiring the first measurement result according to the second request information, the first measurement result being used to indicate the trusted state of the target network element; and sending the first response information, the first response information being used to indicate the first measurement result.

[0025] Based on the possible design, the first network element acquires the trusted state of the target network element, which can respond to the first request information, i.e., send the first response information to the sender of the first request information, so that the sender of the first request information knows the trusted state of the target network element.

[0026] In a possible design, acquiring the first measurement result according to the second request information includes: when the credential verification is passed, receiving the second response information, the second response information being used to indicate the first measurement result, and the second response information responding to the second request information.

[0027] Based on the possible design, when the credential verification is passed, the first network element can receive the trusted state of the target network element (i.e., the second response information) from other network elements (such as the third network element); it can be understood that the credential verification passing indicates that the first network element indeed has the authority to query the trusted state of the target network element; at this time, it can also be considered that the first network element is trusted; that is, the third network element sends the trusted state of the target network element to the first network element only when the first network element is trusted, thereby reducing the probability of information leakage of the target network element.

[0028] In a possible design, the first measurement result is stored in the secure storage network element in response to the second request information; and the credential is further used to indicate that the first network element has the permission to query the secure storage network element; and the first measurement result is obtained by determining the first measurement result from the secure storage network element.

[0029] In a possible design, the secure storage network element is used by a plurality of network elements to share the information stored therein, and the plurality of network elements includes the first network element.

[0030] Based on the above two possible designs, when the first measurement result is stored in the secure storage network element, the first network element can determine the trusted state of the target network element from the secure storage network element, in this way, the first network element can obtain the trusted state of the target network element by itself, thereby saving the resources for interaction between network elements.

[0031] In a second aspect, a communication method is provided, which can be performed by a third network element. In the absence of a special description, the third network element in the present application can refer to the third network element itself, a component (for example, a communication module, a processor, a circuit, a chip, or a chip system, etc.) in the third network element, or a logic module or software capable of realizing all or part of the functions of the third network element. The method comprises: receiving second request information from a first network element, the second request information being used to request a trusted state of a target network element, and the second request information being further used to indicate a credential, the credential being used to indicate that the first network element has the permission to query the trusted state of the target network element; verifying the credential; and when the credential is verified, determining a first measurement result, the first measurement result being used to indicate the trusted state of the target network element.

[0032] Based on this scheme, after the first network element obtains the permission (i.e., the credential) to query the trusted state of the target network element, the first network element can send the second request information to the third network element to obtain the trusted state (e.g., the first measurement result) of the target network element. That is, the first network element can only query the trusted state of the target network element after obtaining the permission, thereby avoiding that the first network element queries the trusted state of a network element without authorization.

[0033] Further, when the first network element requests the trusted state of the target network element from the third network element (i.e., sends the second request information to the third network element), the third network element can first verify whether the query permission (i.e., the credential) of the first network element is valid (i.e., determine the security of the first network element), so that when it is determined that the query permission is valid (i.e., the credential is verified), the first network element can be considered to be trusted, thereby reducing the probability that the information of the target network element is leaked when the third network element determines the trusted state (i.e., the first measurement result) of the target network element.

[0034] In a possible design, before receiving the second request information from the first network element, the communication method further includes: establishing a transport layer security (TLS) with the first network element.

[0035] Based on this possible design, the step of verifying the credential by the third network element is performed after the TLS is established between the first network element and the third network element; the information interaction between the first network element and the third network element can be ensured to be secure, so that the probability of passing the verification due to the credential being attacked during transmission is reduced.

[0036] In a possible design, the credential includes authentication information corresponding to the second information of the target network element, and the second information of the target network element is determined according to first information of the target network element, where the first information of the target network element is information related to the target network element.

[0037] In a possible design, the second information of the target network element includes a first identifier or a second identifier, where the first identifier is an identifier of a vendor to which the target network element belongs, and the second identifier is an identifier of a network function type of the target network element.

[0038] In a possible design, the second request information is further used to indicate the second information of the target network element.

[0039] In a possible design, the communication method further includes: determining a first record, where the first record is a record of the first network element requesting the trusted state of the target network element; and writing the first record into a secure storage network element.

[0040] In a possible design, the secure storage network element is used to enable multiple network elements to share information stored in the secure storage network element, and the multiple network elements include the first network element and a third network element.

[0041] Based on this possible design, the secure storage network element can enable multiple network elements to share information, that is, the multiple network elements can learn information of other network elements (that is, network elements other than the network elements themselves in the multiple network elements) without signaling interaction between the multiple network elements, thereby saving signaling overhead. In addition, when the multiple network elements share information, the information in the secure storage network element does not change with modification of a single network element, thereby avoiding malicious tampering of information by a certain network element and improving the security of the information.

[0042] In a possible design, before writing the first record into the secure storage network element, the communication method further includes: establishing a consensus group, where the consensus group includes multiple verification entities, and the verification entity is used to determine the trusted state of the target network element; and determining a master node from the multiple verification entities, where the master node is a network element in the multiple verification entities, and the master node is used to determine the first record.

[0043] Based on the possible design, multiple verification entities (including the third network element) can establish a consensus group; it can be understood that multiple network elements in the same consensus group can ensure the consistency and credibility of data through cooperation or competition; that is, when the third network element determines the trusted state of the target network element, other network elements in the consensus group will also determine the trusted state of the target network element, and further, multiple network elements can determine whether the mutual verification (i.e., determining the trusted state of the target network element determined by themselves and other network elements) is consistent, and finally determine a unique trusted state of the target network element as the first measurement result. In short, multiple network elements in the same consensus group can verify the trusted state of the target network element, avoid that the trusted state of the target network element determined by a single network element is untrusted, and thus improve the credibility of the first measurement result.

[0044] In a possible design, determining the first measurement result includes: determining whether the first measurement result is stored in the secure storage network element; and when the first measurement result is stored in the secure storage network element, determining the first measurement result from the secure storage network element.

[0045] Based on the possible design, when the first measurement result is stored in the secure storage network element, the third network element can determine the trusted state of the target network element from the secure storage network element, and in this way, the third network element can obtain the trusted state of the target network element by itself, thereby saving signaling overhead of interaction between network elements.

[0046] In a possible design, determining the first measurement result includes: receiving evidence of the target network element, the evidence of the target network element being evidence used to determine the trusted state of the target network element; determining a first trusted state according to the evidence of the target network element, the first trusted state being the trusted state of the target network element determined by the third network element, and the first measurement result indicating the first trusted state.

[0047] Based on the possible design, the third network element can determine the trusted state (i.e., the first trusted state) of the target network element according to the evidence of the target network element, and thus determine the first measurement result.

[0048] In a possible design, the communication method further includes: writing the first measurement result into the secure storage network element.

[0049] Based on the possible design, after determining the first measurement result, the third network element can write the first measurement result into the secure storage network element; so that the first network element and other network elements in the consensus group can obtain the first measurement result from the secure storage network element.

[0050] In a possible design, the communication method further includes: sending the first trusted state. Illustratively, the first trusted state is sent to a fifth network element, the fifth network element being at least one of the multiple network elements in the consensus group.

[0051] In a possible design, the communication method further includes: sending the first measurement result. Exemplarily, the first measurement result can be sent to the first network element.

[0052] In a possible design, the communication method further includes: determining a second measurement result, the second measurement result being used to indicate a trusted state of the first network element; and determining the first measurement result includes: when the second measurement result indicates that the first network element is trusted, determining the first measurement result.

[0053] Based on the possible design, the first network element can determine the trusted state of the first network element, and when the first network element is trusted, the first measurement result is further determined, and the first measurement result can be further sent to the first network element, thereby reducing the probability of information leakage of the target network element.

[0054] The technical effects brought by any design in the second aspect can refer to the technical effects brought by the corresponding design in the first aspect, which will not be repeated here.

[0055] In a third aspect, a communication method is provided, which can be executed by a fifth network element. Unless otherwise specified, the fifth network element in the present application can refer to the fifth network element itself, a component (for example, a communication module, a processor, a circuit, a chip, or a chip system) in the fifth network element, or a logic module or software that can realize all or part of the function of the fifth network element. The method includes: determining a first measurement result, the first measurement result being used to indicate a trusted state of a target network element; obtaining an identifier of the first network element from a secure storage network element or a third network element; and sending the first measurement result to the first network element according to the identifier of the first network element; and the third network element is located in the same consensus group as the fifth network element.

[0056] Based on the scheme, when the fifth network element does not receive the request information of the first network element requesting the trusted state of the target network element, the fifth network element can learn the demand side (for example, the first network element) of the trusted state of the target network element from the secure storage network element or other network elements (that is, the third network element) in the consensus group, thereby being able to send the first measurement result to the first network element, so that the first network element can obtain the first measurement result.

[0057] In a possible design, the identifier of the first network element is obtained from the secure storage network element, including: the fifth network element queries a first record in the secure storage network element, the first record being a record of the first network element requesting the trusted state of the target network element, and the first record including the identifier of the first network element.

[0058] Based on the possible design, the fifth network element does not need to obtain the identifier of the first network element by sending to other network elements, but can directly obtain the identifier of the first network element from the secure storage network element (for example, by the first record in the secure storage network element), thereby saving resources and improving the efficiency of the first network element obtaining the trusted state of the target network element.

[0059] In a possible design, the obtaining, by the fifth network element, the identifier of the first network element from the third network element comprises: receiving first indication information from the third network element, the first indication information being used to indicate second request information, the second request information being the request information for the first network element to request the trusted state of the target network element.

[0060] Based on the possible design, since the third network element can receive the second request information from the first network element, the fifth network element can obtain the second request information from the third network element (for example, receive the first indication information from the third network element), and thus can determine the identifier of the first network element according to the second request information, and further send the first measurement result to the first network element, so that the first network element can obtain the first measurement result.

[0061] In a possible design, the determining the first measurement result comprises: determining whether the first measurement result is stored in the secure storage network element; and when the first measurement result is stored in the secure storage network element, determining the first measurement result from the secure storage network element.

[0062] In a possible design, the determining the first measurement result comprises: receiving evidence of the target network element, the evidence of the target network element being evidence used to determine the trusted state of the target network element; determining a second trusted state according to the evidence of the target network element, the second trusted state being the trusted state of the target network element determined by the third network element, and the first measurement result indicating the second trusted state.

[0063] In a possible design, the determining the first measurement result further comprises: sending the second trusted state; and when the second trusted state is valid, the first measurement result indicating the second trusted state comprises: the first measurement result indicating the first trusted state or the second trusted state, and the first trusted state being the same as the second trusted state.

[0064] In a possible design, the communication method further comprises: writing the second trusted state into the secure storage network element.

[0065] In a possible design, the secure storage network element is used for multiple network elements to share information stored therein, and the multiple network elements include the first network element and the fifth network element.

[0066] The technical effects brought by any design in the third aspect can refer to the technical effects brought by the corresponding design in the first aspect or the second aspect, which will not be repeated here.

[0067] In a fourth aspect, a communication apparatus is provided for implementing various methods. The communication apparatus can be the first network element in the first aspect, or the third network element in the second aspect, or the fifth network element in the third aspect, or an apparatus (e.g., a chip or chip system) included in the first network element or the third network element or the fifth network element. The communication apparatus includes a module, a unit, or a means for implementing each function of the methods, which can be implemented in hardware, software, or a combination of both. The hardware or software includes one or more modules or units corresponding to the functions.

[0068] In some possible designs, the communication apparatus can include a processing module and a transceiving module. The processing module can be used to implement the processing functions in any of the aspects and any of their possible implementations. The transceiving module can include a receiving module and a sending module to implement the receiving functions and the sending functions in any of the aspects and any of their possible implementations, respectively.

[0069] In some possible designs, the transceiving module can include a transceiver circuit, a transceiver, a transceiver, or a communication interface, etc.

[0070] In a fifth aspect, a communication apparatus is provided, which includes a processor and a memory coupled to the processor. The memory is configured to store computer instructions, which, when executed by the processor, cause the communication apparatus to perform the methods in any of the aspects. The communication apparatus can be the first network element in the first aspect, or the third network element in the second aspect, or the fifth network element in the third aspect, or an apparatus (e.g., a chip or chip system) included in the first network element or the third network element or the fifth network element. In some possible designs, the communication apparatus further includes the memory. Optionally, the memory and the processor are integrated together.

[0071] In a sixth aspect, a communication apparatus is provided, which includes a processor and a communication interface. The communication interface is configured to communicate with modules outside the communication apparatus. The processor is configured to execute computer programs or instructions and / or through a logic circuit, so as to cause the communication apparatus to perform the methods in any of the aspects. The communication apparatus can be the first network element in the first aspect, or the third network element in the second aspect, or the fifth network element in the third aspect, or an apparatus (e.g., a chip or chip system) included in the first network element or the third network element or the fifth network element.

[0072] In a seventh aspect, a communication apparatus is provided, which comprises at least one processor; the processor is configured to execute computer programs or instructions, so that the communication apparatus performs the method in any of the aspects. The communication apparatus can be the first network element in the first aspect, or the third network element in the second aspect, or the fifth network element in the third aspect, or an apparatus (such as a chip or chip system) included in the first network element or the third network element or the fifth network element. In some possible designs, the communication apparatus comprises a memory, which is configured to store necessary programs or instructions and data. The memory can be integrated with the processor, or can be independent of the processor.

[0073] In some possible designs, when the apparatus is a chip system, the apparatus can be composed of a chip, or can comprise a chip and other discrete devices.

[0074] It can be understood that, when the communication apparatus in any of the fourth aspect to the seventh aspect is a chip, the sending action / function of the communication apparatus can be understood as outputting information, and the receiving action / function of the communication apparatus can be understood as inputting information.

[0075] In addition, the communication apparatus can be a network device, or a communication module in the network device, or a circuit or chip responsible for communication functions in the network device, or a functional module capable of invoking and executing programs in the network device.

[0076] In an eighth aspect, a computer readable storage medium is provided, which stores computer programs or instructions, when the computer programs or instructions are executed on a communication apparatus, the communication apparatus can perform the method in any of the aspects.

[0077] In a ninth aspect, a computer program product is provided, which comprises instructions, when the instructions are executed on a communication apparatus, the communication apparatus can perform the method in any of the aspects.

[0078] In a tenth aspect, a communication system is provided, which comprises the first network element (or an apparatus such as a chip or chip system included in the first network element) in the first aspect and the third network element (or an apparatus such as a chip or chip system included in the third network element) in the second aspect.

[0079] In some possible designs, the communication system can further comprise the fifth network element (or an apparatus such as a chip or chip system included in the fifth network element) in the third aspect.

[0080] The technical effects brought by any of the fourth aspect to the tenth aspect can be referred to the technical effects brought by different design manners in the first aspect or the second aspect or the third aspect, which will not be repeated here. BRIEF DESCRIPTION OF DRAWINGS

[0081] FIG. 1 is a schematic diagram of a non-roaming architecture of a mobile communication system according to the present application;

[0082] FIG. 2 is a schematic diagram of a remote attestation procedure according to the present application;

[0083] FIG. 3 is a schematic diagram of a network function virtualization (NFV) architecture according to the present application;

[0084] FIG. 4 is a schematic diagram of a remote attestation based NFV architecture according to the present application;

[0085] FIG. 5 is a schematic diagram of a communication system architecture according to the present application;

[0086] FIG. 6 is a schematic diagram of a communication method according to the present application;

[0087] FIG. 7 is a schematic diagram of another communication method according to the present application;

[0088] FIG. 8 is a schematic diagram of yet another communication method according to the present application;

[0089] FIG. 9 is a schematic diagram of yet another communication method according to the present application;

[0090] FIG. 10 is a schematic diagram of yet another communication method according to the present application;

[0091] FIG. 11 is a schematic diagram of yet another communication method according to the present application;

[0092] FIG. 12 is a schematic diagram of yet another communication method according to the present application;

[0093] FIG. 13 is a schematic diagram of yet another communication method according to the present application;

[0094] FIG. 14 is a schematic diagram of a communication apparatus according to the present application;

[0095] FIG. 15 is a schematic diagram of another communication apparatus according to the present application;

[0096] FIG. 16 is a schematic diagram of yet another communication apparatus according to the present application. DETAILED DESCRIPTION

[0097] In the description of the present application, unless otherwise specified, " / " represents a "or" relationship between the objects associated in front and back, for example, A / B can represent A or B; "and / or" in the present application is only a description of the association between the associated objects, which means that there can be three relationships, for example, A and / or B, which can represent: A exists alone, A and B exist together, and B exists alone, where A, B can be singular or plural.

[0098] In the description of the present application, "a plurality of" means two or more than two, unless otherwise specified. "At least one of the following" or similar expressions means any combination of the items, including any combination of single or multiple items. For example, at least one of a, b, or c can mean a, b, c, a-b, a-c, b-c, or a-b-c, where a, b, and c can be single or multiple.

[0099] In addition, in order to facilitate the clear description of the technical solutions of the embodiments of the present application, in the embodiments of the present application, "first", "second" and the like are used to distinguish the same items or similar items with basically the same function and role. Those skilled in the art can understand that "first", "second" and the like do not limit the quantity and execution order, and "first", "second" and the like do not necessarily mean different.

[0100] In the embodiments of the present application, the words "exemplary" or "for example" are used to mean serving as an example, instance, or illustration. Any embodiment or design presented as "exemplary" or "for example" in the embodiments of the present application should not be construed as being more preferred or advantageous than other embodiments or design solutions. Rather, the use of "exemplary" or "for example" is intended to present concepts in a concrete manner, facilitating understanding.

[0101] It can be understood that the "embodiments" mentioned throughout the specification mean that the specific features, structures or characteristics related to the embodiments are included in at least one embodiment of the present application. Therefore, the various embodiments throughout the specification do not necessarily refer to the same embodiment. In addition, these specific features, structures or characteristics can be combined in one or more embodiments in any suitable manner. It can be understood that in various embodiments of the present application, the size of the sequence number of each process does not mean the execution order, and the execution order of each process should be determined by its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0102] It can be understood that in the present application, "when" and "if" both refer to making corresponding processing under certain objective circumstances, not limited to time, and do not require judgment actions when implementing, nor mean that there are other limitations.

[0103] It can be understood that some optional features in the embodiments of the present application can be implemented independently in some scenarios, without relying on other features, such as the scheme currently based on, to solve the corresponding technical problems and achieve the corresponding effects. In some scenarios, it can also be combined with other features according to demand. Correspondingly, the devices given in the embodiments of the present application can also realize these features or functions, which will not be described here.

