Token processing method, communication device, and storage medium
By receiving and updating token status information at the first node, the problem of erroneous responses from NF service consumers when acquiring token status is resolved, thereby improving resource utilization efficiency and response accuracy.
Patent Information
- Application Number
- PCT/CN2024/111315
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-08-11
- Publication Date
- 2026-02-19
AI Technical Summary
In existing technologies, NF service consumers are prone to making erroneous responses when acquiring token status, resulting in invalid or revoked service requests, leading to resource waste and inefficiency.
By receiving information from the second node at the first node, obtaining the token status, and updating the token status according to the local policy, the number of service requests in invalid or revoked states is reduced.
This effectively reduces service requests in invalid or revoked states, improving resource utilization efficiency and response accuracy.
Smart Images

Figure CN2024111315_19022026_PF_FP_ABST
Abstract
Description
Token processing method, communication device and storage medium TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of communication, and particularly relates to a token processing method, a communication device and a storage medium. BACKGROUND
[0002] An NF service producer provides a service for an NF service consumer, and the NF service consumer requests the service based on a token issued by a network repository function (NRF). The token can be used by the NF service producer to determine whether a corresponding request end has the permission to request the corresponding service.
[0003] SUMMARY
[0004] Embodiments of the present disclosure provide a token processing method, a communication device and a storage medium.
[0005] According to a first aspect of embodiments of the present disclosure, a token processing method is provided, wherein the method is performed by a first node, and the method comprises: receiving first information sent by a second node, the first information being used for the first node to obtain a token state of a first token.
[0006] According to a second aspect of embodiments of the present disclosure, a token processing method is provided, wherein the method is performed by a second node, and the method comprises: sending first information to a first node, the first information being used for the first node to obtain a token state of a first token.
[0007] According to a third aspect of embodiments of the present disclosure, a token processing method is provided, wherein the method is performed by a third node, and the method comprises: sending third information to a first node; the third information is used for the first node to perform a token state related operation.
[0008] According to a fourth aspect of embodiments of the present disclosure, a token processing method is provided, wherein the method is performed by a fourth node, and the method further comprises: receiving sixth information sent by a second node; the sixth information is used for indicating the fourth node to update a token state of a third token, or the sixth information is used for indicating the fourth node to store the updated token state.
[0009] According to a fifth aspect of embodiments of the present disclosure, a first node is provided, and the first node comprises: a receiving module configured to receive first information sent by a second node, the first information being used for the first node to obtain a token state of a first token.
[0010] According to a sixth aspect of the embodiments of the present disclosure, a second node is provided, and the second node comprises: a sending module configured to send first information to a first node, the first information being used by the first node to obtain a token state of a first token.
[0011] According to a seventh aspect of the embodiments of the present disclosure, a third node is provided, and the third node comprises: a receiving module configured to send third information to a first node, the third information being used by the first node to perform a token state related operation.
[0012] According to an eighth aspect of the embodiments of the present disclosure, a fourth node is provided, and the fourth node comprises:
[0013] a sending module configured to receive sixth information sent by a second node, the sixth information being used to indicate that the fourth node updates a token state of a third token, or the sixth information being used to indicate that the fourth node stores the updated token state.
[0014] According to a ninth aspect of the embodiments of the present disclosure, a communication system is provided, and the communication system comprises a first node, a second node, a third node and a fourth node; the first node is a network function used to perform the token processing method provided in any of the technical solutions of the first aspect; the second network function node is used to perform the token processing method provided in any of the technical solutions of the second aspect; the third node is used to perform the third aspect; and the fourth node is used to perform the token processing method provided in any of the technical solutions of the fourth aspect.
[0015] According to a tenth aspect of the embodiments of the present disclosure, a communication device is provided, and the communication device comprises: one or more processors; and the processor is used to call instructions to make the communication device perform the token processing method provided in any of the technical solutions of the first aspect to the fourth aspect.
[0016] According to an eleventh aspect of the embodiments of the present disclosure, a storage medium is provided, and the storage medium stores instructions, when the instructions are run on a communication device, the communication device is caused to perform the token processing method provided in any of the first aspect to the fourth aspect.
[0017] According to a fourteenth aspect of the embodiments of the present disclosure, a program product is provided, and the program product comprises a computer program, when the computer program is executed by a communication device, the communication device is caused to implement the token processing method provided in any of the technical solutions of the first aspect to the fourth aspect.
[0018] The technical manner provided by the embodiments of the present disclosure is that the first node receives the first information of the second node, so that the token state of the third node in the current state of the first node is obtained, thereby reducing the false response of the service request of the third node in the invalid state or the revoked state.
[0019] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the embodiments of the present disclosure. BRIEF DESCRIPTION OF DRAWINGS
[0020] The accompanying drawings, which are incorporated into the specification and constitute part of the specification, illustrate embodiments consistent with the present disclosure and, together with the specification, serve to explain the principles of the embodiments of the present disclosure.
[0021] FIG. 1A is a schematic diagram of an architecture of a communication system according to an exemplary embodiment;
[0022] FIG. 1B is a schematic diagram of a token revocation process according to an exemplary embodiment;
[0023] FIG. 2A is a schematic diagram of interactions of a token processing method according to an exemplary embodiment;
[0024] FIG. 2B is a schematic diagram of interactions of a token processing method according to an exemplary embodiment;
[0025] FIG. 3A is a schematic diagram of a flow of a token processing method according to an exemplary embodiment;
[0026] FIG. 3B is a schematic diagram of a flow of a token processing method according to an exemplary embodiment;
[0027] FIG. 4A is a schematic diagram of a flow of a token processing method according to an exemplary embodiment;
[0028] FIG. 4B is a schematic diagram of a flow of a token processing method according to an exemplary embodiment;
[0029] FIG. 5A is a schematic diagram of a flow of a token processing method according to an exemplary embodiment;
[0030] FIG. 5B is a schematic diagram of a flow of a token processing method according to an exemplary embodiment;
[0031] FIG. 6A is a schematic diagram of a flow of a token processing method according to an exemplary embodiment;
[0032] FIG. 6B is a schematic diagram of a flow of a token processing method according to an exemplary embodiment;
[0033] FIG. 7A is a schematic diagram of a structure of a first node according to an exemplary embodiment;
[0034] FIG. 7B is a schematic diagram of a structure of a second node according to an example embodiment;
[0035] FIG. 7C is a schematic diagram of a structure of a third node according to an example embodiment;
[0036] FIG. 7D is a schematic diagram of a structure of a third node according to an example embodiment;
[0037] FIG. 8A is a schematic diagram of a structure of a communication device according to an example embodiment;
[0038] FIG. 8B is a schematic diagram of a structure of a chip according to an example embodiment. DETAILED DESCRIPTION
[0039] Embodiments of the present disclosure provide a token processing method, a communication device, a communication system and a storage medium.
[0040] The first aspect provides a token processing method, wherein the method is performed by a first node, and the method comprises: receiving first information sent by a second node, the first information being used for the first node to obtain a token state of a first token.
[0041] Based on the above scheme, the first node receives the first information of the second node, so that the first node can obtain the token state of the third node under the current condition, thereby reducing the false response of the service request to the third node when the token state is invalid or revoked.
[0042] In some embodiments of the first aspect, before the receiving the first information sent by the second node, the method further comprises:
[0043] sending second information to the second node, the second information being used for the second node to perform an operation related to token state acquisition.
[0044] In this way, the first node can request the first information from the second node by sending the second information, so as to obtain the information required by the first node to update the token.
[0045] In some embodiments of the first aspect, the sending the second information to the second node comprises:
[0046] receiving third information sent by a third node, and sending the second information to the second node; the third information being used for the second node to request a service from the first node based on a second token; or the third information being used for obtaining a token state of the second token; the second token belonging to the first token.
[0047] Based on the above scheme, the first node sends the second information to the second node only after receiving the third information, which can reduce unnecessary requests for the first information and achieve updating of the token state of a single third node.
[0048] In some embodiments of the first aspect, receiving the third information sent by the third node and sending the second information to the second node comprises:
[0049] Receiving the third information sent by the third node and the second token being issued at a time earlier than the configuration update time of the first node, and sending the second information to the second node.
[0050] Based on the above scheme, if the second token is issued at a time later than the configuration update time of the first node, the token state of the second token recorded by the first node is considered correct, and the second information does not need to be sent, thereby reducing unnecessary information transmission.
[0051] In some embodiments of the first aspect, the third information comprises at least one of:
[0052] The second token;
[0053] Token information of the second token; the token information of the second token comprises information of the third node, information of the first node, and first service information, the first service information being used to indicate a first service or a first service operation; the first service being a service that the third node is allowed to request from the first node when the token state of the second token is a first state; and the first service operation being a service operation that the third node is allowed to request from the first node when the token state of the second token is the first state.
[0054] Based on the above scheme, the third node requests a service from the first node based on the second token, and therefore the third information comprises the second token or token information of the second token, which facilitates the first node to determine whether to provide the service to the third node.
[0055] In some embodiments of the first aspect, the second information sent to the second node upon receiving the third information sent by the third node comprises at least one of:
[0056] First identification information, used to identify the first node;
[0057] Second identification information, used to identify the third node;
[0058] The second token;
[0059] Token information of the second token.
[0060] In some embodiments of the first aspect, when the second information comprises the second identification information, the first information comprises first type information; the first type information is used to indicate a first type, and the first type is a node type of the third node.
[0061] Based on the above scheme, after receiving the second information of the third node, the first node obtains the second identification information of the third node. Thus, the first node sends the second token, the token information of the second token, or the node identification of the third node to the first node, so as to facilitate the first node to determine the node type of the third node.
[0062] In some embodiments of the first aspect, the method further comprises: determining whether the first type is a second type according to a local policy of the first node; and updating a state of the second token according to whether the first type is the second type; the second type is a node type allowed to request a service from the first node after a configuration update of the first node.
[0063] Based on the above scheme, the first node determines whether the second token of the third node needs to be revoked or invalidated according to the local policy, so as to accurately provide a service to the third node.
[0064] In some embodiments of the first aspect, according to the local policy of the first node, determining whether the second type is a node type allowed to request a service from the first node after a configuration update of the first node, and updating the state of the second token, comprise:
[0065] According to the local policy of the first node, determining the first type;
[0066] When the first type is different from the second type, marking a token state of the second token as a second state; the second state is a token state not allowed to request a service from the first node;
[0067] When the first type is the same as the second type, marking the token state of the second token as a first state.
[0068] Based on the above scheme, a scheme is given for the first node to determine itself whether the token state of the second token.
[0069] In some embodiments of the first aspect, the method further comprises:
[0070] Sending fourth information to the third node, the fourth information being related to the third information.
[0071] Based on the above scheme, the first node responds to the third information of the third node by fourth information. In some embodiments, the fourth information is also used by the third node to determine the current token state of the second node of the third node.
[0072] In some embodiments of the first aspect, the third information is used to request the third node to request a service from the first node, and the token state of the second token is the first state, and the fourth information is used to indicate acceptance of the service request of the third node; or,
[0073] the third information is used to request the third node to request a service from the first node, and the token state of the second token is the second state, and the fourth information is used to reject the service request of the third node.
[0074] In some embodiments of the first aspect, the fourth information is used to reject the service request of the third node, and the fourth information further includes a failure reason; the failure reason is used to indicate that the token state of the second token is the second state.
[0075] Based on the above scheme, the fourth information contains a failure reason, which informs the third node of the reason why the service is rejected.
[0076] In some embodiments of the first aspect, the sending of the second information to the second node comprises: sending the second information to the second node in the case of configuration update of the first node.
[0077] Based on the above scheme, the second node sends the second information to the second node when the configuration of the second node is updated, so that the second node provides the first information to the first node.
[0078] In some embodiments of the first aspect, the second information sent to the second node in the case of configuration update of the first node comprises at least one of the following:
[0079] First identification information, the first identification information is used to identify the first node;
[0080] Second type information, the second type information is used to indicate a second type; the second type is a type of node allowed to request a service from the first node after the configuration update of the first node;
[0081] The second service information is used for indicating a second service or a second service operation; or the second service information is used for indicating a third service or a third service operation; the second service is a service that can be provided by the first node after the configuration update; the second service operation is a service operation that can be provided by the first node after the configuration update; or the third service is a service that is stopped from being provided by the first node after the configuration update; and the third service operation is a service operation that is stopped from being provided by the first node after the configuration update.
