Wireless communication method and communication device

By using digital certificates for data plane access authentication and access control in communication systems, the problem of secure data plane access and control is solved, privacy and integrity are ensured during data transmission and processing, and the credibility of data management is improved.

WO2026030859A1PCT designated stage Publication Date: 2026-02-12GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/109890
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-08-05
Publication Date
2026-02-12

AI Technical Summary

Technical Problem

In communication systems, how can we achieve secure and reliable access and control of the data plane, especially during data collection, storage, and processing, to ensure data privacy and integrity?

Method used

By using digital certificates for data plane access authentication and access control, the security and trustworthiness of the data plane are ensured. Digital certificates are used to verify the identity of devices and control their access permissions.

Benefits of technology

It enables secure and trusted access and control of the data plane, ensuring the privacy and integrity of data during transmission and processing, and improving the reliability and security of data management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024109890_12022026_PF_FP_ABST
    Figure CN2024109890_12022026_PF_FP_ABST
Patent Text Reader

Abstract

Provided are a wireless communication method and a communication device. The wireless communication method comprises: a first device sends a first message to a second device, the first message being used for requesting access to a data plane, and the first message comprising a first digital certificate; and / or, the first device receives a second message sent by the second device, the second message being used for requesting the first device to participate in a service of the data plane, and the second message comprising a second digital certificate, wherein the second device is used for authenticating and / or controlling the first device to perform data plane access, and the first digital certificate and / or the second digital certificate are / is used for one or more of the following: data plane access authentication and data plane access control.
Need to check novelty before this filing date? Find Prior Art

Description

Method and communication device for wireless communication TECHNICAL FIELD

[0001] The present application relates to the field of communication technology, and more particularly, to a method and a communication device for wireless communication. BACKGROUND

[0002] In some scenarios, a communication system needs to support collection, storage, processing, etc. of a large amount of data, and efficiently and securely provide the data to internal functions of the network or external functions of the network for use. For this purpose, the related technology proposes that trusted data operations can be implemented based on a data plane. In this case, how to implement access and / or control of the data plane is a problem to be solved.

[0003] SUMMARY

[0004] The present application provides a method and a communication device for wireless communication. The various aspects involved in the present application are introduced below.

[0005] In a first aspect, a method for wireless communication is provided, comprising: a first device sending a first message to a second device, the first message being used to request access to a data plane, the first message comprising a first digital certificate; and / or, the first device receiving a second message sent by the second device, the second message being used to request the first device to participate in services of the data plane, the second message comprising a second digital certificate; wherein the second device is configured to authenticate and / or control the first device to access the data plane, and the first digital certificate and / or the second digital certificate are used for one or more of the following: access authentication of the data plane, access control of the data plane.

[0006] In a second aspect, a method for wireless communication is provided, comprising: a second device receiving a first message sent by a first device, the first message being used to request access to a data plane, the first message comprising a first digital certificate; and / or, the second device sending a second message to the first device, the second message being used to request the first device to participate in services of the data plane, the second message comprising a second digital certificate; wherein the second device is configured to authenticate and / or control the first device to access the data plane, and the first digital certificate and / or the second digital certificate are used for one or more of the following: access authentication of the data plane, access control of the data plane.

[0007] In a third aspect, a communication device is provided, the communication device being a first device, the communication device comprising: a sending module configured to send a first message to a second device, the first message being used to request access to a data plane, the first message comprising a first digital certificate; and / or a receiving module configured to receive a second message sent by the second device, the second message being used to request the first device to participate in a service of the data plane, the second message comprising a second digital certificate; wherein the second device is configured to authenticate and / or control the first device to access the data plane, and the first digital certificate and / or the second digital certificate is / are used for one or more of the following: access authentication of the data plane, access control of the data plane.

[0008] In a fourth aspect, a communication device is provided, the communication device being a second device, the communication device comprising: a receiving module configured to receive a first message sent by a first device, the first message being used to request access to a data plane, the first message comprising a first digital certificate; and / or a sending module configured to send a second message to the first device, the second message being used to request the first device to participate in a service of the data plane, the second message comprising a second digital certificate; wherein the second device is configured to authenticate and / or control the first device to access the data plane, and the first digital certificate and / or the second digital certificate is / are used for one or more of the following: access authentication of the data plane, access control of the data plane.

[0009] In a fifth aspect, a communication device is provided, comprising a processor, a memory, and a communication interface, the memory being configured to store one or more computer programs, and the processor being configured to invoke the computer program in the memory to cause the communication device to perform some or all of the steps in the method of the first aspect.

[0010] In a sixth aspect, a communication device is provided, comprising a processor, a memory, and a communication interface, the memory being configured to store one or more computer programs, and the processor being configured to invoke the computer program in the memory to cause the communication device to perform some or all of the steps in the method of the second aspect.

[0011] In a seventh aspect, a communication system is provided, comprising the communication device described above. In another possible design, the system can further comprise other devices interacting with the communication device in the solutions provided by the embodiments of the present application.

[0012] In an eighth aspect, a computer readable storage medium is provided, the computer readable storage medium storing a computer program, the computer program causing a computer to perform some or all of the steps in the methods of the aspects described above.

[0013] In a ninth aspect, an embodiment of the present application provides a computer program product, which includes a non-transitory computer-readable storage medium storing a computer program, the computer program being operable to cause a computer to execute some or all of the steps of the methods in the various aspects described above. In some implementations, the computer program product can be a software installation package.

[0014] In a tenth aspect, an embodiment of the present application provides a chip, which includes a memory and a processor. The processor can invoke and run a computer program from the memory to implement some or all of the steps described in the methods in the various aspects described above.

[0015] In an embodiment of the present application, the first device and the second device can perform access authentication and / or access control of the data plane based on the digital certificate (the first digital certificate and / or the second digital certificate), which is conducive to realizing secure and trusted data plane access. BRIEF DESCRIPTION OF DRAWINGS

[0016] FIG. 1 is an example diagram of a system architecture of a communication system to which embodiments of the present application are applicable.

[0017] FIG. 2 is an example diagram of an implementation of obtaining a certificate of a subscription user.

[0018] FIG. 3 is an example diagram of an implementation of obtaining a certificate authority (CA) certificate.

[0019] FIG. 4 is an example diagram of a communication system architecture including a data plane, provided by an embodiment of the present application.

[0020] FIG. 5 is an example diagram of a format of a digital certificate, provided by an embodiment of the present application.

[0021] FIG. 6 is a flow diagram of obtaining a digital certificate, provided by an embodiment of the present application.

[0022] FIG. 7 is a flow diagram of obtaining a digital certificate, provided by another embodiment of the present application.

[0023] FIG. 8 is a flow diagram of obtaining a digital certificate, provided by yet another embodiment of the present application.

[0024] FIG. 9 is a flow diagram of a method of wireless communication, provided by an embodiment of the present application.

[0025] FIG. 10 is a structural diagram of a communication device, provided by an embodiment of the present application.

[0026] FIG. 11 is a structural diagram of a communication device, provided by another embodiment of the present application.

[0027] FIG. 12 is a schematic structural diagram of a communication apparatus, provided by an embodiment of the present application. DETAILED DESCRIPTION

[0028] Communication System Architecture

[0029] FIG. 1 is an example diagram of a system architecture of a communication system 100 to which embodiments of the present application are applicable. The system architecture shown in FIG. 1 can include terminal devices, access network (AN) devices, and network elements in a core network.

[0030] It should be understood that the technical solutions of the embodiments of the present application can be applied to various communication systems, for example, a 5th generation (5G) system or new radio (NR), a long term evolution (LTE) system, an LTE frequency division duplex (FDD) system, an LTE time division duplex (TDD), and the like. The technical solutions provided in the present application can also be applied to future communication systems, such as a 6th generation mobile communication system, a satellite communication system, and the like.

[0031] The terminal device in the embodiments of the present application can also be referred to as a user equipment (UE), an access terminal, a user unit, a user station, a mobile station, a mobile station (MS), an MT, a remote station, a remote terminal, a mobile device, a user terminal, a terminal, a wireless terminal, a user agent or a user apparatus. The terminal device in the embodiments of the present application can refer to a device providing voice and / or data connectivity for a user, and can be used to connect people, things and machines, such as handheld devices with wireless connection function, vehicle-mounted devices, etc. The terminal device in the embodiments of the present application can be a mobile phone, a tablet computer (Pad), a notebook computer, a palm computer, a mobile internet device (MID), a wearable device, a virtual reality (VR) device, an augmented reality (AR) device, a wireless terminal in industrial control, a wireless terminal in self driving, a wireless terminal in remote medical surgery, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, etc. Optionally, the terminal device can be used to act as a base station. For example, the terminal device can act as a scheduling entity, which provides sidelink signals between terminal devices in vehicle-to-everything (V2X) or device to device (D2D), etc. For example, a cellular phone and a car communicate with each other using sidelink signals. The cellular phone and the smart home device communicate with each other without relaying the communication signals through the base station.

[0032] The access network device can be an access device through which a terminal device accesses the network architecture wirelessly, and is mainly responsible for radio resource management, quality of service (QoS) management, data compression and encryption, etc. on the air interface side. The access network device can also be referred to as a radio access network (RAN) device, for example, the access network device can be a base station. The base station can broadly cover various names in the following or replace the following names, such as: NodeB, evolved NodeB (eNB), next generation NodeB (gNB), relay station, transmitting and receiving point (TRP), transmitting point (TP), master eNB (MeNB), secondary eNB (SeNB), multi-standard radio (MSR) node, home base station, network controller, access node, wireless node, access point (AP), transmission node, transceiver node, baseband unit (BBU), remote radio unit (RRU), active antenna unit (AAU), remote radio head (RRH), central unit (CU), distributed unit (DU), positioning node, etc. The base station can be a macro base station, a micro base station, a relay node, a donor node, or the like, or a combination thereof. The base station can also refer to a communication module, modem, or chip used in the aforementioned device or apparatus. The base station can also be a mobile switching center and a device that performs the function of a base station in D2D, V2X, machine-to-machine (M2M) communication, a network side device in a 6G network, a device that performs the function of a base station in a future communication system, etc. The base station can support networks of the same or different access technologies. The embodiments of the present application do not limit the specific technology and specific device form adopted by the access network device.

[0033] The base station can be fixed or mobile. For example, a helicopter or a drone can be configured to act as a mobile base station, and one or more cells can move according to the location of the mobile base station. In other examples, the helicopter or the drone can be configured to act as a device that communicates with another base station.

[0034] In some deployments, the access network device in the embodiments of the present application can refer to a CU or a DU, or the access network device includes a CU and a DU. The gNB can also include an AAU.

[0035] The type of network element in the core network can include a user plane function (UPF) network element, an access and mobility management function (AMF) network element, a session management function (SMF) network element, a policy control function (PCF) network element, a data network (DN), a network slice selection function (NSSF), an authentication server function (AUSF), a unified data management (UDM), and a network exposure function (NEF). Among them, the UPF network element is mainly responsible for the transmission of user data, and other network elements can be referred to as control plane function network elements, which are mainly responsible for authentication, authorization, registration management, session management, mobility management, and policy control, etc. to ensure reliable and stable transmission of user data.