[0104] It can be understood that, in the present application, "for indicating" can include direct indication and indirect indication, and can also include explicit indication and implicit indication. When describing "the indication information for indicating A" or "the indication information of A", it can include that the indication information directly indicates A or indirectly indicates A, and it does not mean that A is carried in the indication information. The information indicated by certain information is called to-be-indicated information, and there are many ways to indicate the to-be-indicated information in the specific implementation process, for example but not limited to, the to-be-indicated information can be directly indicated, such as the to-be-indicated information itself or the index of the to-be-indicated information. The to-be-indicated information can also be indirectly indicated by indicating other information, where the other information and the to-be-indicated information have an association relationship. The to-be-indicated information can also be only indicated in part, and the other part of the to-be-indicated information is known or agreed in advance. For example, the indication of a specific information can be achieved by means of the arrangement order of various information agreed in advance (for example, specified by a protocol), thereby reducing the indication overhead to a certain extent. At the same time, the common part of each information can be identified and uniformly indicated, so as to reduce the indication overhead caused by separately indicating the same information. In addition, the specific indication manner can also be various existing indication manners, for example but not limited to, the above-mentioned indication manners and various combinations thereof. The specific details of various indication manners can refer to the prior art, and will not be described herein. As can be seen from the above, for example, when multiple information of the same type needs to be indicated, the indication manner of different information can be different. In the specific implementation process, the required indication manner can be selected according to the specific needs, and the selected indication manner is not limited by the embodiments of the present application, so that the indication manner involved in the embodiments of the present application should be understood as covering various methods that can enable the to-be-indicated party to know the to-be-indicated information. The to-be-indicated information can be sent as a whole, or can be sent separately in multiple sub-information, and the sending period or sending occasion of the sub-information can be the same or different. The specific sending method is not limited by the present application. The sending period or sending occasion of the sub-information can be predefined, for example, predefined according to a protocol, or configured by the transmitting end device by sending configuration information to the receiving end device.

[0105] In the present application, the same or similar parts between various embodiments can be mutually referred to, unless otherwise specified. In the present application, the terms and / or descriptions of different embodiments are consistent and can be mutually referred to, unless otherwise specified and logically conflicted. Different embodiments can be combined to form new embodiments according to their inherent logical relationship. The implementation modes of the present application described below do not constitute a limitation on the protection scope of the present application.

[0106] In order to facilitate understanding of the technical solutions of the embodiments of the present application, first, a brief introduction of the related technologies of the present application is given as follows.

[0107] 1. A mobile communication system:

[0108] Fig. 1 is a schematic diagram of a non-roaming architecture of a mobile communication system. As shown in Fig. 1, the mobile communication system comprises an access network (AN) and a core network (CN), and further can comprise a terminal device.

[0109] For example, the mobile communication system can be a 5th generation (5G) mobile communication system (5G system, 5GS), or can also be a future communication system, which is not limited in the present application.

[0110] The terminal device can be a user-side device for implementing a wireless communication function, such as a terminal or a chip used in a terminal. The terminal can be a user equipment (UE), an access terminal, a satellite terminal, a terminal unit, a terminal station, a mobile station, a mobile station, a remote station, a remote terminal, a mobile device, a wireless communication device, a terminal agent, or a terminal device in a 5G network or a public land mobile network (PLMN) evolved after 5G.The terminal can be a cellular phone, a cordless phone, a session initiation protocol (SIP) phone, a wireless local loop (WLL) station, a smart phone (such as a mobile phone), a personal digital assistant (PDA), a handheld device having wireless communication function, a computing device, or other processing device connected to a wireless modem, a vehicle-mounted device (such as a car, a bicycle, an electric vehicle, an airplane, a ship, a train, a high-speed rail, etc.), or a wearable device (such as a smart watch, a smart bracelet, a pedometer, smart glasses, etc.), a smart robot, a mechanical arm, a plant device, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal in industrial control, a wireless terminal in self driving, a wireless terminal in telemedicine or telehealth services, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, a wireless terminal in a smart home (for example, a refrigerator, a television, an air conditioner, an electricity meter, etc.), a wireless data card, a tablet computer, a notebook computer, a palm computer, a mobile internet device (MID), a wireless modem, a handset, a laptop computer, a machine type communication (MTC) terminal, a smart point of sale (POS) machine, a customer-premises equipment (CPE), a light UE, a reduced capability UE (REDCAP UE), a flight device (for example, a smart robot, a hot air balloon, a drone, an airplane), etc.Alternatively, the terminal can be a terminal (or a device assuming a terminal function) having a communication function in the internet of things (IoT), such as a terminal (i.e., a vehicle device such as an on-board device, an on-board module, an on-board chip, an on-board unit (OBU), or a telematics box (T-BOX), a terminal in device-to-device (D2D) system communication, or a terminal in machine-to-machine (M2M) communication, etc.) in vehicle to everything (V2X), etc. The terminal can be mobile or fixed. In some embodiments, the terminal device can also be a device or module having a corresponding communication function accessing the above-mentioned communication system. A communication module for performing a corresponding communication function is usually arranged in the terminal device, or a chip such as a Modem chip (also known as a baseband chip) responsible for the communication function in the terminal device, or a system on chip (SoC) chip or a system in a package (SIP) chip containing a modem module. The terminal device is also configured with program instructions for performing the corresponding communication function.

[0111] The AN is used to implement access-related public, can provide network access functions for authorized users in a specific area, and can determine transmission links of different qualities to transmit user data according to the level of the user, the demand of the service, and the like. The AN forwards control signals and user data between terminal devices and the CN. The AN can include an access network device, which can also be referred to as a radio access network (RAN) device. The CN is mainly responsible for maintaining subscription data of a mobile network, and provides terminal devices with functions such as session management, mobility management, policy management, and security authentication. The CN mainly includes the following: a user plane function (UPF), an authentication server function (AUSF), an access and mobility management function (AMF), a session management function (SMF), a network slice selection function (NSSF), a network exposure function (NEF), a network repository function (NRF), a policy control function (PCF), a unified data management (UDM), a unified data repository (UDR), and an application function (AF).

[0112] As shown in FIG. 1, a UE accesses a 5G network through a RAN device, the UE communicates with an AMF through an N1 interface (referred to as N1 for short), the RAN communicates with the AMF through an N2 interface (referred to as N2 for short), the RAN communicates with a UPF through an N3 interface (referred to as N3 for short), an SMF communicates with the UPF through an N4 interface (referred to as N4 for short), and the UPF accesses a data network (DN) through an N6 interface (referred to as N6 for short). In addition, the AUSF, the AMF, the SMF, the NSSF, the NEF, the NRF, the PCF, the UDM, the UDR, or the AF and the like control plane functions shown in FIG. 1 interact through a service interface. For example, the service interface provided by the AUSF to the outside is Nausf, the service interface provided by the AMF to the outside is Namf, the service interface provided by the SMF to the outside is Nsmf, the service interface provided by the NSSF to the outside is Nnssf, the service interface provided by the NEF to the outside is Nnef, the service interface provided by the NRF to the outside is Nnrf, the service interface provided by the PCF to the outside is Npcf, the service interface provided by the UDM to the outside is Nudm, the service interface provided by the UDR to the outside is Nudr, and the service interface provided by the AF to the outside is Naf.

[0113] The RAN device is a device for accessing a terminal device to a wireless network, and the RAN device can be a node in a wireless access network, and can also be referred to as a base station, and can also be referred to as a RAN node.

[0114] For example, the RAN device can include an evolved Node B (eNB or e-NodeB, or Node B) in an LTE system or an LTE-A system, such as a conventional macro base station eNB and a micro base station eNB in a heterogeneous network scenario. Alternatively, a transmission reception point (TRP), a home base station (e.g., a home evolved Node B, or a home Node B, HNB), a baseband unit (BBU), a BBU pool, or a WiFi access point (AP), and the like can be included. Alternatively, a base station in a non-terrestrial network (NTN) can be included, i.e., a base station that can be deployed on a high-altitude platform or a satellite, in which the network device can act as a layer 1 (L1) relay, or can act as a base station, or can act as a distributed unit (DU), or can act as an integrated access and backhaul (IAB) node. Alternatively, it can also be a gateway station or a ground station. Alternatively, the network device can be a device that implements a base station function in IoT, such as a V2X, D2D, or M2M device that implements a base station function, or can include a vehicle-mounted device or a wearable device, or can include a RAN device in a 5G network or a PLMN evolved after 5G, and the embodiments of the present application are not limited.

[0115] In some embodiments, the RAN device can also be provided with a communication module, circuit, or chip that performs corresponding communication functions. The RAN device can also be configured with program instructions for performing corresponding communication functions and corresponding program instructions. The RAN device in the present application can also be a logical node, a logical module, or software that can implement all or part of the functions of the RAN device.

[0116] In some possible scenarios, the RAN device in the embodiments of the present application can also be a module or unit capable of implementing part of the functions of a base station, for example, the RAN device can include a centralized unit (CU) and a distributed unit (DU). The RAN device including the CU node and the DU node splits the protocol layers of the gNB in the NR system, and the functions of part of the protocol layers are placed in the CU for centralized control, and the remaining part or all of the protocol layer functions are distributed in the DU and controlled by the CU. Further, the CU can also be divided into a control plane (centralized unit control plane, CU-CP) and a user plane (centralized unit user plane, CU-UP). The CU-CP is responsible for the control plane function, mainly including the radio resource control (RRC) and the packet data convergence protocol (PDCP) corresponding to the control plane (PDCP-C). The PDCP-C is mainly responsible for the encryption and decryption of the control plane data, the integrity protection, the data transmission, and the like. The CU-UP is responsible for the user plane function, mainly including the service data adaptation protocol (SDAP) and the PDCP corresponding to the user plane (PDCP-U). The SDAP is mainly responsible for processing the data of the core network and mapping the flow to the bearer. The PDCP-U is mainly responsible for the encryption and decryption of the data plane, the integrity protection, the header compression, the sequence number maintenance, the data transmission, and the like. The CU-CP and the CU-UP are connected through an E1 interface. The CU-CP represents the gNB to connect with the core network through an NG interface, and is connected with the DU through an F1 interface of the control plane (namely, F1-C). The CU-UP is connected with the DU through an F1 interface of the user plane (namely, F1-U). Of course, there is also a possible implementation that the PDCP-C is also in the CU-UP.

[0117] It can be understood that the CU (including CU-CP or CU-UP) or DU can also have different names in different systems, but those skilled in the art can understand its meaning. For example, in an open radio access network (O-RAN) system, the CU can also be referred to as an open centralized unit (O-CU), the DU can also be referred to as an open distributed unit (O-DU), the CU-CP can also be referred to as an open centralized unit-control plane (O-CU-CP), and the CU-UP can also be referred to as an open centralized unit user plane (O-CU-UP). For the convenience of description, the CU, CU-CP, CU-UP and DU are taken as examples for description in the present application. The RAN device can also include an active antenna unit (AAU). The CU implements part of the functions of the gNB, and the DU implements part of the functions of the gNB. For example, the CU is responsible for processing non-real-time protocols and services, and implements the functions of the RRC layer. The DU is responsible for processing physical layer protocols and real-time services, and implements the functions of the radio link control (RLC) layer, the media access control (MAC) layer and the physical (PHY) layer. In some deployments, the CU can also be divided into a centralized unit control plane (CU-CP) node and a centralized unit user plane (CU-UP) node. Among them, the CU-CP is responsible for the control plane function, and the CU-UP is responsible for the user plane function.

[0118] Optionally, the base station in the embodiments of the present application can include various forms of base stations, such as macro base stations, micro base stations (also known as small stations), relay stations, access points, home base stations, TRPs, transmission points (TPs), mobile switching centers, etc., and the embodiments of the present application do not make specific limitations thereto.

[0119] The UPF is mainly responsible for user data processing (forwarding, receiving, charging, etc.). For example, the UPF can receive user data from a data network (DN), and forward the user data to a terminal through an access network device. The UPF can also receive user data from a terminal through an access network device, and forward the user data to a DN. The DN refers to an operator network that provides data transmission services for users. For example, an internet protocol (IP) multi-media service (IMS), the Internet, etc. The DN can be an operator external network or an operator controlled network, and is used to provide service services to terminal devices. In a protocol data unit (PDU) session, the UPF directly connected to the DN through N6 is also called a protocol data unit session anchor (PSA).

[0120] The AUSF is mainly used to perform security authentication of the terminal.

[0121] The AMF is mainly used for mobility management in a mobile network. For example, user location update, user registration network, user handover, etc.

[0122] The SMF is mainly used for session management in a mobile network. For example, session establishment, modification, release. Specific functions, such as allocating an internet protocol (IP) address for a user, selecting a UPF that provides packet forwarding functions, etc.

[0123] The PCF is mainly used to support providing a unified policy framework to control network behavior, providing policy rules to control layer network functions, and being responsible for obtaining user subscription information related to policy decision. The PCF can provide policies such as quality of service (QoS) policies and slice selection policies to AMF and SMF.

[0124] The NSSF is mainly used to select network slices for terminals.

[0125] The NEF is mainly used to support the opening of capabilities and events.

[0126] The UDM is mainly used to store user data, such as subscription data, authentication / authorization data, etc.

[0127] The UDR is mainly used to store structured data, and the stored content includes subscription data and policy data, externally exposed structured data, and application related data.

[0128] AFs mainly support interactions with the CN to provide services such as influencing data routing decisions, policy control functions, or providing some services of third parties to the network side.

[0129] 2. Remote attestation (RA) technology:

[0130] In recent years, with the significant increase in the number of embedded systems, cyber-physical systems, and Internet of Things devices, these systems or devices have been involved in many scenarios of daily life, such as homes, offices, and factories. These systems or devices can access the Internet to provide corresponding network services for users, but at the same time, they also expand the attack surface of attackers. For example, the malicious software of attackers can affect the security or steal private data of these systems or devices when upgrading their drivers. Or, the malicious software of attackers can also turn these systems or devices into "zombie" devices, i.e., maliciously manipulated to become the source of distributed denial of service (DDoS) attacks. However, due to the cost, size, and power factors, security is usually not a priority for these systems or devices, making it difficult for them to prevent attacks on their own.

[0131] In this case, we can verify the security of these systems or devices through remote attestation technology to determine whether they are attacked. Remote attestation includes an attester and a verifier. The attester and the verifier can be separated, for example, the attester can be deployed on the side of these systems or devices, and the verifier can be deployed remotely. The verifier can request the attester to measure these systems or devices to obtain evidence. The verifier can verify the security of these systems or devices according to the evidence.

[0132] Referring to FIG. 2, a flowchart of RA provided by the present application is shown. As shown in FIG. 2, the flow of RA can include the following steps S201-S204:

[0133] S201, the verifier sends a challenge message to the attester. Correspondingly, the attester receives the challenge message from the verifier.

[0134] Exemplarily, the challenge message can carry a request message. The request message is used to request the attester to measure, such as requesting the attester to measure the above-mentioned systems or devices. The challenge message can also carry a random number corresponding to this measurement only. The random number is used for measurement.

[0135] S202, the attester performs measurement.

[0136] For example, the measurement entity can obtain the evidence required for measurement from the system or device according to the challenge message, such as obtaining the programs or files inside the system or device, and calculate the hash value corresponding to the programs or files according to the random number. Specifically, the random number can be a hash value, that is, the measurement entity can perform hash operation on the programs or files.

[0137] S203, the measurement entity sends a response message to the verification entity. Correspondingly, the verification entity receives the response message of the measurement entity.

[0138] For example, the response message can be used to indicate that the measurement is completed. The response message can carry the hash value.

[0139] S204, the verification entity performs verification.

[0140] The verification entity can compare the hash value in the response message with the preset hash value of the system or device. If the hash value in the response message is the same as the preset hash value of the system or device, it indicates that the programs or software of the system or device have not been tampered with, so the verification entity can determine that the system or device is a trusted device, that is, the verification is passed. If the hash value in the response message is different from the preset hash value of the system or device, it indicates that the programs or software of the system or device may have been tampered with, so the verification entity can determine that the system or device is an untrusted device, that is, the verification fails.

[0141] 3, distributed ledger technology (DLT):

[0142] For example, the distributed ledger can be implemented through a blockchain.

[0143] The original Bitcoin blockchain innovation is based on a public, permissionless network of untrusted parties. However, for most industries, business rules, performance and scale requirements, and most importantly, regulatory rules and policies are not suitable for public networks or permissionless node access models.

[0144] Therefore, the technology evolves from the original Bitcoin blockchain innovation to a new permissioned model, that is, to create a "permissioned-distributed ledger" network, which can be understood as a private community with explicit control, known members and member standards. The emergence of distributed ledgers can facilitate the review of cross-industry business workflows and efforts to rebuild new business models on a shared and secure private information platform.

[0145] In terms of consensus mechanism, in a non-permissioned DLT, almost anyone can participate, and each participant is anonymous. In such a case, there is no trust until the DLT state reaches a certain block depth that is immutable. To compensate for the lack of trust, non-permissioned DLTs usually adopt a consensus mechanism such as "proof of work" in combination with economic incentives such as transaction fees to offset the special energy consumption cost of participating in "proof of work".

[0146] A permissioned DLT, on the other hand, operates the DLT among a group of known, identified, and vetted participants who operate under a governance model that generates a certain level of trust. Permissioned DLTs provide a way to secure interactions among a group of entities that share common goals but can not fully trust each other. By relying on the identity of the participants, permissioned DLTs can use more traditional crash fault tolerance (CFT) or byzantine fault tolerance (BFT) consensus protocols without the need for expensive proof of work. In addition, in the case of a permissioned DLT, the risk of participants intentionally introducing malicious code through smart contracts is reduced. First, participants know each other and all operations, whether submitting transactions, modifying network configurations, or deploying smart contracts, are recorded on the DLT according to the endorsement policy and related transaction type that has been determined in the network. Compared with complete anonymity, the criminal party can be easily identified and handled according to the provisions of the governance model.

[0147] 4. Network Function Virtualization (NFV):

[0148] NFV refers to the decoupling of network functions of traditional types of communication equipment from their physical devices and then running them in software form on commercial off-the-shelf (COTS) hosts. In other words, NFV is a virtual entity (Virtual Instance) realized through borrowing virtualization technology in internet technology (IT), which deploys traditional communication technology (CT) services of communication equipment onto the virtual entity. The virtual entity can be a virtual machine (VM) or a container, or any other possible virtualized function entity, without specific limitation.

[0149] Figure 3 is a schematic diagram of an NFV architecture, as shown in Figure 3, the NFV includes: a network function virtualization infrastructure (NFVI), a virtual network function (VNF), an element management system (EMS), a management, automation and network orchestration (MANO).

[0150] The NFVI can be used to provide virtual resources for the VNF. The NFVI includes hardware resources, such as hardware network, computing, storage, etc. devices. In addition, the NFVI also includes software resources, such as a virtualization layer, which can include a hypervisor or a container management system. The virtualization layer can virtualize the hardware resources into virtual resources, such as virtual network, computing, storage, etc. functions, for use by the VNF. Specifically, the virtualization layer and the hardware resources can communicate through a VI-Ha interface.

[0151] The EMS and the VNF are usually in a one-to-one correspondence relationship, used to configure and manage the functions of the VNF.

[0152] A VNF is a virtualized NF. A VNF can be used to provide a network service, such as data forwarding, file sharing, directory service, IP configuration, and so on. A VNF can be in the form of an application software, i.e., an application software providing a network service. A VNF can be deployed in a VM or a container. Taking a VM as an example, a VNF can be deployed on one or more VMs, i.e., the one or more VMs can collectively provide the VNF. Since an operator network can not be aware of a VNF, a VNF can also be understood as an NF in an operator network. In this case, if a VNF provides different network services, the NF can also be in different forms. For example, if a VNF provides a data transmission service, the NF can be a UPF network element; if a VNF provides a mobility management service, the NF can be an AMF network element; if a VNF provides a session management service, the NF can be an SMF network element; if a VNF provides a policy management service, the NF can be a PCF network element, and so on. In embodiments of the present application, a VNF can have an independent identifier (identifier, ID), such as an identifier of a VNF, used to directly identify the VNF. Alternatively, a VNF can not have an independent identifier, and the VNF can be indirectly identified by other identifiers related to the VNF. For example, an identifier of one or more VMs can be used to indirectly identify a VNF provided by the one or more VMs, or an identifier of an NF can be used to indirectly identify a corresponding VNF. It can be understood that since a service can not be aware of a VNF, for the service, the VNF is an NF, or the VNF can also be understood as an NF.