[0082] In some embodiments of the first aspect, the first information comprises at least one of the following in the case of the configuration update of the first node:
[0083] a third token; the third token belongs to the first token; and a token state of the third token is to be updated to a second state.
[0084] token information of the third token, the token information of the third token comprising information of the first node, information of a fourth node, and third service information; the fourth node is a node holding the third token, and the third service information is used for a fourth service or a fourth service operation; the fourth service is a service that the fourth node is allowed to request from the first node in the case that the token state of the third token is a first state; and the fourth service operation is a service operation that the fourth node is allowed to request from the first node in the case that the token state of the third token is the first state.
[0085] Based on the above scheme, the first node carries the above information, and then the first node can conveniently update the state of the first token according to the first information.
[0086] In some embodiments of the first aspect, the method further comprises: the first information comprises the third token, and the token state of the third token is marked as the second state; or the first information comprises token information of the third token, and the token state of the third token is identified as the second state.
[0087] In some embodiments of the first aspect, the second information is sent to the second node in the case of the configuration update of the first node, comprising:
[0088] In the case of the configuration update of the first node and in the case that the issuance time of the first token is earlier than the configuration update time of the first node, the second information is sent to the second node.
[0089] In this case, the first node determines that the issuance time of one or more of the first tokens related to the first node is earlier than the configuration update time of the first node, and sends the second information to the second node, so that unnecessary sending of the second information can be reduced.
[0090] In some embodiments of the first aspect, the method further comprises: sending fifth information to the second node; the fifth information is used to indicate that the token state of the first token has been updated; or the token state of the updated first token has been stored.
[0091] Based on the above scheme, the sending of the fifth information is used to realize that the first node informs the second node that the token state has been updated or the token state of the updated first token has been stored.
[0092] In some embodiments of the first aspect, the first state comprises at least one of the following: an active state, a valid state.
[0093] In some embodiments of the first aspect, the second state comprises at least one of the following: an invalid state, a revoked state, a deactivated state.
[0094] The second aspect provides a token processing method, wherein the method is performed by a second node, and the method comprises:
[0095] Sending first information to a first node, the first information being used by the first node to obtain a token state of a first token.
[0096] In some embodiments of the second aspect, the first information used by the first node to obtain the token state of the first token comprises:
[0097] In the case of detecting a configuration update of the first node, sending the first information to the second node;
[0098] Receiving second information sent by the second node, and sending the first information to the second node.
[0099] In some embodiments of the second aspect, the second information comprises at least one of the following:
[0100] First identification information, used to identify the first node;
[0101] Second identification information, used to identify a third node;
[0102] A second token; the second token is a token held by the third node;
[0103] Token information of the second token; the token information of the second token comprises information of the third node, information of the first node, and second service information, the second service information being used to indicate a service or service operation allowed to be requested by the third node from the first node based on the token state of the second token being a first state.
[0104] In some embodiments of the second aspect, the first information comprises first type information, in case that the second information is received; the first type information is used to indicate a first type, the first type being a node type of the third node.
[0105] In some embodiments of the second aspect, before the first information is sent to the first node, the method further comprises:
[0106] determining a configuration of the third node according to the second token;
[0107] determining a type of the third node according to the configuration of the third node.
[0108] In some embodiments of the second aspect, in case that the configuration of the first node is updated, the second information comprises at least one of:
[0109] first identification information, the first identification information being used to identify the first node;
[0110] second type information, the second type information being used to indicate a second type; the second type being a node type which is allowed to request services from the first node after the configuration of the first node is updated;
[0111] first service information, the first service information being used to indicate services or service operations which can be provided by the first node after the configuration of the first node is updated; or, the first service information being used to indicate services or service operations which are stopped to be provided by the first node after the configuration of the first node is updated.
[0112] In some embodiments of the second aspect, in case that the configuration of the first node is updated, the first information comprises at least one of:
[0113] a third token, the third token belonging to the first token, a token state of the third token being to be updated to a second state;
[0114] token information of the third token, the token information of the third token comprising information of the first node, information of a fourth node and third service information; the fourth node being a node holding the third token, the third service information being used to indicate services or service operations which are allowed to be requested by the fourth node from the first node in case that the token state of the third token is a first state.
[0115] In some embodiments of the second aspect, the method further comprises:
[0116] sending sixth information to a fourth node; the fourth node is a node whose token state needs to be updated to a second state, and the sixth information is used to instruct the fourth node to update the token state of the third token, or the sixth information is used to instruct the fourth node to store the updated token state.
[0117] In some embodiments of the second aspect, the method further comprises:
[0118] receiving seventh information sent by the fourth node, the seventh information being used to indicate that the token state of the third token has been updated, and the seventh information being used to indicate that the fourth node has stored the token state of the third token.
[0119] In some embodiments of the second aspect, before sending the first information to the first node, the method further comprises:
[0120] determining a third type according to the updated configuration of the first node, the third type being a node type of the fourth node; the fourth node being a node that is not allowed to request services from the first node after the configuration of the first node is updated;
[0121] determining third identification information according to the first token of the first node; the third identification information being used to indicate a fifth node holding the first token;
[0122] determining third type information according to the third identification information; the third type information being used to indicate a fourth type of the fifth node;
[0123] determining that the fifth node is the fourth node when the fourth type is the third type;
[0124] determining that the fifth node is not the fourth node when the fourth type is not the third type.
[0125] In some embodiments of the second aspect, the method further comprises:
[0126] receiving fifth information sent by the first node; the fifth information being used to indicate that the token state of the first token has been updated; or the updated token state of the first token has been stored.
[0127] A third aspect provides a token processing method, wherein the method is performed by a third node and comprises: sending third information to a first node; the third information being used to make the first node perform a token state related operation.
[0128] In some embodiments of the third aspect, the third information comprises second identification information; and the third information further comprises at least one of the following: a second token; token information of the second token;
[0129] The second identification information is used for identifying the third node.
[0130] Token information of the second token includes information of the third node, information of the first node, and second service information, the second service information is used for a third service or a third service operation, the third service is a service allowed to be requested by the third node from the first node in a case where a token state of the second token is a first state; and the third service operation is a service operation allowed to be requested by the third node from the first node in a case where the token state of the second token is the first state.
[0131] In some embodiments of the third aspect, the method further includes: receiving fourth information sent by the first node; and the fourth information is related to the third information.
[0132] In some embodiments of the third aspect, the third information is used for requesting the third node to request a service from the first node and the token state of the second token is the first state, and the fourth information is used for indicating that the service request of the third node is accepted; or
[0133] The third information is used for requesting the third node to request a service from the first node and the token state of the second token is the second state, and the fourth information is used for rejecting the service request of the third node.
[0134] In some embodiments of the third aspect, the fourth information is used for rejecting the service request of the third node, and the fourth information further includes a failure cause; and the failure cause is used for indicating that the token state of the second token is the second state.
[0135] In some embodiments of the third aspect, the method further includes: marking the token state of the second token as the second state according to the fourth information; and in a case where the token state of the second token is the second state, the third node is not allowed to request a service from the first node.
[0136] A fourth aspect provides a token processing method, wherein the method is processed by a fourth node, and the method includes:
[0137] Receiving sixth information sent by a second node; the sixth information is used for indicating that the fourth node updates a token state of a third token, or the sixth information is used for indicating that the fourth node stores the updated token state.
[0138] In some embodiments of the fourth aspect, the method further includes:
[0139] The seventh information is used to indicate that the token state of the third token has been updated, and the seventh information is used to indicate that the fourth node has stored the token state of the third token.
[0140] The fifth aspect provides a first node, and the first node comprises:
[0141] The receiving module is configured to receive first information sent by a second node, and the first information is used for the first node to acquire a token state of a first token.
[0142] The sixth aspect provides a second node, and the second node comprises:
[0143] The sending module is configured to send first information to a first node, and the first information is used for the first node to acquire a token state of a first token.
[0144] The seventh aspect provides a third node, and the third node comprises:
[0145] The receiving module is configured to send third information to a first node, and the third information is used to enable the first node to perform a token state related operation.
[0146] The eighth aspect provides a fourth node, and the fourth node comprises:
[0147] The sending module is configured to receive sixth information sent by a second node, and the sixth information is used to indicate that the fourth node updates a token state of a third token, or the sixth information is used to indicate that the fourth node stores the updated token state.
[0148] The ninth aspect provides a communication system, and the communication system comprises a first node, a second node, a third node and a fourth node.
[0149] The first node is used to perform the method in any of the technical solutions of the first aspect.
[0150] The second node is used to perform the method in any of the technical solutions of the second aspect.
[0151] The third node is used to perform the token processing method in any of the technical solutions of the third aspect.
[0152] The fourth node is used to perform the token processing method in any of the technical solutions of the fourth aspect.
[0153] In a tenth aspect, embodiments of this disclosure provide a program product, wherein the program product includes a computer program, which, when executed by a communication device, enables the communication device to implement the token processing method described in the optional implementations of the first to fourth aspects.
[0154] In one aspect, embodiments of this disclosure provide a computer program that, when run on a computer, causes the computer to perform the token processing method described in optional implementations of the first to fourth aspects.
[0155] It is understood that the UE, network device, communication system, program product, and computer program described above are all used to execute the methods provided in the embodiments of this disclosure. Therefore, the beneficial effects that can be achieved can be referred to the beneficial effects in the corresponding methods, and will not be repeated here.
[0156] This disclosure provides a token processing method, a communication device, a communication system, and a storage medium. The embodiments of this disclosure are not exhaustive, but merely illustrative of some embodiments, and are not intended to limit the specific scope of protection of this disclosure. Unless otherwise specified, each step in a particular embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, removing some steps from a particular embodiment can also be implemented as an independent embodiment, and the order of the steps in a particular embodiment can be arbitrarily interchanged. Furthermore, the optional implementations in a particular embodiment can be arbitrarily combined; moreover, the embodiments can be arbitrarily combined, for example, some or all steps of different embodiments can be arbitrarily combined, and a particular embodiment can be arbitrarily combined with optional implementations of other embodiments.
[0157] In each of the disclosed embodiments, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions of the embodiments are consistent and can be referenced by each other. Technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.
[0158] The terminology used in the embodiments of this disclosure is for the purpose of describing particular embodiments only and is not intended to limit the scope of this disclosure.
[0159] In this embodiment of the disclosure, unless otherwise stated, elements expressed in the singular form, such as "a," "an," "the," "the aforementioned," "this," etc., can mean "one and only one," or "one or more," "at least one," etc. For example, when using articles such as "a," "an," "the," etc. in translation, the noun following the article can be understood as either a singular expression or a plural expression.
[0160] In the embodiments of the present disclosure, "plurality" refers to two or more.
[0161] In some embodiments, the terms "at least one of," "one or more of," "a plurality of," "multiple," and the like can be alternatives to each other.
[0162] In some embodiments, the description of "at least one of A, B," "A and / or B," "in one case A and in another case B," "in one case A or in another case B," and the like, according to circumstances, can include the following technical manners: in some embodiments, A is performed (A is performed regardless of B); in some embodiments, B is performed (B is performed regardless of A); in some embodiments, A and B are selectively performed (A and B are selectively performed); in some embodiments, A and B are both performed (A and B are both performed). When there are more branches such as A, B, and C, the above manners are similar.
[0163] In some embodiments, the description of "A or B" and the like, according to circumstances, can include the following technical manners: in some embodiments, A is performed (A is performed regardless of B); in some embodiments, B is performed (B is performed regardless of A); in some embodiments, A and B are selectively performed (A and B are selectively performed). When there are more branches such as A, B, and C, the above manners are similar.
[0164] The prefix words of "first", "second" and the like in the embodiments of the present disclosure are merely used to distinguish different description objects, and do not constitute limitation on the position, order, priority, quantity or content of the description objects. The description objects are described in the claims or embodiments in the context, and should not be construed as redundant limitation because of the use of the prefix words. For example, the ordinal words in front of the description objects "field" in "first field" and "second field" do not limit the position or order between the "fields", and "first" and "second" do not limit whether the "fields" modified thereby are in the same message or not, nor limit the order of "first field" and "second field". For another example, the ordinal words in front of the description objects "level" in "first level" and "second level" do not limit the priority between the "levels". For another example, the quantity of the description objects is not limited by the ordinal words, and can be one or more. For example, "first device", in which the quantity of "device" can be one or more. In addition, the objects modified by different prefix words can be the same or different, for example, the description objects are "device", and "first device" and "second device" can be the same device or different devices, and the types thereof can be the same or different; for another example, the description objects are "information", and "first type of information" and "second type of information" can be the same information or different information, and the contents thereof can be the same or different.