[0036] The UPF network element can be used to forward and receive data of the terminal device. For example, the UPF network element can receive service data from a data network and transmit it to the terminal device through the access network device; the UPF network element can also receive user data from the terminal device through the access network device and forward it to the data network. Among them, the transmission resources allocated and scheduled by the UPF network element for the terminal device are managed and controlled by the SMF network element. The bearer between the terminal device and the UPF network element can include a user plane connection between the UPF network element and the access network device, and a channel established between the access network device and the terminal device. Among them, the user plane connection is a QoS flow that can be established between the UPF network element and the access network device to transmit data.

[0037] The AMF network element can be used to manage the access of the terminal device to the core network, such as location update of the terminal device, registration network, access control, mobility management of the terminal device, attachment and detachment of the terminal device, etc. The AMF network element can also provide storage resources for the control plane of the session for the terminal device in the case of providing services for the session, to store the session identifier, the SMF network element identifier associated with the session identifier, etc.

[0038] The SMF network element can be used to select a user plane network element for a terminal device, redirect a user plane network element for a terminal device, allocate an internet protocol (IP) address for a terminal device, establish a bearer (also referred to as a session) between a terminal device and a UPF network element, modify, release and control QoS of the session.

[0039] The PCF network element is used to provide policies such as QoS policies, slice selection policies, etc. to the AMF network element and the SMF network element.

[0040] The DN can provide data services for users, such as IP multi-media service (IMS) networks, the Internet, etc. There can be various application servers (ASs) in the DN to provide different application services, such as operator services, Internet access or third-party services, etc. The AS can implement the function of an application function (AF). The AF network element is used to interact with the network elements in the 3GPP core network to support application-affected data routing, access network exposure functions, interact with the PCF network element for policy control, etc.

[0041] The AUSF is used to receive a request of the AMF for authentication of a terminal device, request a key from the UDM, and then forward the issued key to the AMF for authentication processing.

[0042] The UDM includes functions such as generation and storage of user subscription data, management of authentication data, and supports interaction with external third-party servers.

[0043] The NEF is used for capability exposure, that is, based on the NEF, the capabilities of the network can be output to external networks. External non-trusted applications can access internal data of the core network through the NEF to ensure the security of the network. The NEF can provide functions such as external application QoS capability exposure, event subscription, AF request distribution, etc.

[0044] In addition, some networks (for example, 5G networks) also add a network data analysis function (network data analytics function, NWDAF) in the core network. Based on the NWDAF, data can be collected from various network elements, network management systems, etc. in the core network, and big data statistics, analysis or intelligent data analysis can be performed to obtain analysis or prediction data on the network side, thereby assisting each network element to more effectively control the access of terminal devices according to the data analysis results.

[0045] In some communication systems (e.g., 5G systems, 6G systems, etc.), network elements in a core network can also be referred to as network functions (NFs).

[0046] In the system architecture shown in FIG. 1, one of the most important features is that these system architectures include a service-oriented architecture, i.e., a service provider (e.g., a network element in a core network) can provide specific services and provide other network elements (consumers) with defined API interfaces.

[0047] It should be noted that each network element in FIG. 1 can be a network element in a hardware device, a software function running on a dedicated hardware, or a virtualized function instantiated on a platform (e.g., a cloud platform). It should be noted that in the network architecture shown in FIG. 1, only the network elements included in the entire network architecture are exemplarily illustrated. In the embodiments of the present application, the network elements included in the entire network architecture are not limited.

[0048] Those skilled in the art can understand that the network architecture shown in FIG. 1 does not constitute a limitation on the network architecture, and in actual implementation, the network architecture can include more or fewer network elements than those shown, or some network elements can be combined, etc. It should be understood that in FIG. 1, the AN or RAN is represented as (R)AN.

[0049] In some scenarios, network devices and terminal devices can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; can also be deployed on water; and can also be deployed on aircraft, balloons and satellites in the air. The scenarios in which the network devices and terminal devices are located are not limited in the embodiments of the present application.

[0050] By way of example and not limitation, in the embodiments of the present application, the network device can have a mobile characteristic, e.g., the network device can be a mobile device. In some embodiments of the present application, the network device can be a satellite, a balloon station. For example, the satellite can be a low earth orbit (LEO) satellite, a medium earth orbit (MEO) satellite, a geostationary earth orbit (GEO) satellite, a high elliptical orbit (HEO) satellite, etc. In some embodiments of the present application, the network device can also be a base station disposed at a location on land, water, etc.

[0051] In the embodiments of the present application, the network device can serve a cell, and a terminal device communicates with the network device through a transmission resource (for example, a frequency domain resource, or a frequency spectrum resource) used by the cell. The cell can be a cell corresponding to the network device (for example, a base station). The cell can belong to a macro base station or a base station corresponding to a small cell. The small cell can include a metro cell, a micro cell, a pico cell, a femto cell, and the like. The small cell has a small coverage range and low transmission power, and is suitable for providing a high-rate data transmission service.

[0052] Certificate issuance for a subscription user

[0053] The certificate of the subscription user stores a public key of the user, and can be used to verify the identity of the user. In the process of communication, the user can use a private key to encrypt or sign communication information, and other users can decrypt or verify the signature through the public key in the certificate.

[0054] In some embodiments, a subscription user (for example, a terminal device) can request a public key infrastructure portal (PKI portal) to configure a certificate of the subscription user. The following describes a process in which a subscription user requests a PKI portal to configure a certificate of the subscription user, taking a terminal device as an example.

[0055] As shown in FIG. 2, the process in which the terminal device requests the PKI portal to configure the certificate of the subscription user can include steps S201 to S211.

[0056] In step S201, the terminal device sends an initial hypertext transfer protocol (HTTP) request to the PKI portal to request to obtain a certificate of the subscription user.

[0057] In some embodiments, the initial HTTP request can be an empty HTTP request.

[0058] In some embodiments, the initial HTTP request sent by the terminal device to the PKI portal can include a public key of the terminal device. In some embodiments, the terminal device can generate a public key and a private key of the terminal device to form a public-private key pair. In some embodiments, the public-private key pair generated by the terminal device can be stored in a tamper-proof area of the terminal device.

[0059] In some embodiments, the initial HTTP request sent by the terminal device to the PKI portal can contain the method of certificate usage expected by the terminal device and the identity of the subscription user (i.e. the identity of the terminal device).

[0060] At step S202, the PKI portal sends an HTTP response to the terminal device. The HTTP response carries authentication challenge information.

[0061] For example, the HTTP response can be used to instruct the terminal device to use HTTP digest authentication.

[0062] At step S203, the terminal device obtains a GetKeyAssurance calculated by a wireless identity module (WIM) and calculates an HTTP digest value.

[0063] At step S204, the terminal device sends an HTTP request to the PKI portal, the HTTP request containing authentication challenge response information and a WIM challenge request.

[0064] At step S205, the PKI portal obtains a session key based on the identity of the terminal device and verifies the authentication information sent by the terminal device.

[0065] For example, the PKI can calculate an HTTP digest value and verify whether the calculated HTTP digest value is consistent with the HTTP digest value in the authentication information.

[0066] In some embodiments, if the verification is successful, the PKI portal processes the WIM challenge.

[0067] At step S206, the PKI portal sends an HTTP response to the terminal device, the HTTP response containing a response to the WIM challenge.

[0068] In some embodiments, the response to the WIM challenge can carry parameters required for generating a public-key cryptography standards (PKCS) #10 request in step S207.

[0069] At step S207, the terminal device generates a PKCS #10 request.

[0070] At step S208, the terminal device sends an HTTP request to the PKI portal, the HTTP request containing the PKCS #10.

[0071] At step S209, the PKI portal processes the PKCS#10 request.

[0072] At step S210, the PKI portal sends an HTTP response to the terminal device, the HTTP response carrying the subscription user's certificate.

[0073] In some embodiments, the PKI portal can receive the terminal device's certificate request and issue the subscription user's certificate to the terminal device based on the terminal device's public key. In some embodiments, the PKI portal can receive the terminal device's certificate request and issue the subscription user's certificate to the terminal device without being based on the terminal device's public key.

[0074] In some embodiments, the subscription user's certificate can be issued to the terminal device by a CA in the PKI portal. In some embodiments, the CA can sign the subscription user's certificate using the CA's private key to ensure that the content of the subscription user's certificate is not tampered with.

[0075] In some embodiments, the subscription user's certificate can include one or more of the following: a signature algorithm identifier, the terminal device's public key, a signature obtained by encrypting the subscription user's certificate using the CA's private key.

[0076] At step S211, the terminal device stores the subscription user's certificate.

[0077] In some embodiments, the terminal device can store the subscription user's certificate to a certificate store, such as a local certificate management system of the terminal device.

[0078] In some embodiments, the above steps S203 to S206 can be omitted if the terminal device does not have a WIM application.

[0079] In some embodiments, the terminal device and the PKI portal can implement transport security based on transport layer security (TLS). For example, the terminal device and the PKI portal can use one or more of the following mechanisms to establish a secure TLS connection: authentication and key management for application (AKMA), generic bootstrapping architecture (GBA), certificate.

[0080] Issuance of CA certificate (or CA public key certificate)

[0081] The CA certificate can be used to obtain the public key of the CA. In some embodiments, a communication device (e.g., a terminal device) can request a CA certificate from a PKI portal to obtain the public key of the CA. The process of requesting a CA certificate by a communication device is described below with an example of a terminal device requesting a CA certificate from a PKI portal.

[0082] As shown in FIG. 3, the process of a terminal device requesting a CA certificate from a PKI portal can include steps S301-S307.

[0083] At step S301, the terminal device sends an initial HTTP request to the PKI portal. In some embodiments, the initial HTTP request can be an empty HTTP request.

[0084] At step S302, the PKI portal sends an HTTP response to the terminal device. The HTTP response carries authentication challenge information.

[0085] For example, the HTTP response can be used to instruct the terminal device to use HTTP digest authentication.

[0086] At step S303, the terminal device generates a root certificate request. That is, the terminal device can generate another HTTP request to request a CA certificate.

[0087] At step S304, the terminal device sends an HTTP request to the PKI portal to request the CA certificate.

[0088] At step S305, the PKI portal obtains a session key based on the identity of the terminal device and calculates a verification information header of a response containing the root certificate.

[0089] At step S306, the PKI portal sends an HTTP response to the terminal device, which carries the CA certificate.

[0090] In some embodiments, the CA certificate can be issued by the CA in the PKI portal to the terminal device. In some embodiments, the CA can sign the CA certificate using a private key of the CA to ensure that the content of the CA certificate is not tampered with.

[0091] At step S307, the terminal device verifies the HTTP response, and if successful, the terminal device stores the CA certificate.

[0092] In some embodiments, the terminal device can store the CA certificate to a certificate store, such as a local certificate management system of the terminal device.