[0153] The MANO can provide a framework for managing the NFVI and the VNF. For example, the MANO can include a network functions virtualization orchestrator (NFVO), a virtualized infrastructure management (VIM), and a network functions virtualization manager (VNFM). The NFVO is used for deployment and management of a network service, and coordinates deployment and management of VNFs according to the network service. The NFVO can interface with an operations support system (OSS) or a business support system (BSS) to obtain a service description of the network service; for example, the NFVO can interface with the OSS / BSS through an Os-Ma interface. The NFVO can deploy and manage a corresponding network service according to the service description; for example, creating the network service, managing the lifecycle of the network service, and the like. The NFVO can coordinate the VIM and the VNFM to deploy or manage a corresponding VNF according to the network service.

[0154] The VNFM is used for deployment or management of a corresponding VNF. For example, the VNFM can obtain a virtualized network function descriptor (VNFD) from the NFVO to add a VNF, delete a VNF, find a VNF, or manage a VNF, such as state monitoring and adjustment of the VNF, according to the VNFD. Specifically, the VNFM can manage the VNF through a Ve-Vnfm interface.

[0155] The VIM is used to control the NFVI to provide corresponding virtual resources for the VNF. For example, the VIM can control the NFVI to provide corresponding virtual resources for deployment or management of the VNF according to a scheduling of the NFVO. Specifically, the VIM can control the NFVI through an Nf-VI interface. The VIM can be a cloud platform, such as an open-source cloud platform or a commercial cloud platform.

[0156] 5. RA-based VNF security scheme:

[0157] Figure 4 is a schematic diagram of an RA based NFV architecture, as shown in Figure 4, the instances of VNFs in the 3rd generation partnership project (3GPP) defined network are various network functions (NFs), which can also be considered as deployed in the 3GPP defined network, i.e. service domain. However, at the NFV architecture level, the VNFs can be considered as deployed in the NFV domain. The verification entity can be deployed in the NFV domain, such as the MANO. The measurement entity can also be deployed in the NFV domain, such as the virtualization layer of the NFVI.

[0158] In addition, since the NFV generally belongs to a service based architecture (SBA) architecture, for example, the network elements or functions within the NFV are generally located in the 3GPP domain and can communicate based on the 3GPP protocol; while the measurement entity and the verification entity generally do not belong to the SBA architecture, for example, the measurement entity and the verification entity are generally located in the european telecommunications standards institute (ETSI) domain and can communicate based on the ETSI protocol.

[0159] Therefore, a profile and attestation check function (PACF) is proposed, which allows access to the attestation result from the 3GPP function level, so that the VNFs in the 3GPP domain can distribute the attestation policy according to the attestation result to control how to apply the attestation. Alternatively, it can also be considered that the PACF can realize the conversion of information under the 3GPP protocol and information under the ETSI protocol; thereby realizing the communication between the VNFs and the verification entity.

[0160] On this basis, the 3GPP roughly defines the cross-domain (service domain-NFV domain) implementation process of the RA based VNF security scheme, and in the system architecture diagram as shown in Figure 4, the network elements can implement the RA scheme of the VNFs across the domains according to the following steps S401-S406.

[0161] S401, the NF consumer entity sends a management NF registration request to the NRF. Correspondingly, the NRF receives the management NF registration request from the NF consumer entity.

[0162] Exemplarily, the management NF registration request can be Nnrf_NFManagement_NFRegister Request. The management NF registration request can carry the NF profile for the registration management of the NF, such as including the identifier of the NF consumer entity.

[0163] For example, the NF consumer entity can also be a VNF, such as an untrusted VNF. The NRF can also be a relying party (RP) VNF.

[0164] S402, the NRF sends an attestation request to the PACF. Correspondingly, the PACF receives the attestation request from the NRF.

[0165] For example, the attestation request is used to request the attestation of the NF consumer entity, and can include the NF profile signed by the NRF.

[0166] S403, the PACF triggers an attestation procedure of the NF consumer entity.

[0167] Specifically, the PACF verifies the signature of the NF profile. If the verification is passed, the PACF triggers the attestation procedure using the identity of the NF consumer entity. For example, the PACF can send an attestation policy and a description of the network element to be attested, such as the NF consumer entity, to the verification entity. The verification entity can request the attestation entity to attest various data of the NF consumer entity according to the attestation policy and the description of the NF consumer entity, so as to obtain corresponding evidence. The verification entity can verify the evidence to obtain attestation results (or also referred to as proof results), and send the attestation results to the PACF.

[0168] S404, the PACF sends an attestation response to the NRF. Correspondingly, the NRF receives the attestation response from the PACF.

[0169] For example, the attestation response is used to respond to the attestation request, such as including the attestation results of the NF consumer entity. It can be understood that the attestation results obtained by the PACF from the verification entity are attestation results supported by the ETSI protocol, and the PACF can convert the attestation results supported by the ETSI protocol into attestation results supported by the 3GPP protocol, and then carry the attestation results supported by the 3GPP protocol into the attestation response.

[0170] S405, the NRF stores the profile of the NF.

[0171] For example, if the attestation results indicate that the authentication is passed, the NRF determines that the NF consumer entity is trusted, marks that the NF consumer entity is available, and stores the profile of the NF of the NF consumer entity. However, if the attestation results indicate that the authentication is failed, the NRF determines that the NF consumer entity is untrusted, and triggers a recovery procedure to handle the untrusted NF consumer entity.

[0172] S406, the NRF sends the management NF registration response to the NF consuming entity. Correspondingly, the NF consuming entity receives the management NF registration response from the NRF.

[0173] Exemplarily, the management NF registration response can be Nnrf_NFManagement_NFRegister Response.

[0174] Exemplarily, in the case that the NRF determines that the NF consuming entity is trusted, the NRF can send the management NF registration response to the NF consuming entity to indicate that the registration of the NF consuming entity is confirmed by the NRF. In addition, S406 is an optional step, for example, in the case that the NF consuming entity is not trusted, S406 can not be performed.

[0175] In the cross-domain implementation process of the above-mentioned RA-based VNF security scheme, since the NRF cannot directly verify the measurement result of the verification entity, the PACF needs to be used to complete the verification each time. Therefore, the PACF can query the trusted state (i.e. the measurement result) of the NF consuming entity without authorization. As known from the foregoing, the measurement result is determined according to the configuration file of the NF consuming entity, and the configuration file is sensitive information of the NF consuming entity. That is, the PACF can query the sensitive information of the NF consuming entity. However, the PACF itself can be untrusted, which can easily cause the information of the NF consuming entity to be leaked. Therefore, how to ensure the security of the PACF is a problem to be solved.

[0176] Embodiments of the present application propose a communication method and device. When a first network element receives a measurement request (such as first request information), the first network element can obtain the right (i.e. the trust letter) to query the trusted state of a target network element; and after obtaining the right, the first network element can obtain the trusted state (such as a first measurement result) of the target network element. That is, the first network element can query the trusted state of the target network element only when the first network element obtains the right; and the first network element can avoid querying the trusted state of a network element without authorization. It can be understood that the first network element that can obtain the authorization is usually trusted, and therefore, it can be considered that obtaining the right of the first network element to query the trusted state of the target network element actually determines the security of the first network element, that is, when the first network element obtains the right, it means that the first network element is trusted; and therefore, the probability of the information of the target network element being leaked can be reduced.

[0177] The technical solutions provided in the present application can be applied to various communication systems, which can be a 3GPP related cellular system, for example, a fourth generation (4th generation, 4G) long term evolution (long term evolution, LTE) system, an evolved LTE system (LTE-Advanced, LTE-A) system, a 5G new radio (new radio, NR) system, a vehicle to everything (vehicle to everything, V2X) system, a system of LTE and NR hybrid networking, or a device-to-device (device-to-device, D2D) system, a machine to machine (machine to machine, M2M) communication system, an internet of things (internet of things, IoT), NFV, and a future communication system.

[0178] Alternatively, the communication system can also be a non-3GPP communication system, for example, an open radio access network (open radio access network, O-RAN or ORAN), a cloud radio access network (cloud radio access network, CRAN), a wireless fidelity (wireless fidelity, WiFi) system, or can also be a communication system combined with the above multiple communication systems, and the present application is not limited.

[0179] Among them, the above-mentioned communication system applicable to the present application is only an example, and the communication system applicable to the present application is not limited thereto. Herein, the following will not be described in detail.

[0180] The present application will present various aspects, embodiments or features around a system that can include multiple devices, components, modules, etc. It should be understood and appreciated that each system can include additional devices, components, modules, etc., and / or can not include all the devices, components, modules, etc. discussed in connection with the drawings. In addition, combinations of these solutions can also be used.

[0181] In addition, in the embodiments of the present application, the words "example", "for example", etc. are used to mean by way of example, illustration or description. Any embodiment or design scheme described as "example" in the present application should not be interpreted as more preferred or more advantageous than other embodiments or design schemes. Rather, the word "example" is intended to present the concept in a specific manner.

[0182] In the embodiments of the present application, "information", "signal", "message", "channel", and "signaling" can be used interchangeably, and it should be pointed out that when the distinction is not emphasized, the meanings expressed are matched. "Of", "corresponding", and "corresponding" can be used interchangeably, and it should be pointed out that when the distinction is not emphasized, the meanings expressed are matched. In addition, " / " mentioned in the present application can be used to represent "or".

[0183] The network architecture and service scenarios described in the embodiments of the present application are used to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those skilled in the art can know that with the evolution of network architecture and the appearance of new service scenarios, the technical solutions provided by the embodiments of the present application are also applicable to similar technical problems.

[0184] In order to facilitate understanding of the embodiments of the present application, first, the communication system shown in FIG. 5 is taken as an example to illustrate the communication system applicable to the embodiments of the present application in detail. For example, FIG. 5 is a schematic diagram of the architecture of a communication system applicable to the communication method provided by the embodiments of the present application.

[0185] As shown in FIG. 5, the communication system mainly includes at least one first network element, at least one second network element, and at least one third network element. Among them, the second network element is used to request the trusted state of the target network element; the third network element is used to verify the trusted state of the target network element, and the first network element is used to realize the communication between the second network element and the third network element.

[0186] For example, the second network element and the third network element are located in different domains; the first network element is used to realize the communication between the network elements in different domains. Specifically, the first network element can realize the communication between the network elements in different domains by converting the information in different domains.

[0187] Specifically, the second network element can be located in the 3GPP domain, and the third network element can be located in the ETSI domain, at this time, the first network element is used to realize the communication between the network elements in the 3GPP domain and the network elements in the ETSI domain. Based on the foregoing, it is generally known that the network element located in the 3GPP domain supports the 3GPP protocol, and the network element located in the ETSI domain supports the ETSI protocol; therefore, it can also be considered that the first network element is used to realize the communication between the network element supporting the 3GPP protocol and the network element supporting the ETSI protocol; for example, the first network element can realize the conversion of information under the 3GPP protocol and information under the ETSI protocol.

[0188] Taking the second network element as a trusted party VNF and the third network element as a verifier as an example, at this time, the target network element is an untrusted VNF, and the first network element can be a PACF. Specifically, the target network element can be a RAN device. The implementation of the RAN device can refer to the related description in the related technology described above, and will not be described here.

[0189] It should be understood that the above is an exemplary description of the first network element, the second network element, and the third network element, and does not mean that the first network element described in the present application only includes the PACF, the second network element only includes the trusted party VNF, and the third network element only includes the verifier; the first network element, the second network element, and / or the third network element can also be any network element having the above functions, and the present application is not limited thereto.

[0190] Optionally, the first network element is further configured to determine the permission of the first network element to query the trusted state of the target network element, and send the trusted state of the target network element to the second network element after obtaining the permission.

[0191] Exemplarily, the first network element can determine the trusted state of the target network element from the data storage unit. Alternatively, the first network element can obtain the trusted state of the target network element from the third network element, and the third network element is configured to verify the trusted state of the target network element.

[0192] Optionally, the communication system can further include a measurement entity, and the measurement entity is mainly configured to measure the target network element to obtain corresponding evidence for verifying whether the target network element is trusted. The measurement entity can be one or more, such as measurement entity #1, measurement entity #2, …, measurement entity #m, and m is an integer greater than or equal to 1. One measurement entity can measure the trusted state of one or more target network elements.

[0193] Optionally, the verifier is mainly configured to verify whether the target network element is trusted according to the evidence provided by the verifier (i.e., verify the trusted state of the target network element). The verifier can locally verify the target network element, or request a remote server to verify the target network element, without limitation. The verifier can be a functional network element or a network management, without limitation.

[0194] In the embodiment of the present application, the measurement entity is usually deployed in an environment capable of measuring the target network element to realize the measurement of the target network element. It can be understood that if the measurement entity is deployed in the target network element, the measurement entity can not have the right to measure the target network element. Therefore, the measurement entity deployed in an environment capable of measuring the target network element usually means that the measurement entity is deployed outside the target network element. The verifier is usually deployed in an environment capable of communicating with the target network element, so that the verifier can manage the target network element, such as initiating the measurement of the target network element.

[0195] In the embodiments of the present application, the target network element being trusted (i.e., the trusted state of the target network element being trusted) can mean that the target network element can not have security risks. For example, the target network element is a measurement entity that performs secure boot, i.e., the running program and the boot sequence of the target network element are executed according to a predetermined plan, the program of the target network element is not tampered with, or the program running index of the target network element is within the expected range, and the like.

[0196] In addition, the verification entity and the measurement entity are usually deployed in the operator network to facilitate the operator network to manage and maintain the target network element, but are not limited thereto. For example, the verification entity can be deployed in the operator network, and the measurement entity is deployed in a third-party network or an NFVI domain of a public cloud platform.

[0197] It can be understood that the verification entity and the measurement entity are an example of a convenient description of the embodiments of the present application, and can be replaced by any other possible name. For example, the measurement entity can also be referred to as a virtual root of trust (vRoT), a first measurer, or a first measurement function, the verification entity can also be referred to as a first verifier or a first verification function, the measurement entity can also be referred to as a root of trust (RoT), a first measurer, or a first measurement function, and the like, without limitation.

[0198] For the convenience of understanding, the interaction process between the network elements / functions in the communication system will be specifically introduced below by means of method embodiments in combination with FIGS. 6-13.

[0199] Referring to FIG. 6, a flowchart of a communication method provided by the present application is shown, which can include the following steps S601-S605.

[0200] S601, the second network element sends first request information to the first network element, and correspondingly, the first network element receives the first request information from the second network element. The first request information is used to request the trusted state of the target network element.

[0201] For example, the first request information can be carried in an attestation request, or the first request information can be carried in other information, and the embodiments of the present application are not limited thereto.

[0202] Optionally, the first request information can be triggered based on a request from the target network element; for example, the request can be a registration request, or the request can be any other request, and the present application is not limited thereto. That is, when the target network element sends a request to the second network element, the second network element can send the first request information to the first network element.

[0203] Optionally, the first request information is further used to indicate first information of the target network element. The first information of the target network element is information related to the target network element.

[0204] For example, the first information of the target network element can include configuration information of the target network element. For example, the configuration information of the target network element can be a target network function profile. The target network function profile can include an identifier of the target network element or an identifier of a group to which the target network element belongs. For example, the identifier of the target network element can be a network function instance identifier (NF instance ID). Alternatively, the first information of the target network element can be any information that can identify the target network element, which is not limited in the present application.

[0205] For example, the identifier of the group to which the target network element belongs can be obtained by pre-grouping a plurality of network elements (or, it can also be considered as a plurality of devices) (the plurality of network elements include the target network element), and each group includes at least one network element.

[0206] Specifically, the network elements in the same group can come from the same manufacturer, in which case the network elements in the same group have the same manufacturer ID; or the network elements in the same group can come from the same vendor, in which case the network elements in the same group have the same vendor ID; or the network elements in the same group can be located in the same public land mobile network (PLMN), in which case the network elements in the same group have the same PLMN; or the types of the network elements in the same group are the same, in which case the network elements in the same group have the same type; or the grouping of the plurality of network elements can also be implemented according to any other form of grouping condition, which is not limited in the present application.

[0207] For example, the type of the network element can include the network function type of the network element, the deployment type of the network element, the type of the deployment location of the network element, etc.

[0208] For example, the network function type includes but is not limited to one or more of the following: AMF, SMF, PCF, NRF, etc. The deployment type of the network element can include but is not limited to VNF, physical network function (PNF). The type of the deployment location of the network element includes but is not limited to one or more of the following: access network element, core network element, etc.

[0209] Based on the optional scheme, the first network element can determine the letter of trust based on the related information of the target network element (i.e., the first information of the target network element), ensure that the letter of trust is the authority for the target network element (e.g., the letter of trust can be used to indicate that the first network element has the authority to query the trusted state of the target network element), and then after the first network element obtains the authority (i.e., the letter of trust), it can be considered that the first network element is trusted (i.e., the first network element is secure), thereby reducing the probability of leakage of information of the target network element.

[0210] S602, the first network element determines the letter of trust according to the first request information. The letter of trust is used to indicate that the first network element has the authority to query the trusted state of the target network element.

[0211] Optionally, when the first request information is also used to indicate the first information of the target network element, the first network element determines the letter of trust according to the first request information, including: the first network element determines the letter of trust according to the first information of the target network element.

[0212] Exemplarily, the letter of trust is used to indicate that the first network element has the authority to query the trusted state of the target network element, which can be understood as: the letter of trust is the proof that allows the first network element to query the trusted state of the target network element, and therefore, the letter of trust can be used to prove that the first network element has the authority of the trusted state of the target network element.

[0213] Exemplarily, the letter of trust is an exemplary name for the convenience of the embodiment of the application, which can also be replaced by any other possible name. For example, the letter of trust can also be called authority indication, authorization proof, etc., which is not limited by the application.

[0214] S603, the first network element sends second request information to the third network element, and correspondingly, the third network element receives the second request information from the first network element. The second request information is used to request the trusted state of the target network element, and the second request information is also used to indicate the letter of trust.

[0215] Optionally, the second request information can include a signature of the letter of trust, and then the signature is used to indicate the letter of trust; or the letter of trust includes the signature.

[0216] Optionally, the second request information can also indicate the issuance time of the letter of trust, or the letter of trust includes the issuance time.

[0217] Optionally, before step S603, the communication method can further include: establishing a transport layer security (TLS) between the first network element and the third network element. That is, step S603 is performed after the TLS is established between the first network element and the third network element.

[0218] Based on the optional scheme, the step of verifying the credential by the third network element is performed after the TLS is established between the first network element and the third network element; it can be ensured that the information interaction between the first network element and the third network element is secure, thereby avoiding the probability of passing the verification due to the attack on the credential in the transmission process.