[0165] In some embodiments, "including A", "containing A", "for indicating A", "carrying A" can be interpreted as directly carrying A, or indirectly indicating A.
[0166] In some embodiments, the terms of "…", "determining …", "in the case of …", "when …", "when …", "if …", "if …" and the like can be replaced with each other.
[0167] In some embodiments, the terms of "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not lower than", "above" and the like can be replaced with each other, and the terms of "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", "below" and the like can be replaced with each other.
[0168] In some embodiments, the apparatus and the like can be interpreted as physical or virtual, and the name thereof is not limited to the name recorded in the embodiments. The terms of "apparatus", "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", "subject" and the like can be replaced with each other.
[0169] In some embodiments, “network” can be interpreted as the devices (e.g., access network devices, core network devices, etc.) included in the network.
[0170] In some embodiments, the terms “access network device (AN device),” “radio access network device (RAN device),” “base station (BS),” “radio base station,” “fixed station,” “node,” “access point,” “transmission point (TP),” “reception point (RP),” “transmission / reception point (TRP),” “panel,” “antenna panel,” “antenna array,” “cell,” “macro cell,” “small cell,” “femto cell,” “pico cell,” “sector,” “cell group,” “serving cell,” “carrier,” “component carrier,” “bandwidth part (BWP),” etc. can be replaced with each other.
[0171] In some embodiments, the terms "terminal," "terminal device," "user equipment (UE)," "user UE," "mobile station (MS)," "mobile UE (MT)," "subscriber station," "mobile unit," "subscriber unit," "wireless unit," "remote unit," "mobile device," "wireless device," "wireless communication device," "remote device," "mobile subscriber station," "access UE," "mobile terminal," "wireless terminal," "remote terminal," "handset," "user agent," "mobile client," "client," and so on can be replaced with each other.
[0172] In some embodiments, the access network device, the core network device, or the network device can be replaced with the UE. For example, the embodiments of the present disclosure can also be applied to a structure in which communication between the access network device, the core network device, or the network device and the UE is replaced with communication between a plurality of UEs (e.g., device-to-device (D2D), vehicle-to-everything (V2X), and so on). In this case, the structure in which the UE has all or part of the functions of the access network device can also be provided. In addition, the terms "uplink," "downlink," and so on can also be replaced with terms corresponding to the inter-UE communication (e.g., "side"). For example, the uplink channel, the downlink channel, and so on can be replaced with the side channel, and the uplink, the downlink, and so on can be replaced with the sidelink.
[0173] In some embodiments, the UE can be replaced with the access network device, the core network device, or the network device. In this case, the structure in which the access network device, the core network device, or the network device has all or part of the functions of the UE can also be provided.
[0174] In some embodiments, obtaining data, information, and the like can comply with laws and regulations of the country where the location is situated.
[0175] In some embodiments, data, information, and the like can be obtained after obtaining consent of the user.
[0176] In addition, each element, each row, or each column in the table of the embodiments of the present disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.
[0177] FIG. 1A is a schematic diagram of an architecture of a communication system according to an embodiment of the present disclosure.
[0178] As shown in FIG. 1A, the communication system 100 includes a terminal (terminal) 101 and a network device 102. The network device 102 can include an access network device and / or a core network device. The terminal can also be referred to as a user equipment (User Equipment, UE).
[0179] In some embodiments, the UE 101 includes at least one of a mobile phone, a wearable device, an Internet of Things device, a car with communication function, a smart car, a tablet computer (Pad), a computer with wireless transceiver function, a virtual reality (virtual reality, VR) UE device, an augmented reality (augmented reality, AR) UE device, a wireless UE device in industrial control, a wireless UE device in self-driving, a wireless UE device in remote medical surgery, a wireless UE device in smart grid, a wireless UE device in transportation safety, a wireless UE device in smart city, a wireless UE device in smart home, and the like, but is not limited thereto.
[0180] In some embodiments, the UE is also referred to as a user equipment (User Equipment, UE).
[0181] In some embodiments, the access network device may, for example, be at least one of a node or a device that accesses a UE to a wireless network, and the access network device may, for example, include at least one of an evolved NodeB (eNB) in a 5G communication system, a next generation eNB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home node B (HNB), a home evolved node B (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an Open RAN, a Cloud RAN, a base station in other communication systems, an access node in a Wi-Fi system, but is not limited thereto.
[0182] In some embodiments, the technical means of the present disclosure can be applicable to an Open RAN architecture, in which case the interfaces between or within the access network devices involved in the embodiments of the present disclosure can become internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces can be implemented through software or programs.
[0183] In some embodiments, the access network device can be composed of a central unit (CU) and a distributed unit (DU), where the CU can also be referred to as a control unit. The CU-DU structure can split the protocol layers of the access network device, and some of the protocol layers can be controlled by the CU, while the rest or all of the protocol layers can be distributed in the DU and controlled by the CU, but is not limited thereto.
[0184] In some embodiments, the core network device can be one device including the first network element, or a plurality of devices or device groups each including the first network element. The network element can be virtual or physical. The core network may, for example, include at least one of an evolved packet core (EPC), a 5G core network (5GCN), and a next generation core (NGC).
[0185] It can be understood that the communication system described in the embodiments of the present disclosure is for more clearly illustrating the technical means of the embodiments of the present disclosure, and does not constitute a limitation on the technical means provided by the embodiments of the present disclosure. It can be known by those skilled in the art that, as the system architecture evolves and new service scenarios appear, the technical means provided by the embodiments of the present disclosure are also applicable to similar technical problems.
[0186] The embodiments of the present disclosure described below can be applied to the communication system 100 shown in FIG. 1A or part of the subjects, but are not limited thereto. The subjects shown in FIG. 1A are exemplary, and the communication system can include all or part of the subjects in FIG. 1A, or other subjects other than those in FIG. 1A. The number and form of each subject is arbitrary, and the connection relationship between the subjects is exemplary. The subjects can not be connected or can be connected, and the connection can be in any manner, can be direct connection or indirect connection, and can be wired connection or wireless connection.
[0187] Embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (Bluetooth (registered trademark)), Public Land Mobile Network (PLMN) network, Device-to-Device (D2D) system, Machine to Machine (M2M) system, Internet of Things (IoT) system, Vehicle-to-Everything (V2X), system using other resources, next-generation system extended based thereon, and the like. In addition, a plurality of systems can be combined (for example, combination of LTE and NR).
[0188] In some cases, due to network service or network management related business updates, network operators can prohibit or restrict a consumer from using one or more services provided by a producer. The NF service producer needs to update the NF profile using the NRF. After the NF profile is updated, the NF service consumer whose token is revoked will no longer have access to the services provided by the NF service producer.
[0189] However, in some cases, the NF consumer whose token is revoked does not know the token status update. At this time, the NF consumer whose token is revoked still accesses the NF service producer based on the token previously issued by the NRF to request the NF service producer to provide services again. For example, the NF consumer requests the NF service producer to provide services using the issued token that has not expired.
[0190] When the NF service producer receives a service request from the NF consumer whose token is revoked, the NF consumer can still successfully obtain services from the NF service producer, while in fact the NF consumer whose token is revoked is not allowed to do so or should not do so. Therefore, it is necessary to study how to revoke the token or invalidate the token.
[0191] In the disclosed embodiments, the communication system can revoke or invalidate the token for disabling the token. The following terms have the same meaning: revoked token, invalid token, inactive token. A valid token is also considered an active token.
[0192] As shown in FIG. IB, a method of invalidating a token can include:
[0193] Step 0: The NF service consumer obtains a token from the NRF to access the NF service producer. In some embodiments, the token can authorize the NF service consumer to access the service, service operation or resource of the NF service producer. In some embodiments, the service includes multiple service operations. For example, the Nudm_UECM (UECM) service includes the Nudm_UECM_Registration service operation. In some embodiments, after the NF service consumer obtains the service authorization, it obtains the authorization of all service operations included in the service.
[0194] Step 1: If it is necessary to limit access to the services provided by a specific NF service producer. For example, a certain NF service consumer is not allowed to access, the NF service producer uses Nnrf_NFManagement_NF Update_request to update its NF profile. Compared with the original NF profile, part of the original authorization information is invalid.
[0195] Step 2: includes Step 2a and Step 2b.
[0196] Step 2a: After performing the NF profile update, the NRF retrieves the token according to the NF service producer’s ID, and identifies the token that needs to be revoked according to the NF instance ID of the consumer in the token. Exemplarily, the NRF identifies the NF profile of the consumer using the NF instance ID of the NF service consumer, and then obtains its NF type. If the profile of the NF service producer does not allow the NF type of the NF service consumer to request the expected service (e.g., Nudm_UECM (UECM) service) or service operation (e.g., Nudm_UECM_Registration service operation) recorded in the token, the token is invalid.
[0197] Step 2b: If Step 1 is not performed, the NRF identifies the token that needs to be revoked or invalidated according to the operator-provided policy, i.e., according to the operator’s policy, when the authorization in the token is not allowed, the token should be revoked or invalidated.
[0198] The NRF sends information (such as token ID) identifying the revoked or invalid token to the NF service producer.
[0199] The NF service producer marks the revoked token by the audience declaration in the revoked token.
[0200] Step 3: After receiving the information (e.g., token ID) that can indicate the revoked token, the NF service producer should store information about the revoked token so as to reject the service request from the revoked authorized consumer later when receiving the service request.
[0201] Step 4: The NF service producer sends a response related to the authorization revocation to the NRF. The response indicates that the authorization revocation has been completed.
[0202] Step 5: The NRF identifies the revoked NF service consumer according to the NF profile update information, and sends information (such as token ID) that can identify the revoked token to the NF service consumer.
[0203] Step 6: The NF service consumer invalidates the token according to the information (such as token ID) that can identify the revoked token.
[0204] Step 7: The NF service consumer sends a response related to the authorization revocation to the NRF. The response indicates that the authorization revocation has been completed.
[0205] Step 8: If the NF service consumer is not notified about the token revocation information (step 5-7 is not performed), the NF service consumer can send the service request to the NF service producer with the revoked token.
[0206] Step 9: After receiving the revoked token, the NF service producer verifies whether the token is revoked according to the information provided by the NRF.
[0207] If the token is revoked, the NF service producer rejects the service request. The NF service producer sends a service response or failure message to the NF service consumer. The service response or failure message indicates that the token is revoked or the service request is rejected due to the token being revoked.
[0208] As shown in FIG. 2A, the embodiments of the present disclosure provide a token processing method processed by the communication system shown in FIG. 1A, and the method comprises:
[0209] S2101: The third node sends third information to the first node.
[0210] In some embodiments, the third node can include but is not limited to an NF service consumer.
[0211] In some embodiments, the third node can be a network device and / or a UE.
[0212] In some embodiments, the third node can be a network function (NF).
[0213] In some embodiments, the first node can include but is not limited to an NF service producer (Network Function Service Producer). Exemplarily, the first node can be various network functions, for example, a core network function. Exemplarily, the first node can include but is not limited to a location management function (LMF) and / or a network data analytics function (NWDAF).
[0214] In some embodiments, the third information is used for the second node to request a service from the first node based on a second token.
[0215] In some embodiments, the third information is used to obtain a token state of the second token.
[0216] In some embodiments, the first node determines whether to respond to the service requested by the first node based on the second token.
[0217] In some embodiments, the first token is a token associated with the first node.
[0218] In some embodiments, the first node requests different tokens in response to different nodes serving, and the tokens used can also be different.
[0219] In some embodiments, the third information comprises at least one of:
[0220] the second token;
[0221] token information of the second token; the token information of the second token comprises information of the third node, information of the first node, and first service information.
[0222] The first service information is used to indicate a first service or a first service operation.
[0223] In some embodiments, the token state comprises a first state and a second state.
[0224] In some other embodiments, the first state comprises at least one of: an active state, a valid state.
[0225] In some embodiments, the second state comprises at least one of: a revoked state, an invalid state, an inactive state.
[0226] The first service is a service that the third node is allowed to request from the first node in a case where the token state of the second token is the first state.
[0227] The first service operation is a service operation that the third node is allowed to request from the first node in a case where the token state of the second token is the first state.