[0093] Data plane (DP)

[0094] In some scenarios (for example, practical experience of 5G network intelligence), it is very difficult to obtain data, and the quality of data is difficult to guarantee. On the one hand, the data collection based on network management also has the problems of less data types, long collection period (15 minutes), non-uniform data format, naming, and calculation method of different manufacturers, which leads to difficulty in opening network management data. On the other hand, it is more difficult to collect data from terminal devices, because collecting data from terminal devices may lead to leakage of private data and reduction of data security. Therefore, how to ensure that the data collected from terminal devices can be processed by a trusted node so as to not leak the privacy of users, or how to track the collected data throughout the life cycle to ensure that the use of any data by any data consumer will be recorded, are problems that cannot be solved at present. In addition, some communication systems (such as 6G systems and future communication systems) can provide support for artificial intelligence / machine learning (AI / ML) and integrated sensing and communication (ISAC) technologies. In this way, the communication system needs to support the collection, storage, processing, analysis, and other operations of a large amount of data, and provide the data to network internal functions or network external functions conveniently, efficiently, and securely.

[0095] To solve the above problems, in some network architectures (for example, 6G network architecture), a scheme of adding a “data plane” is proposed. In some implementation modes, the data elements in the data plane will cover internal and external data of the network, including business data, user data, network data, sensing data, and external data.

[0096] In some implementation modes, the basic data service includes data collection, data preprocessing, data storage, data access, data sharing and collaboration, and the like. The basic data service can have the following characteristics: supporting trusted authentication, authorization, and access, efficient data storage and management, on-demand data collection and data preprocessing, and opening of external data. That is, the data plane can include one or more network elements that provide basic data services for the above data elements, or in other words, the data plane includes one or more functions (or network elements) to support one or more of the following data services: trusted between data sources and data consumers, flexible data collection, data opening, data preprocessing, data storage, and data tracking. The data source and / or the data consumer can be any node, for example, the data source can be any node with data storage requirements, and the data consumer can be any node with data calling requirements.

[0097] In some networks (e.g., 6G networks), "trust" will become an important requirement for users of data services, where data services are mainly embodied in data collection, data storage, data access, data sharing, etc. How to provide trusted storage and traceable characteristics of data in the process of providing data services has become a key problem that needs to be solved in the data plane. For example, how to realize secure access and / or control of the data plane in the process of providing data services is a problem that needs to be solved.

[0098] To solve the above problems, the embodiments of the present application provide a method and a communication device for wireless communication, which can perform access authentication and / or access control of the data plane based on a digital certificate, and is beneficial to realize secure and trusted access of the data plane.

[0099] For ease of understanding, the data plane of the embodiments of the present application will be introduced first.

[0100] In some embodiments, the data plane can be used to support one or more of the following functions: trusted data collection, trusted data storage, trusted data processing, trusted data access, trusted data sharing. It should be understood that in the embodiments of the present application, the name of the data plane is not limited, for example, the data plane can also be referred to as "data plane", "data network element set" or "data service plane", etc. In future communication architectures, this name can be replaced by the name of a network element with the same or similar function in a future communication system. In order to facilitate description, the embodiments of the present application take the data plane as an example for introduction.

[0101] FIG. 4 shows an example diagram of a communication system architecture including a data plane according to the embodiments of the present application. As shown in FIG. 4, the data plane can include a network element 1 and / or a network element 2. In some implementations, the network element 1 is configured to provide data operation functions of the data plane, or in other words, the network element 1 is configured to operate data in the data plane. The embodiments of the present application do not make specific limitations on the data operation functions of the data plane provided by the network element 1. For example, the network element 1 can provide one or more of the following operations: data storage function of the data plane, data retrieval (or called calling, access) function of the data plane, data sharing function of the data plane, data collection function of the data plane, data processing function of the data plane, data opening function of the data plane, data verification function of the data plane, etc.

[0102] The name of the network element 1 is not limited in the embodiments of this application. For example, the name of the network element 1 can include one or more of the following: a data plane operation network element, a data plane repository (DPR) network element, a data plane operation infrastructure, a data plane repository infrastructure, and the like. Of course, the network element 1 can also be other names, such as the name corresponding to the network element with the same or similar function as the network element 1 in a future communication system.

[0103] In some implementations, the network element 1 can be a blockchain node located in a blockchain, which helps to realize functions such as trusted data storage in the communication system architecture by means of the characteristics of the blockchain.

[0104] The network element 1 in the data plane is introduced above, and the network element 2 in the data plane provided by the embodiments of this application is introduced below.

[0105] In some implementations, the network element 2 is used for authenticating and / or controlling data plane access, or in other words, the network element 2 can serve as an interface between data and a data operation network element (such as the network element 1) in the data plane in the communication system. Therefore, the network element 2 can also be referred to as a data plane access controller (DPAC). Of course, the network element 2 can also be referred to as one or more of the following in the embodiments of this application: a data plane management network element, a data plane interface, a data plane control network element, and the like, which are not limited in the embodiments of this application.

[0106] In some implementations, the network element 2 can be located in the core network, that is, the network element 2 can be a network element in the core network. However, the embodiments of this application are not limited thereto, for example, different domains can correspond to one or more network elements 2 respectively to authenticate and / or control data plane access. As an example, the terminal device domain can correspond to one or more network elements 2, the access network domain can correspond to one or more network elements 2, and the like.

[0107] In some implementations, the access authentication and / or access control of the data plane can include one or more of the following: collecting data to be stored in the data plane; performing security verification on the data to be stored in the data plane; managing or verifying information of a data source; managing or verifying information of a data consumer; managing access rights of data stored in the data plane; processing data in the data plane; performing data tracking on data stored in the data plane; and interacting with the network element 1.

[0108] In some implementations, the above-mentioned collection of data to be stored in the data plane can include data to be stored in the data plane of the communication system (for example, the communication system shown in FIG. 1).

[0109] In some implementations, the security verification of the data to be stored in the data plane can include, for example, security verification of the data to be stored by using a smart contract and / or a consensus mechanism.

[0110] In some implementations, the information of the data source can be understood as information of a data source corresponding to the stored data. For example, if the terminal device 1 stores data in the data plane, the information of the data source of the data can include information of the terminal device 1, and accordingly, the network element 2 is configured to authenticate and / or store the information of the terminal device 1 corresponding to the data. For another example, if the AF 1 stores data in the data plane, the information of the data source can include information of the AF 1, and accordingly, the network element 2 is configured to authenticate and / or store the information of the AF 1 corresponding to the data.

[0111] In some implementations, the information of the data consumer can be understood as information of a consumer who purchases or subscribes to the data. For example, if the AF 2 subscribes to data in the data plane, the data consumer corresponding to the data is the AF 2, and accordingly, the network element 2 is configured to authenticate and / or store the information of the AF 2 corresponding to the data.

[0112] In some implementations, the access permission can be used to indicate which user or device can access the data, or in other words, the access permission can be used to indicate which data a certain user or device can access.

[0113] In some implementations, the data tracking of the data stored in the data plane can include tracking the operation process corresponding to the data. Of course, in the embodiments of the present application, the data tracking can include tracking the data source corresponding to the data and / or tracking the data consumer that invokes the data.

[0114] It should be noted that, in the embodiments of the present application, the function corresponding to the network element 2 can be implemented by enhancing a data collection coordination function (DCCF). That is, the network element 2 can be a network element of the DCCF. Of course, in the embodiments of the present application, the network element 2 can be a network element in an independent core network.

[0115] Referring back to FIG. 4, the network element 2 in the data plane can communicate with a control plane (CP) through a service-based interface. Taking the network element 2 as an example, the service-based interface can be represented as Ndpac.

[0116] In some scenarios, the data plane is a distributed architecture, which helps support flexible and efficient data management. That is, the distributed data plane can include multiple network elements 1, and correspondingly, different network elements 1 can be associated with different or same network elements 2. At this time, the data source can access through selecting a data plane (or network element 2) that is relatively close, thereby reducing the transmission delay of data.

[0117] Based on the above introduction of the data plane, the following introduces the digital certificate of the embodiments of the present application.

[0118] In the embodiments of the present application, the digital certificate can be used for one or more of the following: access authentication of the data plane, access control of the data plane. In some embodiments, the access control of the data plane can also be understood or replaced by: authorization of the data plane.

[0119] In some embodiments, the digital certificate used for access authentication of the data plane can include: the digital certificate can be used to verify the identity of both parties when accessing the data plane.

[0120] In some embodiments, the digital certificate used for access control of the data plane can include: the digital certificate can be used to determine the data and / or services of the data plane that the holder of the digital certificate can use. That is, the digital certificate can be used to determine the data and / or services of the data plane that the holder of the digital certificate is authorized to use.

[0121] As an example, the digital certificate can be used for identity authentication between the first device and the second device.

[0122] As another example, the digital certificate can be used for the second device to control the first device to access the data plane.

[0123] As yet another example, the digital certificate can be used for identity authentication between the first device and the second device and for the second device to control the first device to access the data plane.

[0124] In some embodiments, the first device can refer to an entity requesting to access the data plane. Alternatively, the first device can refer to an entity requesting to register to the data plane. It should be noted that the entity requesting to access the data plane can be an entity that has already registered to the data plane, or an entity that has not yet registered to the data plane, and the embodiments of the present application are not limited thereto.

[0125] In some embodiments, the first device can be a data source and / or a data consumer of the data plane. In some embodiments, the data source can provide data (or data resources) and / or services to the data plane, that is, the data source can be understood as a provider of data and / or services of the data plane. In some embodiments, the data consumer can consume (or use, invoke, subscribe to) the data and / or services of the data plane.

[0126] The embodiments of the present application do not limit the data and / or services provided by the data source. For example, the data source can provide various types of data and / or services, such as perception type data and / or services, AI type data and / or services, positioning type data and / or services, and the like. However, the embodiments of the present application are not limited thereto, and the services provided by the data source can be divided in other manners in addition to being divided according to data types. For example, the services provided by the data source can be divided according to data operation types, and in this case, the services provided by the data source can include, for example, data storage services, data processing services, and the like.

[0127] It should be noted that in the case where the services provided by the data source are divided according to data types, the data source can perform one or more operations on the services. For example, the data source can perform data storage and / or data processing on the perception type services. Similarly, the data source can perform data storage and / or data processing on the AI type services. Similarly, the data source can perform data storage and / or data processing on the positioning type services, and the like.

[0128] It should also be noted that in the case where the services provided by the data source are divided according to data operation types, the data source can perform the services on one or more data types. For example, the data source can provide data storage services on one or more of the following: perception type data, AI type data, positioning type data, and the like. Similarly, the data source can provide data processing services on one or more of the following: perception type data, AI type data, positioning type data, and the like.

[0129] Correspondingly, the services that can be invoked by the data consumer can also be divided according to different types, such as being divided according to data types or being divided according to data operation types. For details, reference can be made to the division manners of the services that can be provided by the data source, and for brevity, details are not described herein.

[0130] The embodiments of the present application do not limit the first device, as long as the first device can request to access the data plane. For example, the first device can include one or more of the following: a terminal device, an access network device, a network element in a core network, a network management device, and an application device. However, the embodiments of the present application are not limited thereto, and for example, the first device can also include the network element 2 (such as DPAC) mentioned above.