[0219] S604, the third network element verifies the credential.

[0220] S605, when the credential verification passes, the third network element determines the first measurement result. The first measurement result is used to indicate the trusted state of the target network element.

[0221] For example, the credential verification passing can be understood as: the credential is valid, that is, it is confirmed that the first network element has the right to query the trusted state of the target network element. Therefore, the third network element can determine the first measurement result; and it provides a basic guarantee for the first network element to obtain the first measurement result.

[0222] Optionally, the third network element can determine whether the credential is valid by verifying at least one of the following: whether the signature of the credential is valid, whether the credential is expired, or whether the credential exists in the preconfigured verification information (that is, whether the preconfigured verification information includes the credential, wherein the preconfigured verification information includes at least one credential). When the credential is valid, it means that the credential verification passes, and therefore the third network element can determine the first measurement result; when the credential is invalid, it means that the credential verification fails, and therefore the third network element does not need to determine the first measurement result. Further, the third network element can also inform the first network element that the credential verification fails; for example, the third network element can send a verification failure indication or a request failure indication of the trusted state of the target network element to the first network element.

[0223] For example, when determining whether the trust letter is valid by verifying whether the signature of the trust letter is valid, if the signature of the trust letter is valid, it indicates that the trust letter is valid, i.e., the trust letter verification is passed; or, when determining whether the trust letter is valid by verifying whether the trust letter is expired, if the trust letter is not expired, it indicates that the trust letter is valid, i.e., the trust letter verification is passed; or, when determining whether the trust letter is valid by verifying whether the preconfigured check information exists in the trust letter, if the preconfigured check information exists in the trust letter, it indicates that the trust letter is valid, i.e., the trust letter verification is passed; or, when determining whether the trust letter is valid by verifying whether the signature of the trust letter is valid and whether the trust letter is expired, if the signature of the trust letter is valid and the trust letter is not expired, it indicates that the trust letter is valid, i.e., the trust letter verification is passed; or, when determining whether the trust letter is valid by verifying whether the signature of the trust letter is valid and whether the preconfigured check information exists in the trust letter, if the signature of the trust letter is valid and the preconfigured check information exists in the trust letter, it indicates that the trust letter is valid, i.e., the trust letter verification is passed; or, when determining whether the trust letter is valid by verifying whether the trust letter is expired and whether the preconfigured check information exists in the trust letter, if the trust letter is not expired and the preconfigured check information exists in the trust letter, it indicates that the trust letter is valid, i.e., the trust letter verification is passed; or, when determining whether the trust letter is valid by verifying whether the signature of the trust letter is valid, whether the trust letter is expired and whether the preconfigured check information exists in the trust letter, if the signature of the trust letter is valid, the trust letter is not expired and the preconfigured check information exists in the trust letter, it indicates that the trust letter is valid, i.e., the trust letter verification is passed.

[0224] In the embodiment, the trust letter is not expired means that the issuing time of the trust letter is within the preconfigured time range; correspondingly, the trust letter is expired means that the issuing time of the trust letter is out of the preconfigured time range. For example, the end time of the preconfigured time range is the time when the third network element receives the trust letter, and the time length between the start time and the end time is 5 minutes. At this time, it can also be considered that the preconfigured time range is a time threshold, and the time threshold is 5 minutes. Therefore, if the time difference between the issuing time of the trust letter and the time when the third network element receives the trust letter is less than or equal to 5 minutes, it indicates that the trust letter is not expired; if the time difference between the issuing time of the trust letter and the time when the third network element receives the trust letter is greater than 5 minutes, it indicates that the trust letter is expired.

[0225] It should be understood that the above embodiment is exemplarily introduced the implementation of the preconfigured time range by taking 5 minutes as an example, which does not mean that the time length between the start time and the end time of the preconfigured time range is only 5 minutes; in fact, the time length of the preconfigured time range can also be other time lengths except 5 minutes, such as 10 minutes, 1 hour, etc.; and / or, the start time and / or the end time of the preconfigured time range can also be other times, which are not limited by the present application.

[0226] Optionally, the third network element can also determine whether the credential is valid through the identification of the group to which the target network element belongs. That is, the second request information is also used to indicate the identification of the group to which the target network element belongs. For example, the implementation of the identification of the group to which the network element belongs can refer to the related description of the above embodiment, which will not be described here.

[0227] For example, the identification of the group to which the target network element belongs is taken as the vendor ID, the third network element can determine the virtual image of the target network element through the component (for example, VNFM) in the MANO, and further check whether the vendor ID (vendor ID#1 for short) of the target network element in the configuration file in the virtual image is the same as the vendor ID (vendor ID#2 for short) indicated by the second request information. If they are the same, it means that the credential is valid, that is, the credential verification is passed.

[0228] Optionally, the third network element can also determine whether the credential is valid through whether the verification information corresponding to the credential exists in the preconfigured verification information. At this time, the preconfigured verification information includes at least one credential, and can include the corresponding relationship between the preconfigured verification information and at least one verification information.

[0229] For example, the verification information can be an OAuth certificate. At this time, in the preconfigured verification information, each credential corresponds to an OAuth certificate. For example, the third network element can query in the preconfigured verification information whether the OAuth certificate corresponding to the credential (that is, the credential determined by the first network element) indicated by the second request information exists; if it exists, it means that the credential is valid, that is, the credential verification is passed.

[0230] Optionally, after step S605, the communication method can further include steps S606-S607 as shown in FIG. 7.

[0231] S606, the first network element obtains the first measurement result according to the second request information.

[0232] S607, the first network element sends the first response information to the second network element, and correspondingly, the second network element receives the first response information from the first network element. Wherein, the first response information is used to indicate the first measurement result.

[0233] Optionally, when the second network element obtains the trusted state of the target network element (i.e., the first measurement result), the second network element can determine how to respond to the request from the target network element according to the trusted state of the target network element. For example, when the target network element is trusted (i.e., the trusted state of the target network element is trusted), the second network element can respond to the request from the target network element, for example, send the information requested by the request to the target network element, or send a registration response to the target network element, etc. When the target network element is not trusted (i.e., the trusted state of the target network element is not trusted), the second network element can not respond to the request, or can also send a response failure (or request failure, reject response, etc.) indication to the target network element.

[0234] Alternatively, the first network element can also indicate policy recommendation information to the second network element, wherein the policy recommendation information is related to the request of the target network element. That is, in the above step S607, the first response information used to indicate the first measurement result can be replaced by: the first response information is used to indicate the policy recommendation information; so that the second network element can perform corresponding operations according to the policy recommendation information.

[0235] For example, the policy recommendation information is used to recommend a control policy executed by the second network element; for example, the recommendation information can include: registration, deregistration, temporary prohibition, adjustment of trust level, etc. For example, when the request is a registration request, the policy recommendation information can be: deregistration.

[0236] For example, the first network element obtains the first measurement result based on the following two ways:

[0237] Way one, the first measurement result is stored in the secure storage network element (or said, the first measurement result is located in the secure storage network element); so that, when the first network element also has the permission to query the secure storage network element, the first network element can obtain the first measurement result from the secure storage network element; that is, the first network element obtaining the first measurement result includes: the first network element determining the first measurement result from the secure storage network element.

[0238] Optionally, the trust note is also used to indicate that the first network element also has the permission to query the secure storage network element; or the first network element can determine another trust note (e.g., trust note #1) used to indicate that it has the permission to query the secure storage network element; or the first network element has the permission to query the secure storage network element is preconfigured; or by default, the first network element has the permission to query the secure storage network element, which is not limited in the present application.

[0239] For example, when the trust note #1 is used to indicate that the first network element has the permission to query the secure storage network element, the first network element determines the implementation of the trust note #1 similar to the implementation of the first network element determining the trust note, which can be referred to the related description of the implementation of the trust note below, and will not be repeated here.

[0240] Optionally, in a second way, the second request information is further used to indicate that the first network element also has the permission to query the security storage network element.

[0241] For example, when the credential is also used to indicate that the first network element also has the permission to query the security storage network element, the second request information indicates the credential, i.e., the second request information is used to indicate that the first network element also has the permission to query the security storage network element. Specifically, the second request information can include the credential to explicitly indicate the credential; or the second request information can include a parameter related to the credential to implicitly indicate the credential.

[0242] When the credential #1 is used to indicate that the first network element has the permission to query the security storage network element, the second request information is further used to indicate the credential #1. Specifically, the second request information can include the credential #1 to explicitly indicate the credential #1; or the second request information can include a parameter related to the credential #1 to implicitly indicate the credential #1.

[0243] When the first network element is pre-configured or defaulted to have the permission to query the security storage network element, the second indication information can include an indication used to indicate that the first network element has the permission to query the security storage network element to explicitly indicate that the first network element has the permission to query the security storage network element; or the second indication information can include a parameter related to the indication used to indicate that the first network element has the permission to query the security storage network element to implicitly indicate that the first network element has the permission to query the security storage network element.

[0244] Optionally, when the second request information is further used to indicate that the first network element has the permission to query the target network element and has the permission to query the security storage network element, the first measurement result can be determined and stored in the security storage network element by the third network element after the third network element receives the second request information (i.e., the third network element acquires that the first network element has the permission to query the security storage network element). Therefore, the first network element acquires the first measurement result according to the second request information, which can be understood as that the first network element acquires the first measurement result after the second request information is sent. That is, the acquisition of the first measurement result is triggered after the second request information is sent.

[0245] Exemplarily, when the second request information further indicates that the first network element has the permission to query the trusted state of the target network element and the permission to query the secure storage network element, after the first network element sends the second request information to the third network element, the third network element can learn that the first network element has the permission to query the trusted state of the target network element; thus, the first network element can determine the first measurement result according to the requirement of the first network element (i.e., requesting the first measurement result); in addition, the third network element can also learn that the first network element has the permission to query the secure storage network element, thus, the third network element can store the first measurement result in the secure storage network element after determining the first measurement result, so that the first network element can obtain the first measurement result.

[0246] Optionally, after sending the second request information, the first network element can periodically query whether the first measurement result exists in the secure storage network element; or the secure storage network element can periodically inform the first network element whether the first measurement result exists; thus, when it is determined that the first measurement result exists in the secure storage network element, the first network element can determine the first measurement result from the secure storage network element.

[0247] Exemplarily, the size of the period in which the first network element queries the secure storage network element can be any value, and the time unit of the period can be seconds, milliseconds, nanoseconds, minutes, hours, etc., which are not limited in the present application; or the size of the period can be determined based on the time required by the first network element to obtain the trusted state of the network element in history (such as obtaining the trusted state of other network elements). For example, if the time required by the first network element to obtain the trusted state of the network element in history is 5 milliseconds, the size of the period can be based on 5 milliseconds, or close to 5 milliseconds (such as 4 milliseconds, 6 milliseconds), etc., which are not limited in the present application.

[0248] Optionally, in the following manner, the third network element can be considered to store the first measurement result in the secure storage network element in response to the second request information; that is, the first measurement result is stored in the secure storage network element in response to the second request information.

[0249] Optionally, the secure storage network element is used for multiple network elements to share the information stored therein. The multiple network elements include the first network element and the third network element.

[0250] Exemplarily, the secure storage network element can be a centralized storage network element; that is, information in the storage network element is stored in a certain resource, and multiple network elements can access the resource, thereby realizing sharing of the information stored in the resource. Alternatively, the secure storage network element can be a distributed storage network element; that is, each of the multiple network elements has a storage unit, and the storage units of the multiple network elements store the same information; when a certain network element stores certain information in its storage unit, the storage units of the remaining multiple network elements are synchronously updated, so that the storage units of the multiple network elements store the same information, thereby realizing sharing of the information stored by the multiple network elements. Taking three network elements (that is, network element #1, network element #2, and network element #3) as an example, each network element has a storage unit, that is, network element #1 corresponds to storage unit #1, network element #2 corresponds to storage unit #2, and network element #3 corresponds to storage unit #3; when network element #1 stores information #1 in storage unit #1, information #1 also exists in storage unit #2 and storage unit #3, so that network element #2 and network element #3 can obtain information #1 from their storage units, realizing sharing of information #1.

[0251] Exemplarily, when the secure storage network element is a distributed storage network element, the secure storage network element can be a DLT, for example, the secure storage network element can be implemented through a blockchain.

[0252] Exemplarily, the secure storage network element is an example of a naming convenient for the embodiments of the present application to describe, and can also be replaced by any other possible naming. For example, the secure storage network element can also be referred to as a public storage network element, a shared storage network element, etc., which is not limited in the present application.

[0253] In mode two, the third network element can inform the first network element of the first measurement result; that is, the first network element obtains the first measurement result according to the second request information, including that the first network element can receive the first measurement result from the third network element. The first measurement result is determined by the third network element after receiving the second request information.

[0254] Exemplarily, after determining the first measurement result, the third network element can send second response information to the first network element, and correspondingly, the first network element receives the second response information from the third network element. The second response information is used to indicate the first measurement information. Alternatively, as shown in FIG. 8, step S606 can be replaced by step S606A: the third network element sends second response information to the first network element, and correspondingly, the first network element receives the second response information from the third network element.

[0255] Specifically, the second response information can be considered as response information of the second request information; that is, in response to the second request information, the third network element sends the second response information to the first network element.

[0256] Exemplarily, the above-mentioned manner one and manner two can also be used in combination, that is, the first network element can determine the first measurement result from the secure storage network element and receive the second response information from the third network element, and compare the two, when the comparison is consistent, it can be determined that the first measurement result is accurate, so that step S607 can be performed. For example, the first measurement result indicates that the target network element is trusted, and the second response information also indicates that the target network element is trusted, at this time, it can be considered that the first measurement result is accurate, so that step S607 can be performed.

[0257] The embodiment of the present application proposes a communication method and device, when the first network element receives the measurement request (such as the first request information), it can obtain the right (that is, the trust letter) to query the trusted state of the target network element; and after obtaining the right, it obtains the trusted state (such as the first measurement result) of the target network element. That is, the first network element can only query the trusted state of the target network element after obtaining the right; avoid the first network element to query the trusted state of the network element without authorization.

[0258] Further, when the first network element requests the trusted state of the target network element from the third network element (that is, sends the second request information to the third network element), the third network element can first verify whether the query right (that is, the trust letter) of the first network element is valid (that is, determine the security of the first network element), so that when it is determined that the query right is valid (that is, the trust letter verification is passed), it can be considered that the first network element is trusted, so that when the third network element determines the trusted state (that is, the first measurement result) of the target network element, the probability of the information of the target network element being leaked can be reduced.

[0259] The above is the overall description of the flow of the communication method provided by the present solution, and the "trust letter" involved in the above-mentioned embodiment will be described in detail below. Exemplarily, the trust letter can include the following two possible implementation forms:

[0260] In one possible implementation form, the trust letter is authentication information for authenticating (or, it can also be considered as: confirming) that the first network element has the right to query the trusted state of the target network element; or the trust letter is a signature generated based on the authentication information.

[0261] Exemplarily, the trust letter is used to indicate that the first network element has the right to query the trusted state of the target network element, which includes that the trust letter is used to authenticate the right of the first network element to obtain the trusted state of the target network element.

[0262] Optionally, when the trust letter is a signature (or also can be referred to as a signature of the trust letter, or a signature of the authentication information) generated based on the authentication information authenticating that the first network element has the permission to query the trusted state of the target network element, after determining the authentication information of the target network element, the first network element can generate a signature based on the authentication information of the target network element, and determine the signature as the trust letter. When the trust letter is the authentication information authenticating that the first network element has the permission to query the trusted state of the target network element, after determining the authentication information of the target network element, the first network element can directly take the authentication information as the trust letter.

[0263] The following takes the trust letter as the authentication information authenticating that the first network element has the permission to query the trusted state of the target network element as an example to introduce the implementation of the trust letter. When the trust letter is a signature generated based on the authentication information authenticating that the first network element has the permission to query the trusted state of the target network element, the trust letter is a signature generated based on the authentication information after determining the authentication information, and the process of determining the authentication information is the same as the implementation of the authentication information described below. For details, refer to the related description in the following embodiments, which will not be described here.

[0264] Optionally, the first network element determines the trust letter according to the first information of the target network element, including: the first network element determines the authentication information corresponding to the second information of the target network element according to the second information of the target network element and the preconfigured information, the second information of the target network element is determined according to the first information of the target network element, the preconfigured information includes the correspondence between the second information of the plurality of network elements and the plurality of authentication information, and the trust letter includes the authentication information corresponding to the second information of the target network element.

[0265] Exemplarily, the second information of the network element can be the identifier of the group to which the network element belongs (for example, the second information of the target network element can be the identifier of the group to which the target network element belongs); that is, the first network element can pre-group a plurality of network elements to obtain a plurality of groups; at this time, each network element in the plurality of network elements corresponds to a second information. The second information of at least one network element belonging to the same group (that is, the identifier of the group) is the same. Further, each group corresponds to an authentication information, wherein the authentication information is used to authenticate that the network element in the group has the permission to query the trusted state of the target network element. Therefore, it can also be considered that the first network element pre-configures the correspondence between the second information of the plurality of network elements and the plurality of authentication information (that is, the preconfigured information). Therefore, after the first network element determines the second information of the target network element according to the first information of the target network element, it can be determined whether the preconfigured information exists (that is, the authentication information corresponding to the second information of the target network element). When it exists, the authentication information corresponding to the second information of the target network element is determined as the trust letter, or in other words, it is determined that the first network element has the permission to query the trusted state of the target network element.

[0266] Based on the foregoing, the grouping principle of the plurality of network elements can be that: the network elements in the same group can come from the same vendor, or the network elements in the same group can come from the same vendor (vendor), or the network elements in the same group can be located in the same PLMN, or the network elements in the same group are of the same type, and the like.

[0267] Therefore, correspondingly, the second information of the network element includes a plurality of different implementation forms; when the grouping principle of the plurality of network elements is that the network elements in the same group come from the same vendor, the second information of the network element is the vendor ID; when the grouping principle of the plurality of network elements is that the network elements in the same group come from the same vendor, the second information of the network element is the vendor ID; when the grouping principle of the plurality of network elements is that the network elements in the same group come from the same PLMN, the second information of the network element is the PLMN identifier; and when the grouping principle of the plurality of network elements is that the network elements in the same group are of the same type, the second information of the network element is the type identifier (such as type I, type II, and the like).

[0268] For the convenience of description, the vendor ID, the vendor ID, and / or the PLMN identifier can be referred to as the first identifier, and the type identifier of the network element can be referred to as the second identifier, which are collectively described herein and will not be described again.

[0269] Specifically, taking the network elements #1 to #4 in the plurality of network elements (i.e., network element #1 to network element #8) as an example, the network elements #1 to #4 come from the vendor #1 (the identifier of which is vendor ID #1), the network elements #5 to #8 come from the vendor #2 (the identifier of which is vendor ID #2), and the grouping principle of the plurality of network elements includes that the network elements in the same group come from the same vendor. At this time, the plurality of network elements can be divided into two groups, wherein the second information of the network elements #1 to #4 is all vendor ID #1, and the second information of the network elements #5 to #8 is all vendor ID #2. If the authentication information corresponding to the vendor ID #1 is authentication information #1, and the authentication information corresponding to the vendor ID #2 is authentication information #2, the pre-configuration information includes the vendor ID #1 and the authentication information #1 corresponding thereto, the vendor ID #2 and the authentication information #2 corresponding thereto.