[0228] In some embodiments, the token information of the second token can further comprise a token identifier of the second token, etc., and is not limited to the above examples of information.
[0229] In some embodiments, the third information is used for the third node to request a fourth service from the first node.
[0230] In some embodiments, the third information further comprises a second node identifier of the third node, which can comprise but is not limited to an instance identifier (ID) of the third node. In some embodiments, the instance identifier of the third node is a network function instance identifier (NF instance ID).
[0231] It is worth noting that S2101 is an optional step. For example, the first node actively requests the token state update from the second node, and the third node does not need to send the third information, so S2101 is an optional step. For another example, the second node actively informs the first node of the token state update, and the third node does not need to send the third information to trigger the token state update of the first node.
[0232] S2102: The first node sends second information to the second node.
[0233] In some embodiments, the second node can be a network function that stores tokens of various nodes, and / or token states and / or token information. For example, the second node can be a core network function that stores token states and / or token information. In some embodiments, the second node is a network storage function (NRF).
[0234] In some embodiments, the second information is used to enable the second node to perform an operation related to the token state of the first token obtained by the first node.
[0235] In some embodiments, the first node sends second information to the second node upon receiving the third information.
[0236] In some embodiments, the first node sends second information to the second node upon receiving the third information and not having received the first information sent by the second node.
[0237] Upon receiving the third information sent by the third node and the issuance time of the second token being earlier than the configuration update time of the first node, the second information is sent to the second node.
[0238] Based on the above scheme, in this way, if the issuance time of the second token is later than the configuration update time of the first node, it can be considered that the token state of the second token currently recorded by the first node is correct, and there is no need to send the second information, thereby reducing unnecessary information transmission.
[0239] In some embodiments, the first node can actively send second information to the second node. For example, the first node sends second information to the second node without receiving the third information sent by the third node. For example, the configuration of the first node itself is updated, which may involve token state update, at this time, the first node can send second information to the second node without receiving the third information sent by the third node. For example, the first node sends second information to the second node before detecting the token state that needs to be updated and receiving the first information sent by the second node.
[0240] In some embodiments, the second information is sent to the second node in case of a configuration update of the first node and in case the first token is issued earlier than the configuration update of the first node.
[0241] In some embodiments, S2102 is an optional step, for example, the second node initiatively sends the first information to the first node, then the second node does not need to request the second information from the second node through the second information.
[0242] In some embodiments, the first information is received from the second node before the third information is received from the third node, and the token state associated with the third information is determined according to the first information. In this case, the first node does not need to send the second information to the second node, i.e., the first node sending the second information to the second node is an optional operation.
[0243] In some embodiments, the second information includes at least one of:
[0244] First identification information for identifying the first node;
[0245] Second identification information for identifying the third node;
[0246] The second token;
[0247] Token information of the second token.
[0248] The second identification information can be an instance identity (ID) of the third node.
[0249] In some embodiments, as shown in FIG. 6A, the second information can be a message related to token revocation verification.
[0250] S2103: The second node sends the first information to the first node.
[0251] In some embodiments, the first information includes at least one of: first type information, current token state of the second token, the second token, or information of the second token. For example, the second information includes second identification information, and the first information can include first type information. For example, the second information includes the second token, and the first information can include the current token state of the second token, in which case the token state of the second token can be determined by the second node. For example, the second information includes a network function profile (NF profile) of the first node, and the first information can include second token information, which is information that can identify the second token (for example, the second token itself, a token identity in the second token, or declaration information in the second token).
[0252] In some embodiments, the first type information is used to indicate a first type, the first type being a node type of the third node.
[0253] In some embodiments, the first type information is used to indicate a first type, the first type being a network function type (NF type) of the third node.
[0254] In some embodiments, the first information further comprises second identification information, the second token and / or token information of the second token.
[0255] In some embodiments, the first information is used by the first node to obtain a token status of a first token. The first token is a token related to the first node, which is a general term of tokens that can be used by the first node when responding to a service request. The second token of the third node can belong to one of the first token.
[0256] In some embodiments, the first information is used by the first node to obtain a token status of a second token.
[0257] S2104: The first node updates the token status of the second token.
[0258] In some embodiments, the first node updates the token status of the second token according to the first information.
[0259] In some embodiments, the first node determines the second type according to a local policy. The local policy can be an operator policy pre-configured on the first node. In some embodiments, the second type is a node type allowed to request a service from the first node after a configuration update of the first node. The local policy of the first node can be a policy rule of the first node, for example. The local policy can be a valid policy currently stored by the first node.
[0260] In some embodiments, the second type is a network function type allowed to request a service from the first node after a configuration update of the first node.
[0261] In some embodiments, it is determined according to the local policy of the first node whether the first type is the second type; the status of the second token is updated according to whether the first type is the second type; after receiving the first information, the first node determines the status of the second token and / or whether to provide the service to the third node according to the first information and the second type.
[0262] In some embodiments, in the case where the first type is different from the second type, the token status of the second token is marked as a second status; the second status is a token status not allowed to request a service from the first node.
[0263] In some embodiments, the token state of the second token is marked as the first state in the case that the first type is the same as the second type.
[0264] S2105: The first node sends fourth information to the third node.
[0265] In some embodiments, the fourth information is related to responding to the request of the third node.
[0266] In some embodiments, the third information is used for the third node to request a service from the first node.
[0267] In some embodiments, the first node determines whether to respond to the service requested by the third node according to the token state of the second token after the update. Correspondingly, the fourth information can be response information of the service requested by the third node at this time.
[0268] In some embodiments, the third information is used to request the third node to request a service from the first node, and the token state of the second token is the first state, and the fourth information is used to indicate that the service request of the third node is accepted.
[0269] In other embodiments, the third information is used to request the third node to request a service from the first node, and the token state of the second token is the second state, and the fourth information is used to reject the service request of the third node. In this way, the service requested by the third node can be responded according to the latest token state, thereby reducing false responses.
[0270] In some embodiments, the fourth information rejecting the first service includes a failure cause; the failure cause is used to indicate that the token state of the second token is the second state.
[0271] By carrying the failure cause, the third node can be explicitly informed of the reason why the service request is rejected, thereby improving the service quality of the third node.
[0272] S2106: The first node sends fifth information to the second node.
[0273] In some embodiments, the first node itself completes the token state update and sends the fifth information to the second node. Illustratively, the fifth information is used to indicate that the first node has completed the token state update, or the fifth information is used to indicate that the first node has stored the updated token state.
[0274] In some embodiments, the first node sends the fourth information to the third node and sends the fifth information to the second node. The fifth information is used to indicate that the third node and the first node have completed the token state update, or the fifth information is used to indicate that the third node and the first node have stored the updated token state.
[0275] In some embodiments, the fifth information is used to indicate to the second node that the token state update is completed or the updated token state is stored.
[0276] In some embodiments, the first node completes the token state update and sends the fifth information to the second node.
[0277] In some embodiments, the fifth information can include an indicator indicating that the token state update is completed or the updated token state is stored.
[0278] In some embodiments, the fifth information can further include the token or token information that has completed the state update.
[0279] It is worth noting that S2106 can be an optional step, for example, the first node automatically completes the update after the first node and the second node receive the first information by default, and the fifth information does not need to be sent to the second node unless there is an exception.
[0280] It is worth noting that the steps in S2101 to S2106 can be implemented independently, or can be implemented in combination in a non-contradictory manner.
[0281] As shown in FIG. 2B, the embodiments of the present disclosure provide a token processing method processed by the communication system shown in FIG. 1A, which includes:
[0282] S2201: The first node sends second information to the second node.
[0283] In some embodiments, the first node, the second node, and the related description of the second information can refer to the corresponding embodiments of FIG. 2A.
[0284] In some embodiments, the first node has a configuration update, and the first node sends the second information to the second node.
[0285] In some embodiments, the first node detects that a service is disabled, and the first node sends the second information to the second node.
[0286] In some embodiments, the third node can include but is not limited to an NF service consumer.
[0287] In some embodiments, S2201 is an optional step, for example, the second node can also obtain information about whether the first node has a configuration update, service disablement (deactivation), etc. If the second node actively sends the first information to the first node, the second information can not be sent, that is, S2201 is an optional step.
[0288] In some embodiments, the second information sent to the second node in the case of configuration update of the first node includes at least one of the following:
[0289] first identification information, the first identification information being used to identify the first node;
[0290] second type information, the second type information being used to indicate a second type; the second type being a type of node that is allowed to request a service from the first node after a configuration update of the first node;
[0291] second service information, the second service information being used to indicate a second service or a second service operation; or, the second service information being used to indicate a third service or a third service operation; the second service being a service that is able to be provided by the first node after a configuration update of the first node; the second service operation being a service operation that is able to be provided by the first node after a configuration update of the first node; or, the third service being a service that is stopped to be provided by the first node after a configuration update of the first node; the third service operation being a service operation that is stopped to be provided by the first node after a configuration update of the first node. In some embodiments, the second information is used to cause the second node to perform information related to a token state of the first token.
[0292] In some instances, the second information can further include a configuration (e.g., a current configuration) of the first node. Illustratively, the second information can further include a configuration of the first node after an update. Illustratively, the second service information can be information determined according to a current configuration of the first node. In some embodiments, the configuration of the first node can include a local policy of the first node.
[0293] In some embodiments, the token state includes a first state and / or a second state.
[0294] In some embodiments, the first state includes at least one of: an active state, a valid state.
[0295] In some embodiments, the second state includes at least one of: an invalid state, a revoked state, a deactivated state.
[0296] S2202: The second node sends first information to the first node.
[0297] In some embodiments, the second node receives the second information sent by the second node, and the second node sends the first information to the first node.
[0298] In some embodiments, the second node detects that a configuration of the second node has an update, and the second node sends the first information to the first node.
[0299] In some embodiments, the second node detects that a configuration of the second node has an update and the configuration update results in a need to update a token state of at least one token, and the second node sends the first information to the first node.
[0300] In some embodiments, the second node receives the updated configuration of the first node, and determines the configuration update of the first node, and determines whether the token status of the first token associated with the first node needs to be updated according to the updated configuration of the first node.
[0301] In some embodiments, the second node determines the first token associated with the first node according to the updated configuration of the first node, determines the network function entity identifier (NF instance ID) of the network function service consumer according to the subject claim in the first token, determines the network function type (NF type) of the network function service consumer according to the network function entity identifier, and determines whether the first token needs to be revoked according to the updated configuration of the first node and the network function type of the network function service consumer.
[0302] In some embodiments, the first information is used by the first node to obtain the token status of the first token. The first token is a token associated with the first node, which is a general term of the token used by the first node in response to a service request. The second token of the third node can belong to one of the first tokens.
[0303] In some embodiments, the first information includes at least one of:
[0304] a third token, the third token belongs to the first token, and the token status of the third token needs to be updated to a second state;
[0305] token information of the third token, the token information of the third token including information of the first node, information of a fourth node, and third service information, the fourth node being a node holding the third token, the third service information being used for a fourth service or a fourth service operation, the fourth service being a service allowed to be requested by the fourth node from the first node when the token status of the third token is in a first state, and the fourth service operation being a service operation allowed to be requested by the fourth node from the first node when the token status of the third token is in the first state.
[0306] By way of example, the third token belongs to the first token, and the token status of the third token needs to be updated to a second state. The fourth node is a node holding the third token. The third service information is used for a fourth service or a fourth service operation, the fourth service being a service allowed to be requested by the fourth node from the first node when the token status of the third token is in a first state, and the fourth service operation being a service operation allowed to be requested by the fourth node from the first node when the token status of the third token is in the first state.
[0307] In some embodiments, the fourth node can be one or more. Illustratively, the fourth node can be a type of network function (NF) service consumer that stops serving after the first node is configured.
[0308] In some embodiments, the first information can further include a node identifier of the fourth node, and the information content of the first information is not limited to the above examples.
[0309] In some embodiments, the second information further includes at least one of the following: the first identification information, the second service information, or the configuration of the first node, and the second node provides the third token requiring a state update to the first node through the first information. Illustratively, the third token requiring a state update can be the third token itself or a token identifier in the third token or declaration information in the third token.
[0310] S2203: The first node updates the token state.
[0311] In some embodiments, the first information includes the third token, and the token state of the third token is marked as the second state.