[0131] In some embodiments, the network management device can include, for example, an operations, administration, and maintenance (OAM) device.

[0132] The application embodiments are not limited to application devices. Exemplarily, the application devices can include one or more of the following: an application server, an AF, a third-party application, a third-party server, and the like.

[0133] In the application embodiments, the second device can be used for authenticating and / or controlling data plane access. For example, the second device can be the network element 2 (such as DPAC) mentioned above. For brevity, the introduction of the network element 2 is not repeated here.

[0134] It should be noted that if the first device and the second device are both DPACs, the first device and the second device can be different DPACs. For example, the first device can be DPAC 1, and the second device can be DPAC 2. The DPAC 1 requests to access the data plane through the DPAC 2, or the DPAC 1 requests to register to the DPAC 2.

[0135] In the application embodiments, the first device and the second device can perform data plane access authentication and / or data plane access control based on digital certificates, which is beneficial to improve the credibility and security of data plane access.

[0136] In some embodiments, the digital certificates mentioned in the application embodiments can include various types of digital certificates. Exemplarily, the digital certificates can include one or more of the following types: CA certificates, digital certificates of data plane entities.

[0137] The CA certificate can be used to obtain the public key of the CA. Therefore, the CA certificate can also be understood as or referred to as the public key certificate of the CA. As the issuing center of the digital certificate, the CA can place the public key of the CA in the CA certificate to provide the public key to other entities. The entity receiving the CA certificate can obtain the public key of the CA.

[0138] In some embodiments, the entity receiving the CA certificate can verify, when receiving the digital certificate of the data plane entity sent by another entity, whether the signature of the digital certificate of the data plane entity is signed by a legitimate CA by using the public key of the CA. Taking the entity receiving the CA certificate as the first device as an example, the first device can verify, when receiving the digital certificate of the second device, whether the signature of the digital certificate of the second device is signed by a legitimate CA by using the public key of the CA, so as to verify the identity of the second device. Taking the entity receiving the CA certificate as the second device as an example, the second device can verify, when receiving the digital certificate of the first device, whether the signature of the digital certificate of the first device is signed by a legitimate CA by using the public key of the CA, so as to verify the identity of the first device.

[0139] The digital certificate of the entity of the data plane can be used to obtain the public key of the entity of the data plane. In some embodiments, the digital certificate of the entity of the data plane can also be understood as or referred to as the digital certificate of the subscription user. An entity receiving the digital certificate of the entity of the data plane can obtain the public key of the entity of the data plane.

[0140] The present application does not limit the entity of the data plane. For example, the entity of the data plane can include one or more of the following: the first device, the second device. For the first device and the second device, please refer to the foregoing description. For example, the entity of the data plane includes the first device, the digital certificate of the entity of the data plane can include one or more digital certificates of the first device. For example, the entity of the data plane includes the second device, the digital certificate of the entity of the data plane can include one or more digital certificates of the second device.

[0141] In some embodiments, the entities of the data plane can perform data plane access authentication and / or access control based on their respective digital certificates. For example, the first device and the second device can perform data plane access authentication and / or access control based on one or more of the following: the digital certificate of the first device, the digital certificate of the second device.

[0142] In some embodiments, the second device can send the digital certificate of the second device to the first device, so that the first device verifies the identity of the second device.

[0143] In some embodiments, the first device can send the digital certificate of the first device to the second device, so that the second device verifies the identity of the first device.

[0144] In some embodiments, the digital certificate of the entity of the data plane (such as the first device, the second device) can include the public key of the entity of the data plane. Of course, the digital certificate of the entity of the data plane can also contain other information, which will be described below.

[0145] In some embodiments, the digital certificate of the entity of the data plane can include first information, which is used to indicate the data and / or services of the data plane that the holder of the digital certificate is authorized to use. Alternatively, the first information can be used to indicate one or more of the following: the data that the holder of the digital certificate is authorized to use, the services of the data plane that the holder of the digital certificate is authorized to use, and the type of data operation that the holder of the digital certificate is authorized to perform.

[0146] For example, the digital certificate of the first device can include first information, which is used to indicate the data and / or services of the data plane that the first device is authorized to use. In this way, the data plane can only provide the authorized data and / or services to the first device.

[0147] In some embodiments, the first information corresponding to different entities of different data planes can be different. That is, the data and / or services of the data plane that the different entities of different data planes are authorized to use can be different.

[0148] In some embodiments, the first information can comprise one or more of the following: first indication information, second indication information, third indication information.

[0149] The first indication information can be used to indicate that the holder of the digital certificate is authorized to use all the data and / or services of all the data planes. Exemplarily, if a digital certificate contains the first indication information, the holder of the digital certificate is authorized to perform one or more of the following: access services of different data planes, use different data, use different data operations. For example, the holder of the certificate is authorized to store, process and access perception type data, and is authorized to store, process and access AI type data, and is authorized to store, process and access positioning type data, etc.

[0150] In some embodiments, the first indication information can comprise a wildcard. However, embodiments of the present application are not limited thereto, for example, the first indication information can be "0", or the first indication information can be "1", etc.

[0151] The second indication information can be used to indicate the type of service of the data plane that the holder of the digital certificate is authorized to use. For example, if the type of service of the data plane is divided according to the data type, the second indication information can indicate that the holder of the digital certificate is authorized to use one or more of the following service types: perception type service, AI type service, positioning type service, etc. In this case, it can be understood that the second indication information is associated with different data types. For example, if the type of service of the data plane is divided according to the data operation type, the second indication information can indicate that the holder of the digital certificate is authorized to use one or more of the following service types: storage type service, access type service, processing type service, etc. In this case, it can be understood that the second indication information is associated with different data operation types.

[0152] In some embodiments, different values of the second indication information can be used to indicate that the type of service of the data plane that the holder of the digital certificate is authorized to use is different.

[0153] For example, the second indication information takes 2-bit information indication as an example. Assuming that the second indication information takes value "00" to indicate that the user is authorized to use the perception type service, takes value "01" to indicate that the user is authorized to use the AI type service, and takes value "10" to indicate that the user is authorized to use the positioning type service. However, the embodiments of the present application are not limited thereto. For example, the second indication information takes value "00" to indicate that the user is authorized to use the AI type service, takes value "01" to indicate that the user is authorized to use the positioning type service, and takes value "10" to indicate that the user is authorized to use the perception type service. Alternatively, the second indication information takes value "00" to indicate that the user is authorized to use the storage type service, takes value "01" to indicate that the user is authorized to use the calling type service, and takes value "10" to indicate that the user is authorized to use the processing type service.

[0154] Of course, the second indication information can also take other bit information indication. For example, the second indication information takes 3-bit information indication as an example. Assuming that the second indication information takes value "000" to indicate that the user is authorized to use the perception type service, takes value "001" to indicate that the user is authorized to use the AI type service, takes value "010" to indicate that the user is authorized to use the positioning type service, takes value "011" to indicate that the user is authorized to use the storage type service, takes value "100" to indicate that the user is authorized to use the calling type service, and takes value "101" to indicate that the user is authorized to use the processing type service.

[0155] The third indication information can be used to indicate the data operation type that the holder of the digital certificate is authorized to use. The embodiments of the present application do not limit the data operation type. For example, the data operation type can include one or more of the following: storage, collection, calling, processing (such as analysis, calculation, data preprocessing, etc.).

[0156] In some embodiments, different values of the third indication information can be used to indicate that the holder of the digital certificate is authorized to use different data operation types.

[0157] For example, the third indication information takes 2-bit information indication as an example. The third indication information takes value "00" to indicate that the authorized data operation type is storage, takes value "01" to indicate that the authorized data operation type is calling, and takes value "10" to indicate that the authorized data operation type is processing. However, the embodiments of the present application are not limited thereto. For example, the third indication information takes value "00" to indicate that the authorized data operation type is collection, takes value "01" to indicate that the authorized data operation type is storage, and takes value "10" to indicate that the authorized data operation type is calling.

[0158] Of course, the third indication information can be indicated by other bit information. Taking an example in which the third indication information is indicated by 3-bit information, it is assumed that the third indication information with a value of "000" indicates that the authorized data operation type is collection, the third indication information with a value of "001" indicates that the authorized data operation type is storage, the third indication information with a value of "010" indicates that the authorized data operation type is invocation, and the third indication information with a value of "011" indicates that the authorized data operation type is processing.

[0159] As an example, the first information can include the first indication information.

[0160] As another example, the first information can include the second indication information.

[0161] As yet another example, the first information can include the third indication information.

[0162] As yet another example, the first information can include the second indication information and the third indication information.

[0163] In some embodiments, the digital certificate of the entity of the data plane can further include one or more of the following information: a public key of the holder of the digital certificate, an identity of the holder of the digital certificate, a signature generated by the private key of the CA.

[0164] For ease of understanding, the following describes, with reference to FIG. 5, a format of a digital certificate of an entity of a data plane, taking an X 509 certificate as an example. As shown in FIG. 5, the digital certificate can include one or more of the following parameters: a version number, a serial number, a signature algorithm identifier, an issuer name, a validity period, a name of the holder of the digital certificate, public key related information of the holder of the digital certificate, a unique identifier of the issuer, a unique identifier of the holder of the digital certificate, an extension field, and a signature.

[0165] The version number can be used to indicate the version number corresponding to the digital certificate, for example, the version number of the digital certificate is version 1 or version 2 or version 3.

[0166] In some embodiments, when the version number of the digital certificate is version 1, the digital certificate can include one or more of the following information: a version number, a serial number, a signature algorithm identifier, an issuer (or issuer) name, a validity period, a name of the holder of the digital certificate, public key related information of the holder of the digital certificate, a signature generated by the private key of the CA.

[0167] In some embodiments, when the version number of the digital certificate is version 2, the digital certificate can include one or more of the following information: a version number, a serial number, a signature algorithm identifier, an issuer name, a validity period, a name of the holder of the digital certificate, public key related information of the holder of the digital certificate, a unique identifier of the issuer, a unique identifier of the holder of the digital certificate, a signature generated by the private key of the CA.

[0168] In some embodiments, when the version number of the digital certificate is version 3, the digital certificate can include one or more of the following information: version number, serial number, signature algorithm identifier, issuer name, validity period, name of the holder of the digital certificate, public key related information of the holder of the digital certificate, unique identifier of the issuer, unique identifier of the holder of the digital certificate, extension field, and signature generated by the private key of the CA.

[0169] In some embodiments, when the version number is a default value, it indicates that the version number of the digital certificate is version 1.

[0170] The serial number can be used to indicate the identity of the digital certificate. In some embodiments, the serial number can be an integer. In some embodiments, the serial number of each digital certificate sent by the same CA is unique.

[0171] The signature algorithm identifier can be used to indicate the algorithm and corresponding parameters used to sign the digital certificate.

[0172] The issuer name can be used to indicate the CA that established and signed the digital certificate.

[0173] In some embodiments, the validity period can include two data items: the start time and the end time of the validity period of the digital certificate.