[0270] For example, the pre-configuration information can be implemented in the form of a set, at this time, the pre-configuration information can include {vendor ID #1; authentication information #1}, {vendor ID #2; authentication information #2}; or the pre-configuration information can be implemented in the form of a table, at this time, the pre-configuration information can include the content shown in Table 1:

[0271] Table 1

[0272] Alternatively, the pre-configuration information can also be implemented in other forms other than the above set and table, which is not limited in the present application; as long as the relationship between the second information and the authentication information can be embodied.

[0273] It should be understood that the above is an exemplary description of the pre-configuration information, and does not represent that the pre-configuration information described in the present application can only be implemented based on 8 network elements (i.e. network element #1~network element #8), and the grouping rule is based on the supplier grouping (i.e. the network elements in the same group come from the same supplier). In fact, the pre-configuration information described in the present application can also support the case where the number of network elements is less than 8 or greater than 8, and / or other grouping rules (such as based on manufacturer, PLMN, network function type of network element, etc.). At this time, the implementation of the pre-configuration information is similar to the implementation of the pre-configuration information in the above case based on 8 network elements and the grouping rule based on the supplier grouping. For details, please refer to the related description of the above embodiments, which will not be repeated here.

[0274] It should be noted that the authentication information corresponding to the second information of the network element can also be referred to as a certificate; or it can also be referred to as an authentication identifier, etc., which is not limited in the present application.

[0275] Exemplarily, the first network element can determine the second information of the target network element in different ways:

[0276] As an example, the first information of the target network element can include the configuration information of the target network element, and the configuration information of the target network element includes the identifier of the group to which the target network element belongs.

[0277] Exemplarily, based on the foregoing, the identifier of the group to which the target network element belongs is the second information of the target network element; therefore, it can also be considered that the first request information (or the first information of the target network element) carries the second information of the target network element; thus, the first network element can obtain the second information of the target network element after receiving the first request information.

[0278] Specifically, the implementation of the second information of the target network element can also refer to the related description of the implementation of the second information of the network element in the above embodiments, which will not be repeated here.

[0279] As another example, the first information of the target network element can include the configuration information of the target network element, and the configuration information of the target network element includes the identifier of the target network element (such as NF instance ID) or information capable of identifying the target network element.

[0280] Optionally, the first network element can query the second information of the target network element according to the first information of the target network element. Specifically, a correspondence relationship between the first information of each network element in the plurality of network elements and the second information of the network element (or a correspondence relationship between the first information of the plurality of network elements and the second information of the plurality of network elements) can be stored in advance. Thus, the first network element can determine the second information of the target network element in the correspondence relationship.

[0281] For example, the implementation of the second information of the network element can refer to the related description of the implementation of the second information of the network element in the above embodiments, which will not be repeated here.

[0282] For example, the first information of the network element is the identifier of the network element, and the second information of the network element is the vendor ID. At this time, the first network element can store a correspondence relationship between the identifiers of the plurality of network elements and the vendor IDs of the plurality of network elements in advance. Specifically, the implementation of the correspondence relationship is similar to the implementation of the correspondence relationship between the second information of the plurality of network elements and the plurality of authentication information included in the pre-configuration information, and the related description of the above embodiments can be referred to, which will not be repeated here.

[0283] Optionally, the correspondence relationship (i.e., the correspondence relationship between the first information of the plurality of network elements and the second information of the plurality of network elements) can be stored in the UDM or the operation administration and maintenance (OAM), so that the first network element can query the second information of the target network element in the UDM or the OAM.

[0284] Specifically, the OAM can include one or more of the VNFM, the NFVO, the VIM, the EMS, and the network management system (NMS) to manage the network element. For example, when the OAM is the EMS, it can obtain the virtual image of the target network element through the VNFM; wherein the configuration file in the virtual image includes the second information of the target network element.

[0285] Optionally, the credential can contain the second information of the target network element. That is, the second request information is further used to indicate the credential, including: the second request information is further used to indicate the second information of the target network element. Alternatively, the credential and the second information of the target network element can exist independently, and at this time, the second request can also indicate the second information of the target network element, that is, the second request information is further used to indicate the credential and the second information of the target network element.

[0286] For example, when the credential is the authentication information (e.g., vendor certificate) of the target network element, the second request information can indicate the vendor certificate and the vendor ID; when the credential is the signature (e.g., sign) generated based on the authentication information of the target network element, the second request information can indicate the sign and the vendor ID.

[0287] Based on the optional scheme, the second request information can further indicate the second information of the target network element, so that the third network element can verify the credential based on the second information of the target network element, and improve the accuracy of the verification result of the credential.

[0288] Optionally, in the possible implementation manner, the third network element can determine whether the credential is valid by verifying whether the signature of the credential is valid, whether the credential is expired, whether the credential exists in the preconfigured verification information, and / or the identifier of the group to which the target network element belongs (i.e., the second information of the target network element).

[0289] For example, when the third network element determines whether the credential is valid by verifying whether the signature of the credential is valid, whether the credential is expired, whether the credential exists in the preconfigured verification information, and the identifier of the group to which the target network element belongs, if the signature of the credential is valid, the credential is not expired, the credential exists in the preconfigured verification information, and the second information of the target network element indicated by the second request information is the same as the second information of the target network element determined by the third network element, it is identified that the credential is valid, i.e., the credential verification is passed.

[0290] Specifically, the preconfigured verification information and the implementation of whether the credential is valid can refer to the related description of the above embodiments, which will not be described here.

[0291] Based on the possible implementation manner, it can be understood that the authentication information used to authenticate whether a network element has a certain permission is usually preconfigured for the network element; therefore, when the credential is the authentication information (or the signature generated based on the authentication information) that authenticates that the first network element has the permission to query the trusted state of the target network element, the first network element can know whether it has the permission to query the trusted state of the target network element by querying the preconfigured authentication information (i.e., the preconfigured information) for it; that is, the first network element does not need to rely on other network elements, and it can determine the credential by itself through the preconfigured information, thereby improving the efficiency of determining the credential and saving signaling overhead.

[0292] In another possible implementation manner, the credential is the permission granted to the first network element to query the trusted state of the target network element.

[0293] That is, the trust letter is used to indicate that the first network element has the permission to query the trusted state of the target network element, including: the trust letter is used to grant the first network element the permission to obtain the trusted state of the target network element.

[0294] Exemplarily, the trust letter can be a token or any other information capable of indicating that the first network element has the permission to query the trusted state of the target network element, which is not limited in the application.

[0295] Optionally, the first network element determines the trust letter according to the first information of the target network element, including: the first network element obtains the trust letter from a fourth network element. The fourth network element is used to determine the trust letter according to the first information of the target network element.

[0296] Exemplarily, the fourth network element can be an NRF, or any other network element capable of determining the trust letter, which is not limited in the application.

[0297] Specifically, as shown in FIG. 9, the first network element can determine the trust letter through the following steps S602A-S602B, that is, step S602 can be replaced by the following steps S602A-S602B.

[0298] S602A, the first network element sends third request information to the fourth network element, and correspondingly, the fourth network element receives the third request information from the first network element. The third request information is used to request the trust letter.

[0299] Exemplarily, the third request information can be carried in the OAuth application request information, that is, the OAuth application request information is used to request the trust letter.

[0300] Since the trust letter is also used to indicate that the first network element has the permission to query the secure storage network element, the third request information used to request the trust letter includes: the third request information is used to request the permission of the first network element to query the secure storage network element. Alternatively, the trust letter can also be used to indicate that the third network element has the permission to query the secure storage network element, and therefore, the third request information used to request the trust letter includes: the third request information is used to request the permission of the third network element to query the secure storage network element.

[0301] Exemplarily, the first information of the target network element and the implementation of the secure storage network element can be referred to the related description in the above embodiments, which is not described herein.

[0302] Optionally, the third request information is also used to indicate the first information of the target network element and / or the identifier of the first network element. Exemplarily, when the first information of the target network element includes the identifier of the first network element, the third request information is used to indicate the first information of the target network element. For the convenience of description, the following describes the case that the first information does not include the identifier of the first network element, which is uniformly described herein and is not described herein.

[0303] Exemplarily, when the third request information is further used to indicate the first information of the target network element, the fourth network element can determine the trust note according to the identity of the group to which the target network element belongs determined according to the first information of the target network element, and further determine the trust note according to the identity of the group to which the target network element belongs.

[0304] Specifically, the fourth network element can determine the group identity corresponding to the subscription information of the first network element, that is, one or more group identities pre-configured for the first network element, and query whether the group identity to which the target network element belongs (that is, the second information of the target network element) exists in the one or more group identities. When the group identity to which the target network element belongs exists in the one or more group identities, the fourth network element can determine the trust note; that is, when it is determined that the group identity to which the target network element belongs exists in the one or more group identities, the fourth network element determines the trust note and informs the first network element (that is, grants the first network element the permission to query the trusted state of the target network element).

[0305] Taking the group identity as a vendor ID and the fourth network element as an NRF as an example, the one or more group identities pre-configured for the first network element include one or more vendor IDs; the NRF can query whether the one or more vendor IDs of the target network element exist in the one or more vendor IDs, and if they exist, grant the first network element the permission to query the trusted state of the target network element (that is, determine and send the trust note to the first network element).

[0306] Exemplarily, when the third request information is further used to indicate the identity of the first network element, the fourth network element can determine the trust note according to the identity of the first network element.

[0307] Specifically, after receiving the third request information, the fourth network element can trigger the measurement of the first network element, that is, determine the trusted state of the first network element, and when the measurement result of the first network element is trusted (that is, the trusted state of the first network element is trusted), the trust note can be determined; that is, when the fourth network element determines that the measurement result of the first network element is trusted, the trust note is determined and the first network element is informed (that is, the first network element is granted the permission to query the trusted state of the target network element).

[0308] Specifically, the fourth network element can determine the trusted state of the first network element through the verification entity and the measurement entity, which can be referred to the related description of FIG. 2 above, and will not be described here.

[0309] Optionally, before step S602A, the first network element can determine whether the trust note exists, or whether the unexpired trust note exists; if not, step S602 is executed. If it exists, step S603 is directly executed. In other words, the first network element sends the third request information, including: when the trust note does not exist, or the unexpired trust note does not exist, the third request information is sent.

[0310] Case I: the first network element determines whether there is a credential.

[0311] Optionally, in case I, the first network element can query whether it is granted a credential, and if the first network element is granted a credential, it indicates that the first network element has a credential. Alternatively, when the first network element is granted a credential, the first network element can further determine whether the granted credential is the permission for querying the status of the target network element, and if yes, it indicates that the first network element has a credential.

[0312] For example, taking the token as a credential and the first information of the target network element as a target NF profile, the first network element can determine whether it is granted a token, and if yes, it indicates that the first network element has a token. Alternatively, when the first network element is granted a token, the first network element can further determine whether the target NF profile indicated by the first request information is consistent with the NF profile indicated by the historical request information (i.e., the request information for requesting a credential sent to the fourth network element before the first network element queries whether it is granted a credential) sent by the first network element to the fourth network element, and if yes, it indicates that the first network element has a credential.

[0313] Case II: the first network element determines whether there is an unexpired credential.

[0314] Optionally, in case II, the first network element can query whether it is granted a credential, and if the first network element is granted a credential, the first network element can further determine whether the granted credential is expired, and if the granted credential is not expired, it indicates that the first network element has an unexpired credential. Alternatively, when the granted credential is not expired, the first network element can further determine whether the granted credential is the permission for querying the status of the target network element, and if yes, it indicates that the first network element has an unexpired credential.

[0315] For example, taking the token as a credential and the first information of the target network element as a target NF profile, the first network element can determine whether it is granted a token, and if yes, the first network element can determine whether the granted token is expired, and if the granted token is not expired, it indicates that the first network element has an unexpired token. Alternatively, when the granted token is not expired, the first network element can further determine whether the target NF profile indicated by the first request information is consistent with the NF profile indicated by the historical request information (i.e., the request information for requesting a credential sent to the fourth network element before the first network element queries whether it is granted a credential) sent by the first network element to the fourth network element, and if yes, it indicates that the first network element has an unexpired credential.

[0316] Specifically, the implementation of determining whether the token is expired can refer to the implementation of determining whether the token is expired in the above-mentioned embodiments, which will not be described herein again.

[0317] Based on the optional scheme, the first network element can first query whether the token exists, and if not, request the token from other network elements; if so, it is not necessary to request from other network elements, and it can directly request the third network element to obtain the trusted state of the target network element, thereby saving resources and improving the efficiency of the first network element in obtaining the trusted state of the target network element.

[0318] S602B, the fourth network element sends the token to the first network element; correspondingly, the first network element receives the token from the fourth network element.

[0319] Exemplarily, when the third request information is carried in the OAuth application request information, correspondingly, the token can be carried in the OAuth application response information.

[0320] Exemplarily, when the token is a token, the second request information is further used to indicate the token.

[0321] Optionally, in the possible implementation manner, the third network element can determine whether the token is valid by verifying whether the signature of the token is valid, whether the token is expired, whether the token exists in the preconfigured verification information, and / or whether the verification information corresponding to the token exists in the preconfigured verification information.

[0322] Exemplarily, when the third network element determines whether the token is valid by verifying whether the signature of the token is valid, whether the token is expired, whether the token exists in the preconfigured verification information, and whether the verification information corresponding to the token exists in the preconfigured verification information, if the signature of the token is valid, the token is not expired, the token exists in the preconfigured verification information, and the verification information corresponding to the token exists in the preconfigured verification information, the token is identified as valid, that is, the token verification is passed. Wherein, the determination process of whether the token is valid can refer to the related description in the above-mentioned embodiments, which will not be described herein again.

[0323] Based on the possible implementation manner, it can be understood that the function of granting a network element a certain permission is usually implemented by a network element having the function of granting permission; therefore, when the token is the permission of querying the trusted state of the target network element by the first network element, the first network element can obtain the token from the network element having the function of granting permission (such as the fourth network element); that is, when the first network element has a demand (that is, needs the token), it can request the fourth network element, and the first network element itself does not need to store the permission (such as one or more tokens) indicating that it has the permission, thereby saving the storage space of the first network element.

[0324] In combination with the above two possible implementation manners, optionally, the third network element can further verify the measurement result of the first network element (i.e., the trusted state of the first network element, or also referred to as: second measurement result), when the measurement result of the first network element is trusted, it is determined that the first network element is trusted, or it can also be considered that the trust letter verification is passed, so that step S605 can be performed. When the measurement result of the first network element is untrusted, it is determined that the first network element is untrusted, or it can also be considered that the trust letter verification is not passed, so that step S605 cannot be performed.

[0325] For example, the third network element can determine the trusted state of the first network element through a verification entity (such as the third network element itself or other verification entities other than the point network element) and a measurement entity. For details, please refer to the related description of FIG. 2 above, which will not be repeated here.

[0326] The above is the description of the "trust letter", and the "first measurement result (or the trusted state of the target network element)" involved in the above embodiment is described in detail below.

[0327] For example, based on the foregoing, the first network element can be based on the above-mentioned manner one (i.e., the third network element stores the first measurement result in the secure storage network element, so that the first network element can determine the first measurement result from the secure storage network element) and / or manner two (the third network element can inform the first network element after determining the first measurement result, so that the first network element knows the first measurement result). For details, please refer to the related description in the foregoing embodiment, which will not be repeated here.

[0328] The process of "determining the first measurement result by the third network element" is described in detail below. For example, when the trust letter is also used to indicate that the third network element has the right to query the secure storage network element, after receiving the second request information, the third network element can query whether the first measurement result exists in the secure storage network element. If it exists, the first measurement result can be determined from the secure storage network element. If it does not exist, the third network element can determine the first measurement result through the measurement entity. Therefore, the first measurement result can be realized based on the following two scenarios:

[0329] Scenario one, the first measurement result does not exist in the secure storage network element.

[0330] For example, in scenario one, the first measurement result can be determined by one or more verification entities. The one or more verification entities include the third network element.

[0331] As a possible implementation manner, the first measurement result can be determined by one verification entity. At this time, the one verification entity is the third entity; or in other words, the first measurement result is determined by the third network element alone.

[0332] Optionally, the verifying entity (i.e., the third network element) determines the first measurement result according to the evidence of the target network element from the measuring entity.

[0333] For example, as shown in FIG. 10, the verifying entity can determine the first measurement result through steps S605A-S605D, i.e., step S605 can be replaced by steps S605A-S605D.

[0334] S605A, the verifying entity sends fourth request information to the measuring entity, and correspondingly, the measuring entity receives the fourth request information from the verifying entity. The fourth request information is used to request the target network element, and the fourth request information is also used to indicate the first information of the target network element.

[0335] For example, the implementation of the fourth request information is similar to the implementation of the challenge message in step S201, and details can be referred to the related description of step S201, which will not be repeated here.

[0336] S605B, the measuring entity measures the target network element to obtain the evidence of the target network element.

[0337] For example, the evidence can be a platform configuration register (PCR) registration value; for example, the evidence of the target network element can be a group of PCR registration values or a PCR registration value; and it can include the output value of a hash function.

[0338] For example, the measuring entity can measure the target network element according to the first information of the target network element to obtain the evidence of the target network element. Specifically, the implementation of step S605B is similar to the implementation of step S202, and details can be referred to the related description of step S202, which will not be repeated here.

[0339] S605C, the measuring entity sends the evidence of the target network element to the verifying entity; correspondingly, the verifying entity receives the evidence of the target network element from the measuring entity.

[0340] For example, the evidence of the target network element can be carried in response information for responding to the fourth request information. Specifically, the implementation of step S605C is similar to the implementation of step S203, and details can be referred to the related description of step S203, which will not be repeated here.

[0341] S605D, the verifying entity verifies the evidence of the target network element to obtain the first measurement result.

[0342] For example, the implementation of step S605D is similar to the implementation of step S204, and details can be referred to the related description of step S204, which will not be repeated here.

[0343] Optionally, the verification entity can store the first measurement result in the secure storage network element after determining the first measurement result, at this time, the first network element and the third network element can share the stored information, that is, the network elements capable of sharing information include the first network element and the third network element; so that when the letter of trust is used to indicate that the first network element has the right to query the secure storage network element, the first network element can determine the first measurement result from the secure storage network element.

[0344] And / or, the verification entity can send the first measurement result to the first network element after determining the first measurement result, so that the first network element knows the first measurement result.

[0345] Based on this possible implementation, when the verification entity receives the second request information, the evidence of the target network element can be determined by the measurement entity; for example, after receiving the second request information, the verification entity can request the evidence of the target network element from the measurement entity; so that the measurement entity can obtain information from the target network element to further determine the evidence of the target network element. That is, the measurement entity determines the evidence of the target network element only after receiving the request of the verification entity, thereby ensuring the freshness of the evidence of the target network element and improving the credibility of the trusted state of the target network element determined by the verification entity.

[0346] As another possible implementation, the first measurement result is determined by multiple verification entities. Among them, the multiple verification entities include the third network element, or in other words, the third network element is one of the multiple verification entities.