[0312] In some embodiments, the first information includes token information of the third token, and the token state of the third token is marked as the second state based on the token information of the third token. For example, the token information of the third token is recorded, and the token state of the third token is recorded as the second state.
[0313] In some embodiments, the token information of the third token can further include a token identifier of the third token, and is not limited to the above examples of information.
[0314] S2204: The first node sends fifth information to the second node.
[0315] In some embodiments, the information content of the fifth information can refer to the corresponding embodiment S2106 of FIG. 2A. However, similarly, this step can be an optional step.
[0316] S2205: The second node sends sixth information to the fourth node.
[0317] In an embodiment, the sixth information is used to instruct the fourth node to update the token state of the third token, or the sixth information is used to instruct the fourth node to store the updated token state.
[0318] In this embodiment, the fourth node is triggered by the second node to update the token state of the third token.
[0319] In some examples, if the fourth node is a UE, the sixth information can be carried in a non-access stratum message.
[0320] In some embodiments, the sixth information comprises at least one of:
[0321] a node identity of the fourth node;
[0322] status information indicating an updated status of the third token;
[0323] token identity indicating the third token;
[0324] the third token;
[0325] token information of the third token.
[0326] Of course, the above is only a specific implementation of the sixth information, and different from the above examples in specific implementation.
[0327] It is worth noting that the execution order of S2204 and S2205 is not necessarily, S2204 can be executed first and then S2205 can be executed, or S2205 can be executed first and then S2204 can be executed, or S2204 and S2205 can be executed at the same time.
[0328] S2206: The third node sends seventh information to the second node.
[0329] In some embodiments, the third node receives the sixth information sent by the second node, and sends the seventh information to the second node.
[0330] In some embodiments, the token state of the third token is updated or the updated token state is stored, and the seventh information is sent to the second node, the seventh information indicating that the token state of the third node is updated or the updated token state is stored.
[0331] In some embodiments, the seventh information comprises at least one of:
[0332] a node identity of the fourth node;
[0333] status information indicating an updated status of the third token;
[0334] token identity indicating the third token;
[0335] the third token;
[0336] token information of the third token.
[0337] In some embodiments, S2206 is an optional step. The second node can determine that the first node has updated the token state of the third token by default, and then the fourth node requests the service with the token state before the update. Since the first node has updated the token state, the service request of the fourth node will be rejected. Therefore, S2206 is an optional step.
[0338] It is worth noting that the steps in S2201 to S2206 can be implemented independently, or can be implemented in combination or in a different order without contradiction.
[0339] As shown in FIG. 3A, the embodiments of the present disclosure provide a token processing method, which is executed by a first node. The method can include:
[0340] S3101: receiving third information.
[0341] In some embodiments, the first node receives the third information sent by a third node.
[0342] In some embodiments, the first node, the third node, and the third information can be described with reference to the corresponding embodiments of FIG. 2A.
[0343] It is worth noting that S3101 is an optional step. For example, the third node can not send the third information, or the token state of the first node is triggered by the first information of the second node.
[0344] S3102: sending second information.
[0345] In some embodiments, the first node sends the second information to a second node.
[0346] In some embodiments, the first node, the second node, and the second information can be described with reference to the corresponding embodiments of FIG. 2A.
[0347] In some embodiments, the optional implementation of S3102 can be described with reference to S2102 of the corresponding embodiments of FIG. 2A.
[0348] It is worth noting that S3102 is an optional step. For example, the first node can receive the first information from the second node without sending the second information. For example, the second node detects that the first node has a configuration update, determines that the token state needs to be updated, and then sends the first information to the first node and instructs the first node to update the corresponding token state.
[0349] In the embodiments of the present disclosure, the token state can be described with reference to the corresponding embodiments of FIG. 2A.
[0350] S3103: receiving first information.
[0351] In some embodiments, the first node receives the first information sent by the second node.
[0352] In some embodiments, the related description of the first information can refer to the corresponding embodiments of FIG. 2A.
[0353] S3104: updating the token state.
[0354] In some embodiments, the first node updating the token state can refer to S2104 of the corresponding embodiments of FIG. 2A.
[0355] S3105: sending the fourth information.
[0356] In some embodiments, the first node sends the fourth information to the third node.
[0357] In some embodiments, the related description of the information content and role of the fourth information can refer to the corresponding embodiments of FIG. 2A.
[0358] In some embodiments, the optional way of the first node sending the fourth information can refer to any one of the optional ways of S3105 of the corresponding embodiments of FIG. 2A.
[0359] S3106: sending the fifth information.
[0360] In some embodiments, the first node sends the fifth information to the second node.
[0361] In some embodiments, the related description of the information content and role of the fifth information can refer to the corresponding embodiments of FIG. 2A.
[0362] In some embodiments, the optional way of the first node sending the fifth information can refer to any one of the optional ways of S3106 of the corresponding embodiments of FIG. 2A.
[0363] It is worth noting that: in some embodiments, S3105 and S3106 are optional steps, for example, when the notification of the token state update of the third node is sent by the second node, the first node can not perform S3105. In some embodiments, the first node and the second node default that the first node receives the first information to update the token state, and there is no need to specially send the fifth information to indicate that the updated token state has been stored, etc. At this time, S3106 is an optional step. For another example, the first node responds to the service request of the first node according to the token state, in which case the first node can suppress the error response of the service request after the token state update of the first node is completed, and there is no need to specially indicate the token state update of the third node, so the step S3105 is also an optional step.
[0364] In some embodiments, S3105 and S3106 do not have a certain execution order, for example, S3106 is preferably executed after S3105, and the fifth information is sent to the second node after the first node and the third node are aware of the updated token state, so as to complete the flow. In some embodiments, since the token state update of the first node itself is the most important, S3106 can be executed after S3104.
[0365] As shown in FIG. 3B, the embodiment of the present disclosure provides a token processing method, which is executed by a first node, and the method can include:
[0366] S3201: sending second information.
[0367] In some embodiments, the first node sends the second information to the second node.
[0368] In some embodiments, the first node, the second node, and the related description of the second information can refer to the corresponding embodiments of FIG. 2B.
[0369] In some embodiments, the optional implementation of S3201 can refer to S2201 of the corresponding embodiments of FIG. 2B.
[0370] It is worth noting that: S3202 is an optional step, for example, the first node may receive the first information from the second node before sending the second information. For example, the second node detects that the first node has a configuration update, determines that the token needs to be updated, and then sends the first information to the first node and instructs the first node to update the corresponding token state.
[0371] In the embodiment of the present disclosure, the token state can refer to the related description of the corresponding embodiments of FIG. 2B.
[0372] S3202: receiving first information.
[0373] In some embodiments, the first node receives the first information sent by the second node.
[0374] In some embodiments, the related description of the first information can refer to the corresponding embodiments of FIG. 2B.
[0375] S3203: updating a token state.
[0376] In some embodiments, the first node updating the token state can refer to S2203 of the corresponding embodiments of FIG. 2B.
[0377] S3204: sending fifth information.
[0378] In some embodiments, the first node sends the fifth information to the second node.
[0379] In some embodiments, the information content of the fifth information, the description of the role, etc. can refer to the corresponding embodiments of FIG. 2B.
[0380] In some embodiments, the optional manner of the first node sending the fifth information can refer to any one of the optional manners of S2204 of the corresponding embodiments of FIG. 2B.
[0381] It is worth noting that in some embodiments, S3201 and S3204 are optional steps. In some embodiments, the second node detects that the first node has a configuration update, and actively sends the first information to the first node, so that the first node does not need to request the first information from the second node by sending the second information.
[0382] In some embodiments, S3204 is also an optional step. For example, the first node and the second node default that the first node receives the first information to update the state of the token, and therefore S3204 can be omitted.
[0383] As shown in FIG. 4A, the embodiments of the present disclosure provide a token processing method, which is executed by a second node, and the method comprises:
[0384] S4101: receiving second information.
[0385] In some embodiments, the second node receives the second information sent by the first node. Exemplarily, the second information is sent by the first node in the case of receiving the third information.
[0386] In some embodiments, the second node, the first node, and the related description of the second information can refer to the corresponding embodiments of FIG. 2A.
[0387] S4102: sending first information.
[0388] In some embodiments, the second node sends the first information to the first node.
[0389] In some embodiments, the second node receives the second information and sends the first information to the first node.
[0390] In some embodiments, the second node detects that the configuration of the first node has an update, and sends the first information to the first node.
[0391] In some embodiments, the second node detects that the configuration of the first node has an update, and sends the first information to the first node.
[0392] In some embodiments, the optional implementation of S4102 can refer to S2103 of the corresponding embodiments of FIG. 2A.
[0393] S4103: receiving fifth information.
[0394] In some embodiments, the second node receives the fifth information sent by the first node.
[0395] In some embodiments, the related description of the fifth information can be referred to Figure 2A. It is worth noting that this S4103 is an optional step, and the specific reason can be referred to the related part of the corresponding example of Figure 2A, which will not be repeated here.
[0396] As shown in Figure 4B, the embodiment of the disclosure provides a token processing method, which is executed by a second node, and the method comprises:
[0397] S4201: receiving second information.
[0398] In some embodiments, the second node receives the second information sent by the first node. Exemplarily, the second information is sent by the first node in the case of receiving the third information.
[0399] In some embodiments, the related description of the second node, the first node and the second information can be referred to the corresponding embodiment of Figure 2B.
[0400] S4202: sending first information.
[0401] In some embodiments, the second node sends the first information to the first node.
[0402] In some embodiments, the second node receives the second information and sends the first information to the first node.
[0403] In some embodiments, the second node detects that the configuration of the first node has an update, and sends the first information to the first node.
[0404] In some embodiments, the second node detects that the configuration of the first node has an update, and the configuration update causes the token state to need to be updated, and sends the first information to the first node.
[0405] In some embodiments, the optional implementation of S4202 can be referred to S2203 of the corresponding embodiment of Figure 2B.
[0406] S4203: receiving fifth information.
[0407] In some embodiments, the second node receives the fifth information sent by the first node.
[0408] In some embodiments, the related description of the fifth information can be referred to Figure 2B. It is worth noting that this S4203 is an optional step, and the specific reason can be referred to the related part of the corresponding example of Figure 2B, which will not be repeated here.
[0409] S4204: sending sixth information.
[0410] In some embodiments, the first node sends sixth information to the fourth node.
[0411] In some embodiments, optional implementation of S4204 can refer to any optional implementation of S2205 of the corresponding embodiment of FIG. 2B.
[0412] S4205: receiving seventh information.
[0413] In some embodiments, the first node receives seventh information sent by the third node.
[0414] In some embodiments, S4205 is an optional step. For example, the second node sends sixth information to the fourth node, which is equivalent to informing the fourth node of the update of the token state. By default, the fourth node receives the sixth information, and the fourth node does not need to send seventh information, and the second node also does not need to receive the seventh information.
[0415] As shown in FIG. 5A, the embodiment of the present disclosure provides a token processing method, which can be processed by the third node, comprising:
[0416] S5101: sending third information.
[0417] In some embodiments, the third node sends third information to the second node.
[0418] In some embodiments, optional implementation of the third node sending third information to the second node can refer to S2101 of the corresponding embodiment of FIG. 2A.
[0419] In some embodiments, the related description of the third information can refer to the corresponding part of the embodiment shown in FIG. 2A.
[0420] S5102: receiving fourth information.
[0421] In some embodiments, the third node receives fourth information sent by the first node.
[0422] In some embodiments, the related description of the fourth information can refer to the corresponding part of the embodiment shown in FIG. 2A.
[0423] In some embodiments, S5101 is an optional step. For example, after the first node receives the first message of the second node, the token state is updated, and then the first node actively sends fourth information to the third node. At this time, S5101 is an optional step.
[0424] In some embodiments, if the third node sends third information to the first node, the fourth information can be response information of the third information.
[0425] As shown in FIG. 5B, the embodiment of the present disclosure provides a token processing method, which can be processed by the fourth node, comprising:
[0426] S5201: receiving sixth information.
[0427] In some embodiments, the fourth node receives the sixth information sent by the second node.
[0428] In some embodiments, the fourth node, the second node and the related description of the sixth information can refer to the corresponding embodiments of FIG. 2B.
[0429] In some embodiments, the related description of the sixth information can refer to the corresponding part of the embodiments shown in FIG. 2B.
[0430] S5202: sending seventh information.
[0431] In some embodiments, the fourth node sends the seventh information to the second node.