[0174] The name of the holder of the digital certificate can be used to indicate the name of the user to which the digital certificate belongs (such as the identity of the user). That is, the digital certificate is a certificate used to prove the public key of the holder.

[0175] The public key related information of the holder of the digital certificate can include one or more of the following: the public key, the identifier of the algorithm corresponding to the public key, and the related parameters of the algorithm corresponding to the public key.

[0176] The unique identifier of the issuer is optional, and can be used to uniquely identify the issuer when the issuer name is reused for other entities.

[0177] The unique identifier of the holder of the digital certificate is optional, and can be used to uniquely identify the holder of the digital certificate when the name of the holder of the digital certificate is reused for other entities.

[0178] The unique identifier of the issuer and the unique identifier of the holder of the digital certificate described above can exist in version 2 or version 3.

[0179] The extension field can include one or more extended information items, and the extension field can exist in the third version. For example, the first information mentioned above can exist in the extension field. Of course, the first information can also not be included in the extension field, and embodiments of the present application do not limit this. In this case, the first information can not exist in the entire digital certificate, or the first information can exist in other fields (such as a newly defined field).

[0180] The CA can sign the above information with its own private key to obtain a signature. For example, the CA can sign the hash value of the above information using its own private key. The purpose of the signature is to ensure that the information of the digital certificate is not tampered with.

[0181] The above introduces the content of the digital certificate, and the following introduces the obtaining method of the digital certificate.

[0182] Obtaining method 1:

[0183] Obtaining method 1 is that the device obtains the digital certificate in the process of initial registration to the network. Obtaining method 1 can be used, for example, for the first device to obtain the digital certificate of the first device.

[0184] FIG. 6 is a flow diagram of obtaining a digital certificate according to an embodiment of the present application. In the example of FIG. 6, the first device is a terminal device. The method of FIG. 6 can include steps S610 to S660, which are introduced below.

[0185] In step S610, the first device reports first capability information to a mobility management network element. The first capability information can be used to indicate the data plane service to which the first device has access.

[0186] In some embodiments, the first capability information is sent in the process of initial registration of the first device to the network.

[0187] Embodiments of the present application do not limit the mobility management network element, as long as it is used for mobility management in the core network. For example, the mobility management network element can be an AMF, or it can be a network element in a future communication system that is the same as or similar to the AMF in function.

[0188] In step S620, the mobility management network element performs authorization checking of the first device.

[0189] For example, the mobility management network element can perform authorization checking of the first device according to the subscription information of the first device in the core network.

[0190] In some embodiments, the mobility management network element can obtain the subscription information of the first device in the core network from a UDM.

[0191] At step S630, the mobility management network element requests a CA or a registration authority (RA) to issue a digital certificate based on the result of the authorization check of the first device.

[0192] As an implementation manner, the mobility management network element can request the CA or the RA to issue the digital certificate based on the result of the authorization check of the first device and the information provided by the first device. In other words, the mobility management network element can request the CA or the RA to issue the digital certificate based on the subscription information of the first device in the core network and the information provided by the first device.

[0193] In some embodiments, the information provided by the first device can include information required for issuing the digital certificate. For example, the information provided by the first device can include one or more of the following: the first capability information, the public key of the first device, the purpose of the digital certificate expected by the first device, and the identity of the first device.

[0194] For example, in the case where the first device generates a public-private key pair, the first device can provide one or more of the following to the mobility management network element: the public key of the first device, the first capability information, the purpose of the digital certificate expected by the first device, and the identity of the first device, so that the mobility management network element requests the CA or the RA to issue the digital certificate according to these information.

[0195] Alternatively, in the case where the first device does not provide the public key, the first device can provide one or more of the following to the mobility management network element: the first capability information, the purpose of the digital certificate expected by the first device, and the identity of the first device, so that the mobility management network element requests the CA or the RA to issue the digital certificate according to these information.

[0196] In some embodiments, before the first device provides one or more of the above information to the mobility management network element, a non access stratum (NAS) protection can be started between the first device and the mobility management network element.

[0197] In some embodiments, when the first device does not provide one or more of the above information, the mobility management network element can request the UDM for the above information, so that the mobility management network element requests the CA or the RA to issue the digital certificate based on these information.

[0198] In some embodiments, the subscription information related to the data plane of the first device, such as the first capability information, etc., can be stored in the UDM.

[0199] At step S640, the CA or the RA issues the digital certificate of the first device. In other words, the CA or the RA generates the digital certificate of the first device.

[0200] For example, the CA or the RA can sign the content of the digital certificate of the first device using the private key of the CA, and issue the digital certificate.

[0201] At step S650, the CA or the RA sends the digital certificate of the first device to the first device.

[0202] As an implementation manner, the CA or the RA can send the digital certificate to the first device through a control plane. That is, the CA or the RA can send the digital certificate to a mobility management network element, and the mobility management network element sends the digital certificate to the first device.

[0203] As another implementation manner, the CA or the RA can send the digital certificate to the first device through a user plane. That is, the CA or the RA can send the digital certificate to the first device through a UPF.

[0204] At step S660, the first device stores the digital certificate of the first device.

[0205] In this way, the first device can subsequently perform access authentication and / or access control of the data plane based on the digital certificate.

[0206] The obtaining manner 1 can issue one or more (or all) digital certificates for access authentication and / or access control of the data plane that the first device can use to the first device according to the subscription information of the first device in the core network.

[0207] The obtaining manner 2:

[0208] The obtaining manner 2 is that the device obtains the digital certificate in the process of registering to the data plane. The obtaining manner 2 can be used for the first device to obtain the digital certificate of the first device, for example.

[0209] It should be noted that the first device can find a suitable second device address through the discovery process of the second device. However, considering that one second device can serve as an interface of multiple distributed data planes, that is, the address of the second device and the identifier of the data plane can not be one-to-one, in order to ensure that the first device can accurately interact with the data plane subsequently, the first device needs to initiate registration to the second device to register to the data plane. When the first device initiates registration to the second device, the second device can allocate a unique identifier of the data plane for the first device, so that the first device can use the identifier of the data plane to interact with the data plane, such as operating (such as storing, calling, etc.) data of the data plane.

[0210] FIG. 7 is a flow diagram of obtaining a digital certificate according to another embodiment of the present application. The method of FIG. 7 can include steps S710 to S760, which are described below.

[0211] At step S710, the first device requests a service of a data plane from the second device. For example, the first device can send a registration request to the second device to request the service of the data plane.

[0212] At step S720, the second device performs an authorization check on the first device. For example, the second device can check the authorization of the first device in the data plane.

[0213] As an implementation manner, the second device can obtain the subscription information of the first device in the core network from the UDM, so as to perform the authorization check on the first device according to the subscription information. However, the embodiments of the present application are not limited thereto, for example, the second device can perform the authorization check on the first device according to the implementation of the second device.

[0214] At step S730, the second device requests the CA or the RA to issue a digital certificate based on the result of the authorization check on the first device.

[0215] As an implementation manner, the second device can request the CA or the RA to issue the digital certificate based on one or more of the following information: the subscription information of the first device in the core network, the information provided by the first device, the type of the service of the data plane indicated by the first message.

[0216] The information provided by the first device can be referred to the foregoing description, and is not described herein again for simplicity.

[0217] The first message can be used for the first device to request to access the data plane. In some embodiments, the first message can carry the type of the service of the data plane requested by the first device. The embodiments of the present application do not limit the type of the service of the data plane requested by the first device. Exemplarily, the type of the service of the data plane requested by the first device can include one or more of the following: all services of the data plane, a sensing type of service, an AI type of service, a positioning type of service, a storage type of service, a retrieval type of service, a processing type of service, and the like.

[0218] At step S740, the CA or the RA issues the digital certificate of the first device. In other words, the CA or the RA generates the digital certificate of the first device.

[0219] At step S750, the CA or the RA sends the digital certificate of the first device to the first device.

[0220] At step S760, the first device stores the digital certificate of the first device.

[0221] The description of steps S740 to S760 can be referred to the description of steps S640 to S660, and is not described herein again for simplicity.

[0222] In this way, the first device can subsequently perform data plane access authentication and / or access control based on the digital certificate.

[0223] In the second obtaining manner, the second device can request the first device for a specific digital certificate according to a service request of the first device in the data plane.

[0224] The third obtaining manner is that the device requests the PKI portal to configure the digital certificate. The third obtaining manner can be used for the first device or the second device to obtain the digital certificate, for example.

[0225] The third obtaining manner is that the device requests the PKI portal to configure the digital certificate. The third obtaining manner can be used for the first device or the second device to obtain the digital certificate, for example.

[0226] FIG. 8 is a flow diagram of a method for obtaining a digital certificate according to another embodiment of the present application. The method of FIG. 8 can include steps S810 to S840, which are described below.

[0227] In step S810, the first device or the second device establishes a secure connection with the PKI portal.

[0228] For example, the first device or the second device can establish a secure TLS connection with the PKI portal. The present application does not limit the implementation of the first device or the second device establishing a secure TLS connection with the PKI portal, and for example, the first device or the second device can use one or more of the following mechanisms to establish a secure TLS connection with the PKI portal: AKMA, GBA, certificate.

[0229] In step S820, the first device or the second device sends a request to the PKI portal to request the PKI portal to issue a digital certificate.

[0230] In some embodiments, the first device or the second device can carry information provided by the first device or information provided by the second device in the request sent to the PKI portal.

[0231] For example, the first device can carry information provided by the first device in the request sent to the PKI portal. The present application does not limit the information provided by the first device, and for example, the information provided by the first device can include one or more of the following: first capability information, a public key of the first device, a purpose of the digital certificate expected by the first device, and an identifier of the first device. For details of the information provided by the first device, please refer to the foregoing description.

[0232] For example, the second device can carry information provided by the second device in the request sent to the PKI portal. The present application does not limit the information provided by the second device, and for example, the information provided by the second device can include one or more of the following: a public key of the second device, a purpose of the digital certificate expected by the second device, and an identifier of the second device.

[0233] At step S830, the PKI portal sends the digital certificate to the first device or the second device.

[0234] In some embodiments, the PKI portal performs an authorization check on the first device or the second device before sending the digital certificate to the first device or the second device. The embodiments of the present application do not limit the manner in which the PKI portal performs the authorization check on the first device or the second device. For example, the PKI portal can perform the authorization check based on subscription information obtained from the UDM, or can perform the authorization check based on implementation of the PKI portal, etc. As an example, the PKI portal can perform the authorization check on the first device based on subscription information obtained from the UDM. As another example, the PKI portal can perform the authorization check on the second device based on implementation of the PKI portal.

[0235] At step S840, the first device or the second device stores the digital certificate.

[0236] In this way, the first device or the second device can subsequently perform access authentication and / or access control on the data plane based on the digital certificate.

[0237] The third obtaining manner uses a standardized PKI portal to issue the digital certificate for the first device or the second device, which is simpler to implement, and the first device or the second device can request the digital certificate from the PKI portal before requesting or controlling specific data plane services, which is more flexible.

[0238] The embodiments of the present application are not limited to the above-mentioned ways to obtain the digital certificate. For example, the digital certificate of the first device or the second device can also be configured by an operator or a vendor.