[0347] Optionally, the multiple verification entities are located in the same consensus group, that is, the multiple verification entities can share information in the secure storage network element.

[0348] Optionally, the multiple verification entities respectively determine the trusted state of the target network element, and determine the first measurement result according to the trusted states of the multiple target network elements (i.e., the trusted states of the target network element determined by the multiple verification entities respectively).

[0349] For example, the multiple verification entities can respectively determine the trusted state of the target network element through their corresponding measurement entities, or the multiple verification entities can determine the trusted state of the target through the same measurement entity.

[0350] Specifically, taking an example in which the plurality of verification entities include verification entity #1 to verification entity #X, where X is a positive integer greater than 1, verification entity #1 can determine the trust state of the target network element corresponding thereto through measurement entity #1, verification entity #2 can determine the trust state of the target network element corresponding thereto through measurement entity #2, and so on, and verification entity #X can determine the trust state of the target network element corresponding thereto through measurement entity #X, thereby obtaining the trust states of the plurality of target network elements. Alternatively, verification entity #1 to verification entity #X can respectively determine the trust state of the target network element corresponding thereto through the measurement entity, thereby obtaining the trust states of the plurality of target network elements. Further, the first measurement result can be determined in combination with the trust states of the plurality of target network elements.

[0351] In the process in which the plurality of verification entities respectively determine the trust state of the target network element through the measurement entity corresponding thereto, each verification entity determines the trust state of the target network element corresponding thereto through the measurement entity corresponding thereto (for example, verification entity #1 determines the trust state of the target network element corresponding thereto through measurement entity #1), and the implementation can refer to the related description of steps S605A to S605D above, which will not be described herein again.

[0352] For the convenience of description, taking an example in which verification entity #1 to verification entity #X respectively determine the trust state of the target network element corresponding thereto through the measurement entity, and the value of X is 2, at this time, as shown in FIG. 11, the first measurement result can be implemented based on steps S605E to S605L, that is, step S605 can be replaced by steps S605E to S605L.

[0353] S605E, verification entity #1 and verification entity #2 establish a consensus group.

[0354] The plurality of verification entities in the same consensus group can share the information stored in the secure storage network element.

[0355] Optionally, step S605E is an optional step, that is, when the plurality of verification entities have established the consensus group, step S605E can be omitted.

[0356] S605F, the measurement entity sends the evidence of the target network element to verification entity #1 and verification entity #2; correspondingly, verification entity #1 and verification entity #2 respectively receive the evidence of the target network element from the measurement entity.

[0357] Optionally, the evidence of the target network element can be carried in the proof information; further, the proof information can further include one or more of the following: a timestamp, a public key. The timestamp is used to indicate the generation time of the evidence.

[0358] For example, the public key corresponds to the private key used by the verification entity #1 (and / or the verification entity #2) to sign the evidence of the target network element. The measurer can use the private key to sign the evidence of the target network element, so that the evidence of the target network element cannot be tampered with or forged, and thus the verification entity #1 and the verification entity #2 can use the public key to verify the signature after receiving the signature. Specifically, the public key can be previously notified to the verification entity #1 and the verification entity #2 by the measurer.

[0359] S605G, the verification entity #1 determines the trusted state #1 according to the evidence of the target network element.

[0360] The trusted state #1 is the trusted state of the target network element determined by the verification entity #1, or can also be regarded as the measurement result of the target network element determined by the verification entity #1.

[0361] Optionally, before determining the trusted state #1, the verification entity #1 can verify the signature corresponding to the evidence of the target network element received by it, and when the verification is passed, the trusted state #1 is determined according to the evidence of the target network element.

[0362] For example, the verification entity #1 can verify the signature corresponding to the evidence of the target network element received by it; for example, the verification entity #1 can verify the signature according to the public key. Further, optionally, if the proof information contains a freshness parameter, the verification entity verifies whether the freshness parameter is fresh before verifying the signature (for example, if the freshness parameter is a timestamp, it is verified whether the time indicated by the timestamp has exceeded a preset value, and if not, it is verified whether the signature is valid.) If any verification fails, the verification entity #1 discards the proof information.

[0363] For example, the verification entity #1 can verify the identity of the measurement entity according to the public key, which can be achieved in the following way: way a), the verification entity preconfigures a public key list, and uses the public key as the identity of the measurement entity. The public key that is not in the preconfigured list is not verified. The public key in the preconfigured list is verified. Alternatively, the verification entity #1 can also verify the identity of the measurement entity according to the public key and the identity of the measurement entity. There are the following methods: the measurement entity preconfigures the mapping relationship between the public key and the identity of the measurement entity, and if the public key or the identity of the measurement entity is not in the preconfigured list or the public key and the identity of the measurement entity do not correspond, the verification is not passed. Or the public key or the identity of the measurement entity is in the preconfigured list or the public key and the identity of the measurement entity meet the preset correspondence, then the verification is passed.

[0364] S605H, the verification entity #2 determines the trusted state #2 according to the evidence of the target network element.

[0365] The trusted state #2 is a trusted state of the target network element determined by the verification entity #2, or can be considered as a measurement result of the target network element determined by the verification entity #2.

[0366] Optionally, before determining the trusted state #2, the verification entity #2 can verify the signature corresponding to the evidence of the target network element received by the verification entity #2, and when the verification is passed, the trusted state #2 is determined according to the evidence of the target network element.

[0367] For example, the verification process of the verification entity #2 checking the signature is similar to the verification process of the verification entity #1 checking the signature in step S605G described above, and the specific process can be referred to the related description of step S605G described above, which will not be repeated here.

[0368] Optionally, the trusted state #1 and the trusted state #2 can be the same, or the trusted state #1 and the trusted state #2 can be different.

[0369] For example, the trusted state #1 or the trusted state #2 can indicate that the target network element is trusted, or can also indicate that the target network element is untrusted. Alternatively, the trusted state #1 or the trusted state #2 can indicate the trust degree of the target network element. For example, a high trust degree, a medium trust degree or a low trust degree. Among them, the high trust degree means that the target network element is very trusted, the medium trust degree means that the target network element is trusted, and the low trust degree means that the target network element is untrusted. It can be understood that the high trust degree is higher than the medium trust degree, and the medium trust degree is higher than the low trust degree.

[0370] It should be understood that the execution of steps S605G and S605H is not distinguished in sequence, for example, step S605G can be executed before step S605H, or step S605G can be executed after step S605H, or step S605G and step S605H can be executed at the same time, and the embodiments of the present application do not limit this.

[0371] S606I, the verification entity #1 and the verification entity #2 determine the master node according to the consensus mechanism.

[0372] For example, each of the verification entity #1 and the verification entity #2 will calculate a consensus credential according to the consensus mechanism. Assuming that the verification entity #1 obtains the consensus credential according to the consensus mechanism first, then the verification entity #1 is the master node. For the convenience of description, the following will take the verification entity #1 as the master node as an example for introduction, and the unified description will not be repeated here.

[0373] S606J, the verification entity #1 sends the trusted state #1 to the verification entity #2; correspondingly, the verification entity #2 receives the trusted state #1 from the verification entity #1.

[0374] For example, in step S606J, the primary node can send the determined trusted state to other verification entities in its consensus group. Correspondingly, the other verification entities respectively receive the trusted state from the primary node.

[0375] Specifically, taking the verification entity #1 as the primary node as an example, the verification entity #1 can send the trusted state #1 to the verification entity #2, and correspondingly, the verification entity #2 receives the trusted state #2 from the verification entity #1.

[0376] Optionally, the primary node can also send the consensus credential #1 to the other verification entities, and correspondingly, the other verification entities respectively receive the consensus credential #1 from the primary node. The consensus credential #1 is the consensus credential obtained by the primary node according to the consensus mechanism.

[0377] Specifically, taking the verification entity #1 as the primary node and the consensus credential corresponding to the verification entity #1 as the consensus credential #1 as an example, the verification entity #1 can send the consensus credential #1 to the verification entity #2, and correspondingly, the verification entity #2 receives the consensus credential #1 from the verification entity #1.

[0378] For example, the consensus credential #1 and the trusted state #1 can be carried in the same signaling, or the consensus credential #1 and the trusted state #1 can be carried in different signaling.

[0379] In step S606K, the verification entity #2 determines whether the trusted state #1 is valid according to the trusted state #2.

[0380] Optionally, the verification entity #2 can compare whether the trusted state #1 and the trusted state #2 are the same. When the trusted state #1 and the trusted state #2 are the same, it can be considered that the trusted state #1 is valid. When the trusted state #1 and the trusted state #2 are not the same, it can be considered that the trusted state #1 is invalid.

[0381] Optionally, when the verification entity #1 also sends the consensus credential #1 to the verification entity #2, the verification entity #2 can compare whether the consensus credential #1 and the consensus credential #2 are the same, and compare whether the trusted state #1 and the trusted state #2 are the same. The consensus credential #1 is the consensus credential obtained by the verification entity #2 according to the consensus mechanism.

[0382] When the consensus credential #1 and the consensus credential #2 are the same, and the trusted state #1 and the trusted state #2 are the same, it can be considered that the trusted state #1 is valid. When the consensus credential #1 and the consensus credential #2 are not the same, and / or, the trusted state #1 and the trusted state #2 are not the same, it can be considered that the trusted state #1 is invalid.

[0383] Optionally, when the number of other verification entities in the consensus group where the primary node is located is greater than 1 (i.e., the consensus group includes greater than or equal to 3 verification entities), the primary node can send the trusted state #1 to each of the other verification entities respectively; so that each of the other verification entities can verify whether the trusted state #1 is from the primary node (i.e., verification entity #1) after receiving the trusted state #1, if yes, it means that the verification entity considers the trusted state #1 valid, so it can broadcast the signature of the verification entity to the verification entities other than the verification entity. When there is a verification entity receiving Y signatures, the trusted state #1 can be considered valid. Wherein, Y is greater than or equal to the first threshold, and Y is a positive integer.

[0384] For example, the first threshold can be a positive integer greater than or equal to one half of the number of verification entities in the consensus group; and / or, the first threshold can be a positive integer greater than or equal to two thirds of the number of other verification entities. For example, when the consensus group includes 10 verification entities, the other verification entities include 9 verification entities; at this time, the first threshold can be any of 6, 7, 8, 9, 10.

[0385] For example, taking the verification entity #1 as the primary node as an example, the verification entity #1 can configure a unique number for the trusted state #1, and form a pre-prepare message with the trusted state #1 and the number configured for it; and broadcast to other verification entities. Any of the other verification entities (such as verification entity #2) can query whether the pre-prepare message is from the primary node by relying on the signature field after receiving the pre-prepare message, if yes, the number of the trusted state #1 and the signature of the verification entity are combined to form a prepare message, and broadcast to the verification entities other than the verification entity. In this way, when the number of prepare messages is greater than or equal to the first threshold, it can be considered that most of the verification entities agree with the trusted state #1, that is, it can be considered that the trusted state #1 is valid.

[0386] S606L, when the trusted state #1 is valid, the verification entity #1 determines the trusted state #1 as the first measurement result.

[0387] Optionally, the trusted state #1 is valid, which can be understood as: the primary node is trusted, or the trusted state #1 determined by the primary node is trusted. So the verification entity #1 (i.e., the primary node) can determine the trusted state #1 as the first measurement result.

[0388] Optionally, after step S606L, the verification entity #1 can store the first measurement result in the secure storage network element, so that the first network element can determine the first measurement result from the secure storage network element. That is, the verification entity #1 stores the trusted state #1 in the secure storage network element, or in other words, the verification entity #1 writes the trusted state #1 into the secure storage network element.

[0389] For example, when the secure storage network element is a centralized storage network element, the first measurement result can be stored in the secure storage network element by the verification entity #2; when the secure storage network element is a distributed storage network element, multiple verification entities (such as the verification entity #1 and the verification entity #2) can respectively determine the trusted state #1 as the first measurement result, and store the first measurement result in their storage units.

[0390] Optionally, in this possible implementation, the first network element can send the second request information to multiple verification entities (for example, send the second request information to multiple verification entities respectively, or broadcast the second request information to multiple verification entities); at this time, the above step S603 can be replaced by: the first network element sends the second request information to multiple verification entities. Alternatively, the first network element can send the second request information to one verification entity.

[0391] It should be understood that when there are multiple verification entities, if the first network element obtains the first measurement result from the verification entities, generally: the master node in the multiple verification entities informs the first network element (that is, the master node sends the first measurement result to the first network element); or, the multiple verification entities respectively inform the first network element of their corresponding trusted states (such as the trusted state #1 and the trusted state #2), and further, the first network element can determine the first measurement result according to the multiple trusted states.

[0392] For the convenience of description, the following describes the case where the multiple verification entities include the third network element and the fifth network element, and this description will not be repeated. When the multiple verification entities include more than two verification entities, the implementation of the first network element obtaining the first measurement result is similar to the following embodiments, and specific implementation can be referred to the related description of the following embodiments, which will not be repeated here.

[0393] Based on the above, the first network element can obtain the first measurement result from the verification entities based on the following two cases:

[0394] Case one, the first network element receives the first measurement result from the master node in the multiple verification entities.

[0395] As a first example, when the third network element is the master node, that is, the first network element sends the second request information to the third network element, after the third network element determines the first measurement result, the third network element can send the first measurement result to the first network element, that is, the first network element obtains the first measurement result from the third network element.

[0396] Exemplarily, since the third network element can receive the second request information, the third network element can learn the demander (i.e., the first network element) of the trusted state of the target network element, and thus can inform the first network element of the first measurement result after determining the first measurement result. At this time, it can be considered that the master node sends the first measurement result to the first network element based on the response to the second request information received by the master node.

[0397] Exemplarily, the third network element can determine the first trusted state, and determine the first measurement result after verification by the fifth network element. Alternatively, the third network element can determine the first measurement result from the security storage network element. The first trusted state is the trusted state of the target network element determined by the third network element.

[0398] Specifically, when the third network element determines the first trusted state, the fifth network element can determine the second trusted state. The second trusted state is the trusted state of the target network element determined by the fifth network element. Thus, the third network element can verify the first trusted state (e.g., verify the first trusted state according to the second trusted state) through the fifth network element after determining the first trusted state, and further determine the first measurement result.

[0399] At this time, the implementation of the third network element is the same as the implementation of the verification entity #1 in the above FIG. 11, and the implementation of the fifth network element is the same as the implementation of the verification entity #2 in the above FIG. 11, i.e., the first trusted state is the trusted state #1 in the above FIG. 11, and the second trusted state is the trusted state #2 in the above FIG. 11. In addition, the implementation of the first measurement result can refer to the related description of the above FIG. 11, which will not be described here.

[0400] Optionally, in this example, the first network element can send the second request information to only the master node (i.e., the third network element), or the first network element can send the second request information to multiple verification entities (wherein the multiple verification entities include the third network element).

[0401] As a second example, when the third network element is not the master node, i.e., the first network element sends the second request information to other verification entities (e.g., the third network element) except the master node in the multiple verification entities, the master node (i.e., the fifth network element) can obtain the identifier of the first network element after determining the first measurement result, and further send the first measurement result to the first network element, i.e., the first network element learns the first measurement result from the fifth network element.

[0402] At this time, as shown in FIG. 12, steps S605 and S606A are performed by the fifth network element, i.e., step S605 can be replaced by S605M: when the credential verification passes, the fifth network element determines the first measurement result. Step S606A can be replaced by S606B: the fifth network element sends second response information to the first network element, and correspondingly, the first network element receives the second response information from the fifth network element.

[0403] For example, since the primary node (i.e., the fifth network element) fails to receive the second request information, the primary node is unaware of the demand side (i.e., the first network element) of the trust status of the target network element, and thus after determining the first measurement result, the demand side (such as the identifier of the first network element) of the trust status of the target network element can be queried, and further, the first measurement result can be sent to the demand side. For example, before step S606A, as shown in FIG. 12, the communication method can include step S608: the fifth network element obtains the identifier of the first network element. Thus, after determining the identifier of the first network element, the first measurement result can be sent to the first network element.

[0404] For example, the fifth network element can obtain the demand side of the trust status of the target network element by obtaining the identifier of the first network element, such as the destination address of the first measurement result. Thus, the first measurement result (i.e., the second response information) can be sent so that the first measurement result can reach the first network element.

[0405] Optionally, the fifth network element can determine a second trust status and determine the first measurement result after verification by the third network element. Alternatively, the fifth network element can determine the first measurement result from the secure storage network element. The second trust status is the trust status of the target network element determined by the fifth network element.

[0406] Specifically, when the fifth network element determines the second trust status, the third network element can determine a first trust status. The first trust status is the trust status of the target network element determined by the third network element. Thus, after determining the second trust status, the fifth network element can verify the second trust status by the third network element (such as verifying the second trust status according to the first trust status), and further determine the first measurement result.

[0407] Specifically, the implementation of the fifth network element is the same as the implementation of the verification entity #1 in FIG. 11 described above, and the implementation of the third network element is the same as the implementation of the verification entity #2 in FIG. 11 described above, i.e., the second trust status is the trust status #1 in FIG. 11 described above, and the first trust status is the trust status #2 in FIG. 11 described above. In addition, the implementation of the first measurement result can refer to the related description of FIG. 11 described above, which will not be described here.

[0408] Optionally, the fifth network element can obtain the identifier of the first network element from the security storage network element or the third network element. Illustratively, the identifier of the first network element is stored in the security storage network element by a master node of the consensus group in which the third network element is located, so that the fifth network element can obtain the identifier of the first network element from the security storage network element. The master node used to store the identifier of the first network element and the master node used to determine the first metric result can be the same or different.

[0409] Specifically, in the consensus group in which the third network element and the fifth network element are located, the master node can be selected multiple times. For example, when storing the identifier of the first network element, the master node can be selected once according to the consensus mechanism, so that the master node can store the identifier of the first network element in the security storage network element; when determining the first metric result, the master node can also be selected once according to the consensus mechanism, so that the master node can determine the first metric result. The master node selected each time can be the same or different.

[0410] The implementation of the master node determining the identifier of the first network element and storing it in the security storage network element in the same consensus group is introduced below. Illustratively, a consensus group including a verification entity A and a verification entity B is taken as an example for introduction. Specifically, as shown in FIG. 13, the verification entity A and the verification entity B can store the identifier of the first network element in the security storage network element through the following steps S1301-S1303.

[0411] S1301, the verification entity A and the verification entity B establish a consensus group. The multiple verification entities located in the same consensus group can share the information stored in the security storage network element.

[0412] Optionally, step S1301 is an optional step, that is, when the consensus group has been established between the verification entity A and the verification entity B, step S1301 can be omitted.

[0413] Optionally, in this application, the multiple verification entities include the third network element and the fifth network element, at this time, the third network element and the fifth network element can execute step S1301 when the letter of credit verification is passed. The third network element can be the verification entity A, and correspondingly, the fifth network element can be the verification entity B; or the third network element can be the verification entity B, and correspondingly, the fifth network element can be the verification entity A.

[0414] S1302, the verification entity A and the verification entity B determine the master node according to the consensus mechanism.