[0432] In some embodiments, the related description of the seventh information can refer to the corresponding part of the embodiments shown in FIG. 2B.
[0433] As shown in FIG. 6A, the embodiments of the present disclosure provide a token processing method, which can include:
[0434] Step 0: The NF service consumer obtains a token for accessing the resource of the NF service producer from the NRF.
[0435] Step 1: If the NF service consumer is not notified of the token revocation information, the NF service consumer sends a service request to the NF service producer. The NF service consumer includes the revoked token in the service request. The token can include an issue AT (IAT) statement. The IAT statement can include a timestamp. The timestamp can be an integer indicating the time in Coordinated Universal Time (UTC). Exemplarily, the IAT can represent the time when the token is initially issued.
[0436] Step 2: After receiving the service request, the NF service producer verifies whether the consumer is revoked according to the local policy. Optionally, the NF service producer verifies whether the statement in the token conforms to its local policy. Further, the NF service producer needs to verify the consumer certificate or the NF type of the NRF obtaining the consumer. Exemplarily, the producer sends the NF instance ID of the consumer to the NRF to obtain the corresponding NF type, wherein the NF instance ID of the NF service consumer is obtained through the token. If the NF service producer does not authorize the service access of the NF service consumer according to the local policy, the token is regarded as a revoked token or an invalid token or an unactivated token.
[0437] In some embodiments, if the token contains an IAT statement, the NF service producer records the point in time when the NF profile was updated by the NRF. Upon receiving the service request and the token, if the IAT statement indicates that the token was issued before the NF profile was updated, the NF service producer triggers the token verification described above, otherwise the NF service producer will ignore the token verification.
[0438] Step 3: If the token is revoked, the NF service producer rejects the service request. The NF service producer sends a service response or failure message to the NF service consumer. The service response or failure message indicates that the token is revoked or the service request is rejected due to the token being revoked.
[0439] As shown in FIG. 6B, the embodiments of the present disclosure provide a token processing method, which can include:
[0440] 0. The NF service consumer obtains a token for accessing the NF service producer resource from the NRF.
[0441] 1. The NF service consumer sends a service request to the NF service producer. The NF service consumer includes the revoked token in the service request. The token can include a claim. The IAT statement is an integer timestamp in seconds since January 1, 1970, 00:00:00 UTC, indicating the time when the token was originally issued. In some embodiments, the NF service consumer includes the revoked token in the service request if the NF service consumer is not notified of the token revocation information.
[0442] 2. When the NF service producer receives the token, the token is sent to the NRF, which verifies whether the token is revoked according to the NF profile of the NF service producer. Illustratively, the NRF identifies the NF profile of the consumer using the NF instance ID of the consumer, and then obtains its NF type. If the profile of the NF service producer does not allow the NF type of the consumer to request the expected service (e.g., Nudm_UECM (UECM) service) or service operation (e.g., Nudm_UECM_Registration service operation) recorded in the token, the token is invalid.
[0443] In some embodiments, if the token contains an IAT statement, the NF service producer records the point in time when the NF profile was updated by the NRF. Upon receiving the service request and the token, if the IAT statement indicates that the token was issued before the NF profile was updated, the NF service producer triggers the token verification described above, otherwise the NF service producer will ignore the token verification.
[0444] 3. The NRF sends a response related to the token revocation verification to the NF service producer. The response indicates that the token is a revoked token or an invalid token or an unactivated token or an active token or a valid token.
[0445] 4. If the token is revoked or not activated or invalid, the NF service producer rejects the service request. The NF service producer sends a service response or failure message to the NF service consumer. The service response or failure message indicates that the token is revoked or invalid or not activated or the service request is rejected due to the token being revoked or invalid or not activated.
[0446] In some embodiments, the NFR performs operations can include at least one of:
[0447] The NFR should be able to receive authorization revocation information from the NF service producer or operator.
[0448] The NRF should be able to identify tokens that need to be revoked based on the authorization revocation information.
[0449] The NRF should be able to use the claims in the revoked tokens to identify the NF service consumer or producer.
[0450] The NRF should be able to use the NF instance ID of the consumer in the revoked token to identify the NF type of the consumer.
[0451] The NRF should be able to send information identifying the revoked tokens to the NF service consumer or producer.
[0452] The NRF should be able to receive confirmation information from the NF service consumer or producer that the tokens are revoked.
[0453] The NRF should be able to receive token revocation verification requests from the NF service producer.
[0454] The NRF should be able to send token revocation verification responses to the NF service producer. The response can indicate that the token is a revoked token or an invalid token or a not activated token or an active token or a valid token.
[0455] In some embodiments, the NF service producer performs operations can include at least one of:
[0456] The NF service producer should be able to send authorization revocation information to the NRF.
[0457] The NF service producer should be able to send authorization revocation information to the NRF through the NF profile update service.
[0458] The NF service producer should be able to send confirmation information to the NRF that the tokens are revoked.
[0459] The NF service producer should be able to receive information identifying the revoked tokens from the NRF.
[0460] The NF service producer should be able to reject service requests based on the information identifying the revoked tokens.
[0461] The NF service producer should be able to send a token revocation verification request to the NRF.
[0462] The NF service producer should be able to receive a token revocation verification response from the NRF. The response can indicate that the token is a revoked token or an invalid token or an unactivated token or an active token or a valid token.
[0463] The NF service producer should be able to record the time of NF profile update. After receiving the token, if the IAT declaration indicates that the token is issued before the NF profile update, the NF service producer verifies whether the token is revoked.
[0464] If the token is revoked, the NF service producer should be able to reject the service request.
[0465] The NF service producer should be able to send a service response or failure message to the NF service consumer. The service response or failure message indicates that the token is revoked or the service request is rejected due to the revoked token.
[0466] The NF service producer should be able to identify the NF type of the consumer using the NF instance ID of the consumer in the revoked token.
[0467] If the IAT declaration indicates that the token is issued before the NF profile update, the NF service producer should be able to trigger token verification. Otherwise, the NF service producer will ignore token verification.
[0468] In some embodiments, the NF service consumer performing operations can include at least one of the following:
[0469] The NF service consumer should be able to receive information that can identify the revoked token from the NRF.
[0470] The NF service consumer should be able to invalidate the revoked token according to the information that identifies the revoked token.
[0471] The NF service producer should be able to send confirmation information of the revoked token to the NRF.
[0472] The NF service consumer should be able to receive a service response or failure message from the NF service producer. The service response or failure message indicates that the token is revoked or the service request is rejected due to the revoked token.
[0473] In the embodiments of the present disclosure, part or all of the steps, and optional implementation manners thereof, can be combined with part or all of the steps in other embodiments, or can be combined with optional implementation manners of other embodiments.
[0474] In the embodiments of the present disclosure, part or all of the steps, and optional implementation manners thereof, can be combined with part or all of the steps in other embodiments, or combined with optional implementation manners of other embodiments.
[0475] The embodiments of the present disclosure further provide a device for implementing any of the above methods, for example, providing a device, the device comprising units or modules for implementing the steps performed by the UE in any of the above methods. For another example, another device is provided, comprising units or modules for implementing the steps performed by the network device (for example, an access network device, or a core network device, etc.) in any of the above methods.
[0476] It should be understood that the division of units or modules in the above device is only a logical functional division, and all or part of them can be integrated into one physical entity, or physically separated. In addition, the units or modules in the device can be implemented in the form of processor calling software: for example, the device includes a processor, the processor is connected with a memory, the memory stores instructions, and the processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of the units or modules of the device, wherein the processor is, for example, a general processor, such as a central processing unit (CPU) or a microprocessor, and the memory is a memory in the device or a memory outside the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuit, and the functions of part or all of the units or modules can be implemented by the design of hardware circuit, and the hardware circuit can be understood as one or more processors; for example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC), and the functions of part or all of the units or modules are implemented by the design of the logical relationship of elements in the circuit; for another example, in another implementation, the hardware circuit is a programmable logic device (PLD), and taking a field programmable gate array (FPGA) as an example, it can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by a configuration file, so as to implement the functions of part or all of the units or modules. All units or modules of the above device can be implemented in the form of processor calling software, or all units or modules can be implemented in the form of hardware circuit, or part of the units or modules can be implemented in the form of processor calling software, and the remaining part can be implemented in the form of hardware circuit.
[0477] In the embodiments of the present disclosure, the processor is a circuit with signal processing capability. In one implementation, the processor can be a circuit with instruction reading and running capability, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), a digital signal processor (DSP), and the like. In another implementation, the processor can implement certain functions through a logical relationship of a hardware circuit, and the logical relationship of the hardware circuit is fixed or reconfigurable. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In the reconfigurable hardware circuit, the processor loads a configuration document to implement the hardware circuit configuration. It can be understood that the processor loads an instruction to implement the functions of the above part or all units or modules. In addition, the hardware circuit can also be designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), and the like.
[0478] As shown in FIG. 7A, the embodiments of the present disclosure provide a first node, wherein the first node comprises:
[0479] The receiving module 7101 is configured to receive first information sent by a second node, the first information being used for the first node to obtain a token state of a first token.
[0480] In some embodiments, the first node further comprises a processing module and / or a sending module. For example, the sending module and / or the receiving module can correspond to a network interface and / or a transceiving antenna of the first network function.
[0481] In some embodiments, the first network function further comprises a processing module.
[0482] In some embodiments, the processing module can be used for the first node to perform steps related to information processing in any one of the token processing methods.
[0483] In some embodiments, the sending module can be configured to perform the steps related to information sending in any one of the token processing methods by the first node.
[0484] In some embodiments, the receiving module can be configured to perform the steps related to information sending in any one of the token processing methods by the first node.
[0485] In some embodiments, before receiving the first information sent by the second node, the sending module is configured to send second information to the second node, the second information being used to make the second node perform an operation related to the token state of the first token.
[0486] In some embodiments, the sending module is configured to receive third information sent by a third node, and send the second information to the second node; the third information is used for the second node to request a service from the first node based on a second token; or the third information is used to obtain the token state of the second token; the second token belongs to the first token.
[0487] In some embodiments, the sending module is further configured to receive third information sent by the third node and the issuance time of the second token is earlier than the configuration update time of the first node, and send the second information to the second node.
[0488] In some embodiments, the third information includes at least one of:
[0489] the second token;
[0490] token information of the second token; the token information of the second token includes information of the third node, information of the first node, and first service information, the first service information being used to indicate a first service or a first service operation; the first service is a service that the third node is allowed to request from the first node when the token state of the second token is a first state; the first service operation is a service operation that the third node is allowed to request from the first node when the token state of the second token is a first state.
[0491] In some embodiments, the second information sent to the second node when receiving the third information sent by the third node includes at least one of:
[0492] first identification information, used to identify the first node;
[0493] second identification information, used to identify the third node;
[0494] the second token;
[0495] token information of the second token.
[0496] In some embodiments, the first information comprises first type information; the first type information is used to indicate a first type, the first type being a node type of the third node.
[0497] In some embodiments, the determining module is configured to determine, according to a local policy of the first node, whether the first type is a second type; update a state of the second token according to whether the first type is the second type; the second type being a node type allowed to request services from the first node after a configuration update of the first node.
[0498] In some embodiments, the processing module is configured to perform at least one of the following:
[0499] determine the first type according to a local policy of the first node;
[0500] in a case where the first type is different from the second type, mark a token state of the second token as a second state; the second state being a token state not allowing to request services from the first node;
[0501] in a case where the first type is the same as the second type, mark the token state of the second token as a first state.
[0502] In some embodiments, the sending module is configured to send fourth information to the third node, the fourth information being related to the third information.
[0503] In some embodiments, the third information is used to request the third node to request services from the first node and the token state of the second token is the first state, the fourth information being used to indicate acceptance of the service request of the third node; or,
[0504] the third information is used to request the third node to request services from the first node and the token state of the second token is the second state, the fourth information being used to reject the service request of the third node.
[0505] In some embodiments, the fourth information is used to reject the service request of the third node, the fourth information further comprising a failure cause; the failure cause being used to indicate that the token state of the second token is the second state.
[0506] In some embodiments, the sending module is configured to send the second information to the second node in a case where a configuration of the first node is updated.