[0239] In some embodiments, the digital certificate of the first device and / or the digital certificate of the second device can support access authentication and / or access control on the data plane across domains.

[0240] In some embodiments, the above-mentioned cross-domain can include one or more of the following: the first device and the second device belong to different public land mobile networks (PLMNs), and the first device and the second device belong to different operator networks. This is because, in order to break the data silos, operators can open data services supported by each other, and the CA can issue digital certificates for users of these operators for access authentication and / or access control on the data plane.

[0241] In some embodiments, due to the large number of users of an operator, it is difficult for one CA to issue digital certificates for all users, and therefore, digital certificates of users of different operators can be issued by different CAs. For example, users of operator A can be issued digital certificates by CA X, users of operator B can be issued digital certificates by CA Y, and CA X and CA Y securely exchange public keys. In this way, users of operator A can not only verify other entities within the domain (network of operator A), but also verify entities across domains (such as the network of operator B). This is because digital certificates are based on cryptography, and therefore the trust between digital certificates can be in a chain structure.

[0242] In some embodiments, the above-mentioned cross-domain can include other cross-domains in addition to the above-mentioned cross-domain modes. For example, the above-mentioned cross-domain can include one or more of the following: the first device belongs to the terminal device domain, and the second device belongs to the core network domain; the first device belongs to the access network domain, and the second device belongs to the core network domain; the first device belongs to the network management device domain, and the second device belongs to the core network domain; the first device belongs to the application device domain, and the second device belongs to the core network domain. That is, when the second device belongs to the core network domain, the first device does not belong to the core network domain.

[0243] Based on the above description of the digital certificate, the following describes the process of access authentication and / or access control of the first device and the second device based on the digital certificate.

[0244] FIG. 9 is a flow diagram of a method of wireless communication provided by the present application. The method shown in FIG. 9 is described from the perspective of the interaction between the first device and the second device. For the description of the first device and the second device, please refer to the foregoing description, and for brevity, the description is not repeated here.

[0245] The method shown in FIG. 9 can include one or more of step S910 and step S920. The present application embodiment does not limit the execution order of step S910 and step S920. For example, step S910 can be executed before step S920, or can be executed after step S920. The following describes step S910 and step S920 respectively.

[0246] In step S910, the first device sends a first message to the second device. The first message can be used to request access to the data plane.

[0247] In some embodiments, the first message can include the first digital certificate.

[0248] In some embodiments, the first digital certificate can be one or more of the digital certificates of the first device, for example, the first digital certificate can be any one of the digital certificates of the first device. The content contained in the first digital certificate, the manner of obtaining the first digital certificate can refer to the foregoing description. Exemplarily, the first digital certificate can be obtained based on one or more of the foregoing obtaining manners 1, obtaining manner 2 and obtaining manner 3.

[0249] In some embodiments, the first digital certificate can be used to determine the service of the data plane that the first device is authorized to use. For example, the first digital certificate can include first information. The related description of the first information can refer to the foregoing description.

[0250] In some embodiments, in the case that the first digital certificate can be used to determine the service of the data plane that the first device is authorized to use, the second device can perform access control of the data plane based on the first digital certificate. Alternatively, the second device can obtain one or more of the following information based on the first digital certificate: data that the first device can obtain, service of the data plane that the first device can obtain, data operation that the first device can perform.

[0251] In some embodiments, the first digital certificate is determined based on one or more of the following information: subscription information of the first device in the core network, information provided by the first device, type of the service of the data plane indicated by the first message.

[0252] In some embodiments, the first digital certificate is issued to the first device in the case that the first device passes the authorization check. For example, the authorization check of the first device is based on the subscription information provided by the core network.

[0253] In some embodiments, if the first digital certificate is included in the first message, the second device can authenticate the legality of the first device (see step S930). As an implementation manner, the second device can verify whether the signature in the first digital certificate is signed by a trusted CA based on the public key of the CA in the CA certificate. In some embodiments, the second device can authenticate the first device to be legal in the case that the signature in the first digital certificate is verified to be signed by a trusted CA.

[0254] In some embodiments, the first message can include the identity of the first device.

[0255] In some embodiments, the first message can include indication information of the type of the service of the data plane, which is used to indicate the type of the service of the data plane requested by the first device.

[0256] In step S920, the second device sends a second message to the first device. The second message can be used to request the first device to participate in the service of the data plane.

[0257] In some embodiments, the second device can request the first device to participate in the service of the data plane only if the first device is authorized to pass the data plane.

[0258] In some embodiments, the second message can include a second digital certificate.

[0259] In some embodiments, the second digital certificate can be one or more of the digital certificates of the second device, for example, the second digital certificate can be any one of the digital certificates of the second device. The content contained in the second digital certificate, the way of obtaining the second digital certificate can refer to the foregoing description. Exemplarily, the second digital certificate can be obtained based on the foregoing obtaining method 3.

[0260] In some embodiments, the second digital certificate is determined based on the information provided by the second device. Exemplarily, the information provided by the second device can include one or more of the following: the public key of the second device, the intended use of the digital certificate of the second device, the identity of the second device.

[0261] In some embodiments, the second digital certificate is issued to the second device only if the second device passes the authorization check.

[0262] In some embodiments, if the second message includes the second digital certificate, the first device can authenticate the legality of the second device (see step S940). As an implementation manner, the first device can verify whether the signature in the second digital certificate is signed by a trusted CA based on the public key of the CA in the CA certificate. In some embodiments, the first device can authenticate the second device to be legal if the first device verifies that the signature in the second digital certificate is signed by a trusted CA.

[0263] In some embodiments, the second message can include the identity of the second device.

[0264] In some embodiments, the first device and the second device can perform mutual authentication based on the digital certificate. For example, the first device can send a first digital certificate to the second device, and the second device can send a second digital certificate to the first device. In this case, the first device can authenticate the second device based on the second digital certificate, and the second device can also authenticate the first device based on the first digital certificate.

[0265] As an implementation, the first device can send a first message to the second device, the first message carrying the first digital certificate, and the second device sends a second message to the first device, the second message carrying the second digital certificate. However, the embodiments of the present application are not limited thereto, for example, the first device can send a first message to the second device, the first message carrying the second digital certificate, and the second device can send a message other than the second message (e.g., a message sent after receiving the first message), the other message carrying the second digital certificate.

[0266] In some embodiments, the first device and the second device can perform one-way authentication based on the digital certificates. For example, the first device provides the first digital certificate to the second device, and the second device authenticates the first device. Alternatively, the second device can provide the second digital certificate to the first device, and the first device authenticates the second device.

[0267] In some embodiments, in the case that the first device and the second device can perform one-way authentication based on the digital certificates, the authentication in the other direction can be performed based on the symmetric key. For example, in the case that the second device provides the second digital certificate to the first device, and the first device authenticates the second device, the authentication of the first device by the second device can be performed based on the symmetric key. The second device authenticates the first device by obtaining the key of the first device.

[0268] The method embodiments of the present application are described in detail above in combination with FIG. 1 to FIG. 9, and the device embodiments of the present application are described in detail below in combination with FIG. 10 to FIG. 12. It should be understood that the description of the method embodiments and the description of the device embodiments correspond to each other, and therefore, the parts not described in detail can be referred to the foregoing method embodiments.

[0269] FIG. 10 is a structural schematic diagram of a communication device according to an embodiment of the present application. The communication device 1000 shown in FIG. 10 can be any of the first devices described above. The communication device 1000 can include a sending module 1010 and / or a receiving module 1020. The sending module 1010 can be configured to send a first message to a second device, the first message being used to request access to a data plane, the first message including a first digital certificate. The receiving module 1020 can be configured to receive a second message sent by the second device, the second message being used to request the first device to participate in a service of the data plane, the second message including a second digital certificate; wherein the second device is configured to authenticate and / or control the first device to access the data plane, and the first digital certificate and / or the second digital certificate are used for one or more of the following: access authentication of the data plane, access control of the data plane.

[0270] In some embodiments, the first digital certificate is used to determine the service of the data plane that the first device is authorized to use.

[0271] In some embodiments, the first digital certificate comprises first information indicating that the holder of the first digital certificate is authorized to use services of a data plane.

[0272] In some embodiments, the first information comprises one or more of: first indication information indicating that the holder of the first digital certificate is authorized to use services of all data planes; second indication information indicating that the holder of the first digital certificate is authorized to use a type of services of a data plane; third indication information indicating a type of data operation that the holder of the first digital certificate is authorized to use.

[0273] In some embodiments, the communication device further comprises an obtaining module configured to obtain the first digital certificate, wherein the first digital certificate is obtained based on one or more of: being obtained in a process of initial registration to a network; being obtained in a process of registration to a data plane; being requested by a PKI portal; being configured by an operator; being configured by a vendor.

[0274] In some embodiments, the first digital certificate is determined based on one or more of: subscription information of the first device in a core network; information provided by the first device; a type of services of a data plane indicated by the first message.

[0275] In some embodiments, the information provided by the first device comprises one or more of: first capability information indicating services of a data plane that the first device is entitled to obtain; a public key of the first device; an intended use of the first digital certificate by the first device; an identity of the first device.

[0276] In some embodiments, the second digital certificate is determined based on information provided by the second device.

[0277] In some embodiments, the information provided by the second device comprises one or more of: a public key of the second device; an intended use of the second digital certificate by the second device; an identity of the second device.

[0278] In some embodiments, the first digital certificate is issued to the first device with an authorization check of the first device; and / or, the second digital certificate is issued to the second device with an authorization check of the second device.

[0279] In some embodiments, the authorization check of the first device is based on subscription information provided by a core network.

[0280] In some embodiments, the first digital certificate and / or the second digital certificate support access authentication and / or access control of a data plane across domains.

[0281] In some embodiments, the cross-domain includes one or more of the following: the first device and the second device belong to different PLMNs; the first device and the second device belong to different operator networks; the first device belongs to a terminal device domain and the second device belongs to a core network domain; the first device belongs to an access network domain and the second device belongs to a core network domain; the first device belongs to a network management device domain and the second device belongs to a core network domain; the first device belongs to an application device domain and the second device belongs to a core network domain.

[0282] In some embodiments, the first device includes one or more of the following: a terminal device, an access network device, a network element in a core network, a network management device, and an application device.

[0283] In some embodiments, the sending module 1010 and / or the receiving module 1020 can be a transceiver 1230. The communication device 1000 can further include a processor 1210 and a memory 1220, as shown in FIG. 12.

[0284] FIG. 11 is a structural schematic diagram of a communication device according to another embodiment of the present application. The communication device 1100 shown in FIG. 11 can be any of the second devices described above. The communication device 1100 can include a receiving module 1110 and / or a sending module 1120. The receiving module 1110 is configured to receive a first message sent by a first device, the first message being used to request access to a data plane, the first message including a first digital certificate. The sending module 1120 can be configured to send a second message to the first device, the second message being used to request the first device to participate in services of the data plane, the second message including a second digital certificate; wherein the second device is configured to authenticate and / or control the first device to access the data plane, and the first digital certificate and / or the second digital certificate are used for one or more of the following: access authentication of the data plane, and access control of the data plane.