[0415] Illustratively, each of the verification entity A and the verification entity B will calculate a consensus credential according to the consensus mechanism, assuming that the verification entity A obtains the consensus credential according to the consensus mechanism first, then the verification entity A is the master node. For convenience of description, the verification entity A is taken as the master node as an example for introduction below, and the same is uniformly described here, and will not be described again.

[0416] Optionally, in the present application, the plurality of verification entities include the third network element and the fifth network element, at this time, if the third network element is the verification entity A and the fifth network element is the verification entity B; the master node is the third network element. If the third network element is the verification entity B, and correspondingly, the fifth network element is the verification entity A; the master node is the fifth network element.

[0417] S1303, the verification entity A stores the identifier of the first network element in the secure storage network element.

[0418] Optionally, when the master node is the third network element (i.e., the third network element is the verification entity A), since the third network element can receive the second request information, the third network element can determine the identifier of the first network element according to the second request information and store it in the secure storage network element. When the master node is the fifth network element (i.e., the fifth network element is the verification entity A), since the fifth network element does not receive the second request information, the third network element can inform the fifth network element of the second request information after determining that it is not the master node, so that the fifth network element can determine the identifier of the first network element according to the second request information and store it in the secure storage network element.

[0419] For example, when the master node is the fifth network element (i.e., the fifth network element is the verification entity A), the third network element can send first indication information to the fifth network element after determining that it is not the master node, the first indication information being used to indicate the second request information, so that the fifth network element can obtain the second request information and further determine the identifier of the first network element according to the second request information.

[0420] For example, when the master node is the fifth network element (i.e., the fifth network element is the verification entity A), the third network element can send first indication information to the fifth network element after determining that it is not the master node, the first indication information being used to indicate the second request information, so that the fifth network element can obtain the second request information and further determine the identifier of the first network element according to the second request information.

[0421] Optionally, the verification entity A can determine the first record according to the second request information; and further store the first record in the secure storage network element. The first record is a record of the trusted state of the target network element requested by the first network element.

[0422] For example, when the first network element is the PACF, the second information of the target network element is the vendor ID, and the identifier of the target network element is the target ID, if the first record includes the identifier of the first network element, the second information of the target network element, and the identifier of the target network element, the first record can include: PACF ID, vendor ID, and target ID.

[0423] For example, when the first network element is the PACF, the second information of the target network element is the vendor ID, and the identifier of the target network element is the target ID, if the first record includes the identifier of the first network element, the second information of the target network element, and the identifier of the target network element, the first record can include: PACF ID, vendor ID, and target ID.

[0424] Optionally, after the verification entity A determines the first record, the verification entity A can send the first record to other verification entities (e.g., verification entity B) in the plurality of verification entities, for the other verification entities to verify whether the first record is valid. When the first record is valid, the first record can be stored in the secure storage network element.

[0425] For example, when the number of other verification entities in the consensus group in which the verification entity A is located is greater than 1 (i.e., the consensus group includes more than or equal to 3 verification entities), the verification entity A can send the first record to each of the other verification entities, respectively; so that each of the other verification entities can verify whether the first record is from the verification entity A after receiving the first record, and if so, it means that the verification entity considers the first record to be valid, and thus the verification entity can broadcast its signature to the other verification entities except for the verification entity. When there is a verification entity that receives Y signatures, the first record can be considered valid. Wherein Y is greater than the second threshold value, and Y is a positive integer.

[0426] For example, the verification entity A can configure a unique number for the first record, and form a pre-prepare message with the first record and the configured number, and broadcast it to the other verification entities. After any of the other verification entities (e.g., verification entity B) receives the pre-prepare message, it can query whether the pre-prepare message is from the verification entity A by relying on the signature field, and if so, it can form a prepare message with the number of the first record and its signature, and broadcast it to the other verification entities except for the verification entity. In this way, when the number of prepare messages is greater than the second threshold value, it can be considered that most of the verification entities agree with the first record, i.e., the first record can be considered valid.

[0427] Optionally, when the verification entity A also sends the consensus credential determined by the verification entity A to other verification entities (e.g., verification entity B) in the plurality of verification entities except for the verification entity A, the other verification entity can compare whether the consensus credential determined by the other verification entity is the same as the consensus credential determined by the verification entity A. When the consensus credential determined by the other verification entity is the same as the consensus credential determined by the verification entity A, and the number of prepare messages is greater than the second threshold value, the first record can be considered valid; when the consensus credential determined by the other verification entity is not the same as the consensus credential determined by the verification entity A, and / or the number of prepare messages is less than or equal to the second threshold value, the first record can be considered invalid.

[0428] For example, when the consensus group includes 10 verifying entities, the second threshold value can be any one of 6, 7, 8, 9, and 10.

[0429] As described above, in this example, when the master node is the fifth network element, and the fifth network element does not receive the second request information from the first network element, the fifth network element can obtain the identity of the first network element from the network element (i.e., the third network element) that receives the second request information from the first network element. For example, after receiving the second request information, the third network element can inform other verifying entities in the consensus group of the second request information (e.g., send indication information #1 to other verifying entities, where the indication information #1 is used to indicate the second request information); or, after receiving the second request information and determining that it is not the master node, the third network element can inform the master node (e.g., the fifth network element) in the consensus group of the second request information (e.g., send first indication information to the fifth network element, where the first indication information is used to indicate the second request information). So that the fifth network element learns the identity of the first network element from the second request information, and further sends the first measurement result to the first network element.

[0430] Alternatively, the fifth network element can obtain the identity of the first network element from the secure storage network element. Specifically, the identity of the first network element can be stored in the secure storage network element based on the implementation of FIG. 13 described above. At this time, the fifth network element can be verifying entity B in FIG. 13 described above, and correspondingly, the third network element is verifying entity A in FIG. 13 described above. So that the fifth network element learns the identity of the first network element, and further sends the first measurement result to the first network element.

[0431] Case two, the first network element receives the trusted state determined by the plurality of verifying entities respectively, and further determines the first measurement result according to the plurality of trusted states.

[0432] For example, the plurality of verifying entities include verifying entity #1 to verifying entity #X, where verifying entity #1 determines the first trusted state, verifying entity #2 determines the second trusted state, and so on, verifying entity #X determines the Xth trusted state, etc.; and verifying entity #1 sends the first trusted state to the first network element, verifying entity #2 sends the second trusted state to the first network element,..., and verifying entity #X sends the Xth trusted state to the first network element, so that the first network element obtains X trusted states (i.e., the first trusted state to the Xth trusted state); further, the first network element can compare the X trusted states, and determine the majority of the same trusted state in the X trusted states as the first measurement result. Further, the first network element can warn the verifying entity corresponding to the minority of the same trusted state.

[0433] Based on the possible implementation, the first measurement result can be determined by multiple verification entities, avoiding single-point attack / failure, causing the first measurement result determined by a single verification entity to be untrusted, thereby improving the trustworthiness of the first measurement result.

[0434] Scenario two, the first measurement result exists in the secure storage network element.

[0435] For example, after the verification entity (such as the third network element and / or the fifth network element) determines the first measurement result, it can be stored in the secure storage network element. Specifically, the implementation of the verification entity determining the first measurement result can refer to the related description of scenario one above and will not be repeated here.

[0436] As a possible implementation, when the third network element is the master node, that is, the first network element sends the second request information to the master node, after the third network element receives the second request information, it can directly obtain the first measurement result from the secure storage network element and inform the first network element.

[0437] As another possible implementation, when the third network element is not the master node, that is, the first network element sends the second request information to other network elements (such as the third network element) in addition to the master node among the multiple verification entities, the master node (i.e., the fifth network element) can obtain the identifier of the first network element from the secure storage network element or the third network element, so that after determining the first measurement result, it can inform the first network element according to the identifier of the first network element. For example, the implementation of the fifth network element obtaining the identifier of the first network element can refer to the related description of scenario one above and will not be repeated here.

[0438] It should be noted that in the above embodiments, two verification entities (i.e., the third network element and the fifth network element) are taken as an example for description, and when the multiple verification entities include more than two verification entities, the implementation of other verification entities in addition to the master node can refer to the related description of verification entity #2 and / or verification entity B above, and will not be repeated here.

[0439] Based on scenario two, when the first measurement result exists in the secure storage network element, the verification entity can directly determine the first measurement result from the secure storage network element, improving the efficiency of the verification entity determining the first measurement result, and saving resources.

[0440] It can be understood that, in the above various embodiments, the method and / or steps implemented by the first network element can also be implemented by components (such as a processor, a chip, a chip system, a circuit, a logic module, or software) available to the first network element; the method and / or steps implemented by the third network element can also be implemented by components (such as a processor, a chip, a chip system, a circuit, a logic module, or software) available to the third network element; and the method and / or steps implemented by the fifth network element can also be implemented by components (such as a processor, a chip, a chip system, a circuit, a logic module, or software) available to the fifth network element. The chip system can be composed of a chip, or the chip system can include a chip and other discrete devices.

[0441] It can be understood that, in order to implement the above functions, the communication device includes a hardware structure and / or software module corresponding to the implementation of each function. Those skilled in the art should easily realize that, in combination with the units and algorithm steps of the examples described in the embodiments disclosed herein, the present application can be realized in the form of hardware or a combination of hardware and computer software. Whether a certain function is driven by hardware or computer software to drive hardware depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods for each specific application to implement the described functions, but such implementation should not be considered beyond the scope of the present application.

[0442] The embodiments of the present application can divide the functional modules of the communication device according to the method embodiments described above. For example, each functional module can be divided according to each function, or two or more functions can be integrated into one processing module. The integrated module can be realized in the form of hardware or software function module. It should be noted that the division of modules in the embodiments of the present application is illustrative, and is only a logical functional division. Actual implementation can have another division manner.

[0443] The communication device of FIG. 14 shows a structural schematic diagram of a communication device 1400. The communication device 1400 includes a processing module 1401 and a transceiver module 1402. The communication device 1400 can be used to implement the functions of any of the above-mentioned first network element, or third network element, or fifth network element.

[0444] In some embodiments, the communication device 1400 can further include a storage module (not shown in FIG. 14) for storing program instructions and data.

[0445] In some embodiments, the transceiver module 1402, also known as a transceiver unit, is used to implement the sending and / or receiving functions. The transceiver module 1402 can be composed of a transceiver circuit, a transceiver, a transceiver, or a communication interface.

[0446] In some embodiments, the transceiver module 1402 can include a receiving module and a transmitting module for performing the receiving and transmitting steps, respectively, of the steps of the above-described method embodiments performed by any of the above-described first network element, or third network element, or fifth network element, and / or for otherwise supporting the herein-described techniques; and the processing module 1401 can be for performing the processing steps (e.g., determining, etc.) of the steps of the above-described method embodiments performed by any of the above-described first network element, or third network element, or fifth network element, and / or for otherwise supporting the herein-described techniques.

[0447] When the communication apparatus 1400 is configured to implement the functions of the above-described first network element:

[0448] In some embodiments, the transceiver module 1402 is configured to receive first request information, the first request information being used to request a trust status of a target network element; the processing module 1401 is configured to determine a letter of trust according to the first request information, the letter of trust being used to indicate that the first network element has the permission to query the trust status of the target network element; and the transceiver module 1402 is further configured to send second request information, the second request information being used to request the trust status of the target network element, and the second request information being further used to indicate the letter of trust.

[0449] Optionally, the first request information is further used to indicate first information of the target network element; and the processing module 1401 is further configured to determine the letter of trust according to the first information of the target network element, the first information of the target network element being information related to the target network element.

[0450] Optionally, the transceiver module 1402 is further configured to determine authentication information corresponding to second information of the target network element according to the second information of the target network element and preconfigured information, the second information of the target network element being determined according to the first information of the target network element, the preconfigured information including a correspondence between second information of a plurality of network elements and a plurality of authentication information, and the letter of trust including the authentication information corresponding to the second information of the target network element.

[0451] Optionally, the second information of the target network element includes a first identifier or a second identifier, the first identifier being an identifier of a vendor to which the target network element belongs, and the second identifier being an identifier of a network function type of the target network element.

[0452] Optionally, the second request information is further used to indicate the second information of the target network element.

[0453] Optionally, the letter of trust is used to indicate that the first network element has the permission to query the trust status of the target network element, including that the letter of trust is used to grant the first network element the permission to obtain the trust status of the target network element; further, the transceiver module 1402 is further configured to send third request information, the third request information being used to request the letter of trust, the third request information being further used to indicate the first information of the target network element; and receive the letter of trust.

[0454] Optionally, the processing module 1401 is further configured to determine whether the credential exists according to the first information of the target network element; and the transceiver module 1402 is further configured to send third request information when the credential does not exist.

[0455] Optionally, the third request information is used to indicate the identity of the first network element and / or the first information of the target network element, and the identity of the first network element and the first information of the target network element are used to determine the credential.

[0456] Optionally, the processing module 1401 is further configured to determine whether the credential exists according to the first information of the target network element; and the transceiver module 1402 is further configured to send second request information when the credential exists.

[0457] Optionally, the processing module 1401 is further configured to obtain a first measurement result according to the second request information, the first measurement result being used to indicate the trusted state of the target network element; and the transceiver module 1402 is further configured to send first response information, the first response information being used to indicate the first measurement result.

[0458] Optionally, the transceiver module 1402 is further configured to receive second response information, the second response information being used to indicate the first measurement result, the second response information being in response to the second request information.

[0459] Optionally, the first measurement result is stored in a secure storage network element in response to the second request information; the credential is further used to indicate that the first network element has the permission to query the secure storage network element; and further, the processing module 1401 is further configured to determine the first measurement result from the secure storage network element.

[0460] Optionally, the secure storage network element is used for multiple network elements to share the information stored therein, and the multiple network elements include the first network element.

[0461] When the communication apparatus 1400 is configured to implement the functions of the third network element described above:

[0462] In some embodiments, the transceiver module 1402 is configured to receive second request information from the first network element, the second request information being used to request the trusted state of the target network element, the second request information being further used to indicate the credential, and the credential being used to indicate that the first network element has the permission to query the trusted state of the target network element; the processing module 1401 is configured to verify the credential; and further, when the credential is verified, the processing module 1401 is further configured to determine the first measurement result, the first measurement result being used to indicate the trusted state of the target network element.

[0463] Optionally, the processing module 1401 is further configured to establish a transport layer security (TLS) with the first network element.

[0464] Optionally, the credential includes authentication information corresponding to the second information of the target network element, the second information of the target network element being determined according to the first information of the target network element, and the first information of the target network element being information related to the target network element.

[0465] Optionally, the second information of the target network element includes a first identifier or a second identifier, the first identifier being an identifier of a vendor to which the target network element belongs, and the second identifier being an identifier of a network function type of the target network element.

[0466] Optionally, the second request information is further used to indicate the second information of the target network element.

[0467] Optionally, the processing module 1401 is further configured to determine a first record, the first record being a record of the first network element requesting a trusted state of the target network element, and write the first record into the secure storage network element.

[0468] Optionally, the processing module 1401 is further configured to establish a consensus group, the consensus group including a plurality of verification entities, the verification entities being used to determine the trusted state of the target network element, and determine a master node from the plurality of verification entities, the master node being one network element in the plurality of verification entities, and the master node being used to determine the first record.

[0469] Optionally, the processing module 1401 is further configured to determine whether the first measurement result is stored in the secure storage network element, and when the first measurement result is stored in the secure storage network element, determine the first measurement result from the secure storage network element.

[0470] Optionally, the processing module 1401 is further configured to receive evidence of the target network element, the evidence of the target network element being used to determine the trusted state of the target network element, and the transceiver module 1402 is further configured to determine a first trusted state according to the evidence of the target network element, the first trusted state being the trusted state of the target network element determined by the third network element, and the first measurement result indicating the first trusted state.

[0471] Optionally, the processing module 1401 is further configured to write the first measurement result into the secure storage network element.

[0472] Optionally, the secure storage network element is used for a plurality of network elements to share information stored therein, and the plurality of network elements include the first network element and the third network element.

[0473] Optionally, the transceiver module 1402 is further configured to send the first trusted state.

[0474] Optionally, the transceiver module 1402 is further configured to send the first measurement result.

[0475] Optionally, the processing module 1401 is further configured to determine a second measurement result, the second measurement result being used to indicate a trusted state of the first network element; and further configured to determine the first measurement result when the second measurement result indicates that the first network element is trusted.

[0476] When the communication apparatus 1400 is configured to implement the function of the fifth network element described above, the processing module 1401 is further configured to:

[0477] In some embodiments, the processing module 1401 is configured to determine a first measurement result, the first measurement result being used to indicate a trusted state of a target network element; and further configured to obtain an identifier of the first network element from a secure storage network element or a third network element, the third network element being located in the same consensus group as the fifth network element; and the transceiver module 1402 is configured to send the first measurement result to the first network element according to the identifier of the first network element.

[0478] Optionally, the processing module 1401 is further configured to query a first record from the secure storage network element, the first record being a record of a request of the trusted state of the target network element by the first network element, and the first record including the identifier of the first network element.

[0479] Optionally, the transceiver module 1402 is configured to receive first indication information from the third network element, the first indication information being used to indicate second request information, the second request information being the request information of the request of the trusted state of the target network element by the first network element.

[0480] Optionally, the processing module 1401 is further configured to determine whether the first measurement result is stored in the secure storage network element; and further configured to determine the first measurement result from the secure storage network element when the first measurement result is stored in the secure storage network element.

[0481] Optionally, the transceiver module 1402 is further configured to receive evidence of the target network element, the evidence of the target network element being used to determine a trusted state of the target network element; and the processing module 1401 is further configured to determine a second trusted state according to the evidence of the target network element, the second trusted state being the trusted state of the target network element determined by the third network element, and the first measurement result indicating the second trusted state.

[0482] Optionally, the transceiver module 1402 is further configured to send the second trusted state; and the first measurement result indicates a first trusted state or the second trusted state when the second trusted state is valid, the first trusted state being the same as the second trusted state.

[0483] Optionally, the processing module 1401 is further configured to write the second trusted state into the secure storage network element.

[0484] Optionally, the secure storage network element is configured to share information stored therein by multiple network elements, the multiple network elements including the first network element and the fifth network element.

[0485] All the related content of each step involved in the above method embodiments can be cited to the function description of the corresponding function module, which will not be repeated here.

[0486] In the present application, the communication apparatus 1400 can be presented in the form of integrated division of each function module. The "module" here can refer to a specific application-specific integrated circuit (ASIC), a circuit, a processor and a memory executing one or more software or firmware programs, an integrated logic circuit, and / or other devices that can provide the above functions.

[0487] In some embodiments, when the communication apparatus 1400 in FIG. 14 is a chip or a chip system, the function / implementation process of the transceiver module 1402 can be implemented through the input / output interface (or communication interface) of the chip or chip system, and the function / implementation process of the processing module 1401 can be implemented through the processor (or processing circuit) of the chip or chip system.

[0488] Since the communication apparatus 1400 provided by the present embodiment can execute the above method, the technical effects it can obtain can be referred to the above method embodiments, which will not be repeated here.

[0489] As a possible product form, any of the first network element, or the third network element, or the fifth network element described in the embodiments of the present application can also be implemented using one or more field programmable gate arrays (FPGAs), programmable logic devices (PLDs), controllers, state machines, gate logic, discrete hardware components, any other suitable circuit, or any combination of circuits capable of performing the various functions described throughout this application.