[0507] In some embodiments, the second information sent to the second node in case of the configuration update of the first node comprises at least one of:
[0508] first identification information, the first identification information being used to identify the first node;
[0509] second type information, the second type information being used to indicate a second type; the second type being a type of node allowed to request services from the first node after the configuration update of the first node;
[0510] second service information, the second service information being used to indicate a second service or a second service operation; or, the second service information being used to indicate a third service or a third service operation; the second service being a service able to be provided by the first node after the configuration update of the first node; the second service operation being a service operation able to be provided by the first node after the configuration update of the first node; or, the third service being a service stopped to be provided by the first node after the configuration update of the first node; the third service operation being a service operation stopped to be provided by the first node after the configuration update of the first node.
[0511] In some embodiments, the first information comprises at least one of:
[0512] a third token; the third token belonging to the first token; a token state of the third token being to be updated to a second state;
[0513] token information of the third token, the token information of the third token comprising: information of the first node, information of a fourth node, and third service information; the fourth node being a node holding the third token, the third service information being used for a fourth service or a fourth service operation, the fourth service being a service allowed to be requested by the fourth node from the first node in case that a token state of the third token is a first state; the fourth service operation being a service operation allowed to be requested by the fourth node from the first node in case that the token state of the third token is the first state.
[0514] In some embodiments, the processing module is configured to, in case that the first information comprises the third token, mark the token state of the third token as the second state; or, in case that the first information comprises the token information of the third token, mark the token state of the third token as the second state.
[0515] In some embodiments, the sending module is configured to, in case of the configuration update of the first node and in case that an issuing time of the first token is earlier than a time of the configuration update of the first node, send the second information to the second node.
[0516] In some embodiments, the sending module is configured to send fifth information to the second node; the fifth information is used to indicate that the token state of the first token has been updated; or the token state of the first token after being updated has been stored.
[0517] In some embodiments, the first state comprises at least one of the following: an active state, a valid state.
[0518] In some embodiments, the second state comprises at least one of the following: an invalid state, a revoked state, a deactivated state.
[0519] In some embodiments, the first node is a network function service producer; and / or, the third node is a network function service consumer.
[0520] As shown in FIG. 7B, the embodiments of the present disclosure provide a second node, wherein the second node comprises:
[0521] The sending module 7201 is configured to send third information to the first node; the third information is used to enable the first node to perform token state related operations.
[0522] In some embodiments, the second node comprises a receiving module and a processing module. For example, the sending module and / or the receiving module can correspond to the network interface and / or the transceiver antenna of the second network function.
[0523] In some embodiments, the second node can comprise a processing module.
[0524] In some embodiments, the processing module can be used by the second node to perform information processing related steps in any one of the token processing methods.
[0525] In some embodiments, the sending module can be used by the second node to perform information sending related steps in any one of the token processing methods.
[0526] In some embodiments, the receiving module can be used by the second node to perform information sending related steps in any one of the token processing methods.
[0527] In some embodiments, the sending module is configured to perform at least one of the following: in the case where the configuration update of the first node is detected, sending the first information to the second node;
[0528] In the case where the second information sent by the second node is received, sending the first information to the second node.
[0529] In some embodiments, the second information comprises at least one of the following:
[0530] First identification information, used to identify the first node;
[0531] second identification information, the second identification information being used for identifying the third node;
[0532] a second token, the second token being a token held by the third node;
[0533] token information of the second token, the token information of the second token comprising information of the third node, information of the first node, and second service information, the second service information being used for indicating services or service operations allowed to be requested from the first node by the third node based on a case that a token state of the second token is a first state.
[0534] In some embodiments, in a case that the second information is received, the first information comprises first type information; the first type information is used for indicating a first type, the first type being a node type of the third node.
[0535] In some embodiments, before the first information is sent to the first node, the processing module is specifically configured to determine a configuration of the third node according to the second token; or determine a type of the third node according to the configuration of the third node.
[0536] In some embodiments, in a case that the configuration of the first node is updated, the second information comprises at least one of:
[0537] first identification information, the first identification information being used for identifying the first node;
[0538] second type information, the second type information being used for indicating a second type; the second type being a node type allowed to request services from the first node after the configuration of the first node is updated;
[0539] first service information, the first service information being used for indicating services or service operations capable of being provided by the first node after the configuration of the first node is updated; or the first service information being used for indicating services or service operations stopped to be provided by the first node after the configuration of the first node is updated.
[0540] In some embodiments, in a case that the configuration of the first node is updated, the first information comprises at least one of:
[0541] a third token, the third token belonging to the first token, and a token state of the third token being to be updated to a second state;
[0542] Token information of a third token, the token information of the third token comprising: information of the first node, information of a fourth node, and third service information; the fourth node being a node holding the third token, and the third service information being used to indicate a service or a service operation allowed to be requested by the fourth node from the first node in a case where a token state of the third token is a first state.
[0543] In some embodiments, the sending module is further configured to send sixth information to a fourth node; the fourth node being a node whose token state needs to be updated to a second state, and the sixth information being used to instruct the fourth node to update the token state of the third token, or the sixth information being used to instruct the fourth node to store the updated token state.
[0544] In some embodiments, the apparatus further comprises:
[0545] The receiving module is configured to receive seventh information sent by the fourth node, the seventh information being used to indicate that the token state of the third token has been updated, and the seventh information being used to indicate that the fourth node has stored the token state of the third token.
[0546] In some embodiments, the processing module is further configured to, before sending the first information to the first node, determine a third type according to an updated configuration of the first node, the third type being a node type of the fourth node; the fourth node being a node that is not allowed to request a service from the first node after the configuration of the first node is updated; determine third identification information according to the first token of the first node; the third identification information being used to indicate a fifth node holding the first token; determine third type information according to the third identification information; the third type information being used to indicate a fourth type of the fifth node; the fourth type being the third type, and determining that the fifth node is the fourth node; and the fourth type not being the third type, and determining that the fifth node is not the fourth node.
[0547] In some embodiments, the receiving module is further configured to receive fifth information sent by the first node; the fifth information being used to indicate that the token state of the first token has been updated; or the updated token state of the first token has been stored.
[0548] As shown in FIG. 7C, the embodiments of the present disclosure provide a third node, wherein the third node comprises:
[0549] The sending module 7301 is configured to send third information to a first node; the third information being used to enable the first node to perform a token state related operation.
[0550] In some embodiments, the third node further comprises a sending module and / or a processing module.
[0551] In some embodiments, the sending module and / or the receiving module can correspond to a network interface and / or a transceiver antenna of the third node.
[0552] In some embodiments, the processing module can be configured to perform information processing related steps in any one of the token processing methods.
[0553] In some embodiments, the sending module can be configured to perform information sending related steps in any one of the token processing methods.
[0554] In some embodiments, the receiving module can be configured to perform information sending related steps in any one of the token processing methods.
[0555] In some embodiments, the third information comprises second identification information; and the third information further comprises at least one of the following: a second token; and token information of the second token.
[0556] The second identification information is used to identify the third node.
[0557] The token information of the second token comprises information of the third node, information of the first node, and second service information, the second service information is used for a third service or a third service operation, the third service is a service that the third node is allowed to request from the first node in a case where a token state of the second token is a first state; and the third service operation is a service operation that the third node is allowed to request from the first node in a case where the token state of the second token is the first state.
[0558] In some embodiments, the receiving module is further configured to receive fourth information sent by the first node; and the fourth information is related to the third information.
[0559] In some embodiments, the third information is used to request the third node to request a service from the first node and the token state of the second token is the first state, and the fourth information is used to indicate acceptance of the service request of the third node; or
[0560] The third information is used to request the third node to request a service from the first node and the token state of the second token is the second state, and the fourth information is used to reject the service request of the third node.
[0561] In some embodiments, the fourth information is used to reject the service request of the third node, and the fourth information further comprises a failure cause; and the failure cause is used to indicate that the token state of the second token is the second state.
[0562] In some embodiments, the processing module is configured to mark the token state of the second token as the second state according to the fourth information; and the third node does not allow the first node to request a service in a case where the token state of the second token is the second state.
[0563] As shown in FIG. 7D, the embodiments of the present disclosure provide a fourth node, wherein the fourth node comprises:
[0564] The receiving module 7401 is configured to receive sixth information sent by a second node; the sixth information is used to instruct the fourth node to update a token state of a third token, or the sixth information is used to instruct the fourth node to store the updated token state.
[0565] In some embodiments, the third node further comprises a sending module and / or a processing module.
[0566] In some embodiments, the sending module and / or the receiving module of the third node can correspond to a network interface and / or a transceiving antenna of the third node.
[0567] In some embodiments, the processing module can be used by the third node to perform steps related to information processing in any one of the token processing methods.
[0568] In some embodiments, the sending module can be used by the third node to perform steps related to information sending in any one of the token processing methods.
[0569] In some embodiments, the receiving module can be used by the third node to perform steps related to information sending in any one of the token processing methods.
[0570] In some embodiments, the sending module is further configured to send seventh information to the second node, the seventh information is used to instruct that the token state of the third token has been updated, and the seventh information is used to instruct that the fourth node has stored the token state of the third token.
[0571] The embodiments of the present disclosure also provide a communication device, which can comprise: one or more processors; wherein the processor is used to invoke instructions to enable the communication device to perform the token processing method implemented by any one of the preceding embodiments.
[0572] In some embodiments, as shown in FIG. 8A and / or FIG. 8B, the communication device 8100 further comprises one or more memories 8102 for storing instructions. Optionally, all or part of the memory 8102 can also be outside the communication device 8100.
[0573] The communication device can be the aforementioned UE and network device. In some embodiments, the network device can be a master node and / or a secondary node.
[0574] In some embodiments, the communication device 8100 further includes one or more transceivers 8103. When the communication device 8100 includes one or more transceivers 8103, the communication steps in the above method are performed by the transceiver 8103, and other steps are performed by the processor 8101.
[0575] In some embodiments, the transceiver can include a receiver and a transmitter, which can be separate or integrated together. Optionally, the terms transceiver, transceiving unit, transceiver, transceiving circuit, etc. can be replaced by each other, the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc. can be replaced by each other, and the terms receiver, receiving unit, receiver, receiving circuit, etc. can be replaced by each other.
[0576] Optionally, the communication device 8100 further includes one or more interface circuits 8104 connected with the memory 8102, which can be used to receive signals from the memory 8102 or other devices, and can be used to send signals to the memory 8102 or other devices. For example, the interface circuit 8104 can read the instructions stored in the memory 8102 and send the instructions to the processor 8101.
[0577] The communication device 8100 described in the above embodiments can be a network device or a UE, but the scope of the communication device 8100 described in the present disclosure is not limited to this, and the structure of the communication device 8100 can not be limited to that of FIG. 8A. The communication device can be a standalone device or can be part of a larger device. For example, the communication device can be: (1) a standalone integrated circuit (IC), or a chip, or a chip system or subsystem; (2) a set of one or more ICs, which can optionally also include storage components for storing data, programs; (3) an ASIC, such as a Modem; (4) a module that can be embedded in other devices; (5) a receiver, UE device, smart UE device, cellular phone, wireless device, handset, mobile unit, car-mounted device, network device, cloud device, artificial intelligence device, etc.; (6) other, etc.
[0578] FIG. 8B is a structural schematic diagram of a chip 8200 according to an embodiment of the present disclosure. For the case where the communication device 8100 can be a chip or a chip system, the structural schematic diagram of the chip 8200 shown in FIG. 8B can be referred to, but is not limited thereto.
[0579] The chip 8200 comprises one or more processors 8201 configured to invoke instructions to cause the chip 8200 to perform any of the above token processing methods.
[0580] In some embodiments, the chip 8200 further comprises one or more interface circuits 8202 connected with the memory 8203, which can be configured to receive signals from the memory 8203 or other devices, and can be configured to send signals to the memory 8203 or other devices. For example, the interface circuit 8202 can read instructions stored in the memory 8203 and send the instructions to the processor 8201. Alternatively, the terms interface circuit, interface, transceiver pin, transceiver, etc. can be replaced by each other.
[0581] In some embodiments, the chip 8200 further comprises one or more memories 8203 configured to store instructions. Alternatively, all or part of the memory 8203 can be outside the chip 8200.
[0582] The present disclosure also provides a storage medium having instructions stored thereon, which, when executed on the communication device 8100, cause the communication device 8100 to perform any of the above methods. Alternatively, the storage medium is an electronic storage medium. Alternatively, the storage medium is a computer readable storage medium, but can also be a storage medium readable by other devices. Alternatively, the storage medium can be a non-transitory storage medium, but can also be a transitory storage medium.