[0285] In some embodiments, the first digital certificate is used to determine services of the data plane that the first device is authorized to use.

[0286] In some embodiments, the first digital certificate includes first information, the first information being used to indicate services of the data plane that a holder of the first digital certificate is authorized to use.

[0287] In some embodiments, the first information comprises one or more of: first indication information indicating that the holder of the first digital certificate is authorized to use services of all data planes; second indication information indicating that the holder of the first digital certificate is authorized to use services of a type of data plane; and third indication information indicating a type of data operation that the holder of the first digital certificate is authorized to perform.

[0288] In some embodiments, the communication device further comprises an obtaining module configured to obtain the second digital certificate based on one or more of: being obtained in a process of registering to a data plane; being configured by a PKI portal; being configured by an operator; and being configured by a vendor.

[0289] In some embodiments, the first digital certificate is determined based on one or more of: subscription information of the first device in a core network; information provided by the first device; and a type of service of a data plane indicated by the first message.

[0290] In some embodiments, the information provided by the first device comprises one or more of: first capability information indicating services of a data plane that the first device is entitled to obtain; a public key of the first device; an intended use of the first digital certificate by the first device; and an identity of the first device.

[0291] In some embodiments, the second digital certificate is determined based on information provided by the second device.

[0292] In some embodiments, the information provided by the second device comprises one or more of: a public key of the second device; an intended use of the second digital certificate by the second device; and an identity of the second device.

[0293] In some embodiments, the first digital certificate is issued to the first device subject to an authorization check of the first device; and / or, the second digital certificate is issued to the second device subject to an authorization check of the second device.

[0294] In some embodiments, the authorization check of the first device is based on subscription information provided by a core network.

[0295] In some embodiments, the first digital certificate and / or the second digital certificate support access authentication and / or access control of a data plane across domains.

[0296] In some embodiments, the cross-domain includes one or more of the following: the first device and the second device belong to different PLMNs; the first device and the second device belong to different operator networks; the first device belongs to a terminal device domain and the second device belongs to a core network domain; the first device belongs to an access network domain and the second device belongs to a core network domain; the first device belongs to a network management device domain and the second device belongs to a core network domain; the first device belongs to an application device domain and the second device belongs to a core network domain.

[0297] In some embodiments, the first device includes one or more of the following: a terminal device, an access network device, a network element in a core network, a network management device, an application device.

[0298] In some embodiments, the receiving module 1110 and / or the sending module 1120 can be a transceiver 1230. The communication device 1100 can further include a processor 1210 and a memory 1220, as shown in FIG. 12.

[0299] FIG. 12 is a schematic structural diagram of a communication apparatus according to an embodiment of the present application. The dashed line in FIG. 12 indicates that the unit or module is optional. The apparatus 1200 can be used to implement the method described in the above method embodiments. The apparatus 1200 can be a chip, a terminal device, or a network device.

[0300] The apparatus 1200 can include one or more processors 1210. The processor 1210 can support the apparatus 1200 to implement the method described in the above method embodiments. The processor 1210 can be a general purpose processor or a dedicated processor. For example, the processor can be a central processing unit (CPU). Alternatively, the processor can also be other general purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic, discrete hardware components, etc. The general purpose processor can be a microprocessor or the processor can also be any conventional processor.

[0301] The apparatus 1200 can further include one or more memories 1220. The memory 1220 stores a program, which can be executed by the processor 1210, so that the processor 1210 performs the method described in the above method embodiments. The memory 1220 can be independent of the processor 1210 or integrated in the processor 1210.

[0302] The apparatus 1200 can further include a transceiver 1230. The processor 1210 can communicate with other devices or chips through the transceiver 1230. For example, the processor 1210 can perform data transceiving with other devices or chips through the transceiver 1230.

[0303] The embodiment of the present application further provides a computer readable storage medium for storing a program. The computer readable storage medium can be applied to the terminal device or the network device provided by the embodiment of the present application, and the program causes the computer to execute the method performed by the terminal device or the network device in the various embodiments of the present application.

[0304] The embodiment of the present application further provides a computer program product. The computer program product includes a program. The computer program product can be applied to the terminal device or the network device provided by the embodiment of the present application, and the program causes the computer to execute the method performed by the terminal device or the network device in the various embodiments of the present application.

[0305] The embodiment of the present application further provides a computer program. The computer program can be applied to the terminal device or the network device provided by the embodiment of the present application, and the computer program causes the computer to execute the method performed by the terminal device or the network device in the various embodiments of the present application.

[0306] It should be understood that the terms "system" and "network" can be used interchangeably in the present application. In addition, the terms used in the present application are only used to explain the specific embodiments of the present application, and are not intended to limit the present application. The terms "first", "second", "third", and "fourth" and the like in the specification and claims of the present application and the drawings are used to distinguish different objects, and are not used to describe a particular order. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion.

[0307] In the embodiments of the present application, the "indication" mentioned can be direct indication, or indirect indication, or can be an indication with an associated relationship. For example, A indicates B, which can mean that B can be obtained by A; or A indirectly indicates B, for example, A indicates C, and B can be obtained by C; or A and B have an associated relationship.

[0308] In the embodiments of the present application, "B corresponding to A" means that B is associated with A, and B can be determined according to A. However, it should also be understood that the determination of B according to A does not mean that B is determined only according to A, but B can also be determined according to A and / or other information.

[0309] In the embodiments of the present application, the term "corresponding" can represent a direct or indirect corresponding relationship between the two, can also represent an associated relationship between the two, and can also indicate a relationship with the indicated, configured, and the like.

[0310] In the embodiments of the present application, the "comprising" mentioned can mean direct inclusion or indirect inclusion. Alternatively, the "comprising" mentioned in the embodiments of the present application can be replaced by "indicating" or "for determining". For example, A comprising B can be replaced by A indicating B, or A for determining B.

[0311] In the embodiments of the present application, "predefined" or "preconfigured" can be realized by pre-saving corresponding codes, tables or other means for indicating related information in devices (for example, including terminal devices and network devices), and the specific implementation manner is not limited in the present application. For example, predefinition can mean definition in a protocol.

[0312] In the embodiments of the present application, the "protocol" can mean a standard protocol in the communication field, for example, can include the LTE protocol, the NR protocol and the related protocol applied in the future communication system, and the present application is not limited to this.

[0313] In the embodiments of the present application, the term "and / or" is only a description of the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B can mean that A exists alone, A and B exist together, and B exists alone. In addition, the character " / " in this paper generally represents an "or" relationship between the front and rear associated objects.

[0314] In various embodiments of the present application, the size of the serial number of the above processes does not mean the order of execution, and the execution order of the processes should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0315] In several embodiments provided by the present application, it should be understood that the disclosed system, device and method can be implemented by other ways. For example, the device embodiments described above are only schematic, and the division of the units is only a logical function division, and there can be another division way in actual implementation, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interfaces, devices or units, and can be electrical, mechanical or other forms.

[0316] The units described as separate components may or may not be physically separate, and the components displayed as units may or may not be physical units, that is, may be located in one place, or may be distributed to multiple network units. Part or all of the units can be selected to achieve the purpose of the embodiment of the present application according to actual needs.

[0317] In addition, each functional unit in each embodiment of the present application can be integrated into a processing unit, or each unit can exist physically, or two or more units can be integrated into one unit.

[0318] In the above embodiments, all or part can be realized by software, hardware, firmware or any combination thereof. When realized by software, all or part can be realized in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer readable storage medium or transferred from one computer readable storage medium to another computer readable storage medium, for example, the computer instructions can be transmitted from one website site, computer, server or data center to another website site, computer, server or data center through wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.) mode. The computer readable storage medium can be any available medium readable by a computer or a data storage device such as a server, data center, etc. integrated with one or more available media. The available media can be magnetic media (such as floppy disk, hard disk, magnetic tape), optical media (such as digital video disc (DVD)) or semiconductor media (such as solid state disk (SSD)) and the like.

[0319] The above is only a specific embodiment of the present application, but the protection scope of the present application is not limited thereto. Any skilled person in the art can easily think of changes or replacements within the technical range disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A method of wireless communication, comprising: Comprising: a first device sending a first message to a second device, the first message being used for requesting access to a data plane, the first message comprising a first digital certificate; and / or the first device receiving a second message sent by the second device, the second message being used for requesting the first device to participate in a service of the data plane, the second message comprising a second digital certificate; wherein the second device is configured to authenticate and / or control the first device for data plane access, and the first digital certificate and / or the second digital certificate is / are used for one or more of the following: access authentication of the data plane, access control of the data plane.

2. The method of claim 1, wherein, The first digital certificate is used for determining a service of the data plane that the first device is authorized to use.

3. The method according to claim 1 or 2, characterized in that, The first digital certificate comprises first information, the first information being used for indicating a service of the data plane that a holder of the first digital certificate is authorized to use.

4. The method of claim 3, wherein, The first information comprises one or more of the following: first indication information, used for indicating that a holder of the first digital certificate is authorized to use all services of the data plane; second indication information, used for indicating a type of service of the data plane that a holder of the first digital certificate is authorized to use; third indication information, used for indicating a type of data operation that a holder of the first digital certificate is authorized to perform.

5. The method according to any one of claims 1-4, characterized in that, The method further comprises: the first device obtaining the first digital certificate, the first digital certificate being obtained based on one or more of the following: in a process of initial registration to a network; in a process of registration to the data plane; requested from a Public Key Infrastructure, PKI, portal; configured by an operator; configured by a vendor.

6. The method according to any one of claims 1-5, characterized in that, The first digital certificate is determined based on one or more of the following information: subscription information of the first device in a core network; information provided by the first device; a type of service of the data plane indicated by the first message.

7. The method of claim 6, wherein, The information provided by the first device comprises one or more of the following: first capability information, used for indicating a service of the data plane that the first device is entitled to obtain; a public key of the first device; an intended use of the first digital certificate by the first device; an identity of the first device.

8. The method according to any one of claims 1-7, characterized in that, The second digital certificate is determined based on information provided by the second device.

9. The method of claim 8, wherein, The information provided by the second device comprises one or more of the following: a public key of the second device; an intended use of the second digital certificate by the second device; an identity of the second device.

10. The method according to any one of claims 1-9, characterized in that, The first digital certificate is issued to the first device in a case that the first device passes an authorization check; and / or, the second digital certificate is issued to the second device in a case that the second device passes an authorization check.

11. The method of claim 10, wherein, The authorization check of the first device is based on subscription information provided by a core network.

12. The method according to any one of claims 1-11, characterized in that, The first digital certificate and / or the second digital certificate supports access authentication and / or access control of the data plane across domains.

13. The method of claim 12, wherein, The cross-domain comprises one or more of the following: the first device and the second device belong to different Public Land Mobile Networks, PLMNs; the first device and the second device belong to different operator networks; The first device belongs to a terminal device domain, and the second device belongs to a core network domain. The first device belongs to an access network domain, and the second device belongs to a core network domain. The first device belongs to a network management device domain, and the second device belongs to a core network domain. The first device belongs to an application device domain, and the second device belongs to a core network domain.