[0490] As another possible product form, any of the first network element, or the third network element, or the fifth network element described in the embodiments of the present application can be implemented by a general bus architecture. For ease of illustration, refer to FIG. 15, which is a structural schematic diagram of a communication apparatus 1500 provided by the embodiments of the present application, the communication apparatus 1500 including a processor 1501 and a communication interface 1502. The communication apparatus 1500 can be the first network element, or a chip or chip system therein; or the communication apparatus 1500 can be the third network element, or a chip or module therein; or the communication apparatus 1500 can be the fifth network element, or a chip or module therein. FIG. 15 only shows the main components of the communication apparatus 1500. In addition to the processor 1501 and the communication interface 1502, the communication apparatus can further include a memory 1503, and an input / output device (not shown in the figure).

[0491] Optionally, the processor 1501 is mainly used for processing communication protocols and communication data, and controlling the whole communication apparatus, executing software programs, and processing data of the software programs. The memory 1503 is mainly used for storing software programs and data. Optionally, the communication interface 1502 can include radio frequency circuitry and an antenna, the radio frequency circuitry being mainly used for conversion between baseband signals and radio frequency signals and processing of the radio frequency signals. The antenna is mainly used for transceiving radio frequency signals in the form of electromagnetic waves. Optionally, the communication interface 1502 can also be a transceiver, an input / output circuit, a chip pin, etc. The input / output device, such as a touch screen, a display screen, a keyboard, etc., is mainly used for receiving user input data and outputting data to the user.

[0492] Optionally, the processor 1501, the communication interface 1502, and the memory 1503 can be connected through a communication bus.

[0493] In a possible implementation, after the communication apparatus is powered on, the processor can read software programs in the memory, interpret and execute instructions of the software programs, and process data of the software programs. When data needs to be transmitted wirelessly, the processor 1501 performs baseband processing on the data to be transmitted, and outputs the baseband signal to the radio frequency circuitry, which converts the baseband signal into a radio frequency signal, and transmits the radio frequency signal in the form of electromagnetic waves through the antenna. When data is transmitted to the communication apparatus, the radio frequency circuitry receives the radio frequency signal through the antenna, converts the radio frequency signal into a baseband signal, and outputs the baseband signal to the processor 1501, which converts the baseband signal into data and processes the data.

[0494] For example, the measurement entity can send a signal through the antenna. The measurement entity can send evidence of the target network element to the verification entity through the antenna. In another implementation, the radio frequency circuit and the antenna can be arranged independently of the processor that performs baseband processing, for example, in a distributed scenario, the radio frequency circuit and the antenna can be arranged in a remote manner from the communication device.

[0495] In some embodiments, the communication device 1400 described above can take the form of the communication device 1500 shown in FIG. 15, which can be implemented in hardware.

[0496] As an example, the functions / implementation processes of the processing module 1401 in FIG. 14 can be implemented by the processor 1501 in the communication device 1500 shown in FIG. 15 invoking computer-executable instructions stored in the memory 1503. The functions / implementation processes of the transceiver module 1402 in FIG. 14 can be implemented by the communication interface 1502 in the communication device 1500 shown in FIG. 15.

[0497] As another possible product form, any of the first network element, or the third network element, or the fifth network element in the present application can take the constituent structure shown in FIG. 16, or include the components shown in FIG. 16. FIG. 16 is a constituent diagram of a communication device 1600 provided in the present application. The communication device 1600 can be a terminal device or a chip or system on chip in the terminal device; or can be a module or a chip or system on chip in any of the first network element, or the third network element, or the fifth network element.

[0498] As shown in FIG. 16, the communication device 1600 includes at least one processor 1601, and at least one communication interface (only one communication interface 1604 is shown in FIG. 16 as an example, and the processor 1601 is taken as an example for description). Optionally, the communication device 1600 can further include a communication bus 1602 and a memory 1603.

[0499] The communication bus 1602 is used to connect different components in the communication device 1600, so that different components can communicate. The communication bus 1602 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, only one thick line is shown in FIG. 16, but it does not mean that there is only one bus or only one type of bus.

[0500] The communication interface 1604 is configured to communicate with other devices or communication networks. For example, the communication interface 1604 can be a module, a circuit, a transceiver, or any device capable of implementing communication. Alternatively, the communication interface 1604 can also be an input / output interface in the processor 1601, configured to implement signal input and signal output of the processor.

[0501] The memory 1603 can be a device with a storage function, configured to store instructions and / or data. The instructions can be a computer program.

[0502] It should be noted that the memory 1603 can exist independently of the processor 1601, or can be integrated with the processor 1601. The memory 1603 can be located in the communication device 1600, or can be located outside the communication device 1600, without limitation. The processor 1601 can be configured to execute the instructions stored in the memory 1603, to implement the methods provided in the embodiments described below.

[0503] As an optional implementation manner, the communication device 1600 can further include an output device 1605 and an input device 1606. The output device 1605 communicates with the processor 1601, and can display information in various manners. For example, the output device 1605 can be a liquid crystal display (LCD), a light emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector, etc. The input device 1606 communicates with the processor 1601, and can receive user input in various manners. For example, the input device 1606 can be a mouse, a keyboard, a touch screen device, a sensor device, etc.

[0504] As an optional implementation manner, the communication device 1600 includes multiple processors, for example, in addition to the processor 1601 in FIG. 16, the communication device 1600 can further include a processor 1607.

[0505] In some embodiments, in a hardware implementation, those skilled in the art can conceive that the communication device 1400 shown in FIG. 14 can adopt the form of the communication device 1600 shown in FIG. 16.

[0506] As an example, the functions / implementation processes of the processing module 1401 in FIG. 14 can be implemented by the processor 1601 in the communication device 1600 in FIG. 16 invoking computer execution instructions stored in the memory 1603. The functions / implementation processes of the transceiver module 1402 in FIG. 14 can be implemented by the communication interface 1604 in the communication device 1600 in FIG. 16.

[0507] It should be noted that the structure shown in FIG. 16 does not constitute a specific limitation on any of the first network element, or the third network element, or the fifth network element. For example, in some other embodiments of the present application, any of the first network element, or the third network element, or the fifth network element can include more or fewer components than shown, or combine some components, or split some components, or different arrangement of components. The components shown can be implemented in hardware, software, or a combination of software and hardware.

[0508] In some embodiments, the embodiments of the present application also provide a communication device, which includes a processor for implementing the method in any of the method embodiments described above.

[0509] For example, the processor can be one or more central processing units (CPUs), general processors, network processors (NPs), microprocessor units (MPUs), digital signal processors (DSPs), microcontrollers (MCUs), application-specific integrated circuits (ASICs), field programmable gate arrays, artificial intelligence processors (AI processors), or neural processing units (NPUs), or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, which can implement or execute the methods, steps and logic block diagrams disclosed in the embodiments of the present application. The processor can also be other devices with processing functions, such as circuits, devices or software modules, without limitation.

[0510] Specifically, in the case of the processor being a CPU, the CPU can be a single-core CPU or a multi-core CPU. The general processor can be a microprocessor or any conventional processor, etc.

[0511] The steps of the method disclosed in the embodiments of the present application can be directly embodied as hardware processor execution, or executed by a combination of hardware and software modules in the processor.

[0512] As a possible implementation, the communication apparatus further includes a memory. The memory is configured to store necessary computer programs and data. The computer programs can include instructions, and the processor can invoke the instructions in the computer programs stored in the memory to instruct the communication apparatus to perform the method in any of the above method embodiments. Of course, the memory can also not be in the communication apparatus.

[0513] For example, the memory can be a read-only memory (ROM) or other type of static storage device that can store static information and / or instructions, a cache, a synchronous dynamic random access memory (SDRAM), a hard disk drive (HDD), or a solid-state drive (SSD), a random access memory (RAM) or other type of dynamic storage device that can store information and / or instructions, an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM), or other optical disk storage, a magneto-optical disk, a RAM, a magnetic tape, or other magnetic storage device, etc., without limitation.

[0514] The memory can be any other medium that can be used to carry or store desired program codes in the form of instructions or data structures and that can be accessed by a computer, but is not limited thereto. The memory in the embodiments of the present application can also be a circuit or any other device capable of realizing a storage function, configured to store computer programs or instructions and / or data.

[0515] As another possible implementation, the communication apparatus further includes an interface circuit, which is a code / data read-write interface circuit, configured to receive computer execution instructions (the computer execution instructions are stored in the memory, which can be directly read from the memory or can pass through other devices) and transmit to the processor.

[0516] As yet another possible implementation, the communication apparatus further includes a communication interface, configured to communicate with modules outside the communication apparatus.

[0517] It can be understood that the communication apparatus can be a chip or a chip system, for example, a modem chip, also known as a baseband chip, or a system on chip (SoC) chip or a system in package (SIP) chip containing a modem core. When the communication apparatus is a chip system, the chip system can be composed of a chip or can contain a chip and other discrete devices, and embodiments of the present application do not make a specific limitation in this regard.

[0518] The present application also provides a computer readable storage medium, which stores a computer program or instructions, and the computer program or instructions realize the functions of any of the method embodiments described above when executed by a computer.

[0519] The present application also provides a computer program product, which realizes the functions of any of the method embodiments described above when executed by a computer.

[0520] Those skilled in the art can understand that, for the convenience and brevity of description, the specific working processes of the systems, apparatuses and units described above can refer to the corresponding processes in the foregoing method embodiments, which will not be described here.

[0521] It can be understood that the systems, apparatuses and methods described in the present application can also be implemented in other ways. For example, the apparatus embodiments described above are only schematic, for example, the division of the units is only a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interface, device or unit, and can be electrical, mechanical or other forms.

[0522] The units described as separate components can or can not be physically separate, that is, can be located in one place, or can be distributed on a plurality of network units. The components shown as units can or can not be physical units. Part or all of the units can be selected according to actual needs to achieve the purpose of the present embodiment.

[0523] In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit.

[0524] In the embodiments described above, all or some of the embodiments can be implemented by software, hardware, firmware or any combination thereof. When implemented by software, all or some of the embodiments can be implemented in the form of one or more computer programs that run on a computer. The computer program can be written in any suitable programming language and can be stored in any suitable computer readable medium. The computer readable medium can be stored on a computer that is accessible to the computer program, or can be transferred to the computer from one computer readable medium to another computer readable medium. The computer readable medium can be any suitable medium that can be accessed by a computer. The medium can be a magnetic, optical, semiconductor or other types of storage device. The medium can be fixed or removable. The medium can be a carrier wave or other communication medium. The computer program can be distributed over the Internet or over a number of networks, or can be stored on a distribution medium that is to be distributed, for example, on a compact diskette, DVD, USB flash drive, etc. to name but a few. The computer program can be loaded into a computer that is accessible to the computer program, or can be loaded into a computer from another computer readable medium, to name but a few. The computer can be a general purpose computer, a special purpose computer, a computer network, or other programmable apparatus that can be used to implement the functions described in the embodiments described above.

[0525] Although the present application has been described in connection with the various embodiments thereof, those skilled in the art will understand that the disclosed embodiments can be modified in various ways and that such modifications are intended to be within the scope of the present application. In the claims, the term comprising does not exclude the presence of other elements or additional steps. One or more processing units can carry out one or more functions for each claim. The word 'couple' or 'coupled' does not exclude the presence of intermediate elements between the objects and / or additional steps. Reference to claim elements in the singular, plural, ceil or claim, does not mean they are necessarily claimed as single provisions, and each element can be claimed independently. Reference to claim elements in the alternative (e.g., 'one or the other of the elements or claim) indicates alternative embodiments (e.g., examples that include only the elements in the alternative position or claim).

Claims

1. A communication method, characterized in that, The method is applicable to the first network element, and the method includes: Receive first request information, which is used to request the measurement of the trusted status of the target network element; Based on the first request information, a letter of trust is determined, wherein the letter of trust is used to indicate that the first network element has the authority to query the trusted status of the target network element; Send a second request message, which is used to request the trusted status of the target network element and also to indicate the trust status.

2. The method according to claim 1, characterized in that, The first request information is also used to indicate the first information of the target network element; The step of determining the trust status based on the first request information includes: The trust status is determined based on the first information of the target network element, wherein the first information of the target network element is information related to the target network element.

3. The method according to claim 2, characterized in that, Determining the trust status based on the first information of the target network element includes: Based on the second information of the target network element and the pre-configuration information, the authentication information corresponding to the second information of the target network element is determined; the second information of the target network element is determined based on the first information of the target network element; the pre-configuration information includes the correspondence between the second information of multiple network elements and multiple authentication information; and the trust certificate includes the authentication information corresponding to the second information of the target network element.

4. The method according to claim 3, characterized in that, The second information of the target network element includes a first identifier or a second identifier, wherein the first identifier is the identifier of the supplier to which the target network element belongs, and the second identifier is the identifier of the network function type of the target network element.

5. The method according to claim 3 or 4, characterized in that, The second request information is also used to indicate second information about the target network element.

6. The method according to claim 2, characterized in that, The trust certificate is used to indicate that the first network element has the authority to query the trust status of the target network element, including: The trust certificate is used to grant the first network element the authority to obtain the trusted status of the target network element. The step of determining the trust status based on the first information of the target network element includes: Send a third request message, the third request message being used to request the letter of trust, and the third request message also being used to indicate the first information of the target network element; Receive the letter of trust.

7. The method according to claim 6, characterized in that, Before sending the third request information, the method further includes: Based on the first information of the target network element, determine whether the trust status exists; The sending of the third request information includes: If the trust certificate does not exist, send the third request information.

8. The method according to claim 6 or 7, characterized in that, The third request information is used to indicate the identifier of the first network element and / or the first information of the target network element, and the identifier of the first network element and the first information of the target network element are used to determine the trust status.

9. The method according to claim 2, characterized in that, The sending of the second request information includes: Based on the first information of the target network element, determine whether the trust status exists; When the trust certificate exists, the second request information is sent.

10. The method according to any one of claims 1-9, characterized in that, The method further includes: Based on the second request information, a first measurement result is obtained, which is used to indicate the trusted status of the target network element; Send a first response message, which is used to indicate the first measurement result.

11. The method according to claim 10, characterized in that, The step of obtaining the first measurement result based on the second request information includes: When the trust certificate verification is successful, a second response information is received. The second response information is used to indicate the first measurement result and is in response to the second request information.

12. The method according to claim 10, characterized in that, The first measurement result is in response to the second request information stored in the secure storage network element; and the trust certificate is also used to indicate that the first network element has the authority to query the secure storage network element; Obtaining the first measurement result includes: The first metric result is determined from the secure storage network element.

13. A communication method, characterized in that, The method is applicable to third network elements, and the method includes: The system receives a second request from a first network element. The second request is used to request the trusted status of the target network element. The second request is also used to indicate a letter of trust, which indicates that the first network element has the authority to query the trusted status of the target network element. The letter of trust is verified; When the trust certificate verification is successful, a first metric result is determined, which is used to indicate the trust status of the target network element.

14. The method according to claim 13, characterized in that, Before receiving the second request information from the first network element, the method further includes: Establish a Transport Layer Security (TLS) protocol with the first network element.

15. The method according to claim 13 or 14, characterized in that, The trust certificate includes authentication information corresponding to the second information of the target network element. The second information of the target network element is determined based on the first information of the target network element, which is information related to the target network element.

16. The method according to claim 15, characterized in that, The second information of the target network element includes a first identifier or a second identifier, wherein the first identifier is the identifier of the supplier to which the target network element belongs, and the second identifier is the identifier of the network function type of the target network element.

17. The method according to claim 15 or 16, characterized in that, The second request information is also used to indicate second information about the target network element.

18. The method according to any one of claims 13-17, characterized in that, The method further includes: A first record is determined, which is a record of the first network element requesting the trusted status of the target network element; Write the first record into the secure storage network element.

19. The method according to claim 18, characterized in that, Before writing the first record to the secure storage network element, the method further includes: Establish a consensus group, which includes multiple verification entities, and the verification entities are used to determine the trusted status of the target network element; A master node is determined from the plurality of verification entities, wherein the master node is a network element among the plurality of verification entities, and the master node is used to determine the first record.

20. The method according to any one of claims 13-19, characterized in that, The method further includes: Send the first metric result.

21. The method according to claim 20, characterized in that, The method further includes: Determine a second measurement result, which is used to indicate the trust status of the first network element; The first metric result is determined, including: When the second metric result indicates that the first network element is trustworthy, the first metric result is determined.

22. A communication method, characterized in that, The method is applicable to the fifth network element, and the method includes: Determine a first measurement result, which is used to indicate the trust status of the target network element; Obtain the identifier of the first network element from the secure storage network element or the third network element; Based on the identifier of the first network element, the first measurement result is sent to the first network element; the third network element and the fifth network element are located in the same consensus group.

23. The method according to claim 22, characterized in that, Obtaining the identifier of the first network element from the secure storage network element includes: The first record is queried from the secure storage network element. The first record is a record in which the first network element requests the trusted status of the target network element. The first record includes the identifier of the first network element.

24. The method according to claim 22, characterized in that, Obtaining the identifier of the first network element from the third network element includes: The system receives a first indication message from the third network element, the first indication message being used to indicate a second request message, the second request message being a request message from the first network element requesting the trusted status of the target network element.

25. The method according to any one of claims 22-24, characterized in that, The step of determining the first measurement result includes: determining whether the first measurement result is stored in the secure storage network element; When the first measurement result is stored in the secure storage network element, the first measurement result is determined from the secure storage network element.

26. The method according to any one of claims 22-24, characterized in that, Determining the first measurement result includes: Receive evidence of the target network element, wherein the evidence of the target network element is evidence used to determine the trusted status of the target network element; The first metric result is determined based on the evidence from the target network element.

27. The method according to claim 26, characterized in that, The method further includes: Write the first metric result into the secure storage network element.

28. A communication device, characterized in that, The communication device includes a transceiver module and a processing module. The transceiver module is configured to perform the receiving or sending behavior in the method as described in any one of claims 1-12, or the transceiver module is configured to perform the receiving or sending behavior in the method as described in any one of claims 13-21, or the transceiver module is configured to perform the receiving or sending behavior in the method as described in any one of claims 22-27. The processing module is configured to perform the processing behavior in the method as described in any one of claims 1-12, or the transceiver module is configured to perform the processing behavior in the method as described in any one of claims 13-21, or the transceiver module is configured to perform the processing behavior in the method as described in any one of claims 22-27.

29. A computer-readable storage medium, characterized in that, A computer-readable storage medium stores computer instructions or programs that, when executed on a computer, cause the method as described in any one of claims 1-12 to be performed, or cause the method as described in any one of claims 13-21 to be performed, or cause the method as described in any one of claims 22-27 to be performed.

30. A computer program product containing instructions, characterized in that, When the computer program product is run on a communication device, it causes the communication device to perform the method of any one of claims 1-12, or causes the communication device to perform the method of any one of claims 13-21, or causes the communication device to perform the method of any one of claims 22-27.

Citation Information

Patent Citations

  • Remote attestation in network

    CN111869162A

  • Trusted capability acquisition method and device

    CN117997542A

  • Query method and apparatus, and device

    US20240143613A1