[0583] The present disclosure also provides a program product, which, when executed by the communication device 8100, causes the communication device 8100 to perform any of the above token processing methods. Alternatively, the program product is a computer program product.
[0584] The present disclosure also provides a computer program, which, when executed on a computer, causes the computer to perform any of the above token processing methods.
[0585] Other embodiments of the present disclosure will be apparent to those skilled in the art from consideration of the specification and practice of the features disclosed herein. The present disclosure is intended to cover any variations, uses, or adaptations of the present disclosure embodiments following, in general, the principles of the present disclosure and including such features to the present disclosure as come within the true spirit and scope of the present disclosure. The specification and examples are to be regarded as illustrative only, and the true scope and spirit of the present disclosure are indicated by the following claims.
[0586] It should be understood that the embodiments of the present disclosure are not limited to the precise construction that has been described above and shown in the accompanying drawings and that various modifications and changes can be made without departing from the scope thereof. The scope of the present disclosure is limited only by the appended claims.
Claims
1. A token processing method, wherein, The method is performed by a first node, and comprises: receiving first information sent by a second node, the first information being used for the first node to obtain a token state of a first token.
2. The method of claim 1, wherein, Before the receiving the first information sent by the second node, the method further comprises: sending second information to the second node, the second information being used for the second node to perform an operation related to the token state of the first token.
3. The method of claim 2, wherein, The sending the second information to the second node comprises: receiving third information sent by a third node, the sending the second information to the second node; the third information being used for the second node to request a service from the first node based on a second token; or the third information being used for obtaining a token state of the second token; the second token belonging to the first token.
4. The method of claim 3, wherein, The receiving the third information sent by the third node and the sending the second information to the second node comprises: receiving the third information sent by the third node and the second token being issued earlier than a configuration update time of the first node, and sending the second information to the second node.
5. The method of claim 3 or 4, wherein, The third information comprises at least one of: the second token; token information of the second token; the token information of the second token comprising information of the third node, information of the first node, and first service information, the first service information being used for indicating a first service or a first service operation; the first service being a service that the third node is allowed to request from the first node in a case that the token state of the second token is a first state; the first service operation being a service operation that the third node is allowed to request from the first node in a case that the token state of the second token is the first state.
6. The method according to any one of claims 3 to 5, wherein, The second information sent to the second node upon receiving the third information sent by the third node comprises at least one of: first identification information, used for identifying the first node; second identification information, used for identifying the third node; the second token; token information of the second token.
7. The method of claim 6, wherein, The first information comprises first type information; the first type information being used for indicating a first type, the first type being a node type of the third node.
8. The method of claim 7, wherein, The method further comprises: updating a state of the second token according to whether the first type is a second type; the second type being a node type that is allowed to request a service from the first node after a configuration update of the first node.
9. The method of claim 8, wherein, The method further comprises: determining the second type according to a local policy of the first node. The updating the state of the second token according to whether the first type is the second type comprises: in a case that the first type is different from the second type, marking a token state of the second token as a second state; the second state being a token state that does not allow a service to be requested from the first node; in a case that the first type is the same as the second type, marking the token state of the second token as a first state.
10. The method according to any one of claims 3 to 9, wherein, The method further comprises: sending fourth information to the third node, the fourth information being related to the third information.
11. The method of claim 10, wherein, The third information is used for requesting the third node to request a service from the first node, and a token state of the second token is a first state, and the fourth information is used for indicating acceptance of the service request of the third node; or The third information is used for requesting the third node to request a service from the first node, and a token state of the second token is a second state, and the fourth information is used for rejecting the service request of the third node.
12. The method of claim 11, wherein, The fourth information is used for rejecting the service request of the third node, and the fourth information further comprises a failure cause; and the failure cause is used for indicating that the token state of the second token is the second state.
13. The method of claim 2, wherein, The sending of the second information to the second node comprises: In a case of configuration update of the first node, the second information is sent to the second node.
14. The method of claim 13, wherein, The second information sent to the second node in the case of configuration update of the first node comprises at least one of the following: First identification information, the first identification information being used for identifying the first node; Second type information, the second type information being used for indicating a second type; the second type being a type of node allowed to request a service from the first node after configuration update of the first node; Second service information, the second service information being used for indicating a second service or a second service operation; Or, the second service information is used for indicating a third service or a third service operation; the second service being a service capable of being provided by the first node after configuration update of the first node; The second service operation being a service operation capable of being provided by the first node after configuration update of the first node; Or, the third service being a service stopped from being provided by the first node after configuration update of the first node; The third service operation being a service operation stopped from being provided by the first node after configuration update of the first node.
15. The method of claim 10 or 11, wherein, In the case of configuration update of the first node, the first information comprises at least one of the following: A third token; The third token belongs to the first token; A token state of the third token is to be updated to a second state; Token information of the third token, the token information of the third token comprising: information of the first node, information of a fourth node, and third service information; the fourth node being a node holding the third token, and the third service information being used for a fourth service or a fourth service operation; the fourth service being a service allowed to be requested by the fourth node from the first node in a case that a token state of the third token is a first state; and the fourth service operation being a service operation allowed to be requested by the fourth node from the first node in the case that the token state of the third token is the first state.
16. The method of claim 15, wherein, The method further comprises: The first information comprises the third token, and a token state of the third token is marked as the second state; or The first information comprises token information of the third token, and a token state of the third token is identified as the second state.
17. The method of any one of claims 1 to 16, wherein, The method further comprises: Fifth information is sent to the second node; the fifth information is used for indicating that a token state of the first token has been updated; or a token state of the first token after update has been stored.
18. The method of claim 5, 7, 9, or 15, wherein, The first state includes at least one of the following: an active state, a valid state.
19. The method of any one of claims 8, 9, 10, 15-17, wherein, The second state includes at least one of the following: an invalid state, a revoked state, a deactivated state.
20. A token processing method, wherein, The method is performed by the second node, and the method includes: sending first information to the first node, the first information being used by the first node to obtain a token state of a first token.
21. The method of claim 20, wherein, The sending of the first information to the first node includes: sending the first information to the second node in a case where a configuration update of the first node is detected; sending the first information to the second node in a case where the second node sends second information.
22. The method of claim 21, wherein, The second information includes at least one of the following: first identification information used to identify the first node; second identification information used to identify a third node; a second token; the second token being a token held by the third node; token information of the second token; The token information of the second token includes information of the third node, information of the first node, and second service information, the second service information being used to indicate services or service operations allowed to be requested from the first node by the third node based on a case where a token state of the second token is a first state.
23. The method of claim 22, wherein, In a case where the second information is received, the first information includes first type information; the first type information being used to indicate a first type, the first type being a node type of the third node.
24. The method of claim 22, wherein, Before the sending of the first information to the first node, the method further includes: determining a configuration of the third node according to the second token; determining a type of the third node according to the configuration of the third node.
25. The method of claim 21, wherein, In a case where a configuration of the first node is updated, the second information includes at least one of the following: first identification information used to identify the first node; second type information used to indicate a second type; the second type being a node type allowed to request services from the first node after the configuration update of the first node; first service information used to indicate services or service operations capable of being provided by the first node after the configuration update of the first node; or, the first service information being used to indicate services or service operations stopped from being provided by the first node after the configuration update of the first node.
26. The method of claim 21 or 24, wherein, In a case where a configuration of the first node is updated, the first information includes at least one of the following: a third token; the third token belonging to the first token; a token state of the third token being to be updated to a second state; token information of the third token, the token information of the third token including information of the first node, information of a fourth node, and third service information; the fourth node being a node holding the third token, the third service information being used to indicate services or service operations allowed to be requested from the first node by the fourth node based on a case where a token state of the third token is a first state.
27. The method of claim 25, wherein, The method further includes: sending sixth information to a fourth node; the fourth node is a node whose token state needs to be updated to a second state, and the sixth information is used to instruct the fourth node to update the token state of the third token, or the sixth information is used to instruct the fourth node to store the updated token state.
28. The method of claim 24 or 27, wherein, The method further comprises: receiving seventh information sent by the fourth node, the seventh information being used to indicate that the token state of the third token has been updated, and the seventh information being used to indicate that the fourth node has stored the token state of the third token.
29. The method of claim 26, wherein, Before sending the first information to the first node, the method further comprises: determining a third type according to the updated configuration of the first node, the third type being a node type of the fourth node; the fourth node being a node that is not allowed to request services from the first node after the configuration of the first node is updated; determining third identification information according to the first token of the first node; the third identification information being used to indicate a fifth node holding the first token; determining third type information according to the third identification information; the third type information being used to indicate a fourth type of the fifth node; if the fourth type is the third type, determining that the fifth node is the fourth node; if the fourth type is not the third type, determining that the fifth node is not the fourth node.
30. The method of any one of claims 20 to 29, wherein, The method further comprises: receiving fifth information sent by the first node; the fifth information being used to indicate that the token state of the first token has been updated; or the updated token state of the first token has been stored.
31. A token processing method, wherein, The method is performed by a third node, and the method comprises: sending third information to a first node; the third information being used to enable the first node to perform a token state related operation.
32. The method of claim 31, wherein, The third information comprises second identification information; and the third information further comprises at least one of the following: a second token; token information of the second token; The second identification information is used to identify the third node; The token information of the second token comprises information of the third node, information of the first node, and second service information, the second service information being used for a third service or a third service operation, the third service being a service that the third node is allowed to request from the first node in a case where a token state of the second token is a first state; and the third service operation being a service operation that the third node is allowed to request from the first node in a case where the token state of the second token is the first state.
33. The method of claim 31 or 32, wherein, The method further comprises: receiving fourth information sent by the first node; the fourth information being related to the third information.
34. The method of claim 33, wherein, The third information is used to request the third node to request a service from the first node and the token state of the second token is the first state, and the fourth information is used to indicate acceptance of the service request of the third node; or The third information is used to request the third node to request a service from the first node and the token state of the second token is the second state, and the fourth information is used to reject the service request of the third node.
35. The method of claim 34, wherein, The fourth information is used to reject the service request of the third node, and the fourth information further includes a failure cause; the failure cause is used to indicate that the token state of the second token is the second state.
36. The method of claim 35, wherein, The method further includes: marking the token state of the second token as the second state according to the fourth information; and in a case where the token state of the second token is the second state, the third node is not allowed to request a service from the first node.
37. A token processing method, wherein, The method is processed by a fourth node, and the method includes: receiving sixth information sent by a second node; the sixth information is used to instruct the fourth node to update a token state of a third token, or the sixth information is used to instruct the fourth node to store the updated token state.
38. The method of claim 37, wherein, The method further includes: sending seventh information to the second node, the seventh information being used to indicate that the token state of the third token has been updated, and the seventh information being used to indicate that the fourth node has stored the token state of the third token.
39. A first node, wherein, The first node includes: a receiving module configured to receive first information sent by a second node, the first information being used for the first node to acquire a token state of a first token.
40. A second node, wherein, The second node includes: a sending module configured to send first information to a first node, the first information being used for the first node to acquire a token state of a first token.
41. A third node, wherein, The third node includes: a receiving module configured to send third information to a first node; the third information is used to enable the first node to perform a token state related operation.
42. A fourth node, wherein, The fourth node includes: a sending module configured to receive sixth information sent by a second node; the sixth information is used to instruct the fourth node to update a token state of a third token, or the sixth information is used to instruct the fourth node to store the updated token state.
43. A communication system, wherein, The communication system includes a first node, a second node, a third node, and a fourth node; The first node network function is used to perform the method in any one of claims 1 to 19; The second node is used to perform the method in any one of claims 20 to 30; The third node is used to perform the token processing method in any one of claims 31 to 36; The fourth node is used to perform claim 37 or 38.
44. A communications device, comprising: The communication device includes: one or more processors; The processor is used to call instructions to enable the communication device to perform the token processing method in any one of claims 1 to 19, 20 to 30, 31 to 36, 37, or 38.
45. A storage medium, wherein, The storage medium stores instructions, when the instructions run on the communication device, enable the communication device to perform the token processing method in any one of claims 1 to 19, 20 to 30, 31 to 36, 37, or 38.
Citation Information
Patent Citations
Servitization architecture authorization method
CN112822678A
Service acquisition method, information transmission method, device and network function network element
CN117528522A
Token management
EP3886390A1
Method for token-based authorization for indirect communication between network functions
US20230137034A1
Method for robust token generation in 5g mobile core network
US20240031347A1