14. The method of any one of claims 1-13, wherein, The first device includes one or more of the following: a terminal device, an access network device, a network element in a core network, a network management device, and an application device.

15. A method of wireless communication, comprising: comprises: The second device receives a first message sent by the first device, the first message being used to request access to a data plane, and the first message including a first digital certificate; and / or The second device sends a second message to the first device, the second message being used to request the first device to participate in services of the data plane, and the second message including a second digital certificate; The second device is configured to authenticate and / or control the first device to access the data plane, and the first digital certificate and / or the second digital certificate is / are used for one or more of the following: access authentication of the data plane, access control of the data plane.

16. The method of claim 15, wherein, The first digital certificate is used to determine services of the data plane that the first device is authorized to use.

17. The method according to claim 15 or 16, characterized in that, The first digital certificate includes first information, the first information being used to indicate services of the data plane that a holder of the first digital certificate is authorized to use.

18. The method of claim 17, wherein, The first information includes one or more of the following: First indication information, used to indicate that a holder of the first digital certificate is authorized to use all services of the data plane; Second indication information, used to indicate a type of service of the data plane that a holder of the first digital certificate is authorized to use; Third indication information, used to indicate a type of data operation that a holder of the first digital certificate is authorized to use.

19. The method according to any one of claims 15-18, characterized in that, The method further comprises: The second device obtains the second digital certificate, and the second digital certificate is obtained based on one or more of the following: Obtained in a process of registering to the data plane; Configured by a public key infrastructure (PKI) portal; Configured by an operator; Configured by a vendor.

20. The method of any one of claims 15-19, wherein, The first digital certificate is determined based on one or more of the following information: Subscription information of the first device in a core network; Information provided by the first device; A type of service of the data plane indicated by the first message.

21. The method of claim 20, wherein, The information provided by the first device includes one or more of the following: First capability information, used to indicate services of the data plane that the first device is entitled to obtain; A public key of the first device; An intended use of the first digital certificate by the first device; An identifier of the first device.

22. The method of any one of claims 15-21, wherein, The second digital certificate is determined based on information provided by the second device.

23. The method of claim 22, wherein, The information provided by the second device includes one or more of the following: A public key of the second device; An intended use of the second digital certificate by the second device; An identifier of the second device.

24. The method of any one of claims 15-23, wherein, The first digital certificate is issued to the first device after an authorization check of the first device; and / or, the second digital certificate is issued to the second device after an authorization check of the second device.

25. The method of claim 24, wherein, The authorization check of the first device is based on subscription information provided by a core network.

26. The method of any one of claims 15-25, wherein, The first digital certificate and / or the second digital certificate support access authentication and / or access control of a data plane across domains.

27. The method of claim 26, wherein, The cross-domain includes one or more of the following: The first device and the second device belong to different public land mobile networks (PLMNs); The first device and the second device belong to different operator networks; The first device belongs to a terminal device domain, and the second device belongs to a core network domain; The first device belongs to an access network domain, and the second device belongs to a core network domain; The first device belongs to a network management device domain, and the second device belongs to a core network domain; The first device belongs to an application device domain, and the second device belongs to a core network domain.

28. The method of any one of claims 15-27, wherein, The first device includes one or more of the following: a terminal device, an access network device, a network element in a core network, a network management device, and an application device.

29. A communications device, characterized by The communication device is a first device, and the communication device includes: a sending module configured to send a first message to a second device, the first message being used to request access to a data plane, the first message including a first digital certificate; and / or a receiving module configured to receive a second message sent by the second device, the second message being used to request the first device to participate in services of the data plane, the second message including a second digital certificate; wherein the second device is configured to authenticate and / or control the first device to access the data plane, and the first digital certificate and / or the second digital certificate are used for one or more of the following: access authentication of the data plane, and access control of the data plane.

30. The communication device of claim 29, wherein, The first digital certificate is used to determine services of the data plane that the first device is authorized to use.

31. The communication device of claim 29 or 30, wherein, The first digital certificate includes first information, the first information being used to indicate services of the data plane that a holder of the first digital certificate is authorized to use.

32. The communication device of claim 31, wherein, The first information includes one or more of the following: first indication information, used to indicate that the holder of the first digital certificate is authorized to use all services of the data plane; second indication information, used to indicate a type of service of the data plane that the holder of the first digital certificate is authorized to use; third indication information, used to indicate a type of data operation that the holder of the first digital certificate is authorized to use.

33. The communication device of any of claims 29-32, wherein, The communication device further includes: an obtaining module configured to obtain the first digital certificate, the first digital certificate being obtained based on one or more of the following: obtained in a process of initial registration to a network; obtained in a process of registration to the data plane; requested from a public key infrastructure (PKI) portal; configured by an operator; configured by a vendor.

34. The communication device of any of claims 29-33, wherein, The first digital certificate is determined based on one or more of the following information: subscription information of the first device in a core network; information provided by the first device; a type of service of the data plane indicated by the first message.

35. The communication device of claim 34, wherein, The information provided by the first device includes one or more of the following: first capability information, used to indicate services of the data plane that the first device is entitled to obtain; a public key of the first device; an intended use of the first digital certificate by the first device; and / or a type of service of the data plane that the first device is entitled to obtain. an identity of the first device.

36. The communication device of any of claims 29-35, wherein, The second digital certificate is determined based on information provided by the second device.

37. The communication device of claim 36, wherein, The information provided by the second device comprises one or more of the following: a public key of the second device; an intended use of the second digital certificate by the second device; an identity of the second device.

38. The communication device of any of claims 29-37, wherein, The first digital certificate is issued to the first device in case of an authorization check of the first device; and / or, the second digital certificate is issued to the second device in case of an authorization check of the second device.

39. The communication device of claim 38, wherein, The authorization check of the first device is based on subscription information provided by a core network.

40. The communication device of any of claims 29-39, wherein, The first digital certificate and / or the second digital certificate support access authentication and / or access control of a data plane across domains.

41. The communication device of claim 40, wherein, The cross-domain comprises one or more of the following: The first device and the second device belong to different public land mobile networks (PLMNs); The first device and the second device belong to different operator networks; The first device belongs to a terminal device domain, and the second device belongs to a core network domain; The first device belongs to an access network domain, and the second device belongs to a core network domain; The first device belongs to a network management device domain, and the second device belongs to a core network domain; The first device belongs to an application device domain, and the second device belongs to a core network domain.

42. The communication device of any of claims 29-41, wherein, The first device comprises one or more of the following: a terminal device, an access network device, a network element in a core network, a network management device, and an application device.

43. A communications device, characterized by The communication device is a second device, and the communication device comprises: a receiving module configured to receive a first message sent by a first device, the first message being used to request access to a data plane, and the first message comprising a first digital certificate; and / or a sending module configured to send a second message to the first device, the second message being used to request the first device to participate in services of the data plane, and the second message comprising a second digital certificate; wherein the second device is configured to authenticate and / or control the first device to access the data plane, and the first digital certificate and / or the second digital certificate is / are used for one or more of the following: access authentication of the data plane, and access control of the data plane.

44. The communication device of claim 43, wherein, The first digital certificate is used to determine services of the data plane that the first device is authorized to use.

45. The communication device of claim 43 or 44, wherein, The first digital certificate comprises first information, and the first information is used to indicate services of the data plane that a holder of the first digital certificate is authorized to use.

46. The communication device of claim 45, wherein, The first information comprises one or more of the following: first indication information used to indicate that the holder of the first digital certificate is authorized to use all services of the data plane; second indication information used to indicate a type of service of the data plane that the holder of the first digital certificate is authorized to use; third indication information used to indicate a type of data operation that the holder of the first digital certificate is authorized to perform.

47. The communication device of any of claims 43-46, wherein, The communication device further comprises: an obtaining module configured to obtain the second digital certificate, and the second digital certificate is obtained based on one or more of the following: obtained in a process of registering to the data plane; configured by a public key infrastructure (PKI) portal; configured by an operator. The first digital certificate is configured by a vendor.

48. The communication device of any of claims 43-47, wherein, The first digital certificate is determined based on one or more of the following information: Subscription information of the first device in a core network; Information provided by the first device; A type of service of a data plane indicated by the first message.

49. The communication device of claim 48, wherein, The information provided by the first device comprises one or more of the following: First capability information indicating services of a data plane to which the first device has access; A public key of the first device; An intended use of the first digital certificate by the first device; An identity of the first device.

50. The communication device of any of claims 43-49, wherein, The second digital certificate is determined based on information provided by the second device.

51. The communication device of claim 50, wherein, The information provided by the second device comprises one or more of the following: A public key of the second device; An intended use of the second digital certificate by the second device; An identity of the second device.

52. The communication device of any of claims 43-51, wherein, The first digital certificate is issued to the first device upon passing of an authorization check of the first device; and / or, the second digital certificate is issued to the second device upon passing of an authorization check of the second device.

53. The communication device of claim 52, wherein, The authorization check of the first device is based on subscription information provided by a core network.

54. The communication device of any of claims 43-53, wherein, The first digital certificate and / or the second digital certificate support access authentication and / or access control of a data plane across domains.

55. The communication device of claim 54, wherein, The cross-domain comprises one or more of the following: The first device and the second device belong to different public land mobile networks (PLMNs); The first device and the second device belong to different operator networks; The first device belongs to a terminal device domain and the second device belongs to a core network domain; The first device belongs to an access network domain and the second device belongs to a core network domain; The first device belongs to a network management device domain and the second device belongs to a core network domain; The first device belongs to an application device domain and the second device belongs to a core network domain.

56. The communication device of any of claims 43-55, wherein, The first device comprises one or more of the following: a terminal device, an access network device, a network element in a core network, a network management device, an application device.

57. A communications device, characterized by A communication device comprising a transceiver, a memory and a processor, the memory being configured to store a program, the processor being configured to invoke the program in the memory and control the transceiver to receive or send a signal, so that the communication device performs the method of any one of claims 1-14 or 15-28.

58. An apparatus, comprising: A device comprising a processor configured to invoke a program from a memory, so that the device performs the method of any one of claims 1-14 or 15-28.

59. A chip, comprising: A chip comprising a processor configured to invoke a program from a memory, so that a device installed with the chip performs the method of any one of claims 1-14 or 15-28.

60. A computer-readable storage medium, characterized in that, A computer program product having a program stored thereon, the program causing a computer to perform the method of any one of claims 1-14 or 15-28.

61. A computer program product, characterised in that, A computer program product having a program stored thereon, the program causing a computer to perform the method of any one of claims 1-14 or 15-28.

62. A computer program, characterized in that, The computer program product causes a computer to perform the method of any one of claims 1-14 or 15-28.

Citation Information

Patent Citations

  • End-to-end authentication and key negotiation method, device and system

    CN109905348A

  • User-related data service processing method, device and network element

    CN115915127A

  • Communication authentication method and device

    CN118250687A

  • Mobile network authentication method and apparatus

    WO2017201753A1

  • Session establishment method and related apparatus

    WO2023016160